NTNU Applied Cryptology Lab (NaCl)

Welcome to the unofficial page of the NTNU Applied Cryptology Lab (NaCl), a cryptography group at NTNU with members at the Department of Information Security and Communication Technology and the Department of Mathematical Sciences, in Trondheim and Gjøvik. The official group page only lists current members, so this page aims to list everyone who is or has been part of the group. If you find an omission or a mistake, please send me an email.

Last updated: September 2026.

The NTNU Applied Cryptology Lab in 2024

Faculty

NamePositionFromTo
Jeongeun ParkAssociate Professor2024 
Tjerand SildeAssociate Professor2022 
Staal A. VinterboProfessor2017 
Danilo GligoroskiProfessor2008 
Kristian GjøsteenProfessor2008 
Slobodan PetrovicProfessor2004 
Stig Frode MjølsnesProfessor1999 
Bor de KockAssistant Professor20222024
Anamaria CostacheAssociate Professor20202025
Jiaxin PanAssociate Professor20192025
Colin BoydProfessor20132025
Jan Arild AudestadAdjunct Professor19932012
Svein J. KnapskogProfessor19872013

Years include positions at the Norwegian Institute of Technology (NTH), which became part of NTNU in 1996, and at Gjøvik University College, which merged with NTNU in 2016.

Postdocs and researchers

NamePositionFromTo
Kamil Doruk GurPostdoctoral Fellow2026 
Mattia VeroniPostdoctoral Fellow2023 
Hans HeumPostdoctoral Fellow20232026
Dan ZhangPostdoctoral Fellow and Researcher20222026
Yao Jiang GaltelandResearcher20212023
Chen QianPostdoctoral Fellow20192022
Thomas HainesPostdoctoral Fellow20192021
Christopher CarrPostdoctoral Fellow20182020
Clémentine GrittiPostdoctoral Fellow20182020
Gareth T. DaviesPostdoctoral Fellow20162018
Ruxandra F. OlimidPostdoctoral Fellow20162022
Markku-Juhani O. SaarinenPostdoctoral Fellow20142015
Joe-Kai TsayPostdoctoral Fellow20112013
Danilo GligoroskiPostdoctoral Fellow20052008
Kristian GjøsteenPostdoctoral Fellow20042008

PhD candidates

This list includes PhD candidates and graduates in cryptography and information security from IIK and the Department of Mathematical Sciences, with their main supervisor.

NameFromToThesisSupervisor
Einar Karlsen Thesen2026  Kristian Gjøsteen
Pedro Pablo Cardona Arroyave2026  Jeongeun Park
Reem Salman2026  Staal A. Vinterbo
Espen Sund2025  Staal A. Vinterbo
Charlotte Ida Pauline Mylog2023  Kristian Gjøsteen
Caroline Sandsbråten2022  Tjerand Silde
Emil August Hovd Olaisen2022  Tjerand Silde
Ole Martin Edstrøm2022  Kristian Gjøsteen
Oskar Goldhahn2021  Kristian Gjøsteen
Sahana Sridhar2021  Danilo Gligoroski
Sonu Kumar Jha2019  Danilo Gligoroski
Amir Zarei 2025Differential Privacy in Secure Multiparty Computation and Deep Neural NetworksStaal A. Vinterbo
Enio Marku 2025SafeLib: Secure and High-Performance Outsourcing of Network Functions Made EasyColin Boyd
Lea Nürnberger 2025Analysis and Optimisation of Fully Homomorphic EncryptionAnamaria Costache
Lise Millerjord 2025Key Exchange in a Post Quantum WorldColin Boyd
Jonathan Komada Eriksen 2024Supersingular Endomorphism Rings: Algorithms and ApplicationsColin Boyd
Pia Bauspieß 2024Post-Quantum Secure Biometric SystemsAnamaria Costache
Runzhi Zeng 2024Tightly-secure Key Encapsulation Mechanism and its ApplicationJiaxin Pan
Elsie Mestl Fondevik20212024Key Exchange in Special CircumstancesKristian Gjøsteen
Bor de Kock 2023From Lattice Crypto to Lættis Krypto: Various Approaches to Post-Quantum Key ExchangeColin Boyd
Magnus Ringerud 2023Tight Security for Authenticated Key Exchange Protocols and Signature SchemesJiaxin Pan
Mattia Veroni 2023A Study on Tighter and More Efficient Isogeny-Based Cryptographic ProtocolsDanilo Gligoroski
Morten Rotvold Solberg 2023Security for Electronic Voting SystemsKristian Gjøsteen
Kyle Porter 2022Approximate String Matching and Filesystem Metadata CarvingSlobodan Petrovic
Mayank Raikwar 2022Cryptography for Innovative Blockchain ServicesDanilo Gligoroski
Shuang Wu 2022Cryptography for BlockchainsKristian Gjøsteen
Tjerand Silde 2022Privacy-Preserving Cryptography from Zero-Knowledge ProofsKristian Gjøsteen
Yao Jiang 2021Cryptographic Tools for Cloud SecurityKristian Gjøsteen
Herman Galteland 2020Malicious CryptographyKristian Gjøsteen
Christopher Carr 2019Towards Fairness and Decentralisation in Modern CryptocurrenciesColin Boyd
Martin Strand 2018Fully Homomorphic Encryption with Applications to Electronic VotingKristian Gjøsteen
Britta Hale 2017Low-Latency Key Exchange and Secure ChannelsColin Boyd
Håkon Jacobsen 2017A Modular Security Analysis of EAP and IEEE 802.11Danilo Gligoroski
Simona Samardjiska 2015Multivariate Public Key Cryptosystems Produced by QuasigroupsDanilo Gligoroski
Anton Stolbunov 2012Cryptographic Schemes Based on IsogeniesStig Frode Mjølsnes
Asgeir Bertelsen Steine 2012Privacy-Preserving Cryptographic ProtocolsKristian Gjøsteen
Benedikt Westermann 2012Challenges of Anonymous Communication: Bridging Gaps between Theory and PracticeSvein J. Knapskog
Martin Eian 2012Robustness in Wireless Network Access ProtocolsStig Frode Mjølsnes
Mohamed El-Hadedy Aly 2012Implementing Algorithms on FPGA PlatformsSvein J. Knapskog
Rune Ødegård 2012Hash Functions and Gröbner Bases CryptanalysisSvein J. Knapskog
Tord Ingolf Reistad 2012A General Framework for Multiparty ComputationsStig Frode Mjølsnes
Øystein Øvreås Thuen 2011Bilinear Pairings in CryptographyKristian Gjøsteen
Marie Elisabeth Gaup Moe 2009Security, Privacy and Trust in Dynamic NetworksSvein J. Knapskog
Svein Yngvar Willassen 2008Methods for Enhancement of Timestamp Evidence in Digital InvestigationsStig Frode Mjølsnes
Kristian Gjøsteen 2004Subgroup Membership Problems and Public Key CryptosystemsIdar Hansen
Tønnes Brekne 2001Encrypted ComputationSvein J. Knapskog
Knut Håkon A. Johannessen 2000A Methodology for Engineering Design of Distributed Systems: Application to Security Constrained SystemsSvein J. Knapskog
Kenneth Roar Iversen 1991Applications of Cryptographic “Zero-Knowledge” Techniques in Computerized Secret Ballot Election SchemesSvein J. Knapskog
Stig Frode Mjølsnes 1990Some Issues in Cryptographic ProtocolsSvein J. Knapskog

Events we have organized

Selected publications

Papers at IACR Crypto, Eurocrypt, and Asiacrypt, ACM CCS, and IEEE S&P with at least one author who was a member of the group at the time of publication. Group members are in bold.

YearVenuePaperAuthors
2026ASIACRYPTFormalizing and Strengthening the Security Proof of NTORDupressoir, Gjøsteen, Low, and Mylog
2026ACM CCSOlingo: Threshold Lattice Signatures with DKG and Identifiable AbortGur, Hough, Katz, Sandsbråten, and Silde
2026ACM CCSsPAR: (Somewhat) Practical Anonymous RouterDas, Park, and Sung
2026CRYPTOMulti-key FHE with Non-Interactive Setup in the Plain ModelMin, Park, and Song
2025CRYPTOVerifiable Computation for Approximate Homomorphic Encryption SchemesCascudo, Costache, Cozzo, Fiore, Guimarães, and Soria-Vazquez
2025CRYPTOXHMQV: Better Efficiency and Stronger Security for Signal’s Initial Handshake based on HMQVFiedler, Günther, Pan, and Zeng
2024ASIACRYPTHELIOPOLIS: Verifiable Computation over Homomorphically Encrypted Data from Interactive Oracle Proofs is PracticalAranha, Costache, Guimarães, and Soria-Vazquez
2024EUROCRYPTKey Exchange with Tight (Full) Forward Secrecy via Key ConfirmationPan, Riepel, and Zeng
2024EUROCRYPTToothpicks: More Efficient Fork-Free Two-Round Multi-SignaturesPan and Wagner
2024EUROCRYPTAprèsSQI: Extra Fast Verification for SQIsign Using Extension-Field SigningCorte-Real Santos, Eriksen, Meyer, and Reijnders
2023ACM CCSVerifiable Mix-Nets and Distributed Decryption for Voting from Lattice-Based AssumptionsAranha, Baum, Gjøsteen, and Silde
2023ASIACRYPTA Generic Construction of Tightly Secure Password-Based Authenticated Key ExchangePan and Zeng
2023ASIACRYPTTighter Security for Generic Authenticated Key Exchange in the QROMPan, Wagner, and Zeng
2023ASIACRYPTA Simple and Efficient Framework of Proof Systems for NPWang, Su, Pan, and Chen
2023ASIACRYPTCryptographic Smooth NeighborsBruno, Corte-Real Santos, Costello, Eriksen, Meyer, Naehrig, and Sterner
2023CRYPTOLattice-Based Authenticated Key Exchange with Tight SecurityPan, Wagner, and Zeng
2023CRYPTOOn Optimal Tightness for Key Exchange with Full Forward Secrecy via Key ConfirmationGellert, Gjøsteen, Jacobsen, and Jager
2023EUROCRYPTChopsticks: Fork-Free Two-Round Multi-Signatures from Non-Interactive AssumptionsPan and Wagner
2022ASIACRYPTCompact and Tightly Selective-Opening Secure Public-key Encryption SchemesPan and Zeng
2022ASIACRYPTUnconditionally Secure NIZK in the Fine-Grained SettingWang and Pan
2022EUROCRYPTNon-Interactive Zero-Knowledge Proofs with Fine-Grained SecurityWang and Pan
2021ASIACRYPTSymmetric Key Exchange with Full Forward Security and Robust SynchronizationBoyd, Davies, de Kock, Gellert, Jager, and Millerjord
2021CRYPTOAuthenticated Key Exchange and Signatures with Tight Security in the Standard ModelHan, Jager, Kiltz, Liu, Pan, Riepel, and Schäge
2021CRYPTOFine-Grained Secure Attribute-Based EncryptionWang, Pan, and Chen
2021IEEE S&PDid you mix me? Formally Verifying Verifiable Mix Nets in Electronic VotingHaines, Goré, and Sharma
2020ASIACRYPTThe Direction of Updatable Encryption does not Matter MuchJiang
2020ASIACRYPTUnbounded HIBE with Tight SecurityLangrehr and Pan
2020CRYPTOFast and Secure Updatable EncryptionBoyd, Davies, Gjøsteen, and Jiang
2020IEEE S&PHow not to Prove your Election OutcomeHaines, Lewis, Pereira, and Teague
2019ACM CCSVerified Verifiers for Verifying ElectionsHaines, Goré, and Tiwari
2019ASIACRYPTShorter QA-NIZK and SPS with Tighter SecurityAbe, Jutla, Ohkubo, Pan, Roy, and Wang
2019CRYPTOHighly Efficient Key Exchange Protocols with Optimal TightnessCohn-Gordon, Cremers, Gjøsteen, Jacobsen, and Jager
2018CRYPTOPractical and Tightly-Secure Digital Signatures and Authenticated Key ExchangeGjøsteen and Jager
2017EUROCRYPT0-RTT Key Exchange with Full Forward SecrecyGünther, Hale, Jager, and Lauer
2007CRYPTOA Security Analysis of the NIST SP 800-90 Elliptic Curve Random Number GeneratorBrown and Gjøsteen
2005ASIACRYPTSpreading Alerts Quietly and the Subgroup Escape ProblemAspnes, Diamadi, Gjøsteen, Peralta, and Yampolskiy

Projects

Research projects in cryptography at NTNU with group members as project leaders or participants.

YearsProjectFunding
2027–2031Cryptology and Social Life: digital identity wallets (four PhD positions)NTNU, “A more resilient society”
2026–2028QARC: Quantum-Resistant Cryptography in PracticeHorizon Europe
2025–2026Cryptology and Social Life (seed project)NTNU Community
2025–2028ToppForsk@IE: CryptographyNTNU
2021–2026Realistic Cryptography for Large-scale ApplicationsRCN FRIPRO
2021–2026OffPAD: Optimizing balance between high security and usabilityRCN
2020–2028NORCICS: Norwegian Centre for Cybersecurity in Critical SectorsRCN SFI
2020–2022Key Exchange for Today’s InternetRCN
2019–2024Lightweight Cryptography for Future Smart NetworksRCN
2018–2025Secure, Usable and Robust Cryptographic Voting SystemsRCN
2016–2020Cryptographic Tools for Cloud SecurityRCN
2014–2015Group Homomorphic Encryption and BeyondRCN
2011–2016FRISC: Forum for Research and Innovation in Security and Communications (network)RCN
2008–2012Privacy-preserving Seamless Digital InfrastructuresRCN
2005–2008TID: Time Stamps, Digital Traces and Forensic EvidenceRCN
2004–2010Large Scale PKI ApplicationsRCN
2003–2008Cross-faculty Research Programme in Information SecurityRCN