My work not only explores fundamental research but also considers translations into the real world. The aim to enhance security and efficiency of cryptosystems yields several projects, some of which also involve commercial parties. Below, I highlight my research projects that have large-scale international impacts.
CryptOpt is an optimizer that automatically generates provably correct cryptographic code while also achieving highly competitive performance compared to code manually produced by experts. This work received the Distinguished Paper Award at the 2023 ACM PLDI and the Humies Gold Award at GECCO 2023. Importantly, CryptOpt is integrated into BoringSSL, a Google open-source library that provides secure communications for Chromium-based web browsers such as Google Chrome, Microsoft Edge, and Opera (combined market share of 70% worldwide; StatCounter). This new paradigm shift brought by CryptOpt is popularized in Cyber Today, a magazine of the Australian Information Security Association (AISA) with over 40,000 readers.
NTRU Prime is a cryptosystem that runs on classical computers but is believed to be future-proof against powerful quantum computers. In 2022, NTRU Prime was selected from 82 submissions worldwide as an alternative candidate by the National Institute of Standards and Technology (NIST) in the world-first PQC Standardization. NTRU Prime is now a default option in OpenSSH, an open-source implementation widely adopted in Linux to provide secure remote system administration and communication over unsecured networks.
One of my research projects on post-quantum cryptography is in collaboration with the Legion of the Bouncy Castle and Australian Cyber Security Centre (ACSC). This project evaluates correctness and side-channel security of PQC implementations. This work revealed vulnerabilities of code in the Bouncy Castle Cryptography Package, which is one of the most well-known and widely used cryptographic libraries globally. This project helps strengthen and smoothen the transition from pre- to post-quantum security, within Australia and internationally, for a stronger present and a secure future to protect sensitive information in the quantum-computer era.
Talks and Slides
Speculative Execution and Cache Attacks (invited talk)
At the Cyber in SaintMalo, France, July 2026
Evict+Spec+Time: Exploiting Out-of-Order Execution to ImproveCache-Timing Attacks
At the Cryptographic Hardware and Embedded Systems (CHES 2024), Canada, September 2024
CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives (invited talk)
At the Future Communications Workshop, Australia, June 2024
Cache-Timing Attack Against HQC (invited talk)
At the Quantum Safe Migration Center, Taiwan, December 2023
CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives (invited talk)
At the Workshop on Applied Cryptology and AI (ACAI 2023), USA, August 2023
CryptOpt: Verified Compilation with Randomized Program Search for Cryptographic Primitives (invited talk)
At the Coloquio Nacional de Códigos, Criptografía y Áreas Afines, Mexico (online), June 2023
CryptOpt: Automatic Cryptographic Code Optimization with Verified Compilation (invited talk)
At the Workshop on Cryptography, Robustness, and Provably Secure Schemes for Female Young Researchers (CrossFyre 2023), France, April 2023
A Primer on Cache Attacks (invited talk)
At the Summer School on Real-World Crypto and Privacy, Croatia, June 2022
Optimizing Lattice-Based Cryptography (invited talk)
At the Workshop on Design and Evaluation of New-Generation Cryptography, Japan (online), November 2021
Pairing-Friendly Twisted Hessian Curves
At the Conference on Cryptology in India (Indocrypt 2018), India 2018
Fast Arithmetic on Hessian Curves (invited talk)
At the Workshop on Elliptic Curve Cryptography (ECC 2016), Turkey 2016
Fast and Secure DH Implementation
At the Workshop on Cryptography, Robustness, and Provably Secure Schemes for Female Young Researchers (CrossFyre 2016), Germany 2016
Pond - A Non-Instant Messaging Protocol by Adam Langley
at a Privacy and Surveillance Seminar, UC Davis, USA 2015
New Diffie-Hellman Speed Records (invited talk)
At the Crypto Working Group meeting, Utrecht, the Netherlands 2015
Kummer Strikes Back: New DH Speed Records
At the Conference on the Theory and Application of Cryptology and Information Security (Asiacrypt 2014), Taiwan 2014
Curve41417: Karatsuba Revisited
At the Workshop on Cryptographic Hardware and Embedded Systems (CHES 2014), South Korea 2014