Khandaker Md. Al-Amin
Cryptographer in Berlin. PhD in pairing-based cryptography, then three years shipping elliptic-curve homomorphic encryption and secure multi-party computation. Post-quantum cryptography is where I am taking that next.
Recent writing
Lattices, Part 3: Making Bad Arrows Good
If short arrows are so much better than long ones, why not just shorten them? You can, and the method is one you already learned in school.
Lattices, Part 2: Good Basis, Bad Basis
Finding the nearest dot in a grid is easy with the right description of that grid and hopeless with the wrong one. That gap is the trapdoor lattice cryptography is built on.
Lattices, Part 1: A Grid of Dots
What a lattice is, why one lattice has infinitely many bases, and why that single fact is where lattice cryptography starts.
Selected research
A Study of Efficient Pairing Computation Algorithm Using KSS Curves
Ph.D. dissertation, Okayama University, 2019
Efficient Optimal Ate Pairing at 128-Bit Security Level
Progress in Cryptology - INDOCRYPT 2017, Springer LNCS, December 2017, pp. 186–205
An Improvement of Scalar Multiplication by Skew Frobenius Map with Multi-Scalar Multiplication for KSS Curve
IEICE Transactions on Fundamentals E100.A(9), 2017, pp. 1838–1845
Code
ELiPS
Efficient library for pairing-based cryptography on BN and BLS curves.
BLS signatures + aggregation demo
Interactive BLS short signatures running the Optimal-Ate pairing in the browser via WebAssembly.
DataArmor Gate DB
Database proxy that runs SQL over encrypted data without giving the server the key.
What I work on
Cryptography & secure computing
- Pairing-based cryptography and elliptic curves (KSS, BN, BLS families)
- Homomorphic encryption: lifted ElGamal on BLS curves, running SQL queries over encrypted data
- Secure multi-party computation and private set intersection
- Privacy-preserving machine learning
- Encrypted-database and secure-computing product engineering
- Implementation in Rust and C, with an eye on constant-time behavior
Security engineering & compliance
- EU Cyber Resilience Act readiness and conformity assessment routes
- SBOM management: SPDX, CycloneDX, provenance and signing in CI/CD
- Coordinated vulnerability disclosure (ISO/IEC 29147, 30111) and PSIRT operating models
- Incident response readiness aligned with NIST SP 800-61
- Automotive cybersecurity: ISO/SAE 21434 TARA, UN R155, secure boot, HSM integration
Where I am taking this next
- Lattice cryptography from LWE to Ring-LWE and the BFV scheme, worked through in my Computing on Secrets article
- Post-quantum standards in practice: ML-KEM and ML-DSA, and what migration costs at the protocol layer
- Hybrid key exchange and the transition problem for long-lived systems
- Zero-knowledge proof systems and the pairing-based components I already know well