Markku-Juhani O. Saarinen
Professional
I’m a cryptographer – one of those people who professionally build and sometimes break cryptosystems. Here’s a recent CV.
Since January 2023, I have been a Professor of Practice (työelämäprofessori) at Tampere University, associated with the Network and Information Security Group (NISEC) and the SoC HUB. I also hold the title of Docent, Information Security and Cryptography. I supervise Ph.D. and M.Sc. students interested in cryptography and related mathematical and engineering topics.
Current Projects (Fall 2026)
-
I maintain the ngcc.dev website tracking cryptanalytic attacks against the Chinese Next Generation Commercial Cryptographic (NGCC) program algorithms. Initial write-up went out on September 29: Chinese NGCC Algorithms: The First Week of AI Cryptanalysis.
-
Other AI-assisted cryptanalytic attacks: HOVER on TII-252 McEliece, Two-Anchor Holdout/Hermite on TII-254 McEliece. BSI stopped recommending McEliece on September 29, 2026 (I am cited there twice!)
-
We have released the karu64 open application processor core (and related karudeb Debian Linux support.) I am currently updating karucore.com with relevant technical information.
Recent Papers and Presentations (2025-)
-
Paper accepted to ACM CCS 2026 (November 15-19, 2026): “Lemur: Scalable Post-Quantum Synchronized Multi-Signatures” (Y. Lin, M. F. Esgin, A. Sakzad, R. Steinfeld, and M.-J. O. Saarinen.) Implementation: https://github.com/lemur-sig/lemur.
-
Paper accepted to ACM CCS 2026 (November 15-19, 2026): “LoTRS: Practical Post-Quantum Structured Threshold Ring Signatures from Lattices” (N. Jagganath, M. F. Esgin, R. Steinfeld, A. Sakzad, M.-J. O. Saarinen and D. Liu.) Implementation: https://github.com/lotrs-sig/lotrs.
-
Paper accepted to NORDSEC 2026 (November 11-12, 2026): “HOVER: Higher-Order Vanishing Endomorphism Recovery” (M.-J. O. Saarinen). Artifact: https://github.com/mjosaarinen/tii-solved.
-
Talk at WAC 8 (August 16, 2026). Slides: “On AI & Cryptanalysis (HAWK Guessing Game is not Polynomial-Time / Other Recent AI Adventures)”.
-
Paper at USENIX Security 2026 (August 12-14, 2026): “mmCipher: Batching Post-Quantum Public Key Encryption Made Bandwidth-Optimal” (H. Wang, R. Steinfeld, M.-J. O. Saarinen, M. F. Esgin, and S.-M. Yiu).
-
Journal Article: “A Practical Neighborhood Search Attack on Oracle MLWE” (H. Wang, M. F. Esgin, R. Steinfeld, M.-J. O. Saarinen, and S.-M. Yiu.) IACR Communications in Cryptology, vol. 3, no. 1, May 4, 2026.
-
Talk at EUCA 2026 (March 26, 2026). Slides: “Where Are We With the CRA Cryptography Requirements?”.
-
Talk at IACR Real World Crypto 2026 (March 10, 2026). Slides: “CRA and Cryptography: The Story Thus Far”. Related preprint: IACR ePrint 2025/2092.
-
Paper at SSR 2025 (December 4-5, 2025). “CRA and Cryptography: The Story Thus Far” (M.-J. O. Saarinen). Also IACR ePrint 2025/2092. Slides 2025-12-05.
-
Talk at ENDR Conference Tampere 2025 (December 3, 2025). Slides: “Chip related security and availability”.
-
Talk at RISC-V Summit North America 2025 (October 23, 2025). Slides: “PQCP Support for RISC-V Vector, Future Keccak ISE”. Related mlkem-native GitHub.
-
Talk at Florida Atlantic University (October 17, 2025). Slides: “It’s The Law: Some Technical Things All Hardware Security Architects Ought to Know About CRA, EUCC”.
-
Talk at hardwear.io USA 2025 (May 30, 2025). Slides: “Why “Adams Bridge” Leaks: Attacking a PQC Root-of-Trust”. Related GitHub.
-
Talk at EUCA 2025 (March 27, 2025). Slides: “On Certifying PQC Implementations at “High” Assurance Level”.