Post-Doctoral Research Visit F/M Verification of messaging protocols and verification of protocols in the presence of key compromise
Type de contrat : CDD
Niveau de diplôme exigé : Thèse ou équivalent
Fonction : Post-Doctorant
Niveau d'expérience souhaité : Jeune diplômé
Contexte et atouts du poste
Funding project
This post-doc position is in the framework of the PEPR Cybersecurity SVP project, a collaborative project on the verification of security protocols, funded by the France 2030 programme. It groups the teams Spicy (IRISA), Pesto (LORIA), Splits (Inria Center of University Cote d'Azur), Inspire (ENS Paris-Saclay) and Prosecco (Inria Paris).
Team
The post-doc will take place in the Prosecco team of Inria Paris. In this team, we develop some of the leading security protocol verification tools (CryptoVerif, Squirrel, formerly ProVerif) and Rust program verification tools (Aeneas), targeting in particular verification of implementations of cryptographic primitives and protocols.
Travel
The post-doc will travel to security conferences, in order to present his research work. Travel expenses are covered within the limits of the scale in force.
Mission confiée
The recruited person will do research on the verification of messaging protocols (like Signal, Whatsapp, MLS) and the verification of protocols in case of key compromise. Messaging protocols are widely used and aim at guaranteeing complex security properties in the presence of compromise, such as post-compromise security: the protocols recovers security after a compromise. Hence, they are an interesting target for study. Other protocols are also interesting to study in complex compromise scenarios, for instance the VPN WireGuard, and are also targets for this post-doc.
The research will include theoretical results, case studies using protocol verification tools, and possibly extensions of verification tools.
The considered research directions include:
- proving (parts of) MLS using Squirrel (MLS is a very complex protocol, so we will start with partial proofs);
- proving security protocols using CryptoVerif with complex compromise scenarios;
- designing protocols with as strong as possible post-compromise security properties;
- proving privacy properties (such as anonymity) for messaging protocols;
- detecting the compromise of keys.
The objective will be to publish the research results in major computer security conferences such as IEEE Symposium of Security and Privacy, ACM CCS, Usenix Security, IEEE Computer Security Foundations Symposium.
For more information on our research and our security protocol verification tools, the applicants may consult the web pages of Squirrel https://squirrel-prover.github.io/ and CryptoVerif https://cryptoverif.inria.fr .
This work will be done in collaboration with Adrien Koutsos, who develops in particular Squirrel, and Bruno Blanchet, who develops in particular CryptoVerif.
Principales activités
Main activities :
- Write research papers
- Design new security protocols
- Use protocol verification tools developed in the team Prosecco (Squirrel, CryptoVerif)
Additional activities :
- Extend protocol verification tools developed in the team Prosecco (Squirrel, CryptoVerif)
Compétences
Technical skills and level required : A successful PhD thesis on the verification of security protocols is required, with publications in some of the major computer security conferences (IEEE Symposium of Security and Privacy, ACM CCS, Usenix Security, IEEE Computer Security Foundations Symposium).
Languages : Fluency in English
Relational skills :
- Reliability.
- Integrity.
- Ability to collaborate with the other members of the team as well as to work autonomously.
- Willingness to learn.
Avantages
- Subsidized meals
- Partial reimbursement of public transport costs
- Leave: 7 weeks of annual leave + 10 extra days off due to RTT (statutory reduction in working hours) + possibility of exceptional leave (sick children, moving home, etc.)
- Possibility of teleworking and flexible organization of working hours
- Professional equipment available (videoconferencing, loan of computer equipment, etc.)
- Social, cultural and sports events and activities
- Access to vocational training
- Social security coverage
Informations générales
- Thème/Domaine :
Sécurité et confidentialité
Système & réseaux (BAP E) - Ville : Paris
- Centre Inria : Centre Inria de Paris
- Date de prise de fonction souhaitée : 2027-02-01
- Durée de contrat : 2 ans
- Date limite pour postuler : 2026-08-23
Attention: Les candidatures doivent être déposées en ligne sur le site Inria. Le traitement des candidatures adressées par d'autres canaux n'est pas garanti.
Consignes pour postuler
Sécurité défense :
Ce poste est susceptible d’être affecté dans une zone à régime restrictif (ZRR), telle que définie dans le décret n°2011-1425 relatif à la protection du potentiel scientifique et technique de la nation (PPST). L’autorisation d’accès à une zone est délivrée par le chef d’établissement, après avis ministériel favorable, tel que défini dans l’arrêté du 03 juillet 2012, relatif à la PPST. Un avis ministériel défavorable pour un poste affecté dans une ZRR aurait pour conséquence l’annulation du recrutement.
Politique de recrutement :
Dans le cadre de sa politique diversité, tous les postes Inria sont accessibles aux personnes en situation de handicap.
Contacts
- Équipe Inria : PROSECCO
-
Recruteur :
Blanchet Bruno / Bruno.Blanchet@inria.fr
L'essentiel pour réussir
The ideal applicant will have a strong knowledge in the verification of security protocols, and in particular messaging protocols, as well as the desire to learn more on our verification tools Squirrel and CryptoVerif.
A propos d'Inria
Inria, l'institut national de recherche dans les sciences et technologies du numérique, est en appui de l’État pour les stratégies nationales de recherche et d’innovation du numérique en tant qu'Agence de programmes. Inria mène plus de 300 projets de recherche et d’innovation avec ses 3500 scientifiques, ingénieurs et personnels d’appui, en partenariat avec les universités et l’écosystème numérique (entreprises, entrepreneurs, acteurs publics). Ensemble, nous explorons des domaines clés comme l'intelligence artificielle, la cybersécurité, l’informatique quantique, le Cloud, la transformation numérique de la santé, les jumeaux numériques ou encore les technologies numériques pour la défense. Nous construisons des solutions concrètes telles que des logiciels, des startups technologiques, des partenariats avec les entreprises du tissu national et des formations de pointe. Notre objectif : l’impact scientifique, technologique et industriel au service de la souveraineté numérique de la France.