Home Page

Alfredo Pironti

Researcher

INRIA
23, Avenue d'Italie
75013 Paris - France

e-mail: alfredo.pironti at inria.fr (where 'at' stands for '@')

spacer


News

Oct 25, 2014: I have been acknowledged in Google's Hall of Fame for discovering an authentication bypass flaw in Google App Engine.
Oct 14, 2014: I am hosting and organizing the upcoming IETF TLS Interim Meeting at INRIA, Paris.
Jun 15, 2014: My paper on verification of the TLS handshake has been accepted at CRYPTO 14.
May 1, 2014: I have been acknowledged by Microsoft for my TLS truncation attack.
Mar 4, 2014: My paper on the Triple Handshake attack has been accepted at IEEE S&P 14. Selected press coverage: Ars Technica; The Register; TechWeekEurope; Threatpost; ZDNet.
More news...

Short Bio and Research

I am a researcher in formal methods for security protocol implementations and security-aware applications. My current research interests include traffic analysis and side channel analysis; I recently focused on miTLS, a verified implementation of the TLS security protocol in the computational model of cryptography, via refinement types. I work in the Prosecco research group at INRIA and in the Secure Distributed Computing project at the MSR-INRIA Joint Centre. My main current collaborators are Karthikeyan Bhargavan, Cédric Fournet, Markulf Kohlweiss and Pierre-Yves Strub.

I received my PhD in 2010 at Politecnico di Torino, supervised by Riccardo Sisto. During my PhD I co-developed a framework, called spi2java, that allows to semi-automatically generate Java implementations of security protocols formally specified in the spi calculus language.

For half a year, I have been a visiting PhD student at the Microsoft Research Centre, Cambridge, UK, and the Open University, UK, supervised by Jan Jürjens. During my visit, I developed novel formally-based methodologies to design and develop monitors for legacy security protocols implementations.

I am a member of the CryptoForma network, aimed at bridging the gap between symbolic and computational formal methods.

gipoco.com is neither affiliated with the authors of this page nor responsible for its contents. This is a safe-cache copy of the original web site.