Cryptography at Google
Abstract
This talk will cover the cryptography landscape at Google, broadly describing Google's cryptographic engineering and research initiatives. We will also take a few deep-dives, in particular covering Google’s approach to the PQC transition, the difficulties of key management and storage encryption at scale, and the challenges involved in producing easy-to-use, safe-by-default cryptography libraries. Many of these areas serve as examples of where theory and practice collide, demonstrating that it can be difficult to turn a cryptographic idea into an engineering reality. Lastly, we will comment on the impact of AI on cryptography and what it means for cryptographic security moving forward.
Biography
Thyla van der Merwe leads the Applied Cryptography and Formal Verification teams at Google. The Applied Cryptography team develops cryptographic libraries, and more generally, aims to help everyone at Google, and beyond, to use cryptography correctly. The Formal Verification team verifies Google’s security-critical code, which includes cryptography libraries! Prior to joining Google, Thyla served as the Managing Director of the Future Computing Laboratory at ETH Zurich, where she helped set up an industry-funded research centre focused on next generation computing technologies. Thyla also worked for Mozilla, helping to secure the Firefox browser, and has been involved in several cryptographic standardization initiatives: she represented South Africa on the International Organisation for Standardisation (ISO) committee responsible for standardizing cryptographic mechanisms and protocols, and is listed as an official contributor to the TLS 1.3 specification which was released by the Internet Engineering Task Force (IETF) in 2018. Thyla completed her PhD in Cyber Security at Royal Holloway, University of London as part of the Centre for Doctoral Training in Cyber Security. Her PhD research focused on breaking TLS 1.2 and below, and formally verifying TLS 1.3 prior to its official release.