tl;dr: I wish there was better stuff around than UC for modelling security of cryptosystems.
Links
- Andrew Miller’s course
- List of papers that introduce UC functionalities, from a Google Doc in this course
- For future reference, equivalent AI-generated list for game-based proofs
- List of papers that introduce UC functionalities, from a Google Doc in this course
- UC hackathon
- 6.897 MIT course, Spring ‘04
Papers
- first UC paper1
- “simpler” UC for MPC2
- “simpler” iUC paper3: still not very simplified, IMO.
- A very formally worked-out example of a UC proof for PAKE4
- EasyUC paper5: UC proofs in EasyCrypt
References
For cited works, see below 👇👇
-
Universally Composable Security: A New Paradigm for Cryptographic Protocols, by Ran Canetti, in Cryptology ePrint Archive, Report 2000/067, 2000, [URL] ↩
-
A Simpler Variant of Universally Composable Security for Standard Multiparty Computation, by Ran Canetti and Asaf Cohen and Yehuda Lindell, in Cryptology {ePrint} Archive, Paper 2014/553, 2014, [URL] ↩
-
iUC}: Flexible Universal Composability Made Simple, by Jan Camenisch and Stephan Krenn and Ralf Kuesters and Daniel Rausch, in Cryptology {ePrint} Archive, Paper 2019/1073, 2019, [URL] ↩
-
UC}-Security of Encrypted Key Exchange: A Tutorial, by Jiayu Xu, in Cryptology {ePrint} Archive, Paper 2025/237, 2025, [URL] ↩
-
EasyUC}: Using {EasyCrypt} to Mechanize Proofs of Universally Composable Security, by Ran Canetti and Alley Stoughton and Mayank Varia, in Cryptology {ePrint} Archive, Paper 2019/582, 2019, [URL] ↩