Research division · est. 2016

Diffie Laboratory

Applied Cryptography & Key Management

Strong cryptography is easy to specify and hard to operate. We study the operating part.

24
Researchers
3
Active projects
52
Publications
3
Open datasets

What we work on

Whitfield Diffie and Martin Hellman showed in 1976 that two parties can agree on a secret over a channel everyone can read. Today that idea secures nearly every connection on the Internet, but most real failures come not from broken mathematics — they come from expired certificates, leaked keys and slow rotations.

The Diffie Laboratory studies the operational side of cryptography in distributed systems: certificate and key lifecycles, the performance cost of new handshake algorithms, and the migration of production systems towards post-quantum key exchange.

Lab lead: Dr. Hannah Okafor

Current projects

Post-Quantum Handshake Performance

Measuring latency and packet-size overhead of hybrid key exchange on real paths with different MTUs and loss.

Certificate Lifecycle Telemetry

Detecting expiry risks, mis-issuance and rotation failures across large fleets before they cause outages.

Key Rotation Without Downtime

Patterns and tooling for rotating service credentials in multi-region deployments.

Selected publications

Hybrid Key Exchange on Long-Haul Paths: A Measurement StudyTechnical Report DFL-TR-2025-02 · 2025
Why Certificates Still Expire: Lessons from Fleet TelemetryWorkshop on Operational Security · 2024
Zero-Downtime Credential Rotation in Multi-Region ServicesTechnical Report DFL-TR-2024-04 · 2024

Measurement testbed

StatusOperational
Testbed nodes12
Availability (90 d)99.91%
Last data releaseOctober 2026

Collaborate with us

We welcome joint research, student projects and dataset requests. Write to lab@diffie.network-labs.sm-ventures.ru.