The Big Disappointment

In a previous chapter, I mentioned that my PhD was still underway. In conversations with my advisor, there was one point we kept coming back to: we had a good definition of the protocol, but we hadn’t been able to produce a formal proof of its security. In cryptography, it’s strongly recommended to provide formal proofs of a protocol’s security properties for it to be accepted by the academic community. That was a known issue, and I tried to resolve it several times.

At the time, the most widely used and accepted formal proof method for cryptographic protocols was the Random Oracle model. My advisor pointed me to readings on this method. I read the material, looked for other references to better understand the methodology, and began trying to adapt my protocol to the proposed model. The problem was that there was no direct way to make that fit. I kept ending up with a proof structure that seemed to require two distinct random oracles, which did not match the proof approach I was trying to follow. My protocol was a type of proxy signature, which was not straightforward to treat in the Random Oracle model, making its use extremely challenging. I tried several times in different ways, but nothing seemed to work. I kept wondering whether I wasn’t understanding the method or whether it was a structural limitation in the model itself.

There was a foreign researcher in the cryptography field who had moved to Brazil and worked with some of the biggest names in cryptography. In addition to having experience in traditional cryptography, he also worked in quantum cryptography, a subject that was very much in the spotlight at the time. I imagine those factors led my advisor to want to get closer to him, perhaps even establish a collaboration. My advisor seemed to trust his expertise quite a bit, to the point that he influenced a colleague’s change of thesis topic within the field of quantum cryptography.

If I’m not mistaken, it was this researcher who first mentioned to my advisor about the need to add formal proofs based on the Random Oracle model to my work. Faced with the difficulties I was having fitting the protocol to that model, I took the opportunity when we were both attending the same event in Brasília and invited him to dinner at my place so we could talk about this proof. After dinner, we sat in the living room and I asked for his help fitting my protocol to the suggested model. After some time, we gave up. We couldn’t move forward. The impasse remained. I talked to my advisor about it and we concluded we were not going to be able to produce the formal proof and that the best thing was to move on.

The deadline for the PhD defense was approaching. I talked to my advisor and he agreed to write a thesis in the format of a collection of articles, which would be quicker to prepare than a traditional thesis. A thesis as a collection of articles basically consists of turning the published articles into chapters, writing an introduction and a conclusion, and organizing the material into a coherent whole. I then focused on writing the introduction and conclusion and on assembling a first preliminary version of what would become the thesis. We had a few rounds of revisions and, still within the program deadline, we submitted the text to the graduate studies office for the defense date to be scheduled.

For the committee, my advisor chose two members from outside the university. The first was a longtime friend of his and a professor at a federal university in southern Brazil. He had been working in security for a long time and, while he wasn’t exactly in the field of cryptography, he worked on topics related to security protocols. The second was the European researcher I mentioned above. With the committee defined, we set the defense date and posted the announcement at the institute. I also started organizing the trip to Campinas. I told my parents, who decided to attend the presentation.

Just when I thought everything was in place, my advisor called me again to say that, without the formal proofs of security, the thesis wouldn’t be approved. To me, it was obvious which of the committee members had raised that requirement, since only one of them knew that weak point of the work in depth. It was one of the most unexpected and impactful phone calls I ever received, close in intensity to the day I was called and told that my father had passed away.

With the defense canceled, there was no longer any way to remain actively enrolled in the program. My advisor and I agreed that I would continue the work even without being officially enrolled, and that he would continue advising me. When we were able to fill the gaps, I could re-enroll just to defend the thesis and receive the degree. I had no alternative but to try to complete what was supposedly missing from the thesis.

Over time, I lost not only hope of reaching the expected result, but also the enthusiasm and the will to keep going. What was being asked of me seemed as hard as, or harder than, all the work I had already done. Little by little, I abandoned the PhD. It also no longer made much difference professionally whether or not I had the degree, which further reduced the incentive to persist.

A few years later, as I was becoming more involved with the cryptography community in Brasília, I met a professor at UnB who was a specialist in cryptography, and we ended up becoming friends. At the time, I considered Anderson one of the most promising researchers in the country. We talked a few times about my thesis, over beers and laughs. Then, in one of those conversations, he mentioned that he had read a thesis that had won an important award in the United States. That thesis presented a formal model for security proofs in proxy signature protocols. In other words, what they had asked me to develop was precisely the kind of contribution that would later be recognized, and awarded, as relevant in the field.

I don’t regret having pursued the PhD. I learned a lot and studied topics that still influence the way I think about solutions in computing. What I sometimes regret is that it might have been possible to complete the defense with just the work we had at the time. The advice I left in the chapter on choosing the thesis topic is directly related to this experience. Working on topics closer to your advisor’s area of specialization can avoid situations like the one I went through.