International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

31 December 2025

Quinten Norga, Suparna Kundu, Ingrid Verbauwhede
ePrint Report ePrint Report
ML-DSA is a post-quantum lattice-based digital signature algorithm (DSA) that the National Institute of Standards and Technology (NIST) recently standardized as FIPS 204. Remarkably, there are only a handful of published hardware designs and no open-source hardware implementations of complete ML-DSA. In this work, we present an efficient open-source hardware (OSH) design of ML-DSA, based on a Dilithium implementation by Beckwith et al. (FPT 2021). We discuss the required modifications for migrating existing CRYSTALS-Dilithium implementations to match FIPS 204. In addition, we evaluate and compare the performance of our design with the prior art. Through optimized instruction scheduling in the ML-DSA rejection loop, which enables the pre-computation of critical variables, the average signing latency is improved by $16-36$ %. Finally, we extensively discuss potential applications and directions of research, further enabled through ML-DSA-OSH.
Expand
Jingjing Fan, Xingye Lu, Man Ho Au, Siu Ming Yiu
ePrint Report ePrint Report
Identity-Based Encryption (IBE) is a cryptographic primitive where any string, such as an email address, can serve as a public key. With the advent of quantum computing, post-quantum secure IBE constructions have become critical for ensuring long-term data security. The state-of-the-art construction based on MPLWE introduced by Fan et al. significantly advanced the field by achieving adaptive security under standard assumptions, however the size of the master public key (MPK) grows linearly with the identity length, posing scalability challenges for real-world applications. In this work, we build on Fan et al.'s construction by employing a fully homomorphic trapdoor function to optimize the number of polynomials required for generating secret keys. This approach significantly reduces the MPK size from $O(\ell)$ polynomial vectors to $O(\ell^{1/d})$, where $d$ is a constant. Despite this compactness, our scheme retains the same secret key and ciphertext sizes as Fan et al.'s construction and introduces no additional security assumptions.
Expand
sowle
ePrint Report ePrint Report
In this paper we present a Schnorr-like linkable ring signature scheme we call d/v-CLSAG that is extension for d-CLSAG scheme. The proposed extension allows the use of different group generators for different layers of the ring members, while the original scheme assumes the use of the same generator G across all layers. We provide the security statements for the proposed updated scheme. This work was reviewed by the Cypher Stack.
Expand
Shichang Wang, Meicheng Liu, Shiqi Hou, Chengan Hou, Dongdai Lin
ePrint Report ePrint Report
The stream cipher ChaCha is one of the most widely used ciphers in the real world, such as in TLS, SSH and so on. In this paper, we study the security of ChaCha via differential cryptanalysis based on probabilistic neutral bits (PNBs). We introduce the syncopation technique for the PNB-based approximation in the backward direction, which significantly amplifies its correlation by utilizing the property of ARX structure. In virtue of this technique, we present a new and efficient method for finding a good set of PNBs, and then a refined framework of key-recovery attack is formalized for round-reduced ChaCha. Further, we generalize the PNB-based approximation by a concept called probabilistic neutral expressions (PNEs). In the PNE-based framework, a new key guessing strategy is presented along with the carry-preserving technique. The new techniques allow us to break 7.5 rounds of 256-bit ChaCha, as well as to bring faster attacks on 7 rounds of 256-bit ChaCha. In addition, to the best of our knowledge, we present the first related-key attack on 256-bit ChaCha8 which is one out of three original ciphers in the ChaCha family. Regarding 128-bit ChaCha, our techniques permit us to defeat 7 rounds when excluding the last rotation.
Expand
Betül Askin Özdemir, Vincent Rijmen
ePrint Report ePrint Report
This paper presents a unified framework for generic attacks on Generalized Feistel Ciphers, with a primary focus on Type 1, Type 2, and unbalanced contracting (U-Type 1) Feistel constructions with non-invertible round functions. In recent work, authors reveal a class of vulnerabilities exploitable via key independent multidimensional linear trails for Feistel Ciphers, yielding efficient generic distinguishing and key-recovery attacks. We extend the extended work by formalizing the application of generic multidimensional linear cryptanalysis to Generalized Feistel Ciphers. In this way, we improve upon existing results by extending the maximum number of rounds for the generic distinguishing attack to $t^2 + 2t - 1$ for Type 1 and U-Type 1, and to $2t + 3$ for Type 2. Moreover, we have the maximum number of rounds for generic key recovery attacks on (U)-Type 1 as $t^2+3t-2$ and Type 2 as $4t$. To the best of our knowledge, these findings yield the best results for the maximum number of rounds in key recovery attacks on the corresponding GFC. We further demonstrate the branch-permutation-independence of these attacks, proving that changing internal permutations does not affect the attack applicability, complexities or the maximum number of rounds for generic attacks. The effectiveness of our attacks is validated through experiments on the first-round AES candidate CAST-256 and the MPC-friendly block cipher GMiMC. Both theoretical and experimental results confirm that our proposed branch-permutation-independent generic attacks enhance the maximum number of rounds for generic attacks for GFC and reduce complexity across various interesting cases.
Expand
Abhinav Vishnu
ePrint Report ePrint Report
Domain Control Validation (DCV) is the cornerstone of trust on the web, serving as the prerequisite for issuing TLS certificates and asserting identity. The current industry standard, the Automated Certificate Management Environment (ACME) protocol, relies on synchronous, interactive challenge-response mechanisms (e.g., HTTP-01) that necessitate active server infrastructure and open network ports. This architectural requirement imposes significant friction on modern serverless, static, and air-gapped deployments, often forcing the exposure of sensitive infrastructure solely for validation purposes.

This paper presents the Portable Trust eXtensible (PTX) protocol, a novel mechanism for asynchronous, non-interactive DCV. PTX decouples the assertion of control from the delivery mechanism by utilizing Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge (zk-SNARKs). We introduce a circuit design that cryptographically binds a set of ephemeral secrets (a nullifier and secret key) to a scoped metadata payload—containing audience restrictions and expiration parameters—anchored to the public DNS via a lightweight TXT record.

This approach eliminates the need for an active web server during validation. A prover generates a self-contained, portable, and purely stateless proof artifact that can be verified client-side by any relying party, with revocation handled via O(TTL) DNS record deletion. We implement a reference toolchain using the Groth16 proving system and the Poseidon hash function, achieving a circuit complexity of just 1,756 constraints and sub-15ms verification times on consumer hardware. Our security analysis demonstrates that PTX effectively mitigates replay attacks through context-commitment public inputs while offering a privacy-preserving alternative to interactive DCV for identity assertions in decentralized environments.
Expand

30 December 2025

Baylor University
Job Posting Job Posting
The Department of Computer Science at Baylor University invites applications for a Clinical Assistant or Associate Professor position specializing in Cybersecurity. This position will begin in August 2026. The successful candidate must have a Ph.D. or M.S. in Computer Science or a related field. Relevant industry or government experience in cybersecurity is highly sought. They must also demonstrate a commitment to excellence in teaching, the development of a cybersecurity program, and effective communication and organizational skills. The selected candidate will primarily focus on teaching and curriculum development in cybersecurity at both undergraduate and graduate levels. Responsibilities include mentoring students, growing the cybersecurity program, and potentially engaging in applied research or industry collaborations. Active participation in departmental service and outreach is also expected. The selected candidate will be expected to engage in the Cybersecurity Research and Education Initiative (CREI), which the NSA and DHS designate Baylor as a National Center of Academic Excellence in Cyber Defense Education; additionally, the Central Texas Cyber Range (CTCR), a joint venture with McLennan Community College, focuses on cybersecurity education, applied research, and community engagement.

Closing date for applications:

Contact: [email protected]

More information: https://apply.interfolio.com/172168

Expand
Baylor University
Job Posting Job Posting
The Department of Computer Science at Baylor University seeks qualified candidates for the Patterson Endowed Chair position in Cybersecurity. This tenured position will begin in August 2026. We look for exceptional candidates with vision who will expand innovative research and teaching that addresses challenging problems in the field of cybersecurity. The candidate will have exceptional international research credentials in cybersecurity, a strong track record of securing research funding, and experience leading research initiatives. Excellence in teaching at both the undergraduate and graduate levels is essential. This pivotal role calls for an established leader who will forge and drive research collaborations inside the department or across the university.

Closing date for applications:

Contact: [email protected]

More information: https://apply.interfolio.com/174057

Expand
iTrust @SUTD, Singapore
Job Posting Job Posting
Looking for researchers with outstanding expertise on CPS security in general, AI for CPS security, maritime cybersecurity. Please send CV to Prof. Jianying Zhou ([email protected]). Only short-listed candidates will be contacted for interview.

Closing date for applications:

Contact: Prof. Jianying Zhou

More information: http://jianying.space/

Expand
University of Waterloo
Job Posting Job Posting
The Faculty of Mathematics at the University of Waterloo is seeking internationally renowned scholars and researchers to apply to be nominated for the Canada Impact+ Research Chairs Program. Detail of this program can be found at https://www.canada.ca/en/impact-plus-chairs/program-details/competition/2026/apply.html The field of research of the appointee must be aligned with one or more of the program strategic priority areas. Cybersecurity is included as one of the strategic priority areas. Only candidates who are internationally based (residence and employment outside of Canada) at the time of application are eligible to apply.

Nominees are required to have a PhD (or equivalent) and will be appointed in a University of Waterloo academic department/unit as a full professor or associate professor with a promotion to full professor within two years of starting their appointment, or, if recruited from outside the academic sector, must possess the necessary qualifications to be appointed at these levels. The rank and salary will be commensurate with qualifications and experience.

For the complete job announcement and application procedures, see: https://ofas.uwaterloo.ca/job-details/123

Closing date for applications:

Contact: David Jao ([email protected])

More information: https://uwaterloo.ca/research/sites/default/files/uploads/documents/canadaimpactchairs_job-ad_final.pdf

Expand
Bocconi University, Milano, Italy
Job Posting Job Posting
We invite applications for a post-doctoral research position in cryptography focused on privacy-preserving computation and advanced cryptographic protocols. Relevant research areas include fully homomorphic encryption, secure multi-party computation and threshold cryptography, and lattice-based cryptography.

The successful candidate will join the cryptography group at Bocconi, working in a highly international and interdisciplinary environment.

Requirements: PhD in Computer Science, Mathematics, or a related field (or PhD completion expected within 6 months), strong background in cryptography, particularly FHE, MPC, or threshold cryptography, and a solid publication record in leading venues. Programming experience is a plus.
Fluency in English is required; Italian is not.

Position: Full-time post-doctoral position, 2 years (renewable). Starting date: 1 March 2026 (flexible).
Application deadline: 31 January 2026. Applications must be submitted online at: https://jobmarket.unibocconi.eu/?id=890

Closing date for applications:

Contact: For more information, please contact Emmanuela Orsini ([email protected])

More information: https://jobmarket.unibocconi.eu/?id=890

Expand

29 December 2025

Debrup Chatterjee
ePrint Report ePrint Report
We present SumSig, a code-based digital signature scheme that leverages sum-check protocols to reduce the reliance on repetition in Fiat–Shamir-based constructions. Instead of repeating a constant-soundness $\Sigma$-protocol many times, our approach verifies algebraic consistency of the entire witness via a single sum-check over an extension field, achieving negligible soundness error without repetition.

Our construction introduces three main ideas: (1) a representation of the syndrome decoding witness as a multilinear polynomial suitable for sum-check verification; (2) a degree-doubling binarity enforcement technique based on power-sum constraints $S_1 = S_2 = S_4 = w$ to ensure binary witnesses; and (3) a linearization helper polynomial that enables efficient simulation in the random oracle model.

For 128-bit security, SumSig yields signatures of approximately 5–8 KB with public keys of 50–100 KB, depending on the polynomial commitment scheme. This offers a different trade-off compared to existing code-based signatures such as Wave and LESS, which achieve either very small signatures with large public keys or moderate public keys with larger signatures. The resulting scheme features deterministic signing with no aborts and admits a quasi-tight reduction to the Syndrome Decoding problem in the random oracle model.
Expand
Ioannis Kaklamanis, Wenhao Wang, Harjasleen Malvai, Fan Zhang
ePrint Report ePrint Report
Accurate measurements of user engagement underpin important decisions in various settings, such as determining advertising fees based on viewership of online content, allocating public funding based on a clinic’s reported patient volume, or determining whether a group chat app disseminated a message without censorship. While common, self-reporting is inherently untrustworthy due to misaligned incentives (e.g., to inflate).

Motivated by this problem, we introduce the notion of Verifiable Aggregate Receipts (VAR). A VAR system allows an issuer to issue receipts to users and to verify the number of receipts possessed by a prover, who is given receipts upon serving users. An ideal VAR system should satisfy inflation soundness (the prover cannot overstate the count), privacy (the verifier learns only the count), and be performant for large-scale applications involving millions of users.

We formalize VAR using an ideal functionality and present two novel constructions. Our first protocol, S-VAR, leverages bottom-up secret-sharing to enable tiered ``fuzzy'' audits, and achieves constant-size receipts regardless of the number of supported thresholds. Our second protocol, P-VAR, uses bilinear pairings to aggregate receipts into a proof verifiable in constant time, enables exact auditing, and can be extended to handle a dynamic user set. We prove both constructions secure with respect to our ideal functionality.

We implement and benchmark our VAR constructions. For a million users, issuance takes less than $2$ seconds for either scheme, and for audit proving time, P-VAR requires less than $10$ seconds and S-VAR requires less than $35$ seconds. Compared to our schemes, baseline and existing solutions are either at least an order of magnitude slower in proving and verification time, or they do not scale to one million users. Our benchmarks demonstrate that our VAR protocols can be used to enable verifiable and privacy-preserving user engagement auditing at scale. Finally, we showcase how VAR can be integrated with the aforementioned applications.
Expand
Zhengjun Cao, Lihua Liu
ePrint Report ePrint Report
We show that the secret sharing scheme [Cryptogr. Commun. 16(1): 3-20 (2024)] cannot be put into practice. (1) It confused the elements in a residue class ring modulo a prime $p$ with the points in an elliptic curve group over the finite field $F_p$. (2) It confused the underlying elliptic curve with the Lagrange interpolating curve, and falsely requires the interpolating polynomial to map a point on the elliptic curve to another point on the same elliptic curve. (3) It misuses the bit-wise XOR operator for the operands with unequal bit-length, which results in the exposure of any participant's share, and the loss of confidentiality.
Expand
Eylon Yogev, Ziyi Guan
ePrint Report ePrint Report
We construct the first succinct non-interactive argument (SNARG) for NP in the common reference string model based on the sub-exponential hardness of the learning with errors (LWE) assumption. As a result, our construction is plausibly post-quantum secure. Previous constructions of SNARGs from falsifiable assumptions either relied on indistinguishability obfuscation or were restricted to idealized models (e.g., the random oracle model or generic group model).

Our construction is also the first to instantiate the Micali transformation (Fiat--Shamir applied to Kilian's protocol) in the standard model with concrete hash functions. We achieve this by developing a new mechanism to securely instantiate the Fiat--Shamir hash function for interactive arguments, overcoming the known barriers that limit standard techniques to interactive proofs. Our construction relies on two primitives of independent interest: a PCP with a new property we term "shadow soundness" and a lattice-based vector commitment that provides statistical binding with respect to a hidden function.

While our scheme has non-adaptive security and achieves only partial succinctness with argument size $O(n^{0.91})$, it serves as a foundational proof of concept that SNARGs can be based solely on standard lattice assumptions. Furthermore, our result refutes "universal" attacks on the Micali framework by demonstrating that there exist concrete instantiations of the underlying components for which the transformation is sound.
Expand
Zesheng Li, Xinxuan Zhang, Yi Deng
ePrint Report ePrint Report
Succinct Non-interactive Arguments of Knowledge (SNARKs) allow a prover to convince a verifier of the validity of a statement using a compact proof and sublinear verification time. However, a major obstacle to the broad application of SNARKs is the high memory and computational cost required for proof generation. Distributed proof systems offer a promising solution by distributing the proving workload across multiple machines. While recent pairing-based distributed SNARKs achieve sublinear costs, they suffer from a lack of post-quantum security and transparency. Conversely, recent hash-based schemes offer these features but have been limited to quasi-linear prover time.

In this paper, we present the first fully distributed, transparent, post-quantum SNARK with a linear-time prover while maintaining polylogarithmic verification time and proof size. Our main contributions are two-fold. First, we present a distributed multivariate Polynomial IOP (PIOP) for Rank-1 Constraint Systems (R1CS) based on the Spartan framework. This is achieved by introducing a novel distributed version of the SPARK compiler, which efficiently handles the polynomial commitment scheme for sparse polynomials. Second, we propose the first transparent and post-quantum distributed polynomial commitment scheme with a linear-time prover, building upon the Brakedown framework with proof composition. By compiling our distributed polynomial commitment with both existing and newly proposed distributed PIOPs, we obtain fully distributed SNARKs for Plonkish and R1CS. Both resulting systems are transparent, post-quantum secure, and achieve linear prover time with polylogarithmic verification costs, overcoming the limitations of prior works and enhancing the scalability of zero-knowledge proof systems.
Expand
Sriram Sridhar, Shravan Srinivasan, Dimitrios Papadopoulos, Charalampos Papamanthou
ePrint Report ePrint Report
Despite phenomenal advancements in the design and implementation of Zero-knowledge proofs (ZKPs) that have made them the preeminent tool for cryptographically ensuring the correctness of a wide range of computations, existing ZK protocols still incur high prover overhead in applications that entail accurately evaluating non-polynomial functions over floating-point numbers such as machine learning, decentralized finance, orbital mechanics, and geolocation. Current state-of-the-art approaches typically emulate floating-point numbers using fixed-point representations (via quantization), and handle non-polynomial functions using lookup tables, piece-wise or low-degree polynomial approximations, which lead to sub-optimal performance and/or loss in accuracy or generality, thus limiting their potential for adoption in practice.

In this work, we present a general framework for approximating a large class of non-polynomial functions using Gauss-Legendre quadrature which also supports efficient ZKPs of correct computation. We show that increasing the desired precision up to the limits imposed by quantization only increases does not increase the multiplicative circuit depth, which stays a small constant ($\leq4$) -- which is the main factor in the error growth of an approximation. We implement and evaluate our approach in Noir/Barretenberg, and we obtain absolute errors $2-256\times$ lower than comparable baselines for most non-polynomial functions with low prover overhead. We also demonstrate an efficient prover and low errors for high-precision applications in DeFi and astronomy that require non-polynomial functions, again obtaining errors $4-64\times$ lower than the baseline approximations.
Expand
Geoffroy Couteau, Srinivas Devadas, Alexander Koch, Sacha Servan-Schreiber
ePrint Report ePrint Report
In this paper, we define the notion of pseudorandom correlation generators (PCGs) and functions (PCFs) for garbled circuit correlations.

With a Garbling PCG or PCF, two parties can non-interactively generate a virtually unbounded number of secret-shared garbled circuits and corresponding secret-shared garbled inputs. With the shares of the garbled circuit and garbled input, anyone can recover the garbled circuit and evaluate it to obtain the result of the computation in the clear.

In the process of constructing Garbling PCFs, we introduce a new primitive that we call a Topology-Adaptive PCF (TAPCF), which we construct from two different variants of the learning parity with noise (LPN) assumption. Informally, a TAPCF is a PCF that additionally allows the target correlation to be specified on-demand (i.e., at evaluation time). As a contribution of independent interest, we show that TAPCFs enable the first silent secure computation protocol with function-dependent silent preprocessing. Using our TAPCF construction as a building block, we construct a Garbling PCF that allows the parties to specify the circuit they wish to garble on the fly. Under realistic parameter settings, we estimate that, with our construction, two parties can generate one garbled circuit per second, for circuits with 10,000 AND gates.

Garbling PCFs have several applications: We provide constructions for (1) an efficient homomorphic secret-sharing scheme for specific high-depth circuits, (2) a zero-knowledge proof system over secret shares that supports checking unstructured languages, and (3) a semi-honest reusable two-round, two-party computation protocol supporting non-interactive public outputs.
Expand
Andes Y. L. Kei, Sherman S. M. Chow
ePrint Report ePrint Report
A growing adoption of transformer-based machine learning models is raising concerns about sensitive data exposure. Nonetheless, current secure inference solutions incur substantial overhead due to their extensive reliance on non-linear protocols, such as softmax and Gaussian error linear unit (GELU). Driven by numerical stability needs, softmax approximations (e.g., NeurIPS 2021) typically extract the maximum element of an input vector, incurring logarithmic rounds (in the input length). Existing GELU protocols (e.g., S&P 2024) use piecewise approximations with high-degree polynomials that rely heavily on secure multiplications and comparisons, which are expensive. Such complexities also hinder model owners unfamiliar with cryptography from deploying custom models.

SHAFT, our proposed system, provides a secure, handy, accurate, and fast transformer inference framework for deployment. Highlights of our contributions include 1) the first constant-round (independent of sequence length) softmax protocol for transformers, using input clipping and an ordinary differential equation characterization, and 2) a highly accurate GELU protocol on a novel characterization designed for Fourier series approximation. Extending to broader contexts, our new protocols also apply to general neural networks that use softmax as the final layer and to transformer architectures with different activation functions. Remarkably, SHAFT outperforms state-of-the-art SIGMA (PETS 2024), which uses secret sharing, and BumbleBee (NDSS 2025), which additionally uses RLWE-based homomorphic encryption. More specifically, SHAFT reduces communication by 62–70% and is 1.8–2.4× faster than SIGMA, while also surpassing BumbleBee in terms of running time by 2.6–3.7× under LAN settings. Alongside these improvements, SHAFT attains accuracy comparable to plaintext models, confirming its numerical stability. Next in this progression, SHAFT provides an accessible open-source framework for secure and handy deployment by smoothly integrating with the Hugging Face library (EMNLP Demos 2020).
Expand
Han-Bing Yu, Qun-Xiong Zheng, Wen-Feng Qi
ePrint Report ePrint Report
Sequences over the residue ring of integers modulo $m$ generated by linear feedback shift registers (LFSRs) exhibit ring-level linearity and bit-level nonlinearity, making such kind of LFSRs (denoted as $\mathbb{Z}/(m)$-LFSRs) a key component of stream ciphers. Beyond fundamental cryptographic properties, the unpredictability of truncated $\mathbb{Z}/(m)$-LFSRs has attracted considerable attention as a critical security consideration in the design of stream cipher components. This paper investigates the unpredictability of truncated Fibonacci $\mathbb{Z}/(m)$-LFSRs under various scenarios. First, we provide a practical heuristic estimation for the values of two key parameters based on lattice theory, thereby avoiding previous blind search. This estimation is subsequently applied to determine the number of truncated digits required in different scenarios. Next, we develop a lattice-based method for finding annihilating polynomials over $\mathbb{Z}/(m)$ by the high-order truncated digits when the modulus $m$ is known but coefficients are unknown, filling a methodological gap for this specific case. Finally, we demonstrate that when both the modulus $m$ and coefficients are unknown but $m$ is close to a power of 2, our lattice constructed by the high-order truncated digits can yield annihilating polynomials over $\mathbb{Z}/(m)$ rather than $\mathbb{Z}$ as in [1], achieving a 41% reduction in digits and a 4x speedup for the recovery of ZUC's driving sequence with 17 high-order truncated digits. Experimental results confirm the efficacy of our methods.
Expand
◄ Previous Next ►