International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

25 January 2026

Nathan Nye, Philippe Teuwen, Tiernan Messmer, Steven Mauch, Struan Clark, Zinong Li, Zachary Weiss, Lucifer Voeltner
ePrint Report ePrint Report
This paper presents an in-depth analysis of vulnerabilities in MIFARE Ultralight C (MF0ICU2), MIFARE Ultralight AES (MF0AES), NTAG 223 DNA (NT2H2331G0 and NT2H2331S0), NTAG 224 DNA (NT2H2421G0 and NT2H2421S0), and widely circulated counterfeit Ultralight C cards based on Giantec GT23SC4489, Feiju FJ8010, and USCUID-UL. We reveal multiple avenues to substantially weaken the security of each technology and its implementation across a range of configurations. We demonstrate how, through relay-based man-in-the-middle techniques and partial key overwrites --- optionally combined with tearing techniques --- an attacker can reduce the keyspace of two-key Triple DES (2TDEA) from $2^{112}$ to $2^{28}$ or less in certain real-world deployments, thereby making brute-force key recovery feasible with modest computational resources. We further discuss how the MIFARE Ultralight AES protocol can be similarly affected, particularly when CMAC integrity checks are not enforced. We also find that the security offered by NTAG 223 DNA and NTAG 224 DNA is undermined by the absence of integrity checks on commands and the calculation of a CMAC over Secure Unique NFC (SUN) messages, providing an unauthenticated ciphertext oracle that facilitates key recovery. Field observations, especially in hospitality deployments, underscore the urgent need for proper configuration, key diversification, and counterfeit detection.
Expand
Feifei Yan, Pinhui Ke
ePrint Report ePrint Report
Half-$\ell$-sequences, as a extension of $\ell$-sequences, have attracted research interest over the past decade. The arithmetic correlation of half-$\ell$-sequences is known for connection integers of the form $p^r$. In this paper, we extend this result by deriving the arithmetic correlation for half-$\ell$-sequences with connection integers of the form $p^r q^s $. The results indicate that when $p\equiv -1 \pmod{8}$ and $q\equiv \pm 3 \pmod{8}$, the arithmetic autocorrelation can be determined by the number of odd integers in the cyclic subgroup generated by $2$ modulo $p$.
Expand
Joppe W. Bos, Joost Renes, Frederik Vercauteren, Peng Wang
ePrint Report ePrint Report
The ongoing transition to Post-Quantum Cryptography (PQC) has highlighted the need for cryptographic schemes that offer high security, strong performance, and fine-grained parameter selection. In lattice-based cryptography, particularly for the popular module variants of learning with errors (Module-LWE) and learning with rounding (Module-LWR) schemes based on power-of-two cyclotomics, existing constructions often force parameter choices that either overshoot or undershoot desired security levels due to structural constraints. In this work, we introduce a new class of techniques that are the best of both worlds: structured Module-LWE (or LWR) embeds more algebraic structure than a module such that it significantly improves performance, yet less structure than a power-of-two cyclotomic ring such that it still enables more flexible and efficient parameter selection. We present two concrete instances: a construction based on a radical extension of a two-power cyclotomic field denoted radical Ring-LWE (RR-LWE) or Ring-LWR (RR-LWR), and a cyclotomic block-ring module lattice approach (BRM-LWE or BRM-LWR). These new structured Module-LWE and LWR reduce the required number of uniformly random bytes in its matrix by a factor up to the module rank and allows efficient NTT implementations while enabling more granular security-performance trade-offs. We analyze the security of these constructions, provide practical parameter sets, and present implementation results demonstrating a performance improvement of up to 37% compared to an optimized implementation of ML-KEM. Our techniques apply to both key encapsulation mechanisms and digital signature schemes, offering a pathway to more adaptable and performant PQC standards.
Expand
Alberto Marcos
ePrint Report ePrint Report
We present a fault injection attack against MAYO that, from a single faulty execution, enables the recovery of structural information about the secret. We consider a simple fault model: a controlled perturbation in a single oil coordinate of a signature block, which induces an error $e \in \mathcal{O}$ (the secret subspace) with a known oil part. We show that the observable mismatch in verification, $\Delta t = P^*(s') - t$, can be expressed exactly as the image of $e$ under a publicly derivable linear operator $\mathcal{L}$, obtained by expanding $P^*$ and using (i) the bilinearity of the differential $P'$ in characteristic $2$ and (ii) the key property $P(u)=0$ for all $u \in \mathcal{O}$. This linearization makes it possible to separate vinegar and oil coordinates and to reduce the recovery of the unknown component $e_V$ to solving a linear system over $\mathbb{F}_q$, under generic full-rank conditions for typical parameters. Once $e$ is recovered, the faulty signature can be corrected and, more importantly, a nonzero vector of the secret subspace is obtained, which serves as a starting point to scale to key recovery via known oil-space reconstruction techniques. We further discuss the practical feasibility when the exact position and value of the fault are unknown, showing that a bounded search over $k \cdot o$ positions and $q-1$ values keeps the cost low for the official parameter sets, and that the attack is also applicable to the randomized variant of MAYO.
Expand

24 January 2026

Huiwen Jia, Shiduo Zhang, Yang Yu, Chunming Tang
ePrint Report ePrint Report
Falcon is a selected signature scheme in the NIST post-quantum standardization. It is an efficient instantiation of the GPV framework over NTRU lattices. While the GPV framework comes with an elegant security proof in theory, Falcon had no formal proof involving concrete parameters for a long time. Until recently, Fouque et al. initiate the concrete security analysis of Falcon-type signatures. They give a formal proof of Falcon+, a minor modification of Falcon, in the random oracle model, whereas they claim that Falcon+-512 barely achieves the claimed 120-bit security for plain unforgeability. % and neither Falcon+-512 nor Falcon+-1024 offer strong unforgeability. Furthermore, they show that standard reductions for strong unforgeability are vacuous for Falcon parameters, necessitating the introduction of a new, non-standard assumption.

In this work, we revisit the concrete security analysis of Falcon-type signatures and present positive results. We develop improved analytic tools by leveraging the profile of the NTRU trapdoor bases. This eliminates the security loss for both Falcon+-512 and Falcon+-1024 in the case of plain unforgeability. We also apply our new analysis to the recent weak-smoothness variant Falcon-ws (Zhang et al. Asiacrypt 2025) that admits smaller parameters than Falcon under a non-standard assumption. As a result, we propose new parameters for Falcon-ws allowing for provable security under standard assumptions and signature size 17.8% (resp. 12.8%) smaller than that of Falcon-512 (resp. Falcon-1024) simultaneously. Moreover, we give a refined strong unforgeability security proof by replacing the worst-case analysis with a probabilistic analysis, which leads to a substantial increase in concrete security. Based on this, we show that by using a tighter Gaussian sampler, e.g. the one in Falcon-ws, Falcon-type signatures can achieve concrete security for strong unforgeability closely consistent with the claimed security level while keeping the compact size.
Expand
Dima Grigoriev, Chris Monico, Vladimir Shpilrain
ePrint Report ePrint Report
We use tropical algebras as platforms for a very efficient digital signature protocol. Security relies on computational hardness of factoring a given tropical matrix in a product of two matrices of given dimensions; this problem is known to be NP-complete. We also offer a secret sharing scheme with an arbitrary access structure where security of the shared secret is based on computational hardness of the same problem.
Expand
Islamabad, Pakistan, 24 November - 27 November 2025
School School
Event date: 24 November to 27 November 2025
Expand
Onna, Japan, 9 February - 13 February 2026
Event Calendar Event Calendar
Event date: 9 February to 13 February 2026
Submission deadline: 15 January 2026
Expand
TU Wien (Vienna University of Technology)
Job Posting Job Posting
The Symmetric Cryptography Group at TU Wien, which is part of the Security and Privacy research unit, invites applications for a fully funded PhD position in provable symmetric cryptography. The Security and Privacy research unit at TU Wien is internationally recognized for its research in cryptography, security, and privacy. The working language of the group is English.


Candidate Profile

Applicants must meet the following criteria:

  • A completed Master’s or Diploma degree in Computer Science and/or Mathematics.
  • Formal exposure to cryptography, evidenced by the successful completion of at least one university-level cryptography course.
  • A clear and well-motivated interest in conducting research at the intersection of Arithmetization-Oriented cryptography and classical symmetric cryptography.

Preference will be given to candidates with knowledge of basic provable security, including standard security notions and proof techniques.

Application Deadline: February 20

Documents: human-generated 1. Letter of Motivation (1 p. max), 2. Detailed CV, 3. Degree Certificates and Transcripts, 4. Recommendation Letter/s, 5. Master’s Thesis (or Abstract), and publication list (if applicable).

Reviews will be on a rolling basis, thus early applications are strongly encouraged.

Closing date for applications:

Contact: elena (dot) andreeva (at) tuwien (dot) at

Expand
University of St. Gallen, School of Computer Science, Switzerland
Job Posting Job Posting
We invite applications for a PhD position in applied cryptography, with a focus on designing and analyzing cryptographic protocols that offer strong, provable security guarantees. The role provides the opportunity to work on cutting‑edge research emphasizing efficiency and scalability in real‑world deployments.

Key Responsibilities:
  • Conduct innovative research in applied cryptography and information security, with strong foundations in cryptography and a particular interest in provable security, MPC, and privacy‑preserving computation.
  • Develop secure and privacy‑preserving protocols with rigorous security proofs.
  • Support and assist in teaching courses on computer security and cryptography.
Required Qualifications:
  • MSc degree (or equivalent) in Computer Science, Mathematics, Electrical Engineering, or a related field.
  • Strong background in cryptography and mathematics.
  • Solid programming skills.
  • Excellent written and verbal communication skills in English.

Closing date for applications:

Contact: Prof. Katerina Mitrokotsa, [email protected]
Deadline: 15 February 2026
Submission of applications: online (https://career.hrsuite.unisg.ch/mein-portal/mein-lebenslauf-fuer-meine-bewerbung-fuer-phd-position-in-applied-cryptography-and-privacy-preserving-computation-)

More information: https://jobs.unisg.ch/offene-stellen/phd-position-in-applied-cryptography-and-privacy-preserving-computation-m-w-d/6c682dbd-b33c-4956-b130-7dc7e3890574

Expand
Technical University of Darmstadt, Germany
Job Posting Job Posting
The Department of Computer Science at the Technical University of Darmstadt and the National Research Center for Applied Cybersecurity ATHENE is establishing an ATHENE Research Group in Real-World Cryptography. We are looking for outstanding candidates to become an ATHENE Early Career Fellow and provide generous funding for establishing an independent research group.

The ATHENE Research Group will closely collaborate with researchers within ATHENE and the Cybersecurity and Privacy research field at the Technical University of Darmstadt. We are seeking for candidates in all areas of applied cryptographic research, including (but not limited to):
  • Cryptographic protocols, including blockchains and zero-knowledge proof systems
  • Symmetric cryptography
  • Security of cryptographic implementations
  • Formal methods for real-world cryptography
  • Post-quantum cryptography
  • Cryptography for privacy
  • AI for Cryptography / Cryptography for AI
Candidates must have a completed a PhD in Computer Science or related area, an outstanding publication record, and a demonstrated experience in working with the international research community. The application documents (CV, PhD certificate, publication list, motivation letter, research and teaching statement) should be submitted latest by February 28, 2026 via the following link: https://www.career.tu-darmstadt.de/tu-darmstadt/apply/52139.

The short-listed candidates will then participate in the selection process at the Department of Computer Science. The Research Group is funded by ATHENE initially for 3 years with an extension for additional 3 years upon positive evaluation. For additional information, please contact Sebastian Faust (sebastian.faust (at) tu-darmstadt (dot) de).

Closing date for applications:

Contact: Sebastian Faust (sebastian.faust (at) tu-darmstadt (dot) de).

More information: https://www.career.tu-darmstadt.de/tu-darmstadt/job/52139

Expand
University of Kassel, Germany
Job Posting Job Posting

The Information Security Group at the University of Kassel is looking for motivated candidates for a PhD position.

About the Position:

  • It will be funded for 3 years.
  • The candidate will do research on (password-based) key exchange protocols and related primitives (such as public-key encryption and digital signatures).
  • It is expected to publish research results at major conferences in cryptography and IT security, such as Crypto, Eurocrypt, Asiacrypt, ACM CCS, etc..
  • In addition, the candidate will support the teaching activities of the group.
  • Funding is available for conference travel and research stays.

Your Profile:

We are looking for a highly motivated candidate with:

  • A master’s degree (or equivalent) in Computer Science, Mathematics, or other related fields. We encourage candidates who will finish their master degree in 2026 to apply.
  • A strong background in public-key cryptography and provable security or abstract algebra.
  • Prior knowledge in any of the relevant areas is highly desirable, including key exchange protocols, lattices, isogenies, quantum random oracle techniques, and tight security proofs.
  • Very good English proficiency (German is not required but beneficial).
  • The ability to work independently and as part of a team.

Starting Date: As soon as possible. The starting date is negotiable, provided it is within 2026.

Interested?

Please send the following documents to me via email ([email protected]) until (including) 26 February 2026:

  1. A motivation letter (that describes your research interests and why you would like to work with our group)
  2. A curriculum vitae
  3. Academic transcripts and certificates
  4. Contact details of 1–2 academic referees (At least one should be your thesis supervisor)

Closing date for applications:

Contact: Jiaxin Pan

Expand
Nokia Bell Labs
Job Posting Job Posting
We have two internship positions: (1) Practical Secure Multi-Party Computation (MPC) protocols for AI, Communication and Multimedia, (2) Privacy-preserving fuzzy protocols for biometric-based authentication. In general, we are looking for practical people interested in applications of MPC and FHE. Some knowledge of AI would be a plus, but it's not necessary. The positions in Antwerp (Belgium) with the duration of 3 to 5 months depending on your conditions.

Closing date for applications:

Contact: Emad Heydari Beni ([email protected])

Expand
Department of Mathematical Sciences, NTNU
Job Posting Job Posting
The position is part of the Quantum-Resistant Cryptography in Practice (QARC) project, funded by the Horizon Europe programme. The work will involve cryptographic design and analysis to support secure, practical implementations for real-world quantum-resistant cryptography. The main application topics will be cryptographic voting, secure cloud storage and eGovernment services. Of particular interest will be hybrid schemes and cryptographic agility. There will also be a need to do further theory work, e.g. on QROM and related techniques.

Closing date for applications:

Contact: Kristian Gjøsteen ([email protected])

More information: https://www.jobbnorge.no/en/available-jobs/job/292244/postdoctoral-fellow-in-quantum-safe-cryptography

Expand
Gachon University, South Korea
Job Posting Job Posting
Information Security and Machine Learning Lab (https://ai-security.github.io/index_e.htm) has conducted research in a range of areas including artificial intelligence, cyber security and cryptography. We are also extending our areas to emerging areas such as quantum computing and parallel computing. Post-doctoral research fellows are welcome from computer science/engineering, electric/electronics, and mathematics/statistics. Applicants with good high-impact conference/journal publication records are encouraged to send their CVs, publication records and research statement to Professor Seong Oun Hwang (seongoun.hwang at gmail.com) by February 28, 2026.

Closing date for applications:

Contact: Prof. Seong Oun Hwang

More information: https://ai-security.github.io/index_e.htm

Expand
Fukui, Japan, 27 October - 30 October 2026
Event Calendar Event Calendar
Event date: 27 October to 30 October 2026
Submission deadline: 28 February 2026
Notification: 28 April 2026
Expand
Rome, Italy, 10 May 2026
Event Calendar Event Calendar
Event date: 10 May 2026
Submission deadline: 1 February 2026
Notification: 22 March 2026
Expand
Rome, Italy, 10 May 2026
Event Calendar Event Calendar
Event date: 10 May 2026
Submission deadline: 23 January 2026
Expand
Eindhoven, Netherlands, 26 June 2026
Event Calendar Event Calendar
Event date: 26 June 2026
Expand
Leuven, Belgium, 10 August - 14 August 2026
Event Calendar Event Calendar
Event date: 10 August to 14 August 2026
Submission deadline: 30 April 2026
Notification: 5 June 2026
Expand
◄ Previous Next ►