IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
03 August 2026
Bo-Yin Yang
Leonardo Colò, Maher Mamah, Youcef Mokrani, Bruno Sterner, Nicolas Swanson
We present four constructions that work in various settings. The first, Windmill-ZKP assumes that the prover knows only two parallel isogenies in the diamond. The second, Cube-ZKP assumes the prover has knowledge of four of specified degree isogenies. Finally, Kube-ZKP and Kani-ZKP prove knowledge of isogeny diamonds whose degree sum is smooth. We also provide proof-of-concept implementations of the proposed constructions and compare their performance. Our results demonstrate the trade-offs between security, efficiency and compactness in these constructions.
Timofey Yaluhin
Xiaodong Wang, Shengzhe Meng, Zijie Lu, Bei Liang
In this work, we propose a unified framework for private computation on weighted set intersection. We formalize \textit{Private Filtering and Aggregation for Weighted Set Intersection} (PFA-WSI) as an ideal functionality parameterized by a joint scoring function $f$ and a predicate $P$, supporting two output modes: (i) \emph{predicate-filtered output}, which reveals a predicate-selected subset of intersection items, and (ii) \emph{aggregated output}, which reveals only aggregate statistics over matched items. By instantiating $f$ and $P$ appropriately, PFA-WSI captures deployed and studied tasks such as PI-Sum, inner-product PJC, and IMWS, and also accommodates richer metrics arising in practice, such as $L_1$- and $L_2$-type distance statistics on matched item weights.
To realize PFA-WSI efficiently, we introduce a novel core building block, Oblivious Encrypted Weight Transfer (OEWT), which enables a receiver to obtain encryptions of the sender's weights for intersection items and random-looking ciphertexts otherwise. Building on OEWT and additively homomorphic encryption, we present modular protocol constructions for different instantiations of $f$ and for both output modes. We prove simulation-based security in the semi-honest model and provide detailed communication and computation analyses. Our experiments show that our constructions scale to million-sized sets with practical performance that matches or surpasses the state-of-the-art.
José Luis Delgado
The same fixed root functions support full-key recovery in every security category and allow precomputation to be reused across targets and versions. A streaming first-distinguished-point construction replaces storage of the signature corpus by certified chain coverage and an identifier-free endpoint index. Its membership-hit law is exact conditional on realized distinct coverage, with separate forecasts for chain construction, tags, fingerprints, and MPHF storage. A Category-I \(\mathrm{GF}(2)\) design point uses 52 GiB, \(2^{52}\) signatures, and target coverage \(C=2^{77}\); conditional on that coverage, its success is \(0.631940886333\) and its normalized serial forecast is below \(2^{94}\). Pinned probes reproduce the fixed roots for every official tag from v2.0.0 through v2.1.1 and a pinned current revision in Categories I, III, and V. Salt-bound, domain-separated root expansion eliminates the collision and reusable-precomputation channels.
Yicheng Li, Claudio Orlandi, Lawrence Roy, Yizhou Yao
Our constructions are inspired by recent advances in homomorphic secret sharing and techniques for distributed discrete logarithm computation, and explore complementary points in the design space. The first construction is based on the Damg{\aa}rd--Jurik cryptosystem and standard assumptions, at the cost of a one-time trusted setup. The second eliminates the need for any setup, relying instead on a power-DDH assumption over prime-order groups. For typical parameters with $\lambda=128$, our schemes require approximately $2.5$ KB and $1$ KB of communication, respectively, to generate $128$ random OTs, and outperform existing OT extension techniques for batch sizes up to $\ell \leq 2^{15}$.
Behzad Abdolmaleki, Prastudy Fauzi, Jiaqi Gu, Toomas Krips, Nahid Roustaeifar
31 July 2026
Princeton University DeCenter
Closing date for applications:
Contact: [email protected]
More information: https://apply.interfolio.com/185365
Frontier AI Security Residency - Cambridge, United Kingdom
Closing date for applications:
Contact: [email protected]
More information: https://www.securefrontier.ai/
AWS
See link for application.
Closing date for applications:
Contact: Jake Massimo
More information: https://www.amazon.jobs/en/jobs/10476858/applied-scientist-amazon-cryptographic-libraries
Royal Holloway, University of London
Applications are invited for the post of Lecturer in Information and Cyber Security (Teaching and Research) in the Department of Computing, Security, and Mathematics.
Royal Holloway’s Faculty of Science is home to the world-renowned Information Security Group (ISG). The group is placed within the Faculty’s Department of Computing, Security, and Mathematics. The ISG has a record of outstanding research and hosts established research groups under the themes of: Cryptography, People and Society, Smart Card and IoT Security, Systems and Software Security. The ISG is now recruiting for a research and teaching lectureship in information and cyber security.
The ISG is committed to delivering excellent teaching at both undergraduate and postgraduate level. Our MSc in Information Security, the first of its kind anywhere in the world when it was launched in 1992, is accredited by The National Cyber Security Centre (NCSC) and has over 4,000 alumni worldwide. The Department has received an ACE-CSE Gold Award recognising excellence in cyber security education from the NCSC.
We welcome applications from individuals with a strong academic track record whose work relates to one or more of the ISG’s themes. We particularly welcome applications from those with industry and practice experience as a complement to their academic track record. Applicants will have, or show the potential for, a track record of excellence in both teaching and research and will demonstrate a strong trajectory in academic research that has the potential for significant impact. The successful applicant will demonstrate expertise in undergraduate and postgraduate teaching and the supervision of both undergraduate and postgraduate students.
The post is based in Egham, Surrey where the University is situated in a beautiful, leafy campus near to Windsor Great Park and within commuting distance from London. There will be also the opportunity to develop and deliver postgraduate programmes at our Central London campus, located in Bloomsbury.
Closing Date: 11 September 2026
Interview Date: 28 September to 9 October 2026
Closing date for applications:
Contact: Christian Weinert ([email protected])
More information: https://jobs.royalholloway.ac.uk/Vacancy.aspx?ref=0726-245
30 July 2026
David Rubin, Emanuele Cesena
The speedup comes from rewriting the Number-Theoretic Transform (NTT) and from vectorising all other stages of the verification algorithm. The novelty is to use a 32-bit Barrett-style representation, instead of the reference 16-bit Montgomery, and adopt Shoup-Harvey precomputed multipliers for twiddle reduction.
With all optimizations applied, hash-to-point (and specifically Keccak) is the dominant cost. We therefore propose a non-standard Falcon variant that replaces SHAKE256 with KTP256, an XOF based on KangarooTwelve with parallel squeeze. It cuts verification to 2.2 microseconds on Zen5, yielding 4.2 times over the baseline, and is of independent interest for any post-quantum scheme that uses a Keccak sponge to sample large amounts of data from a fixed seed. All code is open source.
Julia Lieb, Abhinaba Mazumder, Michael Schaller
Yaxi Yang, Xiaojian Liang, Weizhan Jing, Ye Dong, Xiangfu Song, Fangyuan Sun, Pu Duan, Tianwei Zhang
This paper presents the \textit{first} maliciously secure mPSO framework, named UM-PSO, that supports a broad range of set operations with practical efficiency. At the core of our framework is a function-independent preprocessing phase that prepares a reusable pool of secret-shared items, which can then be leveraged to securely compute diverse set functionalities in the online phase. To achieve malicious security efficiently, we design verification mechanisms on top of SPDZ-based authenticated secret sharing, along with tailored techniques and optimizations to further improve practical performance. We implement our protocols and report concrete performance results. For a representative setting with 5 parties and a total of $2^{12}$ 128-bit items, our framework achieves an online running time of $0.627$ seconds and incurs $3.35$ MB of communication. Compared to the baselines, our framework achieves up to $51\times$ speedup and $76\times$ lower communication cost.
Mariya Georgieva Belorgey, Benoit Cogliati, Simon Demarty, Lois Huguenin-Dumittan, Özcan Öztürk, Salma Rasti Samiei, Oana Stan
Manav Mittal, Yogesh Kaushik, Anirudh S Kumar, Mukulika Maity, Sambuddho Chakravarty
ViNET, a system that cleverly repurposes Video over LTE (ViLTE) calls, often operational during shutdowns, into a stealthy conduit for real-time Internet access. By ingeniously embedding network traffic in ViLTE packets, ViNET achieves robust 60 to 400 Kbps transmission rates, matching 2G speeds and surpassing previous solutions like Dolphin by 1500x–4000x, while ensuring end-to-end TLSbased confidentiality and integrity. This performance enables text-based web browsing with page loads in seconds to minutes, 1 MByte file downloads in ≈30s, and seamless messaging over Telegram.
ViNET also outsmarts machine learning-based traffic classifiers, achieving a remarkable false positive rate, at times as high as 40%, when attempting to detect ViNET using SOTA models. With such standout metrics, ViNET emerges as a formidable ally, offering a performant, reliable and privacy-first lifeline, in the face of Internet shutdowns.
Pierre-Augustin Berthet
Thomas Crasson, Florian Méhats
Mihir Bellare, Rishabh Ranjan, Doreen Riepel
Daniel De Almeida Braga, Pierre-Alain Fouque, Bachir Lachguel, Thomas Prest
To address portability issues, Pornin (ePrint 2019/893) proposed an implementation of \falcon that emulates floating-point arithmetic using integer operations. While it enables deployment on a wider range of platforms, this approach incurs a substantial performance penalty compared to the native floating-point implementation.
This work studies the theory and practice of implementing Falcon's signing procedure in fixed-point arithmetic. This requires a specific analysis of the boundedness and precision of intermediate variables.
1. Our boundedness analysis revolves around a key fact: almost every intermediate variable arising during key expansion and signing is bounded by a function of four quantities that can be computed at key generation time. Our modified key generation enforces thresholds on these quantities through a light rejection step that rejects less than 50% of initial Falcon keys. This then yields sharp, unconditional bounds on all fixed-point variables. Establishing these bounds is highly nontrivial, and relies on Gaussian concentration arguments as well as on symplectic pairs, a generalization of symplecticity.
2. Our precision analysis remains, for now, partly empirical. Following a Rényi divergence argument, our main theorem proves the security of fixed-point Falcon conditioned on error bounds of certain intermediate values. These error bounds are derived empirically based on extensive experiments.
We provide a C fixed-point implementation. It is approximately a factor of two slower than the original floating-point \falcon implementation, but achieves a speedup of an order of magnitude compared to emulated floating-point implementations.