IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
23 August 2026
Umeå University, Sweden
Closing date for applications:
Contact: Mustafa Khairallah ([email protected])
More information: https://umu.varbi.com/en/what:job/jobID:959742/
University of Bath
The Department of Computer Science wishes to appoint academic staff in cyber security. The appointments will be made at Lecturer (Assistant Professor), Senior Lecturer (Associate Professor) or Reader (Associate Professor). Two positions are available with the level of employment commensurate with experience, achievements and research standing.
We are especially interested in candidates with a track record in technical areas of cyber security, including but not limited to:
- AI assurance,
- safety-critical systems,
- verification and validation,
- secure software engineering.
You will be a core member of our new Cyber security, Safety and Governance research group, helping to shape its vision, drive its strategic development, and strengthen Bath’s position as an internationally recognised centre for cyber security. You will also have opportunities to build bridges with our established research groups in AI and Machine Learning, Human-Computer Interaction, Mathematical Foundations of Computation, and Visual Intelligence.
Our highly collaborative approach means many opportunities exist to work with researchers in the other groups and across the university, as well as with regional, national and international partners. We will work with you to support the deepening of existing collaborations and the development of new ones. You will offer us a strong research record and the ability and enthusiasm to create an engaging experience for our excellent students.
The University of Bath is based on an attractive, single-site campus that facilitates interdisciplinary research. It is a Top-Ten University (https://www.bath.ac.uk/corporate-information/rankings-and-reputation/) that is located on the edge of the World Heritage City of Bath and offers the lifestyle advantages of working and living in one of the most beautiful areas in the UK.
The lecturer will be appointed at Grade 8, Senior Lecturer and Reader will be appointed at Grade 9.
Closing date for applications:
Contact: Professor Eamonn O’Neill, Head of Department
Institute of Computer Engineering of the University of Luebeck, Germany
- Trustworthy Integrated Circuits (IC) from hardware design to actual implementation.
- Trusted computing architectures and platforms: root-of-trust, secure system-on-chip design, RISC-V based Secure processor extensions and systems.
- EDA tools for reliability and security evaluation spanning all layers from the Electronic System Level down to the gate-level phases.
- Machine learning across the hardware life cycle, covering design-time verification and runtime monitoring, threat detection, and adaptive countermeasures
Teaching responsibilities include participation in the university’s bachelor’s and master's degrees and other STEM programs. A willingness to contribute to the further development of the program curriculum is expected. Candidates are expected to provide evidence of didactic aptitude and a substantial record of independent university teaching.
Fur further details, please check the official job posting. Please submit your applications by August 31.
Closing date for applications:
Contact: For questions regarding the organizational process, please contact [email protected].
More information: https://stellenangebote.uni-luebeck.de/jobposting/145e61a153a0d8ec85e209c5bf32bd06f56cc6370
22 August 2026
Jiayu Li, Gongli Li
We present a verifiable winner-only tally-hiding construction for weighted binary voting. Registered weights are bound to credentials in zero-knowledge ballots, while weighted contributions remain encrypted through aggregation and comparison against a public threshold. The blockchain adjudicates ballots, an off-chain backend performs the encrypted computation, and exact ciphertext and transcript bindings allow any public verifier to check that the published outcome corresponds to the accepted ballots. The only tally-derived plaintext output is the outcome bit.
The construction is parameterized by electorate size and contribution width; our prototype and formal transcript-privacy result deliberately study a bounded eight-voter, eight-bit instance with 134 encrypted gates and an actual three-of-five final release. For honest execution by all five trustees, we prove passive-public-observer backend transcript privacy from the accepted ciphertexts and outcome alone. Privacy against malicious sub-threshold trustees remains open.
Mingli Wu, Tsz Hon Yuen, Man Ho Au, Siu-Ming Yiu
Our experiments show that Multi-PGBF and C-Multi-PGBF obtain the best encoding and decoding efficiency. Multi-PGBF improves the encoding time of RR (CCS’22) by $65.1\%\sim 77.6\%$, while C-Multi-PGBF improves the encoding time of the clustered RR variant by $60.2\%\sim 64.7\%$. For decoding, Multi-PGBF is $28.6\%\sim 62.4\%$ faster than RR (CCS'22) and $89.7\%\sim 96.3\%$ faster than RB-OKVS (Usenix'23). When integrated into the state-of-the-art two-party and multi-party private set intersection protocols (Eurocrypt'21, Usenix'24), Multi-PGBF and C-Multi-PGBF lead to faster protocols than those using existing OKVS constructions in most settings.
Xiaopeng Zhao
Seyedmohammad Nouraniboosjin, Fatemeh Ganji
Shahram Khazaei
Anasuya Acharya, Aditya Patankar, Arpita Patra, Divya Ravi, Raghavendra Vernekar
In this work, we study the round complexity of MPC with fall-back security in the threshold corruption setting, presenting constant-round protocols for optimal thresholds. We present a semi-honest fall-back secure protocol for $t < \frac{n}{2}$ with 3 rounds, in the plain model, whereas the best known protocol in the same setting takes at least 11 rounds. In the CRS model, we present a maliciously fall-back secure protocol for the same threshold with 4 rounds, satisfying unanimous abort (UA). Finally, we extend this to a 5-round protocol that satisfies fairness in the presence of unbounded adversaries for $t < \frac{n}{2}$ corruptions and UA tolerating PPT adversaries for arbitrary corruption beyond that. In the malicious setting, we construct the first constant-round fall-back secure protocols.
Roberto Civino
Over this group the Midori/Craft S-box has four probability-one relations, forming a small subgroup of the dual which the S-box preserves in both directions. Inside that subgroup a mask propagates deterministically and linearly, so the search for the best trail is a minimum weight codeword problem, which we solve exactly by complete enumeration rather than heuristically.
A trail costs correlation, and it restricts the key to a weak-key class. The two are usually derived from the same data. We show that the correct reading, obtained by analysing the diffusion layer and the key addition together rather than separately, gives a class several bits larger than the one obtained cell by cell. One concrete consequence is that Craft’s round constants, whatever their values, impose no restriction at all.
On Craft we obtain weak-key distinguishers up to eighteen rounds. At fourteen rounds the squared correlation is 2−44 over a class of 2^108 keys, against 2−62.12 for the designers’ linear hull, which is the best known linear result on the cipher and holds for all keys. On that class we therefore improve the best linear correlation by eighteen bits at equal round count, and we reach four rounds further than the best known linear hull. Both the distinguishers and the weak-key criterion are verified experimentally, with a negative control on random keys.
Kaniuar Bacho, Alexandru Cojocaru
In this work, we initiate the study of a weaker form of remote state preparation, which we call eavesdropper-blind remote state preparation (EB-RSP). Informally, EB-RSP requires blindness only against external observers who see the transcript of the honest protocol, rather than against the quantum server itself. Despite this relaxed adversarial model, the resulting notion remains sufficient for useful cryptographic applications. In particular, we show that two-message EB-RSP already suffices to construct quantum public-key encryption with classical public keys and quantum ciphertexts. We then construct two-message EB-RSP protocols from specific one-way group actions, yielding a first step toward RSP-type primitives based on assumptions that do not rely on trapdoors. Finally, we observe that existing RSP constructions are likely naturally adaptable to the two-message EB-RSP notion; we demonstrate this explicitly for a concrete TCF-based RSP construction.
Guoqiang Liu, Bing Sun
Porter Eldridge Coggins
Porter E. Coggins, III
Chen Qian, Xingyu Zhao, Hao Cheng, Zengpeng Li, Puwen Wei, Quan Yuan
We construct $\mathsf{TPilaf}$, the first two-round threshold signature scheme that combines partially non-interactive signing with a fully tight proof against adaptive corruptions. The scheme is pairing-free and is built in prime-order groups from the $\mathsf{MDDH}$ assumption in the random-oracle model. Its first-round messages can be generated offline, and any threshold set of signers can aggregate their second-round shares into a single publicly verifiable signature.
The proof combines two ingredients. First, we introduce a linearly homomorphic dual-mode commitment with targetable opening. This lets the simulator open an already fixed commitment to the aggregate target imposed by a later Fiat-Shamir challenge. Second, we use profile-wise zero-sum masking with posterior completion. Corruption openings and signing responses are therefore sampled from the exact conditional law while values already visible to the adversary remain cached. Together, these tools enable a delayed branch-decision argument. The reduction waits until the adversary's own queries determine the last touched coordinate, completes only latent state, and then binds the forged hidden branch. The final bound has no combinatorial loss in the number of users, threshold, sessions, or corruption patterns, and contains only the explicit bad-event and assumption terms appearing in the theorem.
Alex Aïdan, Sébastien Canard, Emmanuel Fouotsa, Nyiang Melchisedech Mbeng
Sunghyeon Jo
Xiaomeng Sun, Eik List, Wenying Zhang
Kyeongtae Lee, Jihye Kim, Hyunok Oh
Our key technical contribution is $\textit{Split-Butterfly-Merge}$ ($\mathsf{SBM}$), an NTT algorithm in the read-write streaming model with $\mathcal{O}(\log N)$ memory, $\mathcal{O}(N \log N)$ total I/O, and $\mathcal{O}(\log N)$ sequential passes over external storage.
Combining SBM with streaming sparse R1CS evaluation and chunked Pippenger MSM yields a verifier-compatible Groth16 proving path that exchanges RAM for sequential storage I/O and wall-clock time. Our prototype uses a fixed-window MSM engineering point; the measurements validate memory reduction and proof compatibility, while the theorem states the asymptotically tuned MSM schedule.
We implement $\textsf{Sluice}$ over BN-254. Direct prove-only runs produce valid 128-byte proofs through $N=2^{25}$. The same-size bounded-memory comparison is at $N=2^{23}$: $\textsf{Sluice}$ succeeds under an 8GB Linux cgroup cap, whereas the standard prover is killed under 8GB and 12GB caps and succeeds only at 16GB. These results position $\textsf{Sluice}$ as a storage-rich, RAM-limited proving option rather than a replacement for optimized in-memory provers.
Paul Gerhart, Nadav Kohen, Jesse Posner, Matias Furszyfer
In this work, we resolve this limitation by formalizing nested threshold multi-signatures, a new cryptographic primitive for thresholdizing one participant inside a multi-signature protocol. As an instance of this primitive, we present Iceberg, the first construction for nested threshold MuSig2 signatures. Iceberg enables one side of a Lightning channel to operate as a $t$-of-$n$ threshold group while appearing to the counterparty as a standard MuSig2 participant. As a result, threshold custody can be deployed unilaterally on today's Lightning Network without requiring any modifications to Bitcoin, the Lightning protocol, or channel counterparties.
We prove the security of Iceberg, integrate a prototype into a production Lightning node, and benchmark its performance. Our measurements show that thresholdizing a Lightning channel incurs only modest overhead, since a threshold group tolerating one corrupted member sustains over $93\%$ of the payment throughput of an unmodified endpoint.