International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

18 December 2025

Francesco Berti, Sasha Petri, Itamar Levi
ePrint Report ePrint Report
We present an extend-and-prune fault Injection attack on serial implementations of Learning With Rounding that drop the least-significant bits. By iteratively isolating and recovering progressively larger key portions via faults, the attack recovers the secret key.
Expand
Francesco Berti, Itamar Levi
ePrint Report ePrint Report
We extend a PUF-based authentication protocol with key refresh, hierarchical groups, and revocation. Our framework enables secure communication among enrolled devices without server interaction, allowing group leaders to derive subordinate keys and the server to exclude compromised parties through controlled key updates.
Expand
Dev Mehta, Seyedmohammad Nouraniboosjin, Maryam S. Safa, Shahin Tajik, Fatemeh Ganji
ePrint Report ePrint Report
Despite decades of research in electromagnetic (EM) side-channel analysis (SCA), practical attacks still require manual effort and domain expertise to identify informative probe locations on target devices. Existing approaches rely heavily on exhaustive grid scanning or handcrafted alignment, limiting attack scalability and realism. In this work, we present the first automated and adaptive EM SCA framework that uses particle swarm optimization (PSO) to navigate the probe. Particles are guided by mutual information (MI) leakage maps, enabling efficient recovery of secret-dependent emissions. We introduce a novel application of the Nyström approximation to accelerate MI estimation across EM trace windows, allowing real-time swarm guidance without full kernel computations. Unlike prior work, our method requires no leakage templates, manual tuning, or alignment assistance, enabling automated attacks with minimal assumptions. We validate our framework on both microcontroller and FPGA platforms running AES-128. PSO-guided scanning identifies high-leakage points faster than grid search and reduces the number of traces required for successful CPA-based key recovery by up to a factor of 16, i.e., saving tens of thousands of traces.
Expand
Varsha Jarali, Shashi Kant Pandey
ePrint Report ePrint Report
Security protocols enable authentication, key distribution, and secure information exchange, making them essential for network security, yet flaws in their design can lead to attacks. To prevent this, formal verification methods are vital for analyzing protocol correctness. The Dolev–Yao (DY) \cite{Dy} model introduced formalization for name-stamp and cascade protocols, where users apply public-key operations on messages. Brook and Otto \cite{DY-extension} later distinguished between symmetric and non-symmetric cascade protocols, noting that all DY cases were symmetric and that attacker choices were not fully addressed. They highlighted the incomplete characterization of an attacker’s power as an open problem. In this work, we extend the DY model by systematically analyzing all remaining symmetric two-party cascade protocol cases, aiming to provide a more complete foundation for building formal verification tools.
Expand
Osama Allabwani, Olivier Blazy, Pascal Lafourcade, Charles Olivier-Anclin, Olivier Raynaud
ePrint Report ePrint Report
Sanitizable signatures authorize semi-trusted sanitizers to modify admissible blocks of a signed message. Most works consider only one sanitizer while those considering multiple sanitizers are limited by their capacity to manage admissible blocks which must be the same for all of them. We study the case where different sanitizers with different roles can be trusted to modify different blocks of the message. We define a model for multi-sanitizer sanitizable signatures which allow managing authorization for each sanitizer independently. We also provide formal definitions of its security properties. We propose two secure generic constructions FSV-k-SAN and IUT-k-SAN with different security properties. We implement both constructions and evaluate their performance on a server and a smartphone.
Expand
Samuel Coulon, Jinjun Xiong, Jiafeng Xie
ePrint Report ePrint Report
Along with the National Institute of Standards and Technology (NIST) post-quantum cryptography (PQC) stan- dardization process, efficient hardware acceleration for PQC has become a priority. Among the NIST-selected PQC digital signature schemes, FALCON shows great promise due to its compact key sizes and efficient Signature Verification procedure. However, FALCON is regarded as highly computationally com- plex, and as a result, few works for hardware acceleration of FALCON can be found in the literature, where the few existing ones only target high-performance. To fill the gap, this paper presents a Lightweight and Efficient hardware accelerator for the Signature Verification portion of FALCON (LEAF), specifically for resource-constrained applications. We propose an efficient design strategy, including a novel data dependence flow, to maximize the utilization of very small resources for all arithmetic procedures. Then, the proposed full-hardware LEAF is built, containing an ultra-lightweight number theoretical transform (NTT) core with a novel twiddle factor access pattern. Finally, we conduct a thorough evaluation to demonstrate the efficiency of LEAF. To the best of our knowledge, this is the first lightweight and mean- while most resource-efficient FALCON Signature Verification full- hardware accelerator in the literature, offering 65% and 66% less aggregate resource usage and achieving 24% and 14% less equivalent area-time product (eATP), compared to the state-of- the-art for FALCON-512 and FALCON-1024, respectively. We hope that this work can spur further research in the field.
Expand
Kamil Otal, Ali Mert Sülçe, Oğuz Yayla
ePrint Report ePrint Report
The zero-difference attack on AES, introduced by Bardeh and Rijmen in [ToSC 2022(2):43--62], exploits some structural properties -referred to as related differentials- in the AES MDS matrix. Daemen and Rijmen earlier demonstrated that these related differentials appear not only in the AES MixColumns matrix but in all $4\times 4$ circulant MDS matrices [CCDS 2009(1):47--69]. In the same paper, they also showed an example of $4\times 4$ Hadamard MDS matrices for which there exists no related differentials. Combining both results, we can say for example that some $4\times 4$ Hadamard MDS matrices are more ``secure" than any $4\times 4$ circulant MDS matrices. Recently, Jha et al. investigated whether it is possible to characterize $4\times 4$ Hadamard MDS matrices for which we can find no related differentials in [ IACR Commun. Cryptol. 2(1): 37 (2025)]. As a result, they gave a systematic method to construct such ``secure" matrices with respect to their parameters. In this paper, we investigate the same problem for all $2\times 2$ and $3\times 3$ matrices to understand the cryptographic resilience of MDS matrices both theoretically and practically. As a result, we obtain the following results:

- There are no related differentials for any $2\times 2$ MDS matrices. - There exist related differentials for all $3\times 3$ circulant MDS matrices. - There exist related differentials for all $3\times 3$ involutory MDS matrices when the finite field has even size. - We characterize all $3\times 3$ MDS matrices for which there exist no related differentials when the size of the finite field is even. In this way, we fill a gap for the cryptographic resilience problem of MDS matrices over finite fields.
Expand
Antoine Douteau, Adeline Roux-Langlois
ePrint Report ePrint Report
Commit-and-prove zero-knowledge proofs are a generalized version of zero-knowledge protocols that permit proving relations over the committed elements in addition testifying to its knowledge of the initial message. For example, the existing framework (LNP, Crypto22) allow a user to prove that the secret element committed satisfies quadratic relations with bounded norm (ℓ2 or ℓ∞). Security of these frameworks, regarding the zero knowledge property, is mainly assumed by the use of rejection sampling introduced by Lyubashevsky (Asiacrypt09). The main problems with rejection sampling are non-constant time execution and the cost of protecting this step from side-channel attacks. Our contribution is a new framework of proof for zero-knowledge property that proves knowledge and quadratic relations over lattices without basing the security over rejection sampling. The security of our framework is based on the recent Hint-MLWE (KLSS, Crypto23) assumption. This variant of MLWE gives additional hints about the secret in addition to the original input, and is shown to be as hard as its associated MLWE instance when secrets follow discrete Gaussian distributions.
Expand
Abdoul Ahad FALL
ePrint Report ePrint Report
We present arya-STARK, a unified post-quantum secure framework that enables Aggregation-Robust Yet Authentic training in Federated Learning through transparent zk-STARK proofs. Current federated learning deployments remain vulnerable to malicious or Byzantine clients capable of submitting statistically valid yet adversarial gradients, while also relying on quantum-fragile primitives for authentication. arya-STARK bridges these gaps by combining (i) transparent, hash-based zk-STARK proofs to verify gradient-descent updates at the AIR level, (ii) CRYSTALS-Dilithium signatures to guarantee post-quantum authentication of client commitments, and (iii) a Byzantine-resilient aggregation layer integrating $\ell_2$-clipping and trimmed-mean filtering to mitigate poisoning and backdoor attacks. We introduce a new finite-field encoding scheme that supports exact reconstruction of signed real-valued gradients inside STARK execution traces, enabling full verifiability without leaking client data. Our Rust-based proof-of-concept demonstrates that arya-STARK achieves scalable proof generation, microsecond-level verification, and strong robustness against up to 20% Byzantine clients while preserving high model accuracy. To our knowledge, this is the first system to unify post-quantum authentication, transparent zero-knowledge verification, and Byzantine-robust aggregation into a single architecture for secure federated learning.
Expand

17 December 2025

Xi’an Jiaotong-Liverpool University, PQC-X, Suzhou, China
Job Posting Job Posting

Position: Postdoctoral Researcher and Faculty (Assistant/Associate/Full Professor) in Post Quantum Cryptography Implementation

Research Area: Efficient, secure, and standards compliant implementation of PQC on software/hardware platforms.

Responsibilities:

  • Conduct research on implementation and optimization of PQC on CPUs, embedded systems, and accelerators, etc.
  • Develop and evaluate PQC libraries/prototypes compliant with emerging standards.
  • Analyze side-channel and fault attack resistance; design and validate countermeasures.
  • Collaborate with internal and external partners on PQC deployment in real systems.
  • Publish results in top-tier crypto/security venues; contribute to standardization efforts.
  • (For Faculty): Usual teaching duties.

    Qualifications:

  • PhD in Crypto, Computer Science/Engineering, or a closely related field.
  • Strong track record (relative to career stage) in crypto, applied cryptography, or hardware/software security.
  • Rich experience in implementation of PKC, side-channel analysis and countermeasures, or embedded systems/FPGA/ASIC design for crypto
  • Excellent programming skills (e.g., C/C++, Rust, etc).

    What we offer:

  • Excellent research environment with global leaders in PQC and with top financial institutions and industry partners.
  • Internationally competitive salary and benefits such as housing allowance, travel allowance, education allowance, relocation support etc.
  • Adequate research funds, and university’s supports to apply for national, provincial and municipal talent programs.

    How to Apply:

  • Post-doc: https://career15.sapsf.cn/sfcareer/jobreqcareer?jobId=4200&company=xjtlu.
  • Faculty: https://career15.sapsf.cn/sfcareer/jobreqcareer?jobId=4087&company=xjtlu.

    For Inquiries, please contact Associate Professor Zhang.

    Closing date for applications:

    Contact: wenbin[.]zhang[at]xjtlu[.]edu[.]cn

  • Expand
    University of the Bundeswehr, Research Institute CODE
    Job Posting Job Posting

    The Research Institute CODE in Munich is inviting applications for multiple PhD and Postdoctoral researcher positions. All positions are fully funded according to the German federal salary scheme TV-ÖD E13/E14, depending on qualifications and experience.

    Successful candidates will contribute to a research project on post-quantum cryptography and side-channel analysis. They will work with the Embedded Systems Security (ESSEC) Lab (Prof. Michael Hutter) and the Quantum-Safe and Advanced Cryptography (QuSAC) Lab (Prof. Daniel Slamanig), with opportunities to travel, collaborate with industry, and tackle cutting-edge hardware and cryptography challenges.

    Research Areas:
    We seek motivated researchers with strong interest and experience in one or more of:

    • Side-channel analysis, physical and fault attacks, hardware tampering
    • Hardware masking: Threshold Implementations, Domain-Oriented Masking, hiding, DRP logic
    • Secure and efficient implementations of cryptography in software or hardware
    • ASIC/FPGA design security, hardware security, low-resource implementations (e.g., smartcards)
    • Post-Quantum Cryptography (PQC)
    • Leakage detection, formal methods, and security verification techniques

    Requirements:

    • Master’s degree or PhD in a relevant field (students near completion may apply)
    • For PostDoc positions:
      • Strong research track record, ideally with publications at IACR venues or top security conferences
      • Excellent academic writing and presentation skills
    • High motivation, ability to work independently, and good communication skills
    • Fluent English (German optional)

    How to Apply:
    Send an email to Prof. Michael Hutter with the subject: "Application CODE".

    Your application should include:
    Cover letter, CV, transcripts, and references (or letters).

    Closing date for applications:

    Contact:
    Prof. Michael Hutter
    Email: michael.hutter [AT] unibw.de

    Applications will be reviewed on a rolling basis until all positions are filled.

    Expand
    Chalmers University of Technology
    Job Posting Job Posting
    The Chalmers CryptoTeam is recruiting! We are seeking two new members:
    • A PhD student, who will work on transparency technologies (key transparency and transparency logs) and post quantum security. We envision a new team member with some prior knowledge in cryptography, a genuine interest in the topic, and willing to work in a collaborative environment. The PhD duration is up to 5 years, including taking courses (part of the PhD education) and participating in teaching activities (up to 20% of the full time equivalent).
    • A Post Doctoral fellow who will be involved in advising PhD students on provable security, digital signatures with advanced properties, post quantum cryptography and transparency. We envision a new team member with experience in: proof techniques, designing and modelling security protocols, and publishing at IACR conferences. The successful applicant will have the opportunity to contribute to advising PhD and Master students and will participate in teaching activities (up to 20% of the full time equivalent).
    The CryptoTeam provides a welcoming, dynamic and forward-thinking environment. Chalmers University is located in Göteborg, Sweden. The starting date for each position is flexible, but expected to be in Spring 2026 or earlier.

    Link to PhD ad: https://www.chalmers.se/en/about-chalmers/work-with-us/vacancies/?rmpage=job&rmjob=14411&rmlang=UK

    Link to PostDoc ad: https://www.chalmers.se/en/about-chalmers/work-with-us/vacancies/?rmpage=job&rmjob=14411&rmlang=UK

    Closing date for applications:

    Contact: Assistant Professor Elena Pagnin

    More information: https://www.chalmers.se/en/about-chalmers/work-with-us/vacancies/?rmpage=job&rmjob=14411&rmlang=UK

    Expand

    14 December 2025

    Monash University, Melbourne, Australia
    Job Posting Job Posting
    We invite applications for a full-time Research Fellow (Postdoc) position funded by the Australian Research Council project “NextGen Blockchain Privacy & Security: Practical and Quantum-Safe Solutions”, led by Prof. Joseph Liu in the Department of Software Systems and Cybersecurity, Faculty of IT, Monash University.

    This is an exciting opportunity to work at the intersection of modern cryptography, blockchain technologies, and post-quantum security, in a highly active research environment with strong international collaborations and a clear pathway to high-impact publications.

    About the role: The successful candidate will contribute to designing and analysing practical and provably secure cryptographic protocols for blockchain applications, with a focus on topics such as:
    • Privacy-preserving blockchain systems
    • Payment channels and Layer 2 solutions
    • Scalable and secure off-chain transactions
    • Quantum-resistant blockchain privacy mechanisms
    You will be expected to conduct high-quality research, lead and co-author papers for top-tier venues, collaborate with local and international partners, and help supervise PhD and honours students working in related areas.

    About you: We are looking for a highly motivated researcher who meets the following criteria:
    • PhD in Cryptography or closely related area, or near completion (thesis submitted or close to submission)
    • Strong background in theoretical and/or applied cryptography, preferably with applications to blockchain
    • Experience in at least one of the following: privacy-preserving blockchain protocols, payment channels, Layer 2 or off-chain transaction mechanisms
    • Knowledge of post-quantum cryptography is highly desirable
    • A strong publication record with papers in top IACR conferences (CRYPTO, EUROCRYPT, ASIACRYPT) or top security conferences (ACM CCS, IEEE S&P, NDSS, USENIX Security)
    Note: This position is not suitable for candidates working primarily on non-cryptographic application on blockchain topics, e.g. consensus mechanism, smart contracts, or purely applied blockchain business use cases.

    Closing date for applications:

    Contact: Interested person please send your CV (with full publication details) to Prof. Joseph Liu (email: joseph.liu @ monash.edu). This position is open until it is filled.

    Expand

    13 December 2025

    Angelo De Caro, Kaoutar Elkhiyaoui, Sandeep Nishad, Sikhar Patranabis, Venkatraman Ramakrishna
    ePrint Report ePrint Report
    Interoperation across distributed ledger technology (DLT) networks hinges upon the secure transmission of ledger state from one network to another. This is especially challenging for private networks whose ledger access is limited to enrolled members. Existing approaches rely on a trusted centralized proxy that receives encrypted ledger state of a network, decrypts it, and sends it to members of another network. Though effective, this approach goes against the founding principle of DLT, namely avoiding single points of failure (or single sources of trust).

    In this paper, we leverage fully-distributed broadcast encryption (FDBE in short) to build a fully decentralized protocol for confidential information-sharing across private networks. Compared to traditional broadcast encryption (BE), FDBE is characterized by distributed setup and key generation, where mutually distrusting parties agree on a BE’s public key without a trusted setup, and securely derive their decryption keys. Given any FDBE, two private networks can securely share information as follows: a sender in one network uses the other network’s FDBE public key to encrypt a message for its members; and the resulting construction is secure in the simplified universal composability framework.

    To further demonstrate the practicality of our approach, we present the first instantiation of an FDBE that enjoys constant-sized decryption keys and ciphertexts, and evaluate the resulting performances through a reference implementation that considers two private Hyperledger Fabric networks within the Hyperledger Cacti interoperation framework.
    Expand
    Zhen Qin, Siwei Sun
    ePrint Report ePrint Report
    The SPHINCS+ framework provides the underlying architecture for modern quantum resistant stateless hash-based signatures. Notable examples include the NIST standard SLH-DSA and its recent variants such as SPHINCS-$\alpha$ and SPHINCS+C. We extend the hypertree structure that underlies the SPHINCS+ framework by allowing trees of different heights to appear on different layers, and we plug generalized hash-based one-time signatures with chains of different lengths into the hypertree. While these structural generalizations do not affect the original security proof for the SPHINCS+ framework as long as the encoding function employed by the underlying one-time signature is injective and incomparable, they lead to enlarged design space, opening up the possibility for finer-grained trade-offs. We perform a systematic exploration of the parameter space for the generalized structure guided by a thorough theoretical cost analysis that minimizes the number of variables to be enumerated in the searching process. As a result, we identify many parameter sets superior to state-of-the-art stateless hash-based signature schemes in terms of signature size, signing or verification efficiency. In particular, we provide some parameter settings not only enjoying smaller signature size, but also more efficient in signing and verification. The improvement can be significant if we do not pursue optimizing all performance metrics simultaneously. One of our constructions with 128-bit security is 8.1% smaller than SPHINCS+C-128s (26.2% smaller than SPHINCS+-128s and 16.7% smaller than SPHINCS-$\alpha$-128s). At the same time, it is faster in verification but slower in signing than SPHINCS+C-128s. Further size reduction is possible with a greater sacrifice in speed. We provide implementations and benchmark results for representative parameter sets.
    Expand
    Mila Anastasova, Panos Kampanakis
    ePrint Report ePrint Report
    Migrating to quantum-resistant cryptographic algorithms, specifically the NIST-standardized Module Learning with Errors (MLWE) primitives, would inevitably result in data transmission overhead in secure transport protocols due to their larger key, ciphertext, and signature sizes. Would the connection setup cost noticeably affect application performance? This study evaluates MLWE's performance impact on practical use cases that rely on TLS 1.3 via real-world experiments. We analyze three distinct scenarios by sharing empirical and experimental data of applications interfacing with cloud service TLS endpoints, Web user metrics, and mutual TLS connections. We argue that some cloud applications will not be significantly affected due to their unconstrained environment. We show that Web performance degradation will remain below 10% for common webpages, corresponding to time delays of under 100ms, which users are unlikely to perceive. For mutual TLS applications, our experiments show that MLWE noticeably affects Time-to-First-Byte, almost doubling the connection times compared to plain TLS. However, when evaluating Time-to-Last-Byte, a metric more closely tied to application performance, the overall impact drops to about 15% for ~150KB data transfers in fast or slow networks. This impact is much lower for large client-server round trips. While these results are reassuring that MLWE could unnoticeably be introduced in common TLS use cases, they do not diminish the value of data trimming techniques proposed in the literature (e.g., session resumption, intermediate certificate authority suppression) to speed up connections.
    Expand
    Guangxian Zou, Isaac Zhang, Ryan Zarick, Kelvin Wong, Thomas Kim, Daniel L.-K. Wong, Saeid Yazdinejad, Dan Boneh
    ePrint Report ePrint Report
    zkVMs promise general-purpose verifiable computation through ISA-level compatibility with modern programs and toolchains. However, compatibility extends further than just the ISA; modern programs often cannot run or even compile without an operating system and libc. zkVMs attempt to address this by maintaining forks of language-specific runtimes and statically linking them into applications to create self-contained unikernels, but this ad-hoc approach leads to version hell and burdens verifiable applications (vApps) with an unnecessarily large trusted computing base. We solve this problem with ZeroOS, a modular library operating system (libOS) for vApp unikernels; vApp developers can use off-the-shelf toolchains to compile and link only the exact subset of the Linux ABI their vApp needs. Any zkVM team can easily leverage the ZeroOS ecosystem by writing a ZeroOS bootloader for their platform, resulting in a reduced maintainence burden and unifying the entire zkVM ecosystem with consolidated development and audit resources. ZeroOS is free and open-sourced at https://github.com/LayerZero-Labs/ZeroOS
    Expand

    12 December 2025

    University College Cork, Ireland
    Job Posting Job Posting
    We are seeking a highly motivated researcher to join the UCC Security Research Group and the Insight SFI Research Centre for Data Analytics. The position will contribute to the project Migrants’ Digital Spaces (MIGDIS), a multidisciplinary initiative exploring technology-assisted analysis of home, border, and belonging, while also contributing to Insight research objectives in privacy/security.

    The successful candidate will investigate privacy risks in online digital spaces, focusing on communities that connect people across countries and those tied to specific physical locations, such as city-based forums. The research will examine potential privacy breaches, including de-anonymisation attacks, and develop countermeasures using techniques such as differential privacy and cryptographic protocols. This work will require close collaboration with social scientists and other stakeholders, ensuring that technical solutions are informed by societal and ethical considerations.

    The ideal applicant holds a PhD in Computer Science or related disciplines and has experience in cyber security and privacy research. They should have a good track record in relevant conferences and journals and has a track record in one or more of the following research areas: privacy enhancing technologies, differential privacy, anonymity, re-identification, and/or cryptography. Previous experience in working on interdisciplinary projects is an asset.

    Preference will be given to candidates at postdoctoral level. If the selected candidate has not yet completed their PhD, they will be appointed at the research assistant level.

    Closing date for applications:

    Contact: Dr. Paolo Palmieri at [email protected]

    More information: https://security.ucc.ie/vacancies.html

    Expand
    Shaoquan Jiang
    ePrint Report ePrint Report
    Quantum authentication is a procedure that sends a quantum message to a receiver without being imperceptibly changed in the channel. How to formalize a proper authentication model is a highly non-trivial task. Existing models have various flaws: they either do not capture serious concerns or are over restricted. Most importantly, none of them have addressed the threat from the verification queries. We show that there is a quantum authentication scheme that is secure when no verification query is allowed while it is completely insecure when verification queries are additionally permitted. The threat of verification queries is not artificial. Our attack only needs to know if a forged authentication message is valid or not. It captures the concern that the adversary can watch if the receiver accepts an authentication or not, without even reading the message authenticated. We propose a quantum authentication model that captures the authentication of multiple messages under the same key as well as the verification queries. We allow the attacker to have his own state entangled with the authentication message. Finally, we propose an authentication framework abstracted from the AQA method in Garg et al. (CRYPTO'17) and prove the security in our model. Our result reduces the security of an authentication protocol to certain properties of its component primitives. We also prove that an impersonation attack implies a substitution attack. To our knowledge, this is the first time to confirm this result.
    Expand
    Suprava Roy, Ratna Dutta
    ePrint Report ePrint Report
    Cloud computing enables data processing, storing and sharing in untrusted environments whose growing adoption necessitates a focus on data security and privacy. Inner product functional encryption (IPFE) is a promising cryptographic technique that enables fine-grained access control over sensitive data in untrusted cloud environments. Post-quantum cryptography focuses on developing cryptographic protocols resilient to quantum computer attacks, with lattice structures being crucial in designing these protocols. This paper aims to implement the lattice-based public key unbounded IPFE (uIPFE) scheme proposed by Dutta et al. (2022) [1] which ensures that no specific vector’s length bound needs to be fixed during public parameter generation. Furthermore, we extend the ALS-IPFE scheme of Agrawal et al. (2016) [2] to create a new public key scheme uIPFE #1, achieving adaptive indistinguishability security in the random oracle model under the Learning with Errors assumption, while avoiding trapdoor generation and pre-image sampling algorithms. This work aims to enhance the practical applicability of uIPFE in cloud computing environments. We implement both the schemes uIPFE and uIPFE #1 in C programming language and execute the code on IBM Power 9 server. Moreover, we analyze the running time and discuss the performance of both schemes based on varying message vector lengths.
    Expand
    ◄ Previous Next ►