IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
09 January 2026
Ming-Shing Chen, Chun-Ming Chiu, Chun-Tao Peng, Bo-Yin Yang
Further optimizations are achieved by caching the FFT transforms of the public and secret keys during or after key generation and reusing the transform of the shared random polynomial during the encapsulation and decapsulation processes. This approach significantly reduces redundant computations.
The effectiveness of these optimizations is evaluated across various hardware platforms, including x86-64 with AVX2 and Galois Field New Instructions (GFNI), as well as ARM NEON on Apple M1 and Cortex-A72 processors. Benchmarks show that on platforms with long carry-less multiplication instructions like PCLMULQDQ, the proposed caching and reuse strategies allow FFT-based implementations to outpace traditional Toom-Karatsuba methods in the Encap and Decap operations of the HQC scheme, even with comparable raw multiplication speeds. On platforms lacking long carry-less multiplication instructions, the additive FFT approach already gives the superior performance.
Sofía Celi, Rafaël del Pino, Thomas Espitau, Guilhem Niot, Thomas Prest
In this work, we present the first threshold signature scheme that is fully compatible with ML-DSA, supporting secure and efficient signing for a small number of parties, with an average communication per party upper bounded by 1 MB up to 6 parties. Our construction leverages advanced short secret sharing techniques and integrates optimized rejection sampling to achieve a favorable balance between communication efficiency and correctness in distributed environments. We implement our construction in Go and evaluate its performance across local, LAN, and WAN network settings. Our benchmarks demonstrate that our threshold ML-DSA scheme is not only practically deployable but also well-suited for real-world applications, including multi-device cryptocurrency wallets, threshold-based TLS authentication, and for Tor's directory authorities.
Jiankuo Dong, Yuze Hou, Shiqin Wang, Letian Sha, Fu Xiao, Zhenjiang Dong, Jingqiang Lin
Jiarui Li, Mengzhen Zou, Chen Qian, Guoyan Zhang
In this work, we propose a Fully Dynamic-Committee model that eliminates the quiescent window by supporting committee reconfiguration in every round. We present two primary contributions. First, we introduce a suite of three perfectly secure Fully Dynamic Verifiable Secret Sharing (FDVSS) schemes that support per-round committee reconfiguration. Among them, our main construction, FDVSS-1, achieves near-optimal round complexity (four rounds) and polynomial communication ($O(n^4)$). Second, building on FDVSS, we construct a perfectly secure Fully Dynamic-Committee Proactive Secret Sharing (FDPSS) protocol. FDPSS achieves share redistribution in a single communication round, removing "quiescent window" during the hand-off phase. Our protocols require no trusted setup and provide optimal resilience ($t < n/3$) against a Byzantine adversary, offering a robust solution for fault-tolerant distributed systems in highly dynamic networks.
Matthew Gregoire, Gabriel Schell, Saba Eskandarian
This paper introduces new techniques that allow E2EE messaging platforms to work with multiple vetted moderators, giving users options in their choice of moderators for messages they send to their friends. Verifiable abuse reporting in a multi-moderator setting requires new security notions to capture deniability requirements with respect to the platform and other moderators, as well as new privacy requirements with respect to users' choice of moderator(s). We comprehensively study these requirements and propose three protocols for verifiable abuse reporting in this setting, offering a range of security and performance tradeoffs for different deployment scenarios. We evaluate the performance of our proposed schemes, showing that in many cases they match or exceed the performance of prior schemes that only support a single moderator.
W.A. Susantha Wijesinghe
08 January 2026
Dario Fiore, San Ling, Khai Hanh Tang, Hong Hanh Tran, Huaxiong Wang, Yingfei Yan
We propose a subsequence scheme that separates proving either subsequence or non-subsequence arguments into two phases: (i) proof of preprocessing and (ii) proof of (non-)subsequence argument, assuming $n \ll N$ (i.e., $|\mathbf{s}| \ll |\mathbf{t}|$). Then, we can make a proof of preprocessing with inputs $\mathbf{t}$ and $\Sigma$ in advance, without any knowledge about $\mathbf{s}$. When $\mathbf{s}$ is known, we can determine whether $\mathbf{s}$ is a subsequence of $\mathbf{t}$ and proceed to prove that $\mathbf{s}$ is a (non-)subsequence of $\mathbf{t}$. Employing cached quotients (IACR ePrint 2022/1763), we achieve the running time quasilinear in $N + |\Sigma|$ for preprocessing, while the running time of proving (non-)subsequences is $\mathcal{O}(n \log_2 (N + |\Sigma|))$. Since $n \ll N$ and $\log_2(N + |\Sigma|)$ is small, this saves the prover's runtime, assuming a preprocessing depending only on $\mathbf{t}$ is computed in advance. As $\mathcal{O}(n \log_2 (N + |\Sigma|))$ is sub-linear in $N + |\Sigma|$, we achieve a text-sub-linear proving time.
07 January 2026
University of Oldenburg, Germany
The Safety-Security-Interaction Group at the Computer Science Department of the University of Oldenburg invites applications for a 4-years post-doc position in trustworthy AI in the context of medical applications (full-time, paygrade E14 TV-L). The term “trust” is to be interpreted broadly and may include topics such as reliability, robustness, fairness, explainability, and auditability, however, the main focus should be on security and privacy aspects. The position is part of the AI Incubator “Connected Health Nordwest”, a collaborative effort of the University Medicine Oldenburg (UMO), the Department of Computer Science at the University of Oldenburg, the Oldenburg Institute for Information Technology (OFFIS), and the German Research Center for AI (DFKI).
The post-doc position will be equipped with 2 Ph.D. student positions (4 years each, full-time, E13 TV-L) and access to extensive laboratories and infrastructure for testing technologies.
Excellent command of the English language is required; German language skills are not required.
Application deadline: 31 January 2026
Complete job announcement and application procedure: https://uol.de/job889en
Closing date for applications:
Contact: Prof. Dr. Andreas Peter ([email protected])
More information: https://uol.de/job889en
Silence Laboratories (remote)
At Silence, you can expect unique and impactful opportunities to put theory to practice, freedom in how you approach your work, competitive pay, and a chance to work with some of the top research and engineering talent.
The position will be fully remote with occasional travel for in-person offsites, as well as for conferences and workshops per your interest.
In order to apply, please send your CV, and a link to your website (if available) to [email protected] with the title “Full-time Researcher 2026 Application [Your Name]” by January 20th 2026 at the latest for full consideration.
A more detailed posting can be found at: https://md.silencelaboratories.com/s/uoCQUi3hz
Closing date for applications:
Contact: [email protected]
More information: https://md.silencelaboratories.com/s/uoCQUi3hz
King's College London
We are looking to recruit a lecturer in cryptography at King’s College London to work with us within the cybersecurity group.
We think it’s fair to say we got strong expertise in lattice-based and post-quantum cryptography here, as well as in protocols with an applied cryptography bent. For this position, we do not aim to strengthen lattices further, but rather aim to strengthen other areas of cryptography, e.g. protocols, applied cryptography, cryptography in the wild or theory.
The application deadline is somewhat far into the future (5 March 2026). So, if you like, there’s time to reach out to discuss or even to come visit us to check us out.
Closing date for applications:
Contact: Martin Albrecht ([email protected])
06 January 2026
Hung T. Dang
Lalita Devadas, Samuel B. Hopkins, Yael Tauman Kalai, Pravesh K. Kothari, Alex Lombardi, Surya Mathialagan
For our main result, we give a candidate non-adaptive $\mathsf{SNARG}$ for $\mathsf{NP}$ and prove its soundness under:
- the learning with errors assumption (or other standard assumptions such as bilinear maps), and - a mathematical conjecture about multivariate polynomials over the reals.
In more detail, our conjecture is an upper bound on the minimum total coefficient size of Nullstellensatz proofs (Potechin-Zhang, ICALP 2024) of membership in a concrete polynomial ideal. We emphasize that this is not a cryptographic assumption or any form of computational hardness assumption.
Of particular interest is the fact that our security analysis makes non-black-box use of the $\mathsf{SNARG}$ adversary, circumventing the black-box barrier of Gentry and Wichs (STOC '11). This gives a blueprint for constructing $\mathsf{SNARG}$s for $\mathsf{NP}$ that is not subject to the Gentry-Wichs barrier.
Luowen Qian, Mark Zhandry
As an additional application, we show that any quantum money scheme that can be verified through only classical queries to any oracle cannot be information-theoretically secure. This significantly generalizes the prior work by Ananth, Hu, and Yuen (ASIACRYPT'23) where they showed the same but only for the specific case of random oracles. Therefore, verifying black-box constructions of quantum money inherently requires coherently evaluating the underlying cryptographic tools, which may be difficult for near-term quantum devices.
03 January 2026
Hemin Rahimi, Amir Moradi
Nico Döttling, Giulio Malavolta, Omer Paneth
Under the hardness of LWE, we construct BARGs where both the CRS size the additive overhead of the proof are independent of $m$. Such BARGs can be recursively composed an unbounded polynomial number of times without losing succinctness. Along the way, we also considerably simplify the construction of fully local somewhere extractable hash functions used in the construction of Devadas et al.
Sarvar Patel, Giuseppe Persiano, Joon Young Seo, Kevin Yeo
Of independent interest, we present improved oblivious merging schemes for specific settings important for our ORAMs. Our constructions solely rely on symmetric cryptography.
02 January 2026
Krijn Reijnders
Kobi Gurkan, Philipp Jovanovic, Andrija Novakovic
Diana Ghinea, Chen-Da Liu-Zhang
We mainly focus on the real-valued variant, and chart the feasibility frontiers in synchronous, asynchronous, and network-agnostic models. We compare protocols in terms of resilience, round complexity, and communication efficiency, while also clarifying overlooked details and gaps.
Beyond standard requirements on the outputs, we discuss stronger conditions, such as having the outputs \emph{close} to the honest inputs' median. Moreover, we briefly situate the real-valued AA problem within the broader landscape of AA, where other input domains such as higher-dimensional spaces and graphs introduce further challenges.