International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

03 March 2026

IE University, School of Science and Technology; Madrid, Spain
Job Posting Job Posting

At IE School of Science and Technology, you contribute to shaping the next generation of applied mathematicians within an international academic community. Our programs combine rigorous mathematical foundations with real-world relevance and remain at the forefront of science and technology education.

As an Adjunct Professor in Cryptography, teaching in the fourth year of the Bachelor of Applied Mathematics (BAM) at our Madrid campus (IE Tower) for the 2026–2027 academic year, you will design and deliver an elective course covering both classical and modern cryptography. Please note that elective courses require a minimum number of students to go forward.

Course Topics

  • Encryption, Shannon’s lower bound, and pseudo-randomness
  • Symmetric and public-key cryptography (Merkle, Diffie–Hellman, RSA)
  • Digital signatures (Lamport, RSA-based schemes)
  • Zero-knowledge proofs and proofs for NP
  • Lattices, LWE, and Fully Homomorphic Encryption
  • Quantum and post-quantum cryptography

Key Requirements

  • Ph.D. preferred in Mathematics, Computer Science, or related STEM field
  • Master’s degree in STEM with teaching experience will also be considered
  • Strong background in mathematics and computing
  • Flexibility to accommodate assigned teaching schedules
  • Excellent communication skills in English (minimum C1)
  • Authorized to work in Spain (visa sponsorship is not available)

Preferred Profile

  • Experience teaching advanced undergraduate mathematics or theoretical computer science
  • Ability to connect rigorous theory with computational implementation
  • Experience supervising student projects or research
Typically, our Adjunct Faculty hold full-time professional or research positions and teach one course with us, bringing valuable real-world and academic expertise directly into the classroom.

Closing date for applications:

Contact: irene.alda(at)ie.edu

More information: https://www.ie.edu/university/studies/academic-programs/bachelor-applied-mathematics/

Expand
Technical University of Denmark, Copenhagen region, Denmark
Job Posting Job Posting

We are looking for a motivated PhD student to join the Cryptography Group in the Cybersecurity Engineering Section at the Department of Applied Mathematics and Computer Science (DTU Compute), located in the Copenhagen region, Denmark.

This fully funded 3-year PhD position, starting on 1 January 2026, will focus on advancing research in Multi-Party Computation and Zero-Knowledge Proofs. The PhD will be carried out under the supervision of Associate Professor Luisa Siniscalchi.

If you are curious, enthusiastic, and eager to learn, we would love to hear from you, and you can apply at https://lnkd.in/gNTXJwEB, including the following:

  1. A letter motivating the application (cover letter)
  2. Curriculum vitae
  3. Grade transcripts and BSc/MSc diploma (in English), including official description of grading scale

Closing date for applications:

Contact: [email protected]

Expand
University of Luebeck, Luebeck, Germany
Job Posting Job Posting

We are looking for an outstanding individual with a strong track record of excellent research in one of the areas of cybersecurity. The future job holder will have an outstanding PhD and excellent scientific achievements in one of the following areas:

  • Theory and Practice of Cryptography
  • Security and Privacy in Machine Learning
  • Formal Methods in Security
  • Secure Protocols and Networks
  • Software and Systems Security
  • Usable Security and Privacy

Applications with complementary or new thematic focus areas in the field of IT Security that expand the existing expertise at the Institute for IT Security are expressly welcome. The establishment of a separate working group at the Institute for IT Security (www.its.uni-luebeck.de) is expected.

The applicant should have high potential to strengthen the university's research profile in the field of IT Security through excellent publications, have high potential for successfully acquiring third-party funding at national and international level, and have the ability to lead research projects. Scientific participation in the institute's main areas of research and the university's profile areas, such as the trustworthiness of systems and the cross-sectional area of intelligent systems, is expected, especially in the context of self-acquired projects (public funding, industrial cooperation, etc.).

Teaching obligations include participation in the IT Security degree programs (German-language Bachelor's and English-language Master's) and other degree programs in the STEM sections of the university.

Junior professorships are initially filled for a fixed term of three years. Following a positive interim evaluation, the position is extended for a further three years. The position will be converted to a permanent W2 professorship if the tenure evaluation is positive.

Applications with the usual documents must be submitted exclusively electronically via the application portal on the University of Luebeck until 01.04.2026.

Closing date for applications:

Contact: Petra Niehoff (petra.niehoff(at)uni-luebeck.de) Thomas Eisenbarth (thomas.eisenbarth(at)uni-luebeck.de)

More information: https://stellenangebote.uni-luebeck.de/jobposting/301599937bbb518a1054be323d3bc7220610f2270

Expand
Rome, Italy, 9 May - 10 May 2026
Event Calendar Event Calendar
Event date: 9 May to 10 May 2026
Submission deadline: 20 February 2026
Notification: 14 March 2026
Expand
University of Surrey; Guildford, England
Job Posting Job Posting

We are inviting applications for a PhD studentship in the Surrey Centre for Cyber Security at the University of Surrey.

This studentship will develop new cryptanalytic techniques for solving post-quantum computational hardness assumptions and will use such analysis to propose secure advanced cryptographic functionality, with a special focus on recent new "spins" on well established lattice-based hardness assumptions.

Eligibility criteria

We seek applicants with a strong background in mathematics and/or computer science. Familiarity with cryptography, number theory, computational algebra or quantum computing will be appreciated, but are not mandatory.

Open to any UK or international candidates. Up to 30% of our UKRI funded studentships can be awarded to candidates paying international rate fees.

How to apply

Applications should be submitted via the University of Surrey Computer Science PhD programme page.

In place of a research proposal, you should upload a document stating the title of the project that you wish to apply for and the name of the relevant supervisor.

More information

More details on the project and answers to FAQs can be found on the University of Surrey website or on FindaPhD advertisement 195082

References
  • Surrey Centre for Cyber Security: https://www.surrey.ac.uk/surrey-centre-cyber-security
  • Fernando Virdia (supervisor): https://fundamental.domains
  • Robert Granger (supervisor): https://www.surrey.ac.uk/people/robert-granger

Closing date for applications:

Contact: Fernando Virdia, f.virdia at surrey.ac.uk

More information: https://www.surrey.ac.uk/fees-and-funding/studentships/cryptanalysis-post-quantum-hardness-assumptions

Expand
RISE Research Institutes of Sweden, Stockholm, Sweden
Job Posting Job Posting

About the Role We are looking for a dedicated PhD student to strengthen our research in trustworthy and verifiable AI. Example research topics include evaluating the trustworthiness of data collection and pre-processing pipelines, designing verification techniques which ensure that model training procedures are not tampered with, and accountable model deployments. The project is part of the multi-disciplinary center for cyber resilient AI, RESIST, which is a national effort funded by the Swedish Strategic Research Foundation to bring together leading researchers in AI and cybersecurity to develop novel solutions to cyber resilient AI for the benefit of Swedish industry and society. You will be based in the RISE office at Kista, Stockholm for 4 years, and you will be enrolled as a doctoral student at a Swedish University. PhD education also involves participation in relevant university courses.

About RISE RISE Research Institutes of Sweden AB is Sweden's research institute and innovation partner. In international collaboration with companies, academia, and the public sector, we contribute to a competitive business sector and a sustainable society. You will be part of the Cybersecurity unit at the department of Computer Science which conducts cutting-edge research on both fundamental and applied cybersecurity topics arising in AI, 6G, Internet of Things, etc.

Requirements a) completed master’s degree in computer science, information security, mathematics, or an equivalent field, b) background in cryptographic primitives for advancing verifiability in AI/ML pipelines, c) strong programming skills, d) good command of spoken and written English.

Application Submission: https://www.ri.se/en/about-rise/work-with-us/open-job-positions/phd-student-in-trustworthy-and-verifiable-ai

Closing date for applications:

Contact: Dr. Apostolos Pyrgelis (apostolos.pyrgelis[at]ri.se)

More information: https://www.ri.se/en/about-rise/work-with-us/open-job-positions/phd-student-in-trustworthy-and-verifiable-ai

Expand
Grenoble INP/TIMA Laboratory
Job Posting Job Posting
Designing secure embedded systems is a critical challenge due to their inherently complex three-layer architecture: hardware, microarchitecture, and software. Cyber threats often exploit vulnerabilities introduced during the design phase, which remain undetected due to a lack of design tools that integrate a realistic attacker model with a holistic approach. Current tools and methods lack a deep understanding of the global system, particularly the interactions between its layers and with its environment (including attacker actions). Existing modeling tools are not yet capable of effectively predicting an embedded systems' resistance to fault attacks, as their generality leads to excessive simulation complexity. This project proposes a more realistic attacker model to identify microarchitecture-specific vulnerabilities. This approach enables designers to develop countermeasures, integrate them into systems, and verify their effectiveness in significantly reducing—or ideally preventing—the attacker’s ability to exploit vulnerabilities. The objective of this PostDoc is to extend the existing work by leveraging RTL fault models existing in the state of the art and proposed by the TwinSec project, to assess and improve the security of RISC-V microarchitectures (e.g., OpenTitan, CV32, CVA6) and their recent countermeasures (e.g., Mafia, AKHACIA). The aim is to improve existing countermeasures or develop new ones at design level that incorporate both hardware and software protections for embedded code, such as, for example, secure boot mechanisms. This PostDoc will take place in TIMA Laboratory, Grenoble and will last 12 to 24 months. The candidate will strictly cooperate with other partners involved in the project, both local (CEA, LCIS, Verimag) and national. The salary will be defined according to the guidelines defined by Grenoble INP and will depend on the experience of the candidate.

Closing date for applications:

Contact: Paolo Maistri

More information: https://tima.univ-grenoble-alpes.fr/join-tima/postdoc-and-research-engineers/postdoc-enhancing-security-risc-v-microarchitectures-against-laser-fault-injection-countermeasure

Expand
Shahzad Ahmad, Stefan Rass
ePrint Report ePrint Report
We introduce $CRISP (\underline{C}ircuit-p\underline{R}ivate ~Single-\underline{I}mage~ \underline{S}teganography ~with ~\underline{P}ermutations),$ a provably secure homomorphic steganography scheme designed to address key limitations in existing approaches to private computation. Current methods often suffer from excessive image overhead and a complete lack of circuit privacy. Specifically, many techniques require a separate cover image for each wire in a circuit, leading to a large number of images for even moderately sized circuits. This also inadvertently reveals the underlying logical gate structure to an honest-but-curious cloud provider, as wire roles are often fixed to specific images.

CRISP resolves these challenges by embedding all three Fredkin gate inputs directly into the RGB channels of a $single$ cover image at a secret pixel position $(\mathit{row},\mathit{col})$. Similarly, all three outputs are written to a single output image. To ensure robust circuit privacy, CRISP employs two independently sampled permutations: $\pi_{\mathrm{in}}$ assigns input channel roles, and $\pi_{\mathrm{out}}$ reassigns output channel roles. These permutations work in tandem to prevent an adversary from deducing the circuit's structure. Without $\pi_{\mathrm{out}}$ varying per gate, the Fredkin gate's pass-through of the control bit could enable a deterministic channel-matching attack, fully exposing the logical gate structure to the cloud provider. By resampling $\pi_{\mathrm{in}}$ and $\pi_{\mathrm{out}}$ independently for each gate, CRISP effectively prevents cross-gate correlation attacks.

Our security analysis demonstrates that an adversary's advantage in locating the secret pixel and inferring the embedded bits decays as\\ $\Theta\!\left(1/(h{\times}w)\right)$, where $h{\times}w$ is the image resolution. This bound is cryptographically negligible for any practical image size. CRISP significantly reduces image overhead: per gate, it uses just two images (one input cover plus one independent output cover). This represents a substantial reduction compared to other methods that might require multiple images per wire. For an obfuscated benchmark circuit, CRISP further demonstrates a notable reduction in total image count. Crucially, CRISP delivers circuit privacy, a qualitatively new and essential security guarantee.

The correctness, security, and efficiency of CRISP are formally proved and experimentally validated.
Expand
Zhaopeng Ding, Zhaopeng Dai, Baofeng Wu, Rundong Wang, Yanshuo Zhang
ePrint Report ePrint Report
The selection of shift polynomials is a pivotal yet challenging step in Coppersmith's method for computing modular roots of multivariate polynomials. We propose a novel, determinant-based strategy for generating these polynomials, thereby presenting an improved variant of Coppersmith's method tailored for certain multivariate modular equations. Our approach is first validated on solving the Modular Inversion Hidden Number Problem (MIHNP) and predicting the Inversive Congruential Generator (ICG), where it is shown to outperform prior methods both in theory and in practice. Furthermore, when applied to the Modular Inversion Double Hidden Numbers Problem (MIDHNP), our analysis reveals that MIDHNP is not harder than MIHNP, thereby disproving a conjecture by Boneh et al. (Asiacrypt 2001).
Expand
Jan Bormet, Sebastian Faust, Hussien Othman
ePrint Report ePrint Report
Recently, Boneh, Partap, and Rotem [Crypto’24] initiated the study of threshold traitor tracing, which aims to enhance threshold decryption with anti-collusion mechanisms through a tracing functionality. In their model, a set of colluders constructs a decryption box, called a decoder, and sells it to an external buyer. Collusion-resilience is guaranteed by a tracing algorithm that, given only black-box access to the decoder, can identify at least one of the colluders. However, in this paper, we argue that the state-of-the-art definition and constructions are not resilient against attacks where the decoder is sold to an insider, i.e., a member of the decryption committee.

Motivated by this gap, we introduce new definitions to model decoder boxes that are sold to insiders. We show that existing threshold traitor tracing techniques are inherently vulnerable to insider attacks. Then, we introduce a novel approach to achieve insider resilience through multi-traitor tracing, i.e., identifying multiple traitors. We present compilers that amplify the number of traitors that can be found, thereby achieving insider-resilience with efficient parameters, in particular, sublinear ciphertext size. These compilers may also be of independent interest.
Expand
Rahinatou Yuh Njah Nchiwo
ePrint Report ePrint Report
Lattice-based cryptography (LBC) has emerged as one of the most promising fields supporting post-quantum cryptography (PQC). The Learning With Errors (LWE) problem \cite{Regev}, due to its strong security guarantees, plays a fundamental role in LBC, although it is not very efficient for cryptographic applications. To address this limitation, several variants of LWE have been developed, such as Ring-LWE (RLWE) \cite{LPR2010}, which is suitable for theoretical purposes, and Polynomial-LWE (PLWE) \cite{BV}, which is more practical. This survey provides a systematic review of vulnerable instances of PLWE. These attacks may extend to RLWE in instances where the two problems are equivalent.. This paper serves as a resource for those seeking a structured overview of the state-of-the-art attacks on PLWE.
Expand
Felix Gunther, Vadim Lyubashevsky, Rolfe Schmidt
ePrint Report ePrint Report
FALCON (Prest et al. NIST submission) is a lattice-based digital signature scheme that is intended to be standardized by NIST under the name FN-DSA. This scheme has smaller signature and public key sizes than the ``primary'' NIST scheme, ML-DSA, but is more complicated to implement due to floating-point requirements. For this reason, NIST has recommended the scheme be used in special situations where smaller key and signature sizes are particularly important.

There are certain situations, where one can make small modifications to FALCON which results in even shorter outputs, which is particularly interesting for FALCON's intended use cases where smaller outputs are important. In the scenario where one would like to minimize the total public key plus signature length, one could use FALCON in key recovery mode, which is a fairly straight-forward procedure specified in the FALCON document.

In the scenario where one would like to minimize the total signature plus message length, one could use the message recovery mode (which is a somewhat less straight-forward modification) as described in (del Pino et al. SCN 2017). The purpose of this note is to fully specify the details of this latter mode for developers wishing to implement it. The savings of using FALCON in message recovery mode is up to 226 bytes as compared to FALCON-512 and up to 434 bytes compared to FALCON-1024 for the same security levels (i.e. NIST levels 1 and 5, respectively). We also sketch how the same technique can be applied to the ring signature version of FALCON from (Gajland et al. Crypto 2024).

The main algorithmic building blocks of FALCON, such as key generation and trapdoor sampling, remain exactly the same. The only algorithmic changes are in the hashing and parsing of the messages, randomness, and the hash function.
Expand
Giacomo Borin, Sofía Celi, Rafael del Pino, Thomas Espitau, Shuichi Katsumata, Guilhem Niot, Thomas Prest, Kaoru Takemure
ePrint Report ePrint Report
Threshold signatures have regained a strong interest recently, driven by applications in cryptocurrencies and NIST's ongoing call for threshold schemes. Among them, FROST - a classical threshold Schnorr signature scheme already in real-world deployment - stands out. Its appeal lies in three core features: partially non-interactive signing, non-interactive identifiable abort (IA), and proactive security. In contrast, while post-quantum (PQ) threshold signatures have seen significant advances in recent years, no existing scheme simultaneously provides even two of these features. Considering the imminent need to migrate to PQ cryptography, this state-of-the-art remains unsatisfactory.

In this work, we propose Hermine, a lattice-based threshold signature that offers the full feature set of FROST under standard lattice assumptions. Hermine is designed to efficiently support the Medium scale of parties ($N \le 64$) as defined in the NIST threshold call, producing a small \Raccoon signature of size $11$ KB. Our main technical contribution is introducing an everywhere-short secret sharing, which splits a short secret vector $\mathbf{s} \in R_q^\ell$ into short shares and admits a short linear reconstruction algorithm. While the resulting construction appears intuitive, its security proof requires a non-trivial, fine-grained analysis of the information on $\mathbf{s}$ that is inherently leaked by the short shares. Furthermore, we formalize game-based unforgeability and IA definitions with proactive security, which may be of independent interest.
Expand
Deokhwa Hong, Heesoo Lee, Young-Sik Kim, Yongwoo Lee
ePrint Report ePrint Report
We propose an efficient and numerically stable sign evaluation over the Cheon–Kim–Kim–Song (CKKS) homomorphic encryption (HE) scheme by introducing a new bootstrapping. Sign evaluation underpins applications such as comparison, sorting, and machine learning. Extensive studies exist, such as the polynomial-composition method by Lee et al. (IEEE TDSC'22). A critical oversight in the literature is that evaluating composite polynomials consumes substantial multiplicative depth, necessitating intermediate bootstrapping. Such bootstrapping introduces considerable noise, which harms convergence and degrades accuracy. Inspired by bootstrapping bits (Eurocrypt'24), we propose a new white-box bootstrapping for sign evaluation. We prove that our bootstrapping, unlike traditional bootstrapping, intrinsically reduces noise. Consequently, (i) it admits an interpretation as a polynomial composition, accelerating convergence “for free,” and (ii) it removes the bootstrapping-induced noise that disrupts convergence in prior art. Our implementation validates that the proposed method achieves approximately 40-bit precision—bounded only by the fundamental rescaling noise—doubling the $\approx$ 20 bits of prior work under identical parameters. Moreover, our approach requires less depth and is numerically more stable.
Expand
Kaijie Jiang, Stefano Tessaro, Hoeteck Wee, Chenzhi Zhu
ePrint Report ePrint Report
This paper gives the first lattice-based two-round threshold signature scheme that tolerates the adaptive corruption of up to $T -1$ out of $N$ signers. Our construction is based on the MLWE and MSIS assumptions. We substantially improve upon the only existing adaptively secure lattice-based construction, recently given by Katsumata, Reichle, and Takemure (CRYPTO '24), which requires five rounds.
Expand
Ikhlas Mastour, Layth Sliman, Boussad Ait Salem, Balthazar Bauer, Raoudha Ben Djemaa, Kamel Barkaoui
ePrint Report ePrint Report
Federated Learning is an emerging machine learning paradigm that enables distributed model training directly at data sources and transmitting only model updates, thereby reducing communication bottlenecks and mitigating risks associated with raw data exposure. Despite these advantages, recent advances have demonstrated that privacy in federated learning remains limited and subject to inference attacks that exploit shared model updates to extract sensitive information. To address this limitation, we propose Robust and Resilient Federated Learning using Distributed Homomorphic Encryption (RRFL-DHE), a privacy-preserving federated learning framework that combines a distributed homomorphic encryption scheme with threshold linear secret sharing. The framework enables clients to encrypt their model updates to allow secure aggregation without exposing individual contributions. To maintain resilience against client dropouts, RRFL-DHE incorporates a dropout management protocol, maintaining training continuity and accurate global model reconstruction. To assess our framework, we provide a rigorous security proof against a semi-honest server model and evaluate RRFL-DHE on non-IID MNIST and Fashion MNIST datasets using SVM and CNN models. The results show that RRFL-DHE preserves model utility with less than 1% deviation compared to the FedAvg approach, while outperforming the xMK-CKKS approach by approximately 15% in accuracy. These findings highlight the importance of RRFL-DHE as a promising solution for distributed computing, while preserving privacy, maintaining utility, and ensuring resilience against dropouts.
Expand

02 March 2026

Mohammed Barhoush, Tomoyuki Morimae, Ryo Nishimaki, Takashi Yamakawa
ePrint Report ePrint Report
Mahadev [SIAM J. Comput. 2022] introduced the first protocol for classical verification of quantum computation based on the Learning-with-Errors (LWE) assumption, achieving a 4-message interactive scheme. This breakthrough naturally raised the question of whether fewer messages are possible in the plain model. Despite its importance, this question has remained unresolved.

In this work, we prove that there is no quantum black-box reduction of non-interactive classical verification of quantum computation of $\textsf{QMA}$ to any falsifiable assumption. Here, “non-interactive” means that after an instance-independent setup, the protocol consists of a single message. This constitutes a strong negative result given that falsifiable assumptions cover almost all standard assumptions used in cryptography, including LWE. Our separation holds under the existence of a $\textsf{QMA-QCMA}$ gap problem. Essentially, these problems require a slightly stronger assumption than $\textsf{QMA}\neq \textsf{QCMA}$. To support the existence of such problems, we present a construction relative to a quantum unitary oracle.
Expand
Yannis Rouselakis, Junichi Tomida
ePrint Report ePrint Report
Registered attribute-based encryption (Reg-ABE) is a new variant of attribute-based encryption (ABE) that was introduced to resolve the notorious key escrow problem. In a Reg-ABE system, there is no authority that generates secret keys, and each user joins the system by generating its own public/secret key pair. Because of its public-key infrastructure-like model and versatile access control functionality, Reg-ABE is a promising alternative of ABE. In this work, we present a highly space efficient non-monotone Reg-ABE scheme with strong security. Specifically, the sizes of MPK and ciphertext of our scheme are both about 7.5KB, which could be more than 2000$ \times $ and 5$ \times $ smaller than those of the state-of-the-art scheme by Garg \textit{et al.}~(Crypto'24, GLWW), respectively, in a realistic parameter setting. The sizes of other elements such as helper secret key and a state that the system maintains could also become more than 40$ \times $ smaller. Furthermore, our scheme supports non-monotone policies and CCA-security, neither of which GLWW supports. We implement our scheme together with GLWW and show that encryption of ours outperforms that of GLWW even with the above features, while decryption of ours is a few times less efficient than that of GLWW but still takes less than 0.1 seconds with a laptop. Our scheme is proven secure in the generic group model. We also present a dual system variant of our main scheme, which is CPA-secure under the MDDH assumption in the plain model. The variant is much simpler and more efficient than the only known non-monotone Reg-ABE scheme by Attrapadung \textit{et al.}~(Crypto'24).
Expand
Aparna Gupte, Jiahui Liu, Luowen Qian, Justin Raizes, Bhaskar Roberts, Mark Zhandry
ePrint Report ePrint Report
One-time programs (OTPs) aim to let a user evaluate a program on a single input while revealing nothing else. Classical OTPs require hardware assumptions, and even with quantum information, deterministic functionalities remain impossible due to gentle-measurement attacks (Broadbent, Gutoski and Stebila, 2013). While recent works achieve positive results for randomized functionalities with high-entropy outputs, the fundamental limits and the strongest achievable security notions remain poorly understood.

Inspired by analogous successes in the classical obfuscation setting, we ask for a "best-possible" analogue of obfuscation for OTPs: a generic transformation that, for any functionality, achieves the strongest one-time security achievable by any construction. Our first result is negative. We show that a generic best-possible one-time compiler cannot exist even for classical randomized functionalities. We prove this under the assumption that lossy encryption schemes exist (e.g. from either the Learning with Errors or weakly pseudorandom group actions). Our proof identifies computationally indistinguishable families for which any best-possible transformation would be forced to behave incompatibly.

Given this impossibility, we introduce a natural subclass of one-time compilers called "testable one-time program" compilers, which output quantum states augmented with reflection oracles for themselves. We show that best-possible security for this subclass, i.e. best-possible testable one-time compilers, are most likely achievable. For this, we give two results. (1) We formulate a simplified, generalized Single-Effective-Query (SEQ) simulation security notion for quantum channels and show that SEQ security implies best-possible testable one-time security. (2) We construct SEQ-secure OTPs for all quantum functionalities in the classical oracle model, yielding the first positive results for arbitrary quantum channels beyond classical randomized functionalities. Thus, SEQ security could serve as a testable one-time analogue of virtual black-box (VBB) security in the many-time obfuscation setting. Finally, we propose stateful quantum indistinguishability obfuscation (stateful quantum iO) --- quantum state obfuscation for stateful quantum programs. We show that (1) stateful quantum iO implies best-possible testable OTPs and (2) stateful quantum iO is also achievable in the classical oracle model. These results identify stateful quantum iO as a promising approach towards best-possible testable OTPs.
Expand
Shengke Zeng, Zehui Tang, Song Han, Mingxing He
ePrint Report ePrint Report
Deduplication of encrypted data is a feasible way to optimize cloud storage against cloud curious. However, encrypted data is prone to incurring the attention for its chaotic form. In this work, we focus on the improvement of security and efficiency of deduplication technology. We introduce a notion of Visual Fuzzy Deduplication to hide the sensitive multi-media data (i.e., images) to retain only one copy of cloud storage. Moreover, our deduplication realizes batch detection for duplicates and Brute Force Attacks (BFA) resistance without server aided. We simulate our experiments on three datasets to achieve the desired results, which shows our scheme is practical and efficient to optimize privacy-preserving cloud storage.
Expand
◄ Previous Next ►