International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

05 March 2026

Si-Woo Eum, Min-Ho Song, Hwa-Jeong Seo
ePrint Report ePrint Report
The transition to post-quantum cryptography (PQC) significantly increases the computational cost of TLS~1.3 handshakes. In particular, hybrid handshakes incur even greater overhead, as they require performing both classical and PQC algorithms for key exchange and authentication. This paper systematically analyzes the performance of hybrid PQC TLS~1.3 handshakes using a POSIX thread pool-based parallel execution model. We evaluate a total of 135 combinations comprising 3 classical KEMs, 3 ML-KEM variants, 3 classical DSAs, and 5 PQC DSAs. Sequential execution times range from 429.2 to 1,907.0~$\mu$s, while parallel execution times range from 356.7 to 1,380.8~$\mu$s, achieving speedups of 1.08$\times$ to 1.40$\times$ across all combinations. The highest speedup is observed in P-384-based configurations, where the overlap between classical and PQC operations is most pronounced. Furthermore, we recommend both throughput-oriented combinations based on FN-DSA and currently standardized ML-DSA combinations for each NIST security level. These results provide practical design guidance for mitigating performance degradation in hybrid PQC TLS deployments.
Expand
Sanketh Menda, Mihir Bellare, Viet Tung Hoang, Julia Len, Thomas Ristenpart
ePrint Report ePrint Report
We specify OCH, the first authenticated encryption with associated data scheme built to provide 128-bit multi-user AE security, 128-bit context commitment security, and 256-bit nonces with optional nonce privacy. It therefore addresses pressing limitations of currently widely-deployed schemes. We construct and formally analyze the security of OCH in a modular fashion, with transforms that are of broader applicability. On Intel Raptor Lake CPUs, OCH using the Areion permutation family has a peak encryption speed of 0.62 cycles per byte (cpb), not far off from AES128-GCM (0.38cpb) and outperforming both ChaCha20/Poly1305 (1.63cpb) and TurboSHAKE128-Wrap (3.52cpb).
Expand
Junxin Liu, Peihan Miao, Mike Rosulek, Xinyi Shi, Jifeng Wang
ePrint Report ePrint Report
Private set intersection (PSI) has become extremely practical, in large part due to the fact that modern protocols rely almost exclusively on cheap, symmetric-key cryptography. The same cannot be said for the variant of PSI called updatable PSI (UPSI; Badrinarayanan et al., PoPETS 2022), where parties’ input sets evolve over time, and the cost of re-computing the intersection depends only on the changes to their sets. In existing UPSI protocols, the number of public-key operations scales with the number of items.

In this work, we introduce the first UPSI protocol that largely avoids public-key operations. In fact, our protocol uses mostly the same protocol tools/techniques that have been so successful in making (plain) PSI truly practical. By leveraging symmetric-key primitives, our implementation achieves orders-of-magnitude improvements over prior work.

Additionally, we observe that existing UPSI security proofs do not consider an adversary who can choose protocol inputs adaptively (i.e., choose which items to add to the set the current epoch based on the adversary’s view in previous epochs). We observe that several existing UPSI protocols are trivially broken by such adaptive input selection (even with semi-honest corruption). Several variants of our protocol are secure in the presence of adaptively chosen inputs.

Along the way, we also introduce a new and cleaner abstraction for a common idiom of using an oblivious key-value store (OKVS; Garimella et al., Crypto 2021) to represent a set of items. Our new abstraction, called affine set encoding, may be of independent interest.
Expand
Pranav Shriram Arunachalaramanan, Ling Ren
ePrint Report ePrint Report
Recently, Stateful Private Information Retrieval (PIR) has emerged as a promising new paradigm of PIR. Despite significant recent progress, state-of-the-art single-server schemes in this paradigm still suffer from practical inefficiencies in communication, computation, and/or client storage. In this work, we construct a new single-server stateful PIR scheme called HarmonyPIR that achieves efficient communication, computation, and client storage. From a technical standpoint, we build on the recent work of Wang and Ren (EUROCRYPT 25) and propose a new hint organization that uses only a single random permutation. The random permutation can be instantiated using either AES or the recently standardized FF1 Format-Preserving Encryption, yielding two variants of HarmonyPIR. Our new scheme achieves up to two orders of magnitude better amortized computation and up to five times better amortized communication than state-of-the-art schemes.
Expand
Chris van Noorden, Paola de Perthuis
ePrint Report ePrint Report
Post-quantum assumptions may not rely on the difficulty of finding secret subgroups as many classical schemes did. Instead, several assumptions make use of more general group actions, with the belief that quantum algorithms are not helpful in this less structured setting. Famously, some isogeny constructions use the action of an ideal class group on elliptic curves, but equivalence problems in error-correcting codes and lattices also exhibit such structures.

Previous works hence presented anonymity-preserving constructions in a generic group action framework; however, they were not general enough to encompass the group action underlying the Lattice Isomorphism Problem (LIP), for which the acting group is infinite (in fact, not even compact) and non-commutative.

We bridge this gap by, from zero-knowledge proofs of OR statements, building generic blind signature and strong designated-verifier signature with non-delegability constructions from standard assumptions corresponding to a generalised group action inverse problem.
Expand
Oriol Farràs, Miquel Guiot
ePrint Report ePrint Report
Traceable secret sharing complements traditional schemes by enabling the identification of parties who sell their shares. Recently, two independent works extended traceable secret sharing to general access structures.

Goyal, Jain, and Partap [EC'26] introduced a model in which a reconstruction box is augmented with a label $I \subseteq [n]$ and is only required to distinguish between two secrets when queried with the shares of parties in $I$. Based on how this label relates to the corrupted set $J$ that built the box, they defined two notions of traceability. If $I \cap J = \emptyset$, the model is called $\emptyset$-strong traceability, for which they presented a construction based on indistinguishability obfuscation (iO). Otherwise, their model is calledstrong traceability, for which they proved an impossibility result. Farràs and Guiot [EC'26] proposed a different model, which we call hiding traceability, where the reconstruction box has no label and the access structure is hidden from the parties.

In this work, we improve traceable secret sharing for general access structures in three directions. First, we present a fully information-theoretic scheme for the $\emptyset$-strong traceability model, eliminating the need for strong cryptographic assumptions. This resolves an open question posed by Goyal, Jain, and Partap, who asked what are the minimal assumptions needed in the $\emptyset$-strong traceability model.

Second, motivated by the impossibility of strong traceability, we introduce a relaxed notion calledhidden mildly strong traceability. This model is relevant in practice and bridges the strong and hidden models. For this setting, we present an information-theoretic scheme for general access structures.

Finally, we consider the more general model of stateful traceability, where reconstruction boxes may keep state across queries, and we prove an impossibility result for this setting.
Expand
Jonas Janneck, Doreen Riepel
ePrint Report ePrint Report
End-to-end cloud storage solutions are deployed at large scale, yet recent works have demonstrated severe attacks against their confidentiality and integrity. Motivated by this, a first formal treatment of secure cloud storage was given at CRYPTO 2024 by Backendal, Davis, Günther, Haller and Paterson (BDGHP). They define syntax and security notions, capturing client-to-client security of cloud storage schemes with respect to a password distribution. They also give an efficient construction using the Two-Hash Diffie-Hellman (2HDH) OPRF and standard cryptographic building blocks, which they prove secure under selective corruptions in the random oracle model. However, several aspects of practical security guarantees remain open. We extend and refine the work of BDGHP along multiple dimensions, advancing the analysis of secure cloud storage schemes. First, we prove that their construction can be proven secure against adaptive corruptions (with a slight modification), circumventing technical challenges posed by file sharing. Second, we modularize the scheme further by introducing an abstraction for the authentication procedure. This allows us to identify the concrete role of 2HDH and alternative instantiations. Third, we introduce a weaker model that captures adversaries who can arbitrarily control the network, except during registration. This allows us to prove concrete guarantees about online password guessing attacks, whereas the stronger model inherently allows for offline guessing. Finally, we formalize and prove explicit authentication, relying on the security of our new authentication abstraction and the MAC scheme, where the latter was previously not used in the security analysis.
Expand
Georg Fuchsbauer, Fabian Regen, Hoeteck Wee
ePrint Report ePrint Report
This paper presents the first round-optimal threshold blind signature without random oracles. Our construction achieves security in the algebraic group model (AGM) for asymmetric pairing groups, and tolerates adaptive corruption of up to $t-1$ signers, where $t$ is the threshold. We improve upon the recent threshold blind signatures of Lehmann, Nazarian and Özbay (EUROCRYPT 2025) and Jarecki and Nazarian (ASIACRYPT 2025) in two ways: we eliminate both the reliance on random oracles and the need for $q$-type assumptions in the AGM. As a core building block, we introduce a new pairing-based round-optimal blind signature without random oracles, based on the $2$-DL assumption in the AGM. Both blind signature schemes achieve communication and computation costs only twice that of the celebrated blind BLS signature.
Expand
Masaaki Shirase
ePrint Report ePrint Report
The processing of ML-KEM (formerly CRYSTALS-Kyber), a key encapsulation mechanism with post-quantum security, is performed by multiplication, addition, and subtraction of polynomials whose coefficients lie in the finite field ${\mathbb F}_{3329}$. To reduce the number of such operations, it is common to use the Number Theoretic Transform (NTT). This paper focuses on arithmetic over ${\mathbb F}_{3329}$ and proposes the use of a logarithmic representation with respect to a primitive element $\alpha$ of ${\mathbb F}_{3329}^*$ for implementing multiplication, addition, and subtraction over ${\mathbb F}_{3329}$. In this representation, multiplication in ${\mathbb F}_{3329}^*$ can be reduced to addition in $\mathbb{Z}_{3328}$. Furthermore, addition and subtraction in ${\mathbb F}_{3329}^*$ can be computed in the logarithmic domain by using Zech's logarithm. However, special treatment is required when $0 \in {\mathbb F}_{3329}$ is involved in the operations. This paper proposes a new implementation method of the logarithmic representation for arithmetic over ${\mathbb F}_{3329}$, including the handling of such exceptional cases.
Expand
Ojaswi Acharya, Georg Fuchsbauer, Adam O'Neill, Marek Sefranek
ePrint Report ePrint Report
We revisit the three-round threshold Schnorr signature scheme Sparkle of Crites, Komlo, and Maller (CRYPTO 2023), as well as its variant Sparkle+. While Sparkle+ was accompanied by a claim of full adaptive security, subsequent work identified a gap in the analysis. Moreover, the original—and simpler and more efficient—Sparkle scheme has so far lacked even a proof of static security.

We resolve this state of affairs by giving the first proof of static security for Sparkle and then, as our main result, a tight proof of full adaptive security in the pure random oracle model, i.e. without relying on the algebraic group model. The core obstacle is that, in the fully adaptive setting for Sparkle, rewinding arguments fundamentally break down. To address this, our proof is based on a new Vandermonde circular discrete-logarithm (VCDL) assumption, an interactive strengthening of the circular discrete-logarithm assumption of Cho et al. (CRYPTO 2025), originally introduced to prove tight security of basic Schnorr signatures. In particular, circular-style assumptions eliminate the need for rewinding. Beyond tightness, our analysis highlights circular-style assumptions as a general approach to achieving security in settings—such as full adaptive security—where rewinding is inherently problematic.

We justify VCDL by reducing it to the low-dimensional vector representation (LDVR) problem of Crites et al. (CRYPTO 2025) in the elliptic-curve generic group model; conversely, VCDL implies LDVR in the standard model. Finally, we generalize VCDL (and similarly LDVR) by abstracting away the specific choice of Vandermonde vectors. As an application, we identify a different assumption within this framework that yields a tight proof of adaptive multi-user security for the basic Schnorr signature scheme, a result of independent interest.
Expand
Magali Bardet, Axel Lemoine, Jean-Pierre Tillich
ePrint Report ePrint Report
It has been a very long standing open question whether the CFS signature scheme whose security is basically that of a McEliece scheme based on very high rate binary Goppa codes could be attacked or not. There was a first cryptanalytic result by Faugère et al in 2011 consisting in finding a distinguisher for the binary Goppa codes used in this scheme showing that these codes can be distinguished in polynomial time from a random binary linear code. However despite numerous cryptanalytic attempts and even if the original distinguisher has been significantly improved, no attack on the McEliece scheme based on binary Goppa codes has been found so far except for very peculiar Goppa codes of degree $2$. We show here that the Pfaffian modeling used in the distinguishing attack of Couvreur, Mora and Tillich of Asiacrypt 2023 can actually be used together with a shortening trick and looking for squares in the corresponding ideal to find a polynomial attack on the CFS scheme based on very high rate binary Goppa codes.This breaks this 25 years old signature scheme. We demonstrate the effectiveness of this approach by recovering the key of TII McEliece challenges with a claimed key security of up to 210 bits.
Expand
Pranav Shriram Arunachalaramanan, Ananya Appan, David Heath, Ling Ren
ePrint Report ePrint Report
Range queries can filter, aggregate, and retrieve database entries that lie in a specified multi-dimensional rectangle. Private range queries allow a client to query a server's public database while keeping the client's multi-dimensional rectangle hidden.

We construct RangeR, a constant-round private range query scheme that supports any associative aggregation function (e.g., SUM, MAX, TOP-K) and works with any number of servers. In the single-server setting, RangeR is orders of magnitude faster and uses 50%-90% less communication than HADES (VLDB 2025), a prior single-server private range query scheme that only supports linear aggregation functions.

We describe how RangeR can be used to implement a privacy-preserving map application that can return the highest-rated restaurants near a user. Using data from $\mathtt{OpenStreetMaps}$, we estimate that a user can find the highest-rated restaurants within one kilometer of their location within $2$ seconds, while revealing only that the user is somewhere in the USA.
Expand
Ikhlas Mastour, Imane Haidar, Layth Sliman, Raoudha Ben Djemaa
ePrint Report ePrint Report
The distributed nature of federated learning systems makes them vulnerable to backdoor attacks in which malicious clients manipulate local training data using trigger-dependent behaviors to cause targeted misclassification. Although homomorphic encryption preserves the privacy of model updates during aggregation, it limits the application of conventional defenses that require access to plaintext updates. Moreover, distinguishing poisoned models from benign variations becomes more challenging under non-independent and identically distributed (non-IID) data distributions.To address this challenge, we introduce a defense strategy that operates at inference time by identifying abnormal internal activation patterns within the aggregated global model, rather than filtering encrypted individual updates during training. The proposed approach analyzes neurons that exhibit low activation on clean inputs, referred to as "dormant" neurons, but become disproportionately active in the presence of trigger patterns. By constructing a statistical activation baseline using a small clean dataset, we derive class-specific thresholds that serve as decision boundaries to detect and reject suspicious predictions. Since the proposed method relies on global model behavior at inference time instead of inspecting individual client updates, it does not introduce additional training overhead and remains robust under non-IID data settings. Our approach maintains a strong balance between privacy, security, and accuracy by defending against backdoor attacks without requiring access to client updates. Experimental results demonstrate that even with a 99% attack success rate and 90% main-task accuracy, the proposed defense method successfully detects 100% poisoned images.
Expand
Deirdre Connolly, Mike Ounsworth, Sophie Schmieg, Douglas Stebila
ePrint Report ePrint Report
This paper formally specifies and analyzes the CK hybrid key encapsulation mechanism (KEM) construction from the IRTF CFRG’s recent draft on hybrid (post-quantum/traditional) KEMs CK combines two KEMs using a PRF to produce a hybrid KEM. Unlike the QSF framework of Barbosa et al., which combines an IND-CCA KEM with a nominal group (Diffie-Hellman-style), CK combines a C2PRI-secure post-quantum-secure KEM with an IND-CCA traditionlly-secure KEM constructed from an IND-CCA2 public key encryption (PKE) scheme, such as RSA-OAEP. We additionally show how to securely promote an IND-CCA2 PKE into an IND-CCA KEM. We perform two complementary security analyses of CK in the standard model: the first shows CK is IND-CCA assuming the traditional KEM is IND-CCA, the post-quantum KEM is C2PRI, and the KDF is a secure PRF; the second shows CK is IND-CCA assuming the post-quantum KEM is IND-CCA and the KDF is a secure PRF, even if the traditional KEM is completely broken. Neither proof requires the random oracle model.
Expand
Nilanjan Datta, Avijit Dutta, Sougata Mandal, Hrithik Nandi, Amlan Sinha
ePrint Report ePrint Report
The rapid advancement of quantum computing poses significant challenges to the security of existing cryptographic constructions. Several constructions that are provably secure in the classical setting, e.g., the $3$-round Luby–Rackoff, Even–Mansour, Keyed Sum of Permutations, become vulnerable when the adversary is granted quantum oracle access (the Q2 model). In contrast, when the adversary is restricted to classical oracle queries while retaining the ability to perform quantum computations locally (the Q1 model), such attacks no longer apply. In this paper, we investigate the Q1 security of the Keyed Sum of Permutations construction and two closely related variants - one employing identical permutations and another using a single key. We prove that all three constructions achieve $n/3$-bit security in the Q1 model. In addition, for the same-key variant, we exhibit a key-recovery attack with matching complexity, thereby establishing the tightness of our security bound. For the remaining two constructions, we derive key-recovery attacks with complexity $2^{2n/3}$.
Expand

03 March 2026

Sougata Mandal, Hrithik Nandi, Amlan Sinha
ePrint Report ePrint Report
Committing security has recently emerged as an essential property for message authentication codes (MACs), driven by applications such as abuse reporting in end-to-end encrypted messaging systems. Traditional notions, such as unforgeability or pseudorandomness, are insufficient in these contexts, prompting the introduction of stronger security notions. Bhaumik et al. (CRYPTO'24) initiated this line of research by formalizing the notions of commitment and context-discovery for MACs and analyzing several standardized birthday-bound secure constructions. We extend this line of work to beyond-birthday-bound (BBB) secure MACs. In particular, we examine the class of constructions identified by Chen et al. (ASIACRYPT'21), which employ two block ciphers and a single block hash function, together with well-studied BBB MACs from the DbHtS paradigm. Our findings depict a heterogeneous picture: while several constructions succumb to simple attacks, others exhibit some resilience, highlighting that committing and context-discovery security for BBB MACs depends strongly on structural design choices.
Expand
University of Bergen, Norway
Job Posting Job Posting
We are looking for a PhD-student in cryptography at the Department of Informatics at the University of Bergen. The position is for a fixed-term period of 3 years with the possibility of a 4th year with career-promoting work (e.g. teaching).

Algebraic cryptanalysis examines the security of cryptographic algorithms through solving polynomial systems of equations. It is crucial for building confidence in quantum safe cryptography, as well as novel symmetric encryption algorithms designed for use with advanced protocols, such as fully homomorphic encryption, multi-party computation or zero-knowledge protocols. Specific research areas will be discussed with the successful applicant, but may include designing and improving general algorithms for algebraic cryptanalysis, or developing concrete attacks against proposed ciphers. This PhD position is an opportunity to explore and shape your own research project at the very forefront of research in cryptography.

The application deadline is April 6, 2026. For more information see the official job announcement at: https://www.jobbnorge.no/en/available-jobs/job/296272/phd-research-fellow-in-cryptography

Closing date for applications:

Contact: Morten Øygarden ([email protected])

More information: https://www.jobbnorge.no/en/available-jobs/job/296272/phd-research-fellow-in-cryptography

Expand
University of Luxembourg
Job Posting Job Posting
Senior Post-Quantum Cryptography Researcher VRF Construction for Consensus Systems Quantova QVM Research | IACR Community Quantova QVM is assembling a team of senior cryptographic researchers to complete the transition of its consensus architecture to a fully post quantum design. Our live testnet already operates with post quantum primitives embedded across the protocol stack, including CRYSTALS Dilithium, Falcon, SPHINCS+, and SHA 3. Classical ECDSA and BLS signing have been removed from validator authentication. The remaining classical dependency is the EC VRF used for proposer selection and committee sampling. The objective is to replace the existing EC based VRF with a rigorously defined post quantum VRF, aligning the randomness layer with our post quantum signing infrastructure. The role requires formal design and security analysis of a VRF satisfying uniqueness, pseudorandomness, and public verifiability under quantum adversarial models. Constructions may be lattice based, hash based (QROM), or derived from established post quantum signature frameworks. Efficiency, bounded proof size, and consensus level verification constraints must be considered. Candidates should possess advanced research experience in cryptography, strong familiarity with VRF security definitions and reduction techniques, and demonstrated work in post quantum systems. Researchers are invited to submit a CV and relevant publications.

Closing date for applications:

Contact: Dean - Head of Research @ Quantova

More information: https://quantova.org/

Expand
University of Wollongong, Australia
Job Posting Job Posting

PhD Scholarship Opportunity – Homomorphic Encryption (UOW, Australia)

Our group is recruiting one PhD student to work on Homomorphic Encryption at the Institute of Cybersecurity and Cryptology (IC²), School of Computing and Information Technology, University of Wollongong (UOW).

Scholarship package

  • Full tuition fee waiver
  • Stipend: ~ AUD 35,000 per year
  • Duration: 3.5 years

Requirements

  • Master’s degree in Computer Science / Mathematics (or a closely related field)
  • IELTS 6.5+ (no band below 6.0)
  • Research experience (publications preferred)
  • Background in Cryptography is a strong advantage

How to apply (Deadline: 31 March 2026)
Please email your CV and academic transcripts to Dr. Steven Duong at [email protected].

Closing date for applications:

Contact: Dr. Steven Duong ([email protected])

Expand
School of Computer Science, Shanghai Jiao Tong University, Shanghai.
Job Posting Job Posting

The John Hopcroft Center for Computer Science at Shanghai Jiao Tong University (SJTU) invites applications for multiple fully funded PhD and Postdoctoral Research Fellow positions in the areas of post-quantum cryptography, multi-party computation (MPC), and quantum algorithms.

These positions offer an exciting opportunity to conduct cutting-edge research in a dynamic and internationally collaborative environment, working closely with Prof. Yu Yu and Prof. Shi Bai.

Position Details

PhD Candidates: Open to applicants with a Bachelor’s or Master’s degree in a relevant field (students near completion are also encouraged to apply). A solid foundation in cryptography, mathematics, or computer science is required. Strong programming skills are a plus.

Postdoctoral Fellows: Applicants should hold a PhD in a related field (or near completion) and demonstrate a strong research track record, preferably with publications at leading IACR venues or security conferences.

Desired Qualifications

  • High motivation and ability to work both independently and collaboratively
  • Strong communication skills
  • Excellent academic writing and presentation abilities
  • For PhD applicants: Please include an updated CV with your transcripts, and names of referees (if any)
  • For Postdoctoral applicants: Please include an updated CV with a full list of publications and names of referees in your application

How to Apply

Interested candidates should send their applications (including CV, academic transcripts for PhD positions, and a brief statement of research interests) to one of the following contact.

Closing date for applications:

Contact:

Prof. Yu Yu: [email protected]
Prof. Shi Bai: [email protected]

Expand
◄ Previous Next ►