IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
31 May 2026
Ivan Damgård, Sebastian Kolby, Claudio Orlandi, Stanislas Pawlak
As a main application, we use these techniques to construct efficient threshold decryption protocols for lattice-based fully homomorphic encryption (FHE), including BFV, BGV, and related schemes. The resulting protocols are special-purpose MPC protocols with a small constant number of rounds. They avoid noise flooding, allowing the parameters of the underlying FHE scheme to be chosen without making room for additional decryption noise.
The resulting protocols achieve statistical UC security against malicious adversaries.
We improve substantially on previous work on MPC-based threshold FHE decryption: as a concrete example, the state-of-the-art protocol by Zyskind et al. (ACM CCS 2025) implements decryption of the BFV scheme (with ciphertext modulus $2^{64}$), using about 17.000 bits of preprocessed correlated randomness, while we need only 63.
Yuchao Chen, Chun Guo, Muzhou Li, Shuo Peng, Hao Lei, Guang Zeng, Meiqin Wang
Given an arbitrary matrix, it is typically difficult to determine how many EGFN rounds are sufficient for pseudorandom permutation (PRP) and strong PRP (SPRP) security. Remarkably, security proofs for structures with a larger number of branches have to analyze a huge amount of collision events, which is overly complicated and prone to errors.
To remedy this situation, we present AutoEGFN, a computer-aided proof tool that determines the number of rounds sufficient for PRP and SPRP security for various variants of EGFN. The tool operates by calculating three parameters: $r_1$, $r_2$, and $r_3$. The validity and soundness of AutoEGFN are formally established by a detailed security proof. To demonstrate the effectiveness of AutoEGFN, we have applied it to multiple structures such as Type-1/2 GFN (Zheng et al., CRYPTO 1989), YI11's Type-1 GFN (Yanagihara and Iwata, CANS 2011), DFLM19's GFN (Derbez et al., FSE 2019), DDGP22's GFN (Delaune et al., INDOCRYPT 2022), Type-1.x GFN (Yanagihara and Iwata, IEICE 2014), SH/TH GFN (Yanagihara and Iwata, CANS 2011), Nyberg's GFN (Nyberg, ASIACRYPT 1996), SM's GFN (Suzaki and Minematsu, FSE 2010), and BMT's EGFN (Berger et al., SAC 2013). As a result, we provide a systematic analysis of the (S)PRP security for Type-1 and Type-2 structures for different numbers of branches. Our tool efficiently determines the concrete number of rounds required to ensure PRP and SPRP security for EGFNs with different branch numbers. For comparison, previous work only proved the (S)PRP security for 8- and 16-branch BMT's EGFN. Our tool completes the proof within several minutes, even for variants with $32$ branches. Meanwhile, for the other structures, we provide the first concrete (S)PRP security proofs without any restrictions on their permutation layers. Furthermore, AutoEGFN will significantly contribute to the enhancement of EGFN designs and implementations in various cryptographic applications.
Ramona Corbeanu, Diana Maimut, George Teseleanu
Nicolas Mohnblatt, Benedikt Wagner
In this short note, we give a novel security analysis that extends the results of FRIDA beyond the unique decoding radius of the code being used. This strict improvement leads to data availability sampling schemes with smaller commitments.
Towards our novel analysis, we define a variant of the opening-consistency property introduced in FRIDA, which we name opening-consistency with assign. Crucially, our new property does not depend on the unique decoding radius of the code. We then show that the FRIDA compiler can be applied to IOPPs that have opening-consistency with assign to produce secure code commitments. Finally, we show that under mutual correlated agreement, the batched FRI protocol (FOCS'20) satisfies opening-consistency with assign. This latter result is enabled by a recent analysis of FRI by Garreta, Mohnblatt and Wagner (ePrint 2025/1993).
Hideki Asanuma, Yilong Chen, Hiroki Furue, Kosuke Sakata, Tsuyoshi Takagi
29 May 2026
Egham, United Kingdom, 28 June - 1 July 2027
Submission deadline: 24 September 2026
Notification: 26 November 2026
Bengaluru , India, 13 December - 16 December 2026
Submission deadline: 15 August 2026
Notification: 10 October 2026
Jeju Island, South Korea, 26 August - 28 August 2026
Submission deadline: 13 June 2026
Notification: 18 July 2026
Antalya, Turkey, 11 October 2026
Amiens, France, 22 June - 25 June 2026
Jeju, South Korea, 26 August - 28 August 2026
Submission deadline: 13 June 2026
Notification: 18 July 2026
Simula UiB, Bergen, Norway
We are currently hiring at Simula UiB for a permanent Research Scientist or Senior Research Scientist position [*] in the Department of Cryptography, specialising in post-quantum cryptography.
We are seeking candidates with a PhD in cryptography, computer science, applied mathematics, or a related discipline. The successful candidate should be able to conduct both independent and collaborative, high-impact research and have experience in the design, analysis or implementation of post-quantum cryptographic schemes, demonstrated through publications in leading international venues. Expertise in related areas, such as cryptographic engineering, implementation security, side-channel analysis or applied cryptography more broadly will be an advantage.
Application deadline: 28 June 2026
For more information and how to apply: https://www.simula.no/careers/job-openings/research-scientist-in-cryptography-at-simula-uib
About Simula UiB: Simula UiB (simula-uib.com) is a research institute in Cryptography and Information Theory based in Bergen, Norway. The Department of Cryptography conducts research on the design and analysis of cryptographic algorithms, side-channel analysis and privacy-enhancing technologies. It currently comprises 13 members, including permanent staff, postdoctoral researchers and PhD students, and is led by Dr Martijn Stam. Simula UiB also hosts the Centre for Quantum Communication Networks and Applications (QCNA), one of Norway’s four national centres for quantum technology research, launched in May 2026.
[*] The Research Scientist and Senior Research Scientist levels at Simula UiB are broadly equivalent to Assistant Professor and Associate Professor positions in the university sector, respectively.
Closing date for applications:
Contact: Martijn Stam ([email protected])
More information: https://www.simula.no/careers/job-openings/research-scientist-in-cryptography-at-simula-uib
ENS Lyon, France
- The candidate should hold a PhD degree in Mathematics or Computer Science
- They should have a strong record related to some of the following topics: number theory, computational number theory, lattice-based cryptography, isogeny-based cryptography
Closing date for applications:
Contact: Benjamin Wesolowski, https://emploi.cnrs.fr/Offres/CDD/UMR5669-BENWES-004/Default.aspx?lang=EN
Department of Information Security and Communication Technology at NTNU in Trondheim, Norway
The role entails a balanced portfolio of research, teaching, and academic leadership. The successful applicant will be expected to develop and lead research projects, obtain external funding, and publish in top-tier international venues (such as IACR CHES, IACR CRYPTO, IACR EUROCRYPT, ACM CCS, IEEE S&P). The position also involves contributing to the department’s educational mission through research-based teaching, supervision, and curriculum development at bachelor, master, and PhD levels.
The successful candidate is expected to conduct advanced research in cryptographic engineering, with emphasis on areas such as high‑assurance and performance‑optimized implementations of cryptographic primitives, formal verification techniques, and resistance against side‑channel, fault‑injection, and microarchitectural attacks. Research activities may also involve system‑level integration and deployment of cryptographic mechanisms in resource‑constrained or security‑critical environments, including wireless and embedded communication systems. The position further offers opportunities for interdisciplinary collaboration with researchers in adjacent domains within the department and across the university.
Closing date for applications:
Contact: Tjerand Silde
More information: https://www.jobbnorge.no/en/available-jobs/job/300865/associate-professor-in-cryptographic-engineering
University College Cork, Ireland
Cybersecurity is an area of strategic research importance to the School, and a focus area of teaching with a new MSc in Cybersecurity due to start in September 2026. The post will support the further development and delivery of this new MSc, engage in research that spans cybersecurity, cyber-physical security, data privacy, and security of AI.
We are looking for a world-class scientist with expertise in cybersecurity and specifically the intersection of AI and cybersecurity. The candidate requires expertise in cybersecurity, a track record of applying AI methods to cybersecurity problems and the ability and desire to:
- develop and lead research and teaching activities in Cybersecurity;
- establish and manage a significant world-class research team supported by competitively won research funding;
- supervise research students at PhD level;
- publish in leading conferences and journals in the cybersecurity domain;
- develop and strengthen links between the School of Computer Science and key industry organisations working in Cybersecurity;
- take leadership roles in cybersecurity across the University, nationally and internationally;
- contribute to the overall strategic development of the School;
- represent the School at internal and external events.
Closing date for applications:
Contact: Prof Dirk Pesch at [email protected]
More information: https://my.corehr.com/pls/uccrecruit/erq_jobspec_version_4.jobspec?p_id=094546
27 May 2026
Jiawei Bao, Tibor Jager, Eike Kiltz, Aysan Nishaburi, Samin Nooripoor, Jiaxin Pan
Full Key Recovery of Masked PRESENT on an Out-of-Order RISC-V Processor: A First Reported Case Study
Siddhartha Chowdhury, Nimish Mishra, Sarani Bhattacharya, Debdeep Mukhopadhyay
We present \texttt{OoOLyzer}, a trace-driven analysis framework that reconstructs physical-register reuse and backend execution interactions from OoO RISC-V pipeline traces. Using \texttt{OoOLyzer}, we identify leakage arising from backend physical-register reuse and transient overlap of masked-share operations inside OoO execution structures.
We evaluate the framework on a masked PRESENT implementation and composable PINI gadgets. Our analysis shows that although rotated-share computations protect selected nonlinear operations, affine share pairs remain directly represented in the architectural execution state. OoO register renaming can therefore induce physical-register transitions of the form \[ \operatorname{HW}_{\mathrm{bit}}(a_0[b]\oplus a_1[b]), \] which reconstruct affine PRESENT intermediates and create key-dependent leakage.
We validate the leakage experimentally in two stages. First, using a modified gem5 OoO RISC-V model, we attribute the dominant leakage source to backend physical-register reuse and demonstrate first-round PRESENT subkey recovery from masked execution traces. Second, on a real SiFive P550-class OoO RISC-V processor, we perform a temperature-based side-channel experiment using Linux-accessible thermal telemetry and recover 60 out of 80 key bits from the masked PRESENT implementation.
The results establish a complete cross-layer leakage path from masked software execution to OoO backend interactions, physical-register transitions, thermal behavior, and practical key recovery on real hardware. Our findings demonstrate that masking schemes appearing secure under software-level analysis may still leak on OoO processors, motivating hardware-aware verification of masked software deployments.
Alex Davidson, Nuno Nogueira, Samuel Pearson, João Ribeiro
This work explores the possibility of deriving SPIR from PIR directly, utilising noise flooding to maintain the privacy of the database. While the common analysis based on the statistical distance leads to impractical parameters, we instead utilise arguments based on the Rényi divergence to obtain significantly improved parameters. We obtain simple single-server SPIR from state-of-the-art LWE-based PIR schemes with polynomial noise dimension and ciphertext modulus (concretely of 64 bits in size). Along the way, we note that practical schemes that utilise preprocessing via client-downloaded offline hints require extra protections for the database.
Overall, via an implementation of our approach, we show that post-quantum, round-optimal SPIR schemes can be constructed requiring online communication of 8 MB and server computation costs of 302 ms for a database of 1 million 1 kB elements.