International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

19 June 2026

Yağmur Gürel, Uğur Şen, Oğuz Yayla
ePrint Report ePrint Report
Rate Limiting Nullifier (RLN) is a privacy-preserving and decentralized spam-prevention mechanism for anonymous broadcast networks: each member can emit at most $r$ signals per epoch, and any violation reveals a secret that enables the member's stake to be slashed. The standard construction binds each membership to a single secret key $\mathsf{sk}_G$, so the unit of identity, the unit of authorization, and the unit of slashing all coincide with one party. This rules out settings in which a group should speak with one voice, share one rate budget, and stand behind one collective bond without any single member being able to act unilaterally. We introduce Collaborative RLN Signaling (coRLN), a protocol that lets $n$ parties register as a single RLN member and signal only by acting jointly. The group secret $\mathsf{sk}_G$ is held as additive shares under SPDZ and never reconstructed; the identity (or rate) commitment, the per-epoch RLN evaluation, and the broadcast proof are produced inside an MPC network using collaborative zk-SNARKs. The group occupies one leaf in the membership Merkle tree, locks one aggregated stake $\mathsf{stake}_G$, and is bound by one rate limit. We present the construction in both the rate-limit-1 and the general $r \geq 1$ settings, and we extend the protocol with a collaborative withdrawal procedure that lets the group exit without ever reconstructing $\mathsf{sk}_G$. We prove three security properties of coRLN by reduction to the collaborative-SNARK composition and the standard primitives underneath: (i) no PPT adversary corrupting up to $n-1$ parties recovers $\mathsf{sk}_G$ as long as one party is honest; (ii) two signals in the same epoch with the same $\mathsf{messageId}$ yield an efficient extractor that recovers $\mathsf{sk}_G$ and triggers forfeiture of $\mathsf{stake}_G$; and (iii) no strict subset of $G$ can produce a verifying signal. The verifier interface and signal shape match classical RLN at the byte level, so coRLN deploys on existing RLN-aware infrastructure with only the verification key updated.
Expand
Adrian Cinal, Oliwer Sobolewski, Gabriel Wechta, Filip Zagorski
ePrint Report ePrint Report
Distributed shuffling is a core primitive underlying mix-nets, electronic voting, and, more recently, single secret leader election (SSLE) protocols for proof-of-stake blockchains. In these settings, a collection of resource-constrained parties jointly permutes a list of ciphertexts or commitments in order to conceal the correspondence between inputs and outputs. Existing security analyzes of such protocols typically rely on heuristic anonymity measures or implicitly assume honest behavior; therefore, they fail to capture statistical dependencies that arise when shuffling is partial and some participants are corrupted.

In this work, we introduce a new security model for distributed shuffling that explicitly accounts for adversarial corruption and information leakage. Our model allows an adversary to corrupt a subset of shufflers and to track selected elements throughout the execution, and defines anonymity in terms of statistical distance from the uniform distribution over permutations. This yields a quantitative, composable notion of security that subsumes commonly used anonymity-set arguments and aligns with standard cryptographic indistinguishability frameworks.

Using this model, we analyze Whisk, the shuffle-based SSLE mechanism proposed for Ethereum. We show that, under realistic protocol parameters and even in the absence of adaptive attacks, the induced distribution over permutations deviates significantly from the uniform distribution. Consequently, the resulting anonymity guaranties are substantially weaker than what is suggested by heuristic analyzes. We show how to modify the scheme parameters to meet the security requirements.
Expand

17 June 2026

rome, Italy, 14 September - 18 September 2026
Event Calendar Event Calendar
Event date: 14 September to 18 September 2026
Submission deadline: 25 June 2026
Notification: 21 July 2026
Expand
Heilbronn, Germany, 4 April - 7 April 2027
Event Calendar Event Calendar
Event date: 4 April to 7 April 2027
Submission deadline: 10 November 2026
Notification: 15 January 2027
Expand
Department of Computer Science and Engineering, Indian Institute of Technology Roorkee
Job Posting Job Posting
Applications are invited for a Junior Research Fellow and Research Associate position for the project "Comprehensive security analysis of NIST Accordion mode proposals and their implications to hash functions over Galois fields”. The positions are based at the Department of Computer Science and Engineering, Indian Institute of Technology Roorkee, and the successful candidates will join Dr. Raghvendra Rohit’s research group. For the Qualifications, Emoluments and Job description, kindly check the advertisement at https://iitr.ac.in/Careers/static/Project_Jobs/CSE/2026/adv16062026.pdf. Interested candidates are requested to send an email to Dr. Raghvendra Rohit at [email protected] with their resume. Application deadline: June 30, 2026.

Closing date for applications:

Contact: Dr. Raghvendra Rohit ([email protected])

More information: https://iitr.ac.in/Careers/static/Project_Jobs/CSE/2026/adv16062026.pdf

Expand
Royal Holloway, University of London
Job Posting Job Posting

Applications are invited for a 2-year full-time Postdoctoral Research Associate position in Cryptography at Royal Holloway, University of London (RHUL), funded through Dr Elizabeth Quaglia’s EPSRC Open Plus Fellowship.

The successful candidate will work on the design and analysis of cryptographic protocols, with a particular focus on privacy and on understanding how cryptographic systems can better align with real-world user requirements.

Application areas may include electronic voting, auctions, anonymous credentials, peer-review systems, and other privacy-enhancing technologies.

The position offers an excellent opportunity to conduct cryptographic research with real-world impact, collaborate with international partners, and join the vibrant Information Security Group (ISG) at RHUL.

For informal enquiries about the position please contact Dr Elizabeth Quaglia. This is an exciting opportunity to join a growing research team dedicated to contributing to an ambitious programme of research in cryptography and privacy.

Closing date for applications:

Contact: Dr Elizabeth Quaglia

More information: https://jobs.royalholloway.ac.uk/Vacancy.aspx?ref=0626-193

Expand
University of New South Wales, Sydney
Job Posting Job Posting
The School of Computer Science and Engineering in the Faculty of Engineering at UNSW has four open positions for Lecturer/Senior Lecturers and Associate Professors in Cryptography and Cybersecurity. All are Teaching and Research roles. Details of the roles are available here.

  • Lecturer/Senior Lecturer in Cryptography:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540324/lecturersenior-lecturer-in-cryptography

  • Lecturer/Senior Lecturer in Cybersecurity:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540329/lecturersenior-lecturer-in-cybersecurity

  • Associate Professor in Cryptography:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540099/associate-professor-in-cryptography

  • Associate Professor in Cybersecurity:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540329/lecturersenior-lecturer-in-cybersecurity

UNSW is a member of Group of Eight (Go8) highly research-intensive universities in Australia and a world‑leading institution recognised for its scale, prestige, and impact. With strong industry engagement and partnerships across sectors, UNSW provides a unique environment where academic expertise translates into real‑world outcomes. The School of Computer Science and Engineering is one of the largest and most prestigious schools of computing in Australia. For academics, UNSW offers an outstanding platform to flourish — combining world‑class facilities, collaborative networks, and a culture of innovation that supports both career growth and meaningful contributions to the wider community.

Closing date for applications:

Contact: Please apply via UNSW Jobs Portal https://external-careers.jobs.unsw.edu.au/

Expand
University of Glasgow, UK
Job Posting Job Posting

We are looking for a (fully funded) PhD student. This PhD studentship focuses on provable security, with an emphasis on post-quantum cryptography, including but not limited to the theoretical proof frameworks and practical applications, such as secure communication and authentication.

You will be co-supervised by Dr. Tianxin Tang and Prof. Shahid Raza.

What we expect from you:
  • Passionate about the research topics and motivated to lead the projects.
  • Background: a master's degree (or strong candidates with a bachelor's degree) in computer science, mathematics, or related subjects.
  • Strong analytical skills are preferred.
  • Research experience in the related areas is a plus.
What you can expect from us:
  • At least one weekly supervision meeting to help keep you on track.
  • Guidance on writing, presentation, and career development.
  • Flexible working hours.
  • A shared interest in producing high-quality research results.
What you will like about Glasgow:
  • Easy train/bus access to all the resources of the "rival" city, Edinburgh, including the famous Festival Fringe, but without quite as many tourists and lower living costs.
  • Hogwarts-style architecture and a not-so-Hogwarts-style computer science department.
Application deadline: Friday, July 31, 2026

Please apply through https://www.findaphd.com/phds/project/phd-in-computing-science-post-quantum-cryptography-and-its-applications/?p197380.

After submitting your application, please also send an email to [email protected] with the subject title "Application IACR PhD Position: [Your Name]", so that we know you applied after seeing this ad on IACR :)

If you have general questions regarding this job post instead, you can also email [email protected] with a subject title starting with "Regarding IACR PhD Position:".

Closing date for applications:

Contact: Tianxin Tang ([email protected])

Expand
University of Vienna, Austria
Job Posting Job Posting
We focus on foundations of cryptography and are searching for a motivated PhD candidate to join our team. We develop new security definitions which match practical applications, explore complexity-theoretic relations, develop novel, sophisticated proof techniques, and design schemes that provably satisfy strong security guarantees. In the current project (see WWTF project FARCry) we explore the foundations and applications of resource-restricted cryptography. Strong mathematics skills are advantageous and arguing by formal mathematical proofs is essential.

The position is funded for 4 years with a competitive salary and available from October 2026. For eligibility, an MSc degree in Computer Science or Mathematics (or a related field) is required. Applications must contain all required documents and be done exclusively through the linked job portal of University of Vienna.

University of Vienna is located centrally and public transport is extraordinarily good. Vienna is internationally very well connected by train, plane and bus. There are several cryptography research groups in and around Vienna and we encourage regular exchange through a joint reading group.

Closing date for applications:

Contact: Karen Azari (karen.azari(at)univie.ac.at)

More information: https://jobs.univie.ac.at/job/Scientific-project-assistant-predoctoral-%28group-Foundations-of-Cryptography%29/1402740533/

Expand
Epita Research Laboratory
Job Posting Job Posting
Automated Cryptanalysis using Constraint
Programming Domain: Symmetric Cryptography, Constraint Programming (CP/SAT/ILP), Security

Context & Objectives: In the context of global encryption standardization (e.g., NIST calls), evaluating the security of block ciphers is critical. Recent advances have shifted manual cryptanalysis toward automated constraint models. However, current tools (like TAGADA or CLAASP) only solve isolated sub-problems, requiring manual complexity compilation. This PhD aims to unify these steps into a single framework to optimize global attack complexity directly and find finer security bounds on established or forthcoming ciphers.

Core Research Axes:
  • Fully Automated Differential Attacks: Merge separate attack phases into a single model using generic solvers to optimize global complexity instead of sub-problems.
  • Improving Truncated & Boomerang Attacks: Implement new constraint types directly into the core of CP solvers to improve abstraction quality and refine theoretical bounds.
  • Solver Scalability: Leverage structural patterns of encryption algorithms to guide solvers, reducing resolution times from months to days on high-round ciphers.

Profile Required:
  • Master’s degree or equivalent in Computer Science, Applied Mathematics, or Cryptography.
  • Prior internship experience in automated cryptanalysis techniques is highly desired.
  • Strong background in symmetric cryptography and/or optimization techniques (SAT, CP, ILP).
The candidate MUST BE EU or UK citizen.

Closing date for applications:

Contact: [email protected]

Expand
INSA Lyon, France
Job Posting Job Posting

The CITI Lab at INSA Lyon in France is looking for a PhD student to carry out cutting-edge research in privacy-preserving Federated Learning (FL).

FL enables collaborative model training without sharing raw data, preserving privacy by exchanging model updates instead. However, FL remains vulnerable to privacy leakage, poisoning attacks, and challenges from client heterogeneity. Secure Aggregation techniques, such as Homomorphic Encryption, improve privacy, while defenses like anomaly detection and robust aggregation enhance security but often increase computational costs. Asynchronous FL (AsyncFL) improves scalability by processing updates as they arrive, and Buffered AsyncFL helps maintain privacy by aggregating updates in batches. Despite its benefits, FL can be energy-intensive, motivating sustainable approaches such as fog computing and communication-efficient protocols. The proposed SURPRISA-FL framework addresses these challenges by combining privacy preservation, Byzantine robustness, asynchronous participation, and energy efficiency.

This fully funded position has a 3-year duration, with a negotiable start date.

Responsibilities:

  • Collaborate with faculty and researchers to design innovative cryptographic protocols.
  • Publish research findings in leading computer science conferences and journals.
  • Participate in academic activities, including seminars, workshops, and conferences.
  • Potentially assist in teaching duties.

Requirements:

  • A strong background in cryptography, with an MSc in Computer Science, Engineering, Mathematics, or a related discipline.
  • Excellent communication and interpersonal skills.
  • Strong organizational and time-management abilities to balance research, coursework, and teaching responsibilities.
  • Critical thinking and analytical skills, with fluency in technical English.
  • Proficiency in programming.

To apply, please send a copy of your CV and all your transcripts (Bachelor's and Master's).

Closing date for applications:

Contact:

To apply, please send a copy of your CV and all your transcripts (Bachelor's and Master's) to clementine(dot)gritti(at)insa-lyon(dot)fr.

Expand
TU Darmstadt, Department of Computer Science, ENCRYPTO; Germany
Job Posting Job Posting

The Cryptography and Privacy Engineering Group (ENCRYPTO) @CS Department @Technical University of Darmstadt offers a fully funded position for a Doctoral Researcher (Research Assistant/Ph.D. Student) in Cryptography & Privacy Engineering, available immediately and for initially 3 years with the possibility of extension.

Our mission is to demonstrate that privacy can be efficiently protected in real-world applications via cryptographic protocols.

TU Darmstadt is a top research university for IT security, cryptography and computer science in Europe. The position is based in the City of Science Darmstadt, which is very international, livable and well-connected in the Rhine-Main area around Frankfurt.

Job description

You work in the ERC Consolidator Grant project Tools for Protecting Data and Function Privacy (PRIVTOOLS), where we build composable protocols, optimizations and tools to protect data & functions in applications. We use Multi-Party Computation (MPC), Private Function Evaluation (PFE), and Private Set Operations (PSO) such as Private Set Intersection (PSI) & Private Set Union (PSU). You will design, optimize, implement and benchmark efficient cryptographic protocols and tools for their automatic generation, and publish & present your research results at top conferences and journals. You will also be involved in our teaching activities, e.g., the integrated course Cryptographic Protocols and the basic course Digital Technology, and supervise thesis students and mentor student assistants.

Your profile
  • Completed Master's degree at a university with excellent grades in IT security, computer science, or a similar field (degree must be completed by starting date of employment).
  • Extensive knowledge in applied cryptography/IT security and very good software development skills.
  • Additional knowledge in cryptographic protocols such as MPC, PFE, PSO, compiler construction, and/or hardware synthesis is a plus.
  • The working language at ENCRYPTO is English, so you must discuss/write/present scientific results in English. For the area of teaching, German is beneficial but not required.

Closing date for applications:

Contact: Thomas Schneider <[email protected]>

More information: https://encrypto.de/jobs/PRIVTOOLS26

Expand
Seoul, South Korea, 15 July - 16 July 2026
Event Calendar Event Calendar
Event date: 15 July to 16 July 2026
Expand
Bengaluru Urban, India, 16 December - 19 December 2026
Event Calendar Event Calendar
Event date: 16 December to 19 December 2026
Expand

16 June 2026

Fintan Costello, Paul Watts
ePrint Report ePrint Report
We give a witness-finding cryptanalysis of Stickel-type key exchange schemes, which involve two-sided multiplication of $n \times n$ matrices over $\mathbb{F}_p$, where these matrices are drawn from public subspaces with a particular commuting structure. This analysis covers Stickel's original proposal, Shpilrain's polynomial extension of that scheme, Nager's algebraic extension of that scheme, and more generally all Stickel-type approaches using public subspaces over matrix algebra in finite fields: all such schemes can be broken in polynomial time. We also describe a new key establishment scheme using two-sided matrix multiplication in which the commuting subspaces used to form the key are hidden via conjugation by private terms, blocking this specific public-subspace analysis; the witness-finding problem in this new scheme has a direct reduction from a standard NP-hard problem (Edmonds' problem).
Expand
I. Buchinskiy, M. Kotov, A. Treier
ePrint Report ePrint Report
In 2011, Grigoriev and Shpilrain proposed using tropical algebraic structures in cryptography. In recent years, numerous protocols based on tropical and related structures have been introduced, as well as many attacks on some of these protocols. This direction of research is now known as tropical cryptography. As a result of the efforts both to design secure schemes and to analyze their vulnerabilities, many purely algebraic and computational problems have emerged. In this paper, we give an overview of several results and open questions in this area. We discuss the complexity of solving certain classes of systems of equations over tropical and similar structures, as well as algorithms and approaches for solving such systems. We also present results on the asymptotic density of satisfiable systems of equations of special forms over tropical algebras. Furthermore, we discuss the discrete logarithm problem, the two-sided discrete logarithm problem, the knapsack problem, and the subset sum problem over tropical matrix structures. We consider a generalization of marginal sets for tropical semirings and semigroups. We also explore different classes of pairwise commuting matrices.
Expand
Pan Xiao, Rending Ouyang, Heng Zhang, Jiawen Zhang, Jian Liu
ePrint Report ePrint Report
Fully homomorphic encryption (FHE) enables non-interactive secure transformer inference (NISTI). Due to the high cost of bootstrapping, conventional approaches typically choose parameters that support a large multiplicative depth to reduce bootstrapping frequency. However, larger depth directly increases ciphertext size, resulting in higher communication and computation overheads.

In this paper, we introduce a novel functional bootstrapping (FBS) scheme that fundamentally reshapes the computation paradigm for NISTI: by fusing as many operations as possible into each bootstrapping operation, our approach significantly reduces the prescribed multiplicative depth.

Our FBS achieves a trigonometric minimax approximation for the target function, making it well suited for precision-sensitive components such as transformer nonlinear layers. Furthermore, we incorporate linear layers into the slot-to-coefficient (S2C) transformation within FBS, thereby eliminating the need to evaluate them separately. Building on these innovations, we present a complete NISTI framework that achieves a 1.9$\times$ speedup in runtime (from 662.3s to 349.5s) and a 3$\times$ reduction in communication (from 48.3MB to 16.1MB) compared with the state-of-the-art.
Expand
Antonio Sanso, Giuseppe Vitto
ePrint Report ePrint Report
Poseidon is one of the most widely deployed arithmetization-oriented cryptographic permutations and plays a central role in modern zero-knowledge proof systems. Although several algebraic attacks on reduced-round variants have been proposed, the security of the recommended parameter sets remains intact. A central difficulty in such attacks is controlling the degree growth of the polynomial representations induced by the permutation.

In this work, we introduce degree annihilation, a new framework for algebraic cryptanalysis of Poseidon. Unlike round-skipping techniques, which reduce complexity by removing rounds from the algebraic model, degree annihilation reduces the contribution of existing rounds by imposing algebraic constraints that force dominant degree terms to vanish. This yields polynomial systems of substantially lower effective degree.

We first present a simple bivariate form of degree annihilation and show how it combines naturally with classical round-skipping techniques. The gain depends on the multiplicity with which the annihilated degree contribution propagates through the remaining nonlinear layers; when this multiplicity matches the contribution of one S-box layer, the effect is the same as skipping an additional nonlinear layer. We then generalize the technique to multivariate settings, where systems of control equations are used to annihilate successive partial-round degree contributions. These systems can be solved using elimination, resultants, and Gröbner basis techniques.

As a proof of concept, we apply the framework to reduced-round Poseidon instances and obtain new CICO-2 attacks. More broadly, our results suggest that constructing algebraic varieties that actively control degree growth may provide a new direction for the cryptanalysis of arithmetization-oriented primitives.
Expand
Dongkun Hou, Yuanzhe Zhang, Shujie Cui, Tsz Hon Yuen, Joseph K. Liu, Jiangshan Yu
ePrint Report ePrint Report
Universal multi-party swaps were proposed for secure cross-chain cryptocurrency exchanges across multiple blockchains that require only signature verification from the underlying blockchains. However, existing universal swap protocols remain vulnerable to griefing attacks, where a deviating party aborts the swap to lock a compliant party’s assets for a long period, potentially causing indirect economic losses. A natural approach is to lift existing griefing-free solutions to the universal setting; however, we observe that this direct approach still faces three key challenges: (i) a timeout race attack, which arises from the absence of an upper bound on the transaction validity; (ii) a premium escape attack, which results from multiple refund transactions for the same assets being simultaneously valid; and (iii) a topological limitation, which implies that universal multi-party swaps can support only a special class of strongly connected digraphs, called reuniclus graphs.

In this paper, we propose GumSwap, a Griefing-free universal multi-party atomic Swap, which guarantees that a compliant party receives a premium if its asset is locked but not redeemed. To mitigate the timeout race attack and the premium escape attack, we impose minimum timeout intervals for the principal and premium timeouts, respectively, and introduce an asset migration mechanism that ensures that, during any time interval, at most one refund transaction is valid. Given the topological limitations of universal swap protocols, we further design a novel premium distribution mechanism that accommodates two classes of leaders in reuniclus graphs. Our experimental results demonstrate that GumSwap can be performed in less than 0.5 seconds per party, while reducing gas costs by 10.3X compared with existing contract-based solutions.
Expand

14 June 2026

Dongkun Hou, Ying-Teng Chen, Shujie Cui, Tsz Hon Yuen, Joseph K. Liu, Jiangshan Yu
ePrint Report ePrint Report
Universal atomic swaps [Oakland'22] replace hashed timelock contracts with adaptor signatures and verifiable timed dlogs, enabling secure cross-chain cryptocurrency exchanges that only require basic signature verification from the underlying blockchains. However, existing universal swap protocols remain vulnerable to griefing attacks, where a deviating party aborts the swap to lock a compliant party's assets for a long period. A natural approach is to lift existing contract-based solutions to the universal setting, but we identify that this straightforward solution faces two key challenges: (i) timeout race attacks, first identified in PipeSwap [Oakland'25], which arises from the absence of an upper bound on the transaction validity; (ii) a timeout overlap dilemma, which results from multiple overlapping refund periods.

In this paper, we propose HedgeSwap, a universal hedged atomic swap protocol against griefing attacks, which compensates a compliant party with a premium if its asset is locked but not redeemed. To mitigate the timeout race attacks and timeout overlap dilemma, HedgeSwap eliminates the premium timeout and instead relies on a hard relation to refund the premium. For high-value asset swaps where the parties acceptable premium ranges do not overlap, we further propose a round-based HedgeSwap that utilizes a premium migration mechanism to solve these two timeout challenges, where parties iteratively increase the premium until the lock-up risk premium acceptable to both. Our experimental results show that our HedgeSwap can complete in under 0.5 seconds, and round-based HedgeSwap completes in under 1.3 seconds for a five-round setting, while HedgeSwap reduces gas cost by 2.69X compared to existing contract-based solutions.
Expand
◄ Previous Next ►