International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

03 April 2026

Hanoi, Vietnam, 29 October 2026
Event Calendar Event Calendar
Event date: 29 October 2026
Submission deadline: 30 June 2026
Notification: 31 July 2026
Expand
Cotswold District, United Kingdom, 15 December - 16 December 2026
Event Calendar Event Calendar
Event date: 15 December to 16 December 2026
Submission deadline: 31 July 2026
Expand
Tokyo, Japan, 24 November - 26 November 2026
Event Calendar Event Calendar
Event date: 24 November to 26 November 2026
Submission deadline: 8 June 2026
Notification: 20 August 2026
Expand
Queenstown, New Zealand, 24 September - 26 September 2026
Event Calendar Event Calendar
Event date: 24 September to 26 September 2026
Submission deadline: 31 May 2026
Notification: 15 July 2026
Expand
Xiamen University, Xiamen, China
Job Posting Job Posting

Xiamen University, located in Xiamen—one of China’s top ten most livable cities—is widely recognized as one of the most beautiful universities in China. It has long been regarded as one of the leading academic institutions in Southern China. With its beautiful campus, rich cultural heritage, and vibrant academic atmosphere, Xiamen University offers an outstanding environment for research and professional growth.

We are now inviting applications for a postdoctoral position in the theory and practice of symmetric-key cryptography, with an initial appointment of two years. Potential research topics include, but are not limited to, the following:

  1. Design, analysis, and implementation of high-speed AEAD schemes for 5G and 6G systems
  2. Design, analysis, and implementation of cryptographic hash algorithms
  3. Security analysis and provable security of modes of operation

Candidates with a strong publication record in established cryptography and security venues are encouraged to apply. Applicants are invited to send their CV and a motivation letter to Dr. Yaobin Shen (yaobin.shen [at] xmu.edu.cn).

Closing date for applications:

Contact: Yaobin Shen

Expand
Chalmers University of Technology, Gothenburg, Sweden
Job Posting Job Posting
The Chalmers CryptoTeam is recruiting! We are seeking a PhD student, who will work on transparency technologies ( key transparency and transparency logs) and post quantum security. We envision a new team member with some prior knowledge in cryptography, a genuine interest in the topic, and willing to work in a collaborative environment. The PhD duration is up to 5 years, including taking courses (part of the PhD education) and participating in teaching activities (up to 20% of the full time equivalent). The starting date for each position is flexible, but expected to be around Summer 2026 or earlier.

Closing date for applications:

Contact: Asst. Prof. Elena Pagnin

More information: https://www.chalmers.se/en/about-chalmers/work-with-us/vacancies/?rmpage=job&rmjob=14409&rmlang=UK

Expand
Remote, small post-quantum cryptography company with HQ in Texas
Job Posting Job Posting
Job Title: Post-Quantum Cryptography Specialist Location: Remote (Dallas preferred) or Hybrid (ability to travel to Dallas TX when needed) Employment: Full-Time with a small company founded in 2017, the position comes with a base and equity Note: they can only hire US Citizens due to their relationship with the Department of Defense Overview: We are seeking a highly skilled Post-Quantum Cryptography Specialist to join a cutting-edge team focused on next-generation security solutions. This role will play a critical part in designing, implementing, and evaluating cryptographic systems that are resilient against quantum computing threats. The ideal candidate brings deep expertise in modern cryptography, emerging post-quantum algorithms, and secure system design. Key Responsibilities: • Design and implement post-quantum cryptographic algorithms and protocols • Evaluate and integrate NIST PQC standardization candidates (e.g., lattice-based, hash-based, multivariate schemes) • Conduct cryptographic research, benchmarking, and performance analysis • Collaborate with engineering teams to embed quantum-resistant security into applications and infrastructure • Assess current systems for quantum vulnerability and recommend mitigation strategies • Contribute to secure architecture design for distributed systems, cloud platforms, and data pipelines • Stay current on advancements in quantum computing and cryptographic research Required Qualifications: • Strong background in cryptography, computer security, or applied mathematics • Hands-on experience with post-quantum cryptography (PQC) algorithms and frameworks • Proficiency in programming languages such as Python, C/C++, Rust, or Go • Experience implementing cryptographic protocols and secure communication systems • Familiarity with NIST PQC standardization process and leading candidate algorithms • Understanding of classical cryptographic systems (RSA, ECC, AES, TLS, etc.) • Ability to translate complex cryptographic concepts into practical implementations Preferred Qualifications: • Advanced degree (MS or PhD) in Cryptography, Computer Science, Mathematics, or related field

Closing date for applications:

Contact: Jeff Hennigan, 469-936-1742

Expand
The Italian Institute of Artificial Intelligence (AI4I)
Job Posting Job Posting

The Italian Institute of Artificial Intelligence (AI4I) invites applications for a Postdoctoral Researcher to join the newly established Crypto4AI Lab, under the supervision of Dr. Tamer Mour.

The Crypto4AI Lab, will conduct cutting-edge research grounded in computer science theory and mathematics, aiming to establish solid foundations for next-generation cryptographic solutions tailored to artificial intelligence systems.

Research topics include, but are not limited to:

  • Private inference
  • Model integrity
  • Model privacy
  • Watermarking
  • Cryptanalysis of new cryptographic assumptions

The research activity of the lab spans both theoretical and applied domains, including protocol design, Cryptanalysis, mathematical work, Experimentation with ML models, implementation and optimization.

AI4I provides a dynamic and interdisciplinary research environment with strong institutional support, including access to dedicated software engineers, high-performance computing resources, and close interaction with industrial partners.

Required qualifications:

  • PhD in computer science, mathematics or related fields.
  • Strong background in at least one of the following areas or closely related disciplines:
    • Theoretical Computer Science
    • Cryptography (theoretical and/or applied)
    • Machine Learning
    • Mathematics
    • Statistical Physics
  • Fluent in spoken and written English.

Start date: Flexible (as soon as possible).

Application:

  • CV (including publications)
  • contact information of three references.

Applications will be reviewed on rolling basis.

Closing date for applications:

Contact: https://app.ncoreplat.com/jobsharingredirect/788404/postdoctoral-position-in-cryptography-for-machine-learning-it/research-and-development?type=1&platform=19&sharing=5056798

More information: https://app.ncoreplat.com/jobsharingredirect/788404/postdoctoral-position-in-cryptography-for-machine-learning-it/research-and-development?type=1&platform=19&sharing=5056798

Expand
Durham University, UK
Job Posting Job Posting

This is an exciting opportunity to join the newly established team of Professor David Oswald at Durham, working in hardware and embedded security, confidential computing, trusted execution, secure AI, and related areas. This post is suitable for postdoctoral candidates with a wide range backgrounds relevant to cyber security, including but not limited to embedded/hardware security, security of AI systems, (post-quantum) cryptography, quantum algorithms, confidential computing/trusted execution, or microarchitectural security.

As the post is funded internally and not connected to a grant, there is substantial freedom and flexibility in scoping the research directions. Applicants should have a PhD (or be close to submission) in cyber security, computer science, maths, electrical engineering, or another relevant discipline. Candidates with extensive industry experience and a relevant publication track record might be exceptionally considered as well. A strong publication track record appropriate to the career stage is expected.

This post is fixed term for 1.5 years, with an opportunity for a 6-month extension subject to positive evaluation after the first year and funding availability.

Durham, the third oldest University in England, is located within a beautiful historic city, home to a UNESCO World Heritage Site, and surrounded by stunning countryside. The Department of Computer Science is one of the very best UK departments with an outstanding reputation for excellence in teaching, research and employability of our students.

To apply, please complete the online form at https://durham.taleo.net/careersection/du_ext/jobdetail.ftl?job=26000319&tz=GMT%2B01%3A00&tzname=Europe%2FLondon

Applications close on 28 April 2026. Shortlisted candidates will be invited to an online interview in mid-May. Please submit:

  • A CV (normally up to 2 pages A4)
  • A cover letter
  • A short statement identifying your publication that you feel is your strongest/most relevant research output with a brief justification.

Closing date for applications:

Contact: For informal enquiries, contact Prof David Oswald at david.f.oswald (at) durham.ac.uk

More information: https://durham.taleo.net/careersection/du_ext/jobdetail.ftl?job=26000319&tz=GMT%2B01%3A00&tzname=Europe%2FLondon

Expand
Chalmers University of Technologyersity
Job Posting Job Posting
The Chalmers CryptoTeam is recruiting! We are seeking a PhD student who will work on transparency technologies (key transparency and transparency logs) and post quantum security. We envision a new team member with some prior knowledge in cryptography, a genuine interest in the topic, and willing to work in a collaborative environment. The PhD duration is up to 5 years, including taking courses (part of the PhD education) and participating in teaching activities (up to 20% of the full time equivalent).

The CryptoTeam provides a welcoming, dynamic and forward-thinking environment. Chalmers University is located in Göteborg, Sweden. The starting date is expected to be by the end of Summer 2026 the latest. Only applications via the official portal (linked below) are considered valid.

Link to official ad: https://www.chalmers.se/en/about-chalmers/work-with-us/vacancies/?rmpage=job&rmjob=14409&rmlang=UK

Closing date for applications:

Contact: Asst. Prof. Elena Pagnin

More information: https://www.chalmers.se/en/about-chalmers/work-with-us/vacancies/?rmpage=job&rmjob=14409&rmlang=UK

Expand
Hong Kong, China, 7 December - 11 December 2026
Asiacrypt Asiacrypt
Event date: 7 December to 11 December 2026
Expand
Saclay, France, 1 June - 5 June 2026
Event Calendar Event Calendar
Event date: 1 June to 5 June 2026
Submission deadline: 15 April 2026
Notification: 4 May 2026
Expand

02 April 2026

Giuseppe D'Alconzo, Andrea Gangemi, Lorenzo Romano, Giuliano Romeo
ePrint Report ePrint Report
Among the schemes in the second round of NIST's additional call for Post-Quantum signatures, PERK builds its security on the intractability of the Permuted Kernel Problem (PKP). In its original formulation, this problem asks, on input three matrices $\mathbf H,\mathbf X,\mathbf Y$, to find a permutation matrix $\mathbf P$ such that $\mathbf H \mathbf P \mathbf X = \mathbf Y$. To achieve better performance and smaller signatures, in its first proposal, the PERK signature modified the security assumption in the following way: given a PKP instance, the matrix $\mathbf P$ does not have to verify the exact previous equation but a relaxed one, taking care of a non-null vector $\mathbf v$ such that $(\mathbf H \mathbf P \mathbf X)\mathbf v = \mathbf Y \mathbf v$. In this work, we rephrase the relaxed problem so that it no longer depends on the PKP instance nor the vector $\mathbf v$. We show that it suffices to find $\mathbf P$ such that $\mathbf H\mathbf P \mathbf X - \mathbf Y$ has rank deficiency. This generalized formulation is easier to model and allows us to design an algebraic attack inspired by those of MinRank and Rank Syndrome Decoding, writing a polynomial system in the entries of $\mathbf P$. Moreover, we can consider it as linear in the minors of $\mathbf P$ and provide some results on them, which may be of independent interest.
Expand
Byoungchan Chi, Nathan Cho, Jiseung Kim, Changmin Lee
ePrint Report ePrint Report
We present an asymptotic analysis of the ternary variant of Sparse Learning with Errors (spLWE), a structured LWE variant proposed by Jain--Lin--Saha (CRYPTO'24) in which each equation involves only $k \ll n$ of the $n$ secret coordinates, enabling significantly more efficient computation than dense LWE. Unlike standard LWE, the small-secret regime of spLWE is not automatically reducible to its large-secret counterpart, leaving asymptotic hardness unclear, particularly when $k$ is very small.

We develop a two-pronged attack framework that depends explicitly on the sparsity parameter $k$. In the geometric regime $q > 3^k$, each sparse row reduces to a short-vector problem in a $k$-dimensional lattice, yielding complexity $2^{0.292k}$ via a sieving algorithm. In the statistical regime $q \leq 3^k$, we propose a greedy coordinate-recovery attack with running time $O(m \cdot k \cdot 3^k)$, where $m$ is the number of samples.

Heuristically, under mild assumptions, full recovery holds with high probability once the sample size is large enough; the resulting complexity is exponential only in $k$ and otherwise mild (up to polylogarithmic factors), i.e., polynomial in $n$, which makes very small $k$ vulnerable even at large dimensions.

Experiments on toy instances confirm the predicted sharp transition. Complexity comparisons with prior works indicate lower complexity on a few of their parameter sets, while identifying regimes where our method is not applicable.
Expand
Haruhisa Kosuge, Keita Xagawa
ePrint Report ePrint Report
Recent MPC-in-the-Head (MPCitH) signatures increasingly rely on aggressive GGM-tree optimizations to reduce signature size and cost, culminating in _secret-key-root correlated_ GGM tree as used in MQOM (NIST PQC Standardization for Additional Signature Round-2, 2024). While this technique yields substantial compression, it introduces a dependency loop in the proof. The transcript we would like to randomize for simulation is generated by expanding a GGM tree from a root that is part of the secret key, so this randomization must be justified via a reduction to the hardness of recovering the secret key. However, the hiding of the secret key relies on masking randomness that is a part of the transcript derived from the same GGM tree. As a result, justifying the randomization requires hiding, while proving hiding requires the randomization, and standard MPCitH proof templates do not apply directly.

We propose and analyze two variants of MQOM and provide the EUF-CMA security proofs. The first variant makes a minor change to salts and replaces blockcipher-based hash functions in the GGM trees with random functions; we then prove its EUF-CMA security in the (quantum) random oracle model under partial-domain one-wayness or slightly stronger one-wayness assumptions. The second variant also makes a minor change to salts and adjusts security parameters to admit a proof under standard one-wayness in the ideal-cipher and random-oracle models. The proof exploits the H-coefficient technique with one-wayness, which might be of independent interest.
Expand
Tianwei Zhang, Xiuquan Ding, Giulio Malavolta, Nico Döttling
ePrint Report ePrint Report
Registration-based Encryption ($\mathsf{RBE}$) is an emerging paradigm to remove the key escrow problem in identity-based encryption (IBE) systems. $\mathsf{RBE}$ represents a promising alternative to a public-key infrastructure, attaining the best of both worlds between IBE and traditional public-key encryption. Despite a lot of recent progress, existing constructions of $\mathsf{RBE}$ are not yet on-par with other approaches in terms of practical efficiency. To make things worse, all known concretely efficient constructions are based on bilinear pairings and are broken by quantum algorithms.

In this work, we make progress on this problem. We construct a lattice-based, and therefore with plausible post-quantum security, $\mathsf{RBE}$ scheme with compact ciphertexts and fast encryption/decryption algorithms. Compared to the state-of-the-art lattice-based $\mathsf{RBE}$, our scheme reduces ciphertext size to $0.148$\,MB, down from $9$\,MB, for $1000$ users, and improves the encryption/decryption runtime by an order of magnitude. To the best of our knowledge, this is the first lattice-based $\mathsf{RBE}$ construction with ciphertexts well below one megabyte and competitive end-to-end performance, representing a significant step toward the practical adoption of $\mathsf{RBE}$.
Expand
Weize Wang, Yi-Fu Lai, Kaizhan Lin, Yunlei Zhao
ePrint Report ePrint Report
Recent work by Houben (Asiacrypt'25) introduced a new formulation for class group actions on supersingular elliptic curves oriented by an imaginary quadratic order for an arbitrarily large discriminant. The algorithm is not only constant-time but also fully deterministic, dummy-free, and branch-free. As a result, it gives the fastest isogeny-based non-interactive key exchange (NIKE) in theory, referred to as OSIDH-LD in this paper. However, the current proof-of-concept SageMath implementation remains substantially slower than mainstream post-quantum key-exchange candidates.

In this paper, we develop an efficient implementation of OSIDH-LD with several approaches. First, we provide algorithmic-level optimizations: (i) we develop the ``tail pruning'' approach such that key agreement avoids redundant orientation updates. This optimization maintains the fully deterministic and dummy-free feature of OSIDH-LD; (ii) we adapt a faster codomain isomorphism identification adapted from the technique used in the SQIsign implementations; and (iii) we present effective isogeny-computation strategies tailored to the cost profile of OSIDH-LD. Second, we adapt the parallelism technique. We apply the fork-join parallel execution model to optimize the class group action performance, and achieve near-perfect parallelism in key generation, as well as improved performance in key agreement.

We provide two kinds of implementations to show the impacts of our improvements. The first one is in C with assembly language for field arithmetic, which verifies the correctness of our optimization techniques targeting OSIDH-LD. The experimental results show that our techniques lead to an overall $1.56\times$ and $1.87\times$ acceleration for key generation and key agreement, respectively. Second, we provide parallel implementations that exploit multi-threading and AVX-512 vector extensions, respectively, by batching independent subroutines in the class group action. In particular, the AVX-512 vectorized implementation is $4.97\times$ faster than the improved C+assembly implementation in key generation, which is close to the theoretical optimum.
Expand
Kok Ping Lim, Dongyang Jia, Iftekhar Salam
ePrint Report ePrint Report
Lightweight cryptographic primitives are widely deployed in resource-constraint environment, particularly in the Internet of Things (IoT) devices. Due to their public accessibility, these devices are vulnerable to physical attacks, especially fault attacks. Recently, deep learning–based cryptanalytic techniques have demonstrated promising results; however, their application to fault attacks remains limited, particularly for stream ciphers. In this work, we investigate the feasibility of deep learning assisted differential fault attack on three lightweight stream ciphers, namely ACORNv3, MORUSv2 and ATOM, under a relaxed fault model, where a single-bit bit-flipping fault is injected at an unknown location. We train multilayer perceptron (MLP) models to identify the fault locations. Experimental results show that the trained models achieve high identification accuracies of 0.999880, 0.999231 and 0.823568 for ACORNv3, MORUSv2 and ATOM, respectively, and outperform traditional signature-based methods. For the secret recovery process, we introduce a threshold-based method to optimize the number of fault injections required to recover the secret information. The results show that the initial state of ACORN can be recovered with 21 to 34 faults; while MORUS requires 213 to 248 faults, with at most 6 bits of guessing. Both attacks reduce the attack complexity compared to existing works. For ATOM, the results show that it possesses a higher security margin, as majority of state bits in the Non-linear Feedback Shift Register (NFSR) can only be recovered under a precise control model. To the best of our knowledge, this work provides the first experimental results of differential fault attacks on ATOM.
Expand
Ryan Babbush, Adam Zalcman, Craig Gidney, Michael Broughton, Tanuj Khattar, Hartmut Neven, Thiago Bergamaschi, Justin Drake, Dan Boneh
ePrint Report ePrint Report
The expected emergence of cryptographically relevant quantum computers (CRQCs) will represent a singular discontinuity in the history of digital security, with wide ranging impacts. This whitepaper seeks to elucidate specific implications that the capabilities of developing quantum architectures have on blockchain vulnerabilities and potential mitigation strategies. First, we provide new resource estimates for breaking the 256-bit Elliptic Curve Discrete Logarithm Problem over the secp256k1 curve, the core of modern blockchain cryptography. We demonstrate that Shor's algorithm for this problem can execute with either $\leq 1200$ logical qubits and $\leq 90$ million Toffoli gates or $\leq 1450$ logical qubits and $\leq 70$ million Toffoli gates. In the interest of responsible disclosure, we use a zero-knowledge proof to validate these results without disclosing attack vectors. On superconducting architectures with $10^{-3}$ physical error rates and planar connectivity, those circuits can execute in minutes using fewer than half a million physical qubits. We introduce a critical distinction between ``fast-clock'' (such as superconducting and photonic) and ``slow-clock'' (such as neutral atom and ion trap) architectures. Our analysis reveals that the first fast-clock CRQCs would enable ``on-spend'' attacks on public mempool transactions of some cryptocurrencies. We survey major cryptocurrency vulnerabilities through this lens, identifying systemic risks associated with advanced features in some blockchains such as smart contracts, Proof-of-Stake consensus, and Data Availability Sampling mechanism, as well as the enduring concern of ``abandoned'' assets. We argue that technical solutions would benefit from accompanying public policy and discuss various frameworks of ``digital salvage'' to regulate the recovery or destruction of dormant assets while preventing adversarial seizure. We also discuss implications for other digital assets and tokenization as well as challenges and successful examples of the ongoing transition to Post-Quantum Cryptography (PQC). Finally, we urge all vulnerable cryptocurrency communities to join the migration to PQC without delay.
Expand

01 April 2026

Tim Beyne
ePrint Report ePrint Report
This note describes a weak-key attack on the tweakable block cipher Blink, which was recently introduced at FSE 2026. Specifically, it is shown that two rounds of Blink admit several nonlinear invariants. To illustrate that these invariants indeed lead to attacks, we describe a partial key-recovery attack on Blink-64 with data and time complexity $2^{23}$, for a fraction of $2^{-96}$ weak keys or tweaks. There is a trade-off between the fraction of weak keys and the data complexity, e.g., with $2^{56}$ data the fraction of weak keys increases to $2^{-63}$. The attack is based on the same strategy as our attack on Midori-64 from Asiacrypt 2018.
Expand
◄ Previous Next ►