International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

02 June 2026

Nasit Sarwar Sony
ePrint Report ePrint Report
We present a Byzantine agreement protocol to address the inefficiencies inherent in multi-valued Byzantine agreement protocols, i.e., a version of the Byzantine agreement protocol where every party broadcasts its request, and at the end of the protocol, every party agrees on one of the party’s requests. The protocol we present is a validated asynchronous Byzantine agreement protocol, i.e., a party’s request must be validated by some external validity property before it is proposed for agreement. Differently from most of the MVBA protocols, we allow only a subset of total parties to broadcast their requests instead of all, and we make the subset selection stochastic each time the parties choose to broadcast a new set of requests. Then, at the time of the agreement, we choose a party from the selected subset, and the parties reach an agreement on the selected party’s broadcast. Extensive theoretical analysis shows that this approach can produce efficient output regarding messages and computation overhead, but the protocol is time-consuming.
Expand

01 June 2026

Eindhoven, Netherlands, 11 April - 15 April 2027
Eurocrypt Eurocrypt
Event date: 11 April to 15 April 2027
Submission deadline: 17 September 2026
Notification: 18 January 2027
Expand
Santa Fe, Argentina, 2 March - 13 March 2026
School School
Event date: 2 March to 13 March 2026
Expand
Santiago, Chile, 27 July - 7 August 2026
School School
Event date: 27 July to 7 August 2026
Expand
Hammamet, Tunisia, 6 July - 7 July 2026
School School
Event date: 6 July to 7 July 2026
Expand
Hanoi, Vietnam, 22 August - 28 August 2026
School School
Event date: 22 August to 28 August 2026
Expand
Virtual event, Anywhere on Earth, 3 December - 4 December 2026
Event Calendar Event Calendar
Event date: 3 December to 4 December 2026
Submission deadline: 25 November 2026
Notification: 29 July 2026
Expand

31 May 2026

Tianyao Gu, Hanjun Li, Elaine Shi
ePrint Report ePrint Report
Minimizing round complexity is a central goal in secure Multi-Party Computation (MPC), particularly for deployment on high-latency networks. While constant-round protocols with concrete efficiency have been constructed, they are typically designed for Boolean circuits and each gate incurs a bandwidth cost linear in the security parameter. Moreover, for arithmetic-heavy applications such as privacy-preserving machine learning and statistical analysis, compiling arithmetic operations into Boolean gates incurs another substantial overhead in circuit size and communication. Conversely, existing arithmetic MPC protocols, such as SPDZ, require interaction rounds proportional to the circuit depth, imposing significant latency.

In this work, we bridge this gap by presenting the first concretely-efficient maliciously-secure MPC protocol that achieves both constant-round and constant-rate communication, where the rate is defined as the bandwidth cost per party divided by the number of gates and the size of the values each gate operates on. Our protocol computes over bounded integers and is secure against a static, malicious adversary corrupting up to $n-1$ parties. The protocol is built upon the arithmetic garbling framework of Ball et al. (Eurocrypt 2023) and follows the BMR template, assuming the Decisional Composite Residuosity for the garbling phase and Learning Parity with Noise for preprocessing.

We evaluate our protocol on matrix-vector multiplication, a fundamental operation for data analysis. For standard computation parameters, we reduce communication bandwidth by $101\times$ to $247\times$ and improves end-to-end runtime by $4.4\times$ to $10.7\times$ compared to state-of-the-art constant-round Boolean MPC baselines, even when accounting for the overhead of a full bit-decomposition on the output vector.
Expand
Tim Beyne, Lorenzo Grassi, Morten Øygarden, Berenika Richterová, Arne Sandrib
ePrint Report ePrint Report
Designing a secure symmetric-key cipher over a vector space over a field $\mathbb F_{p^n}^t$ is well known and understood by the cryptographic community. Even if the attacks are continuously improving, our current understanding regarding the design and security of the majority of the symmetric-key primitives has not fundamentally changed in the last 20 years.

How does this picture change when we move to an integer ring $\mathbb Z_{p^n}^t$? Although the question is easy to state, it turns out to be far harder to answer. Indeed, there is a significant difference between the arithmetics of $\mathbb F_{p^n}^t$ and $\mathbb Z_{p^n}^t$ and attack vectors do not apply/translate directly between the two. As a case in point, a few ciphers have already been designed over integer rings, yet their initial versions have already been broken.

In this paper, we lay the foundations for a more rigorous approach to designing ciphers over integer rings, noting that this is not only of theoretical interest, but also has concrete applications. We analyze how existing statistical and algebraic attacks will behave for these ciphers and also present new attacks that take into account that not all functions over integer rings admit a polynomial representation. Based on this, we discuss possible design strategies, in which we analyze the security effect of having/not having polynomial S-boxes. In particular, we introduce new properties for the non-polynomial S-boxes that measure their resistance against the attacks presented in this paper. Finally, we discuss how to design such non-polynomial S-boxes, presenting two concrete constructions, and one based on the "digit manipulation".
Expand
Nadim Kobeissi
ePrint Report ePrint Report
Few-time signatures cap how many signatures a signer can safely issue. Jevil is, to our knowledge, the first post-quantum and transparent (setup-free) few-time signature scheme with a sharp key-recovery cliff: its cap is enforced by a single sharp threshold rather than a slow slope. Signatures one through $n^{\star}$ are existentially unforgeable at approximately $124$-bit classical security; at the $(n^{\star}+1)$-th the entire secret polynomial becomes publicly recoverable. The cap is founded on a secret polynomial together with the degree-binding of a polynomial commitment, and is intrinsic to any accepted public key: even a malicious signer who chooses $\mathsf{pk}$ adversarially cannot construct one that lets them keep signing past the cliff without the same polynomial becoming publicly recoverable, achieving catastrophic failure as a key design requirement. All prior post-quantum few-time schemes (HORS, FORS, PORS, HORSIC$^{+}$, eBiBa, Syrga$_2$) degrade softly as $(nK/T)^K$; cliff-style behaviour was previously confined either to one-time-only Schnorr/ECDSA nonce reuse (not post-quantum, not designed) or to polynomial-witness constructions that depend on KZG/IPA commitments (not post-quantum, not transparent).

Concretely, Jevil provides $\sim 68$-byte public keys, $32$-byte secret keys, and $40$-$500$KB signatures across signing budgets $n^{\star} \in \{1, 3, 7, 15, \ldots, 2^{14} - 1\}$, the limit imposed by the $2$-adicity of the working field. All primitives are believed to be post-quantum.
Expand
Tim Seuré, Elias Suvanto
ePrint Report ePrint Report
We propose a CKKS-based technique for evaluating arithmetic over finite fields F_{p^r} with small characteristic p under homomorphic encryption. The core of our approach is a pair of complementary ciphertext representations. In the so-called spectral encoding, ciphertext addition and multiplication realize addition and multiplication in the field F_{p^r}. In another encoding, coefficient encoding, the same operations act as slotwise addition and multiplication in the slot algebra (F_p)^r. We show that one can switch homomorphically between these encodings at cost linear in r, and that F_p-linear maps, such as taking p-th powers in F_{p^r}, can be folded into these switches or applied directly in either representation. We complement the construction with theoretical and practical correctness-management techniques. To support unbounded computations, we integrate our framework with existing CKKS bootstrapping techniques and benchmark it against BGV-based implementations of F_{p^r}-arithmetic, a natural baseline for high-throughput finite-field computation. Across the fields we tested, this yields speedups ranging from 1.7x to 178x in amortized multiplication time when bootstrapping is taken into account. The gains are parameter-dependent: roughly speaking, our advantage over BGV increases as the characteristic p becomes smaller and the extension degree r becomes larger.
Expand
Bernardo David, Lucia Lavagnino, Elena Pagnin, Paul Stankovski Wagner
ePrint Report ePrint Report
Techniques to randomly select sets of anonymous parties are ubiquitous in efficient and adaptively secure consensus protocols, as well as in Multi-Party Computation in the YOSO model, where each round is executed by a different random anonymous committee. Anonymous committee selection aims at randomly selecting a set of $n$ parties (the committee), where at most $t$ parties are corrupted (except with negligible probability), drawing from a population of $N \gg n$ parties with at most $T$ corrupted parties. Additionally, each party knows (and can prove) if they belong to the committee, but ignores other members' identities. A very common and efficient instantiation of anonymous committee selection is to select parties according to a VRF output, this however, leads to committees of probabilistic size ($n$ behaves as a Binomial random variable). Despite wide adoption, only Blum et al. (CCS23) provides an analysis of VRF-based probabilistic anonymous committee selection that estimates the size of committees. This analysis relies on lose bounds (Chernoff) and approximations (Poisson). In this work, we revisit Blum et al.'s estimates and derive accurate closed-form formulas (based on a tight Binomial approximation), as well as an efficient high-precision library called Tail-Hammer for computing exact parameters. Notably, Tail-Hammer identifies smaller committee sizes (approximately -25% on average) than Blum et al. (CCS23) for the same security level, leading to improved efficiency in protocols relying on random committee selection, also when anonymity is not needed. Our analysis applies to committee selection techniques that employ unbiased (uniformly random), or bounded-bias randomness, to both synchronous and asynchronous communication settings, and it can account for inactive parties. As a new application, we present a verifiable consistent broadcast protocol that leverages quorums in anonymous committees to achieve efficiency without requiring threshold signatures.
Expand
Renas Bacho, Yanbo Chen, Julian Loss
ePrint Report ePrint Report
Publicly verifiable secret sharing (PVSS) is a fundamental primitive in threshold cryptography that allows a dealer to share a secret $S$ among a set of $n$ parties via a publicly verifiable transcript. Any subset of $t+1$ parties can then use their individual shares to reconstruct the full secret $S$, whereas $t$ or fewer shares give no information about $S$. As such, the secret $S$ remains hidden from an adversary that corrupts up to $t$ parties. Recently, Bacho and Loss (CCS 2023) gave the first proof of any PVSS scheme under an adaptive adversary. However, their security proof relies on strong and non-standard assumptions such as the algebraic group model (AGM) and the hardness of the one-more discrete logarithm (OMDL) problem. In particular, any protocol (e.g., distributed randomness beacon or distributed key generation) that makes use of a PVSS scheme either inherits these limitations or is not provably adaptively secure.

In this work, we present for the first time an adaptively secure PVSS scheme from well-established assumptions. In more detail, we provide two PVSS schemes with different properties. Our first scheme works over any pairing-free cyclic group and its security relies on the decisional Diffie-Hellman (DDH) assumption. Our second scheme works over an asymmetric pairing group, its security relies on the DDH and the co-computational Diffie-Hellman (co-CDH) assumption, and has the particularly valuable feature of aggregatability, which allows the aggregation of multiple PVSS transcripts into a single transcript while preserving verifiability. Notably, both our schemes are highly efficient, non-interactive, and work in the established plain public key model. These properties along with their provable adaptive security make them suitable candidates as building block in higher-level distributed protocols that aim to minimize communication.
Expand
Lin Jiao, Hongsen Yang, Hongrui Cui, Yituo He, Yonglin Hao, Xiaojie Guo, Qunxiong Zheng, Jiang Zhang, Yu Yu, Kang Yang
ePrint Report ePrint Report
VOLE-in-the-Head (VOLEitH) is one of the most promising frameworks to design post-quantum digital signatures based on symmetric primitives. However, all existing symmetric primitives do not capture the specialized characteristics of the VOLEitH framework and are not VOLEitH-friendly, leaving room for improving the efficiency of VOLEitH-based signatures. In this paper, we propose a VOLEitH-friendly symmetric primitive called Lynx, which is optimal in terms of the number of required VOLE correlations that directly determines the efficiency of VOLEitH-based signature schemes. In particular, Lynx adopts a multi-branch structure featuring a new truncation function: (a) nonlinear components are customized to minimize the witness length and polynomial degree, as well as the number of finite-field multiplications; (b) linear layers are strategically interleaved to strengthen security. The security of Lynx is rigorously validated by covering all possible attacks in the presence of both classical and quantum adversaries. Built upon Lynx, we design a post-quantum signature scheme, Lynxer, in the VOLEitH framework, which is shorter and faster than all known post-quantum signature schemes from symmetric primitives. According to our experimental results, compared to the state-of-the-art symmetric-based signature schemes in the same setting, i.e., Rainier (CCS’22), AIMer (CCS’23) and FAESTv2 (Crypto’25), our signature scheme Lynxer reduces the “public-key size + signature size” by 25% ∼ 51%, and improves the signing (resp., verification) time up to 90.6% (resp., 89.3%).
Expand
Alfred Menezes
ePrint Report ePrint Report
We present the quantum-safe Kyber key encapsulation mechanism (ML-KEM) and the Dilithium signature scheme (ML-DSA). We also develop the mathematical background on lattices needed to understand why Kyber and Dilithium are regarded as lattice-based cryptosystems, and we provide insight into the computational hardness of the underlying lattice problems. The exposition is intended to be accessible to senior undergraduate students and beginning graduate students.
Expand
Marian Dietz, Dennis Hofheinz
ePrint Report ePrint Report
Schnorr's signature scheme and many of its variants are among the most efficient group-based digital signature schemes. Schnorr's scheme has very compact signatures (consisting of only two exponents in its most compact form). However, its security reduction is notoriously non-tight and requires a strong (“programmable”) version of the random oracle model. Variants with a tight(er) security proof in a more realistic model exist, but are less compact and efficient.

In this work, we investigate whether these disadvantages are inherent to Schnorr's signatures and its variants. In particular, we define a family of “Schnorr-like” signature schemes, which contains group-based signature schemes with verification similar to Schnorr's scheme. To explore the necessity of (heavy) random oracle abstractions for such schemes, we allow only for a very weak (“non-programmable, non-observable”) version of a random oracle in the security proof. Our main result is that there is no tight reduction of the security of any such “Schnorr-like” scheme to any group-based assumption that holds generically.

We also show that this result itself is tight, in the sense that non-tightly secure schemes exist. Similarly, already for a slightly generalized definition of “extended Schnorr-like” schemes, tightly secure schemes exist.

Our main result employs a meta-reduction with a new “filtering” technique that may be of independent interest.
Expand
Yi-Fu Lai, Luciano Maino
ePrint Report ePrint Report
Zero-knowledge proofs are a fundamental building block of modern privacy-preserving systems. In isogeny-based cryptography, existing zero-knowledge proof constructions are either limited to chains of small-degree isogenies or are quite inefficient. As a result, many relations used in recent cryptosystems lack support in generic proof systems.

In this work, we take a step toward making zkSNARKs practically usable for a broader set of isogeny relations beyond the classical isogeny path knowledge language. Leveraging optimized Vélu-style formulas, we provide an efficient R1CS encoding for $3^m$- and $4^n$-isogenies, along with their masked evaluations. We also present an R1CS for non-smooth isogenies of special degree $q(2^e - q)$, where $q$ is an odd integer, together with their evaluation. This latter encoding is based on the efficient formulas for $(2,2)$-isogenies in the theta model.

Finally, we demonstrate several concrete applications of our tools. We present a compiler that removes the ``one-more'' evaluation assumption in the signature based on DeuringVRF. We also discuss how to eliminate the hint-based assumption in SQISign and explain how to construct a key-validation mechanism for recent public-key encryption designs, such as POKÉ on the concept level. We provide the experimental results with respect to the constraint numbers under various isogeny NIST-1 primes for reference. Under the setting, the proof sizes considered in this work are bounded by 400 KB by the default setting. We hope our results will inspire further advances in isogeny-based constructions.
Expand
Sebastian Clermont, Antoine Gansel, Patrick Struck
ePrint Report ePrint Report
Quantum key distribution (QKD) enables the exchange of information-theoretically secure symmetric keys, but is fundamentally limited in range. Existing long-distance QKD networks rely on trusted relay nodes, any one of which can compromise the entire key. We propose a key-transport protocol that removes this trust assumption by combining proactive secret sharing with one-time pad encryption over pairwise QKD links. At each layer of relay nodes, shares are reshared so that corruptions across different layers cannot be combined; security depends only on the maximum number of corruptions within any single layer, not on the total number of corrupted nodes. We formalize a game-based security model for layered secret transport, identify a cross-layer attack that affects a prior construction, and prove our protocol information-theoretically secure against a semi-honest adversary corrupting up to $t{-}1$ nodes per layer.
Expand
Milan Gonzalez-Thauvin, Keitaro Hashimoto
ePrint Report ePrint Report
Asymmetric Message Franking (AMF), proposed by Tyagi et al. at Crypto’19, is a sort of signature scheme that aims to provide privacy-preserving content moderation in secure messaging applications. In this work, we present the first generic construction of AMF using a public-key encryption scheme, a signature scheme, and a ZAP proof system for NP languages. This construction yields the first AMF scheme provably secure in the plain model from standard assumptions, and has tight security. To improve the efficiency of AMF in the plain model, we build a concrete scheme from asymmetric pairing groups based on our idea for the generic construction. It achieves a signature size of 47 group elements, which is significantly smaller than an instantiation of the generic construction. Also, we provide a variant of the generic construction that yields a post-quantum secure AMF scheme in the plain model from a polynomially hard LWE assumption, demonstrating its feasibility.
Expand
Rosario Giustolisi, Emad Heydari Beni, Daniele Marletta, Maryam Sheikhi Garjan
ePrint Report ePrint Report
Demand Response (DR) in energy systems is a flexibility mechanism enabling consumers to modify their electricity demand in response to signals from network operators, designed to ensure power grid reliability. In particular, incentive-based DR programs, in which consumers provide load reduction in exchange for financial remuneration, have proven more effective than alternative approaches such as price-based programs. However, incentive-based approaches have taken only partial account of privacy considerations, mainly because they require smart meters to disclose user energy baselines and consumption patterns to aggregators in order to determine rewards.

In this paper, we propose a privacy-preserving scheme that supports incentive-based DR programs while ensuring the confidentiality of user data and identities. We prove that our scheme provides data privacy, participation privacy, and public verifiability, and we present a prototype implementation together with a performance evaluation. Our results show that our construction is practical for real-world DR deployments with considerably large user populations.
Expand
◄ Previous Next ►