International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

17 June 2026

University of New South Wales, Sydney
Job Posting Job Posting
The School of Computer Science and Engineering in the Faculty of Engineering at UNSW has four open positions for Lecturer/Senior Lecturers and Associate Professors in Cryptography and Cybersecurity. All are Teaching and Research roles. Details of the roles are available here.

  • Lecturer/Senior Lecturer in Cryptography:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540324/lecturersenior-lecturer-in-cryptography

  • Lecturer/Senior Lecturer in Cybersecurity:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540329/lecturersenior-lecturer-in-cybersecurity

  • Associate Professor in Cryptography:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540099/associate-professor-in-cryptography

  • Associate Professor in Cybersecurity:

    https://external-careers.jobs.unsw.edu.au/cw/en/job/540329/lecturersenior-lecturer-in-cybersecurity

UNSW is a member of Group of Eight (Go8) highly research-intensive universities in Australia and a world‑leading institution recognised for its scale, prestige, and impact. With strong industry engagement and partnerships across sectors, UNSW provides a unique environment where academic expertise translates into real‑world outcomes. The School of Computer Science and Engineering is one of the largest and most prestigious schools of computing in Australia. For academics, UNSW offers an outstanding platform to flourish — combining world‑class facilities, collaborative networks, and a culture of innovation that supports both career growth and meaningful contributions to the wider community.

Closing date for applications:

Contact: Please apply via UNSW Jobs Portal https://external-careers.jobs.unsw.edu.au/

Expand
University of Glasgow, UK
Job Posting Job Posting

We are looking for a (fully funded) PhD student. This PhD studentship focuses on provable security, with an emphasis on post-quantum cryptography, including but not limited to the theoretical proof frameworks and practical applications, such as secure communication and authentication.

You will be co-supervised by Dr. Tianxin Tang and Prof. Shahid Raza.

What we expect from you:
  • Passionate about the research topics and motivated to lead the projects.
  • Background: a master's degree (or strong candidates with a bachelor's degree) in computer science, mathematics, or related subjects.
  • Strong analytical skills are preferred.
  • Research experience in the related areas is a plus.
What you can expect from us:
  • At least one weekly supervision meeting to help keep you on track.
  • Guidance on writing, presentation, and career development.
  • Flexible working hours.
  • A shared interest in producing high-quality research results.
What you will like about Glasgow:
  • Easy train/bus access to all the resources of the "rival" city, Edinburgh, including the famous Festival Fringe, but without quite as many tourists and lower living costs.
  • Hogwarts-style architecture and a not-so-Hogwarts-style computer science department.
Application deadline: Friday, July 31, 2026

Please apply through https://www.findaphd.com/phds/project/phd-in-computing-science-post-quantum-cryptography-and-its-applications/?p197380.

After submitting your application, please also send an email to [email protected] with the subject title "Application IACR PhD Position: [Your Name]", so that we know you applied after seeing this ad on IACR :)

If you have general questions regarding this job post instead, you can also email [email protected] with a subject title starting with "Regarding IACR PhD Position:".

Closing date for applications:

Contact: Tianxin Tang ([email protected])

Expand
University of Vienna, Austria
Job Posting Job Posting
We focus on foundations of cryptography and are searching for a motivated PhD candidate to join our team. We develop new security definitions which match practical applications, explore complexity-theoretic relations, develop novel, sophisticated proof techniques, and design schemes that provably satisfy strong security guarantees. In the current project (see WWTF project FARCry) we explore the foundations and applications of resource-restricted cryptography. Strong mathematics skills are advantageous and arguing by formal mathematical proofs is essential.

The position is funded for 4 years with a competitive salary and available from October 2026. For eligibility, an MSc degree in Computer Science or Mathematics (or a related field) is required. Applications must contain all required documents and be done exclusively through the linked job portal of University of Vienna.

University of Vienna is located centrally and public transport is extraordinarily good. Vienna is internationally very well connected by train, plane and bus. There are several cryptography research groups in and around Vienna and we encourage regular exchange through a joint reading group.

Closing date for applications:

Contact: Karen Azari (karen.azari(at)univie.ac.at)

More information: https://jobs.univie.ac.at/job/Scientific-project-assistant-predoctoral-%28group-Foundations-of-Cryptography%29/1402740533/

Expand
Epita Research Laboratory
Job Posting Job Posting
Automated Cryptanalysis using Constraint
Programming Domain: Symmetric Cryptography, Constraint Programming (CP/SAT/ILP), Security

Context & Objectives: In the context of global encryption standardization (e.g., NIST calls), evaluating the security of block ciphers is critical. Recent advances have shifted manual cryptanalysis toward automated constraint models. However, current tools (like TAGADA or CLAASP) only solve isolated sub-problems, requiring manual complexity compilation. This PhD aims to unify these steps into a single framework to optimize global attack complexity directly and find finer security bounds on established or forthcoming ciphers.

Core Research Axes:
  • Fully Automated Differential Attacks: Merge separate attack phases into a single model using generic solvers to optimize global complexity instead of sub-problems.
  • Improving Truncated & Boomerang Attacks: Implement new constraint types directly into the core of CP solvers to improve abstraction quality and refine theoretical bounds.
  • Solver Scalability: Leverage structural patterns of encryption algorithms to guide solvers, reducing resolution times from months to days on high-round ciphers.

Profile Required:
  • Master’s degree or equivalent in Computer Science, Applied Mathematics, or Cryptography.
  • Prior internship experience in automated cryptanalysis techniques is highly desired.
  • Strong background in symmetric cryptography and/or optimization techniques (SAT, CP, ILP).
The candidate MUST BE EU or UK citizen.

Closing date for applications:

Contact: [email protected]

Expand
INSA Lyon, France
Job Posting Job Posting

The CITI Lab at INSA Lyon in France is looking for a PhD student to carry out cutting-edge research in privacy-preserving Federated Learning (FL).

FL enables collaborative model training without sharing raw data, preserving privacy by exchanging model updates instead. However, FL remains vulnerable to privacy leakage, poisoning attacks, and challenges from client heterogeneity. Secure Aggregation techniques, such as Homomorphic Encryption, improve privacy, while defenses like anomaly detection and robust aggregation enhance security but often increase computational costs. Asynchronous FL (AsyncFL) improves scalability by processing updates as they arrive, and Buffered AsyncFL helps maintain privacy by aggregating updates in batches. Despite its benefits, FL can be energy-intensive, motivating sustainable approaches such as fog computing and communication-efficient protocols. The proposed SURPRISA-FL framework addresses these challenges by combining privacy preservation, Byzantine robustness, asynchronous participation, and energy efficiency.

This fully funded position has a 3-year duration, with a negotiable start date.

Responsibilities:

  • Collaborate with faculty and researchers to design innovative cryptographic protocols.
  • Publish research findings in leading computer science conferences and journals.
  • Participate in academic activities, including seminars, workshops, and conferences.
  • Potentially assist in teaching duties.

Requirements:

  • A strong background in cryptography, with an MSc in Computer Science, Engineering, Mathematics, or a related discipline.
  • Excellent communication and interpersonal skills.
  • Strong organizational and time-management abilities to balance research, coursework, and teaching responsibilities.
  • Critical thinking and analytical skills, with fluency in technical English.
  • Proficiency in programming.

To apply, please send a copy of your CV and all your transcripts (Bachelor's and Master's).

Closing date for applications:

Contact:

To apply, please send a copy of your CV and all your transcripts (Bachelor's and Master's) to clementine(dot)gritti(at)insa-lyon(dot)fr.

Expand
TU Darmstadt, Department of Computer Science, ENCRYPTO; Germany
Job Posting Job Posting

The Cryptography and Privacy Engineering Group (ENCRYPTO) @CS Department @Technical University of Darmstadt offers a fully funded position for a Doctoral Researcher (Research Assistant/Ph.D. Student) in Cryptography & Privacy Engineering, available immediately and for initially 3 years with the possibility of extension.

Our mission is to demonstrate that privacy can be efficiently protected in real-world applications via cryptographic protocols.

TU Darmstadt is a top research university for IT security, cryptography and computer science in Europe. The position is based in the City of Science Darmstadt, which is very international, livable and well-connected in the Rhine-Main area around Frankfurt.

Job description

You work in the ERC Consolidator Grant project Tools for Protecting Data and Function Privacy (PRIVTOOLS), where we build composable protocols, optimizations and tools to protect data & functions in applications. We use Multi-Party Computation (MPC), Private Function Evaluation (PFE), and Private Set Operations (PSO) such as Private Set Intersection (PSI) & Private Set Union (PSU). You will design, optimize, implement and benchmark efficient cryptographic protocols and tools for their automatic generation, and publish & present your research results at top conferences and journals. You will also be involved in our teaching activities, e.g., the integrated course Cryptographic Protocols and the basic course Digital Technology, and supervise thesis students and mentor student assistants.

Your profile
  • Completed Master's degree at a university with excellent grades in IT security, computer science, or a similar field (degree must be completed by starting date of employment).
  • Extensive knowledge in applied cryptography/IT security and very good software development skills.
  • Additional knowledge in cryptographic protocols such as MPC, PFE, PSO, compiler construction, and/or hardware synthesis is a plus.
  • The working language at ENCRYPTO is English, so you must discuss/write/present scientific results in English. For the area of teaching, German is beneficial but not required.

Closing date for applications:

Contact: Thomas Schneider <[email protected]>

More information: https://encrypto.de/jobs/PRIVTOOLS26

Expand
Seoul, South Korea, 15 July - 16 July 2026
Event Calendar Event Calendar
Event date: 15 July to 16 July 2026
Expand
Bengaluru Urban, India, 16 December - 19 December 2026
Event Calendar Event Calendar
Event date: 16 December to 19 December 2026
Expand

16 June 2026

Fintan Costello, Paul Watts
ePrint Report ePrint Report
We give a witness-finding cryptanalysis of Stickel-type key exchange schemes, which involve two-sided multiplication of $n \times n$ matrices over $\mathbb{F}_p$, where these matrices are drawn from public subspaces with a particular commuting structure. This analysis covers Stickel's original proposal, Shpilrain's polynomial extension of that scheme, Nager's algebraic extension of that scheme, and more generally all Stickel-type approaches using public subspaces over matrix algebra in finite fields: all such schemes can be broken in polynomial time. We also describe a new key establishment scheme using two-sided matrix multiplication in which the commuting subspaces used to form the key are hidden via conjugation by private terms, blocking this specific public-subspace analysis; the witness-finding problem in this new scheme has a direct reduction from a standard NP-hard problem (Edmonds' problem).
Expand
I. Buchinskiy, M. Kotov, A. Treier
ePrint Report ePrint Report
In 2011, Grigoriev and Shpilrain proposed using tropical algebraic structures in cryptography. In recent years, numerous protocols based on tropical and related structures have been introduced, as well as many attacks on some of these protocols. This direction of research is now known as tropical cryptography. As a result of the efforts both to design secure schemes and to analyze their vulnerabilities, many purely algebraic and computational problems have emerged. In this paper, we give an overview of several results and open questions in this area. We discuss the complexity of solving certain classes of systems of equations over tropical and similar structures, as well as algorithms and approaches for solving such systems. We also present results on the asymptotic density of satisfiable systems of equations of special forms over tropical algebras. Furthermore, we discuss the discrete logarithm problem, the two-sided discrete logarithm problem, the knapsack problem, and the subset sum problem over tropical matrix structures. We consider a generalization of marginal sets for tropical semirings and semigroups. We also explore different classes of pairwise commuting matrices.
Expand
Pan Xiao, Rending Ouyang, Heng Zhang, Jiawen Zhang, Jian Liu
ePrint Report ePrint Report
Fully homomorphic encryption (FHE) enables non-interactive secure transformer inference (NISTI). Due to the high cost of bootstrapping, conventional approaches typically choose parameters that support a large multiplicative depth to reduce bootstrapping frequency. However, larger depth directly increases ciphertext size, resulting in higher communication and computation overheads.

In this paper, we introduce a novel functional bootstrapping (FBS) scheme that fundamentally reshapes the computation paradigm for NISTI: by fusing as many operations as possible into each bootstrapping operation, our approach significantly reduces the prescribed multiplicative depth.

Our FBS achieves a trigonometric minimax approximation for the target function, making it well suited for precision-sensitive components such as transformer nonlinear layers. Furthermore, we incorporate linear layers into the slot-to-coefficient (S2C) transformation within FBS, thereby eliminating the need to evaluate them separately. Building on these innovations, we present a complete NISTI framework that achieves a 1.9$\times$ speedup in runtime (from 662.3s to 349.5s) and a 3$\times$ reduction in communication (from 48.3MB to 16.1MB) compared with the state-of-the-art.
Expand
Antonio Sanso, Giuseppe Vitto
ePrint Report ePrint Report
Poseidon is one of the most widely deployed arithmetization-oriented cryptographic permutations and plays a central role in modern zero-knowledge proof systems. Although several algebraic attacks on reduced-round variants have been proposed, the security of the recommended parameter sets remains intact. A central difficulty in such attacks is controlling the degree growth of the polynomial representations induced by the permutation.

In this work, we introduce degree annihilation, a new framework for algebraic cryptanalysis of Poseidon. Unlike round-skipping techniques, which reduce complexity by removing rounds from the algebraic model, degree annihilation reduces the contribution of existing rounds by imposing algebraic constraints that force dominant degree terms to vanish. This yields polynomial systems of substantially lower effective degree.

We first present a simple bivariate form of degree annihilation and show how it combines naturally with classical round-skipping techniques. The gain depends on the multiplicity with which the annihilated degree contribution propagates through the remaining nonlinear layers; when this multiplicity matches the contribution of one S-box layer, the effect is the same as skipping an additional nonlinear layer. We then generalize the technique to multivariate settings, where systems of control equations are used to annihilate successive partial-round degree contributions. These systems can be solved using elimination, resultants, and Gröbner basis techniques.

As a proof of concept, we apply the framework to reduced-round Poseidon instances and obtain new CICO-2 attacks. More broadly, our results suggest that constructing algebraic varieties that actively control degree growth may provide a new direction for the cryptanalysis of arithmetization-oriented primitives.
Expand
Dongkun Hou, Yuanzhe Zhang, Shujie Cui, Tsz Hon Yuen, Joseph K. Liu, Jiangshan Yu
ePrint Report ePrint Report
Universal multi-party swaps were proposed for secure cross-chain cryptocurrency exchanges across multiple blockchains that require only signature verification from the underlying blockchains. However, existing universal swap protocols remain vulnerable to griefing attacks, where a deviating party aborts the swap to lock a compliant party’s assets for a long period, potentially causing indirect economic losses. A natural approach is to lift existing griefing-free solutions to the universal setting; however, we observe that this direct approach still faces three key challenges: (i) a timeout race attack, which arises from the absence of an upper bound on the transaction validity; (ii) a premium escape attack, which results from multiple refund transactions for the same assets being simultaneously valid; and (iii) a topological limitation, which implies that universal multi-party swaps can support only a special class of strongly connected digraphs, called reuniclus graphs.

In this paper, we propose GumSwap, a Griefing-free universal multi-party atomic Swap, which guarantees that a compliant party receives a premium if its asset is locked but not redeemed. To mitigate the timeout race attack and the premium escape attack, we impose minimum timeout intervals for the principal and premium timeouts, respectively, and introduce an asset migration mechanism that ensures that, during any time interval, at most one refund transaction is valid. Given the topological limitations of universal swap protocols, we further design a novel premium distribution mechanism that accommodates two classes of leaders in reuniclus graphs. Our experimental results demonstrate that GumSwap can be performed in less than 0.5 seconds per party, while reducing gas costs by 10.3X compared with existing contract-based solutions.
Expand

14 June 2026

Dongkun Hou, Ying-Teng Chen, Shujie Cui, Tsz Hon Yuen, Joseph K. Liu, Jiangshan Yu
ePrint Report ePrint Report
Universal atomic swaps [Oakland'22] replace hashed timelock contracts with adaptor signatures and verifiable timed dlogs, enabling secure cross-chain cryptocurrency exchanges that only require basic signature verification from the underlying blockchains. However, existing universal swap protocols remain vulnerable to griefing attacks, where a deviating party aborts the swap to lock a compliant party's assets for a long period. A natural approach is to lift existing contract-based solutions to the universal setting, but we identify that this straightforward solution faces two key challenges: (i) timeout race attacks, first identified in PipeSwap [Oakland'25], which arises from the absence of an upper bound on the transaction validity; (ii) a timeout overlap dilemma, which results from multiple overlapping refund periods.

In this paper, we propose HedgeSwap, a universal hedged atomic swap protocol against griefing attacks, which compensates a compliant party with a premium if its asset is locked but not redeemed. To mitigate the timeout race attacks and timeout overlap dilemma, HedgeSwap eliminates the premium timeout and instead relies on a hard relation to refund the premium. For high-value asset swaps where the parties acceptable premium ranges do not overlap, we further propose a round-based HedgeSwap that utilizes a premium migration mechanism to solve these two timeout challenges, where parties iteratively increase the premium until the lock-up risk premium acceptable to both. Our experimental results show that our HedgeSwap can complete in under 0.5 seconds, and round-based HedgeSwap completes in under 1.3 seconds for a five-round setting, while HedgeSwap reduces gas cost by 2.69X compared to existing contract-based solutions.
Expand
Kamil Otal, Ali Mert Sülçe, Oğuz Yayla
ePrint Report ePrint Report
A pair of differences $(x,y)$ is a \emph{related differential} for a linear layer $M$ if, for every coordinate at both the input and the output, at least one of the two values vanishes or the two values coincide. Related differentials underlie the zero-difference attack on AES of Bardeh and Rijmen, and the question of which maximum distance separable (MDS) matrices admit them was raised by Daemen and Rijmen, who showed that every $4\times4$ circulant MDS matrix does while some Hadamard ones do not. In earlier work we characterized the $3\times3$ MDS matrices over $\mathbb{F}_{2^r}$ admitting related differentials by fifteen explicit equations. In this paper we settle the $4\times4$ case completely: an MDS matrix $M=DNE$ over $\mathbb{F}_{2^r}$ admits a related differential if and only if at least one of $280$ explicit polynomial equations in the nine free entries of its reduced form $N$ holds. The equations, $70$ quadratic and $210$ cubic, are pairwise distinct, irreducible and pairwise coprime, and fall into $27$ orbits under the natural symmetries. We further determine the structure of the equation set: the fifteen equations of the $3\times3$ case are exactly the points of $\mathrm{PG}(3,2)$, while the $280$ equations span a $14$-dimensional $\mathbb{F}_2$-space, satisfy exactly $560$ additive relations, and contain exactly $840$ pairs that can never hold simultaneously on an MDS matrix. The discarded zero patterns split into $525$ whose determinant condition is equivalent to the failure of MDS-ness and $289$ vacuous cases. Over $\mathbb{F}_8$, the smallest field carrying $4\times4$ MDS matrices, exhaustive enumeration shows that there are exactly $720$ reduced MDS matrices; each satisfying exactly $28$ of the equations and each equation being satisfied by exactly $72$ matrices; in particular every $4\times4$ MDS matrix over $\mathbb{F}_8$ admits a related differential. Over $\mathbb{F}_{2^{10}}$ we exhibit an explicit MDS matrix admitting none. All results are verified by exact computation against an independent exhaustive search.
Expand
Tao Lu, Jipeng Zhang, Yanpei Guo, Xuanming Liu, Wenjie Qu, Zonghui Wang, Wenzhi Chen, Jiaheng Zhang
ePrint Report ePrint Report
GPU Tensor Cores, specialized hardware units designed to accelerate matrix multiplication, have served as the primary engine behind the AI revolution. Given the exponential performance gains they have delivered, aligning cryptographic implementations with this hardware evolution is critical. This is particularly acute for zero-knowledge proofs (ZKPs), a cryptographic primitive that currently grapples with high proof generation costs. Existing GPU implementations for ZKPs rely exclusively on general-purpose SIMT cores, leaving the massive computational power of Tensor Cores untapped.

In this paper, we introduce TensorZKP, the first GPU framework to harness Tensor Cores for ZKP acceleration. Since Tensor Cores are designed for low-precision matrix multiplication, mapping ZKP's arithmetic to this hardware is non-trivial. To bridge this gap, we develop Tensor-Core-compatible finite field arithmetic and reformulate ZKP modules, specifically sum-check protocols and Spielman code, into matrix multiplication tasks. Furthermore, we design an asynchronous warp-specialized framework that pipelines memory access, Tensor Core matrix operations, and SIMT-based modular reductions. We instantiate these optimizations with HyperPlonk as the Polynomial Interactive Oracle Proof (PIOP) and Brakedown as the Polynomial Commitment Scheme (PCS) to enable end-to-end proof generation.

The evaluation results show that TensorZKP exhibits remarkable efficiency. At a $2^{25}$ scale, the underlying building blocks complete in $0.85$ ms for inner product, $0.91$ ms for scalar-vector multiplication, $4.04$ ms for degree-2 sum-check, and $11.58$ ms for the encoder. For a circuit with $2^{25}$ multiplication gates, TensorZKP achieves a proof generation time of only $215.28$ milliseconds, representing a $955\times$ speedup over the CPU baseline and a $36.2\times$ improvement over state-of-the-art SIMT-based GPU implementations.
Expand

13 June 2026

Xiao-Xin Zhao, Deng Tang, Zhong-Xiao Wang, Qun-Xiong Zheng
ePrint Report ePrint Report
Shift-invariant maps have been employed to design nonlinear layers in many symmetric cryptographic schemes, such as the $\chi$-map used in Keccak. In this paper, we study the shift-invariant maps on $\mathbb{F}_2^n$, whose defining functions come from a family of $n$-variable Boolean functions induced by a bifix-free sequence $\underline{a}=(a_1,a_2,\ldots,a_m)\in \mathbb{F}_2^m$ with $2\leq m
Expand
Foteini Baldimtsi, Aayush Yadav
ePrint Report ePrint Report
Anonymous tokens with private metadata bit (ATPM) allow an issuer to embed a hidden trust flag, as a single bit, within issued tokens. The bit remains hidden from the clients, but verifiers can read the bit and rate-limit or discard tokens marked suspect. A series of ATPM constructions exist in the literature, however all current constructions rely on classical hardness assumptions such as RSA groups, pairings, or elliptic-curve VRFs and do not provide any post-quantum security guarantees.

In this work we present, the first ATPM scheme based on lattice assumptions. Tokens generated with our scheme are publicly verifiable, and privately bit-extractable given partial knowledge of the issuing authority's secret. Our design follows the Fischlin blind-signature paradigm and enriches it with lattice-based linearly-homomorphic encryption to carry the hidden bit.

We also instantiate our scheme from Falcon-512 and the efficient LNP22 lattice NIZK proof system (Lyubashevsky et. al, Crypto '22). The resulting protocol, which we call $\textsf{Atlantis}$, requires 70 KB of client-issuer communication and yields 129 KB tokens.
Expand
Kota Urushigaki, Hayato Kimura, Atsushi Tanaka, Takanori Isobe
ePrint Report ePrint Report
Session is a widely deployed decentralized messenger application that emphasizes user anonymity and privacy through end-to-end encryption. Session currently employs its own uniquely designed messaging protocol, Session Protocol V1, having migrated from the extensively studied Signal Protocol. In this paper, we conduct a comprehensive, implementation-driven security analysis of the Session Protocol V1, focusing on its 1-to-1 and closed-group communication mechanisms. Our analysis reveals two fundamental design vulnerabilities: the absence of mutual public key authentication and the lack of cryptographic bindings to monotonic sequence counters. Exploiting these weaknesses within the context of actual application environments, we demonstrate three practical attacks: an impersonation attack, a message timestamp forgery attack, and message dropping and replay attacks. These attacks allow malicious server nodes or unprivileged malicious insiders to substitute public keys, silently suppress or duplicate messages, and manipulate the perceived chronological order of conversations. The findings highlight that these exploits severely undermine the fundamental security guarantees of the messenger. Finally, we propose immediate, actionable mitigation strategies to address the identified flaws and secure the protocol against these threats.
Expand
Enanko Basak, Sayandeep Saha
ePrint Report ePrint Report
Leakage-resilient rekeying schemes aim to maintain cryptographic security in the presence of side-channel leakage by periodically refreshing ephemeral keys before sufficient information can be accumulated by an adversary. Fallen Sanctuary (LR4) is a recent higher-order leakage-resilient rekeying construction that achieves exponential security amplification with respect to the number of primitive encryption invocations and the number of traces required to compromise the physical security of the implementation. Its security, however, relies on the correct maintenance of internal counters and cached intermediate keys that enforce the prescribed trace bounds. In this work, we investigate the security of LR4 under a combined fault and side- channel attack model. We show that transient faults targeting the counter-update and counter-validation mechanism can prevent the advancement of the rekeying state, causing repeated reuse of temporal keys that are intended to be short-lived. As a consequence, the bounded-trace assumptions underlying the LR4 security proof no longer hold. We demonstrate that an adversary can accumulate an arbitrary number of leakage traces corresponding to the same secret state, effectively reducing the security of the protected primitive to that of a conventional implementation without rekeying. We evaluate the attack on a fault simulated implementation and analyze its impact on the leakage-resilience guarantees claimed by LR4. Our findings emphasize that leakage-resilient rekeying schemes must consider fault- induced violations of state evolution assumptions in addition to conventional side- channel leakage.
Expand
◄ Previous Next ►