IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
06 July 2026
Divesh Aggarwal, Haoxiang Jin
In this work, we address this gap by systematically analyzing and tightly characterizing the time-success probability tradeoff for SVP and BDD, focusing on algorithms that exploit the fine-grained structure of slide-reduced bases. We present new blockwise guessing algorithms for SVP and BDD that utilize small-dimension SVP and CVP oracles; by leveraging the consecutive-product properties of Slide Reduction, we obtain the tightest known lower bounds on the success probability as a function of time. Assuming that we cannot do much better than this, we conjecture that no algorithm can outperform this tradeoff---for any subexponential time bound $T(n)=2^{o(n)}$, the success probability of solving worst-case SVP or BDD cannot exceed $2^{-\frac{n^2\log\log T(n)}{c\log T(n)}}$ for some constant $c>1$, up to polynomial factors.
Applying this conjecture, we derive sharply improved, modular worst-case to average-case reductions for LWE and SIS that are robust against all time-bounded adversaries, not just those restricted to polynomial time. Our results provide the first fine-grained, quantitative foundation for the bit-security of lattice-based cryptography across the full spectrum of adversarial resources, closing a key gap in both the theory and practice of cryptographic security reductions.
Calvin Abou Haidar, Thomas Espitau, Clément Hoffmann, Mehdi Tibouchi
Two recent works proposed masked gadgets at arbitrary order for that operation: one by Gérard and Guerreau (CASCADE 2026), which simply masks each of the comparisons with the table elements (using a ripple carry adder as the Boolean comparison circuit), and another by Eid et al. (TCHES 2026), that uses a novel approach based on a binary search tree, significantly reducing the number of masked comparisons for larger tables. Eid et al. also choose the Kogge-Stone adder as the basis for their comparison circuit.
In this paper, we provide an extensive analysis of the choices and trade-offs involved in masked CDT-based sampling, and propose several optimizations that further improve upon these previous works by a considerable margin. In particular, since FrodoKEM, like almost all the schemes that rely Gaussian sampling, generates hundreds of samples at a time, we find it beneficial to utilize approaches that lend themselves to a high degree of parallelization. This includes bitslicing (with which, importantly, the ripple carry adder has been proved optimal for comparisons), as well as techniques such as the use of algebraic normal form in masked multiplexers.
As a result, on an ARM Cortex-M4 STM32F4 target board, our companion implementation in pure C outperforms the hand-crafted assembly of Eid et al. (resp. Gérard-Guerreau) by a factor of around 2 (resp. 7 to 9) at masking order 1. The gap is even larger at higher order: we outperform the higher-order code of Eid et al. (in C with assembly for expensive gadgets) by a factor ranging from 5 at masking order 2 to 9 as masking order 8.
Zhengjun Cao, Lihua Liu
Ziran Tu, Claude Carlet, Xiangyong Zeng, Xibo Zhang
Chilume O. Gabriel, Hlomani B. Hlomani, Kabo Nkabiti
Raja Adhithan Radhakrishnan
Hyun Ji Kwag, Junhyuk Kwon, Changmin Lee, Yongha Son
In this work, we propose a substantially faster RPMT protocol by replacing the elliptic-curve core with RLWE-based one. Our starting point is the Oblivious Key-Value Store (OKVS) based RPMT framework, whose direct adaptation to RLWE is obstructed by the batching structure of RLWE encryption. To address this, we introduce a batching-friendly variant of OKVS together with a homomorphic batched decoding procedure. We believe that this batching-friendly OKVS and its homomorphic decoding process may be of independent interest.
For a set size $2^{20}$, our RPMT-based PSO protocols take only about $3$ seconds over LAN network and $120$-$138$MB communication, whose running time is comparable to state-of-the-art PSI. Compared to state-of-the-art PSI-Cardinality and PSI-Card-SUM, this is up to \(13.0\times\) speedups. Compared to state-of-the-art PSU, this is up to \(3.0\times\) smaller communication while achieving comparable computational cost, which results in up to $3.9\times$ faster running time over WAN.
PQC-X, Xi’an Jiaotong-Liverpool University
PQC-X invites applications for multiple fully funded PhD and Postdoctoral Research Fellow positions in the areas of post-quantum cryptography, advancing key technologies in post-quantum migration and facilitating their industry transfer.
Position Details
PhD Candidates: Open to applicants with a Bachelor’s or Master’s degree in a relevant field (students near completion are also encouraged to apply). A solid
foundation in cryptography, mathematics, or computer science is required. Strong programming skills are a plus.
Postdoctoral Fellows: Applicants should hold a PhD in a related field (or near completion) and demonstrate a strong research track record, preferably with publications at leading IACR venues or security conferences.
Research topics include, but are not limited to:
Desired Qualifications
How to Apply
Interested candidates should send their applications (including CV, academic transcripts and a brief statement of research interests) to [email protected]
Closing date for applications:
Contact: [email protected]
The University of Edinburgh
We are hiring three (3) researchers (post-doc or equivalent) for a project at the intersection of cryptography, agentic systems, and automated verifiable design.
Project: We are building an end-to-end framework that automates the specification, verification, and deployment of cryptographic protocols for multi-agent systems. LLM-driven agents explore the design space, synthesise protocols for specific security needs, and formally verify them (e.g. ProVerif, Lean) with machine-checkable proofs, exposed through the Verified Agentic Interaction Substrate (VAIS).
Details: School of Informatics, University of Edinburgh, UK. Salary: UoE Grade 7 (£41,064-48,822). Start: as soon as possible. Duration: 1 year, extension possible.
Essential
- Doctorate (or nearing completion) in Cryptography, Computer Science, Mathematics or related, specialising in applied/theoretical cryptography.
- Strong foundations in provable security (game- and simulation-based definitions).
- Familiarity with core cryptographic primitives and their security models (signatures, encryption, key exchange).
- Ability to reason formally about protocol composition.
- Track record of publications at recognised venues.
Desirable
- Hands-on experience with secure multi-party computation (MPC), including familiarity with function-to-protocol compilers such as SPDZ.
- Experience with zero-knowledge proof systems, including the design or use of ZK circuits and compatible compilers.
- Exposure to formal verification tools (e.g. ProVerif, CryptoVerif, Tamarin) or proof assistants (e.g. Lean), and an interest in bridging pen-and-paper proofs with machine-checkable ones.
- Programming skills for prototyping cryptographic tooling.
- Interest in AI/agentic systems and LLMs.
Closing date for applications:
Contact: Michele Ciampi ([email protected])
Lund University
How to apply:
Applications are to be submitted via the University’s recruitment system. Application link: https://lu.varbi.com/en/what:job/jobID:942295/
The application should include:
- a CV including your educational qualifications, work experience, and a list of publications. The publications should mention all the co-authors (following the same author order as in the published version) and include DOIs or links to publicly accessible versions.
- a personal letter justifying your interest in the position and how it matches your qualifications.
- a research statement (no more than two pages).
- The application should also include a degree certificate or equivalent and any other document to which you would like to draw attention (copies of grade transcripts, details of referees, letters of recommendation, etc.).
- Contact details of at least two referees.
Closing date for applications:
Contact: Debajyoti Das ([email protected])
More information: https://lu.varbi.com/en/what:job/jobID:942295/
IBM Research Zurich
The Foundational Cryptography group at IBM Research Zurich has an opening for a PhD position for research on cryptographic proof systems.
Position Details
-Funded for 4 years
-Possibility of joint supervision at EPFL
-Ideal start date late 2026 or early 2027
Cryptographic proof systems allow a prover to convince a verifier that a computation was performed correctly. These systems have applications in secure cloud computing, verifiable machine learning, and privacy-preserving technologies.
However, many proof systems require the prover to use significantly more time and memory than the original computation. The research will develop new proof systems with reduced time and memory overheads, making it practical to verify the integrity of large-scale computations efficiently.
Requirements-MSc (or equivalent) in Computer Science or Mathematics (or another relevant field)
The ideal candidate would enjoy using a mixture of algebra, combinatorics, and probability to analyze and optimize algorithms. Strong background in one or more of the following areas is valuable:
-Cryptographic proof systems (zero-knowledge proofs, succinct arguments)
-Error-correcting codes and coding theory
-Streaming algorithms and memory-efficient computation
-Lightweight cryptography
IBM is committed to fostering diversity and inclusion in the workplace. You will join an open, multicultural research environment that values different perspectives and supports flexible working arrangements. Our goal is to help all genders and backgrounds thrive professionally while maintaining a healthy work–life balance.
Closing date for applications:
Contact:
Please apply via https://www.zurich.ibm.com/careers/2026_022.html
If you have questions, please contact Jonathan Bootle at [email protected]
More information: https://www.zurich.ibm.com/careers/2026_022.html
University of Oldenburg, Germany
- Full-time position
- Start date: flexible, to be discussed with the applicant
- End date: 30 September 2030
- Research area: cryptography, privacy-enhancing technologies, and trustworthy AI, with a focus on applications to healthcare systems
- Possible research topics: homomorphic encryption, secure multi-party computation, differential privacy, secure collaborative machine learning, robustness, explainability, fairness, and auditability
- Position highlights:
- Goal of publishing at leading international conferences and journals in security, privacy, cryptography, and machine learning
- Full support for conference travel and international networking
- Young and growing research environment with close supervision
- Room to shape the PhD project according to the candidate’s interests
- Opportunities to collaborate with our many academic and non-academic partners
- Requirements:
- Master’s degree or equivalent in Computer Science, Mathematics, or a related field
- Strong background in cybersecurity and machine learning
- Good programming skills
- Excellent English level
- Application deadline: 31 July 2026
Closing date for applications:
Contact: Dr. Federico Mazzone ([email protected])
More information: https://uol.de/en/job/wissenschaftlicher-mitarbeiterin-promotionsstelle-trustworthy-ai-1137
Tampere University, Finland
Closing date for applications:
Contact: For questions related to the security area, you may contact Markku-Juhani O. Saarinen: [email protected]
More information: https://projects.tuni.fi/futurechips/
Brahim Chnioune, Mohammed Rahmani, Abderrahmane Nitaj, Mhammed Ziane
03 July 2026
Zachary DeStefano, Noah Golub, Zile Huang, Julius Zhang, Sam Frank, Michael Walfish
Yuval Ishai, Hugo Krawczyk, Tal Rabin
We observe that the above generalizes to other types of useful target correlations ${\cal C}_T$ by using a *secret* replication pattern obtained via a random secret assignment of parties in $\cal C$ to parties in ${\cal C}_T$.
We present several corollaries of this general blueprint. These include a re-derivation of two-party PCF constructions for VOLE and subfield-VOLE over small domains (Roy, Crypto 2022) as well as new multiparty PCFs for small-domain VOLE-style correlations, including scalar-vector multiplication triples and their authenticated variants. Finally, we discuss applications to secure computation.
Zahra Seyedi, Stefan Rass, Shahzad Ahmad, Farhad Rahmati
Cas Cremers, Abhinav Nakarmi, Aleksi Peltonen, Eyal Ronen
However, current approaches only work partially, and their healing effects are extremely limited. For example, recent work showed that due to real-world constraints such as resilience against state loss, even highly secure messengers such as Signal may not achieve it in practice. Moreover, since healing is session-specific, healing effects do not carry over to newly spawned sessions, different groups, or different services that use the same identity.
In this work, we tackle these issues by designing the first protocol that can provide PCS as a Service for identities through a third party. The major challenge is privacy: achieving PCS requires regular updates among participants, and involving a third party can lead to significant privacy concerns. Moreover, the type of update that PCS requires (updating a user's secret, but only once) seems to require servers to verify the users' identities in a way that contradicts the unlinkability required for privacy: the server should not learn anything about the users' activities.
We develop the 3PaaS protocol, including the first efficient zero-knowledge proofs for blind signatures, to achieve our goals, and even allow for revocation, without revealing the identity to the server. We formally analyze our protocol for high assurance, provide an implementation of our novel ZK building blocks, and show how our protocol could be used with a messaging application.
Shalini Banerjee, Andrey Bozhko, Raphael Heitjohann, Andy Rupp
We identify Dead Man's Switch (DMS) as a standalone cryptographic primitive with two modes: release and delete, capturing these dual functionalities. Our abstraction isolates the core conceptual properties of this primitive, and gives its first rigorous treatment in the UC framework. To realize the notion, we introduce Dealer-Controlled Evolving-Committee Proactive Secret Sharing (DC-EPSS), an extension of the Evolving-Committee Proactive Secret Sharing by Benhamouda et al. (TCC '20). We provide the UC formalization of DC-EPSS and instantiate it generically using the nested YOSO framework of Abraham, Chouatt, Damgard, Gilad, Stern, and Yakoubov.
Building on DC-EPSS, we realize DMS-release by coupling it with a multi-recipient authorized recovery mechanism based on a PKI infrastructure, a multi-recipient PKE, a key committing SKE, and NIZK proof systems, while DMS-delete directly follows from DC-EPSS instantiated in the delete mode. We prove the security of both constructions in the UC framework under standard assumptions.
Frederik Reiter, Amir Moradi
In this work, we present HPCC, the first low-latency 3-input multiplication gadget for arbitrary fields that maintains a constant latency of one cycle, independent of the number of shares. HPCC additionally allows for the computation of any number of multiplications in a single cycle with relatively little overhead when two of the three operands are identical. When instantiated with two shares and for $\mathbb{F}_2$, HPCC halves the previous record for lowest number of fresh masks required at comparable area cost. With more shares, HPCC is the only single-cycle gadget realizing 3-input multiplications in arbitrary fields. We leverage HPCC to implement the first composable AES S-Box with two cycles of latency with an arbitrary number of shares. This S-Box design significantly outperforms the previous record in terms of area and randomness when instantiated with three shares and stands as the only two-cycle solution for more shares.