IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
23 July 2026
Chenkai Zeng, Qi Feng, Debiao He, Min Luo
Benjamin Wesolowski
Ahmet Malal, Tolun Tosun, Oğuz Yayla, Erkay Savas
Giulio Berra, Felix Linker, Luca Maier, Cory Francis Myers, Kenneth G. Paterson, Rowen Shane, Shannon Veitch
In this work, we present and formally analyse a new protocol for SecureDrop which addresses the challenges of off-premises deployment. Our protocol composes an encryption scheme with hybrid post-quantum guarantees and an identity-hiding message-fetching mechanism to provide strong anonymity guarantees. In contrast to existing systems, we minimise incriminating evidence against whistleblowers by providing message-level deniability and by having sources remain stateless. Our formal security analysis combines the Tamarin prover for symbolic analysis and game-based proofs for computational analysis. Finally, our benchmarks demonstrate that the protocol achieves practical levels of performance in a browser context. The Freedom of the Press Foundation plans to deploy the new protocol, with integration efforts beginning in 2026.
Stelios Manasidis, Quinten Norga, Suparna Kundu, Ingrid Verbauwhede
Pavel Hubáček, Kristýna Mašková, Berenika Richterová
First, we demonstrate that the current security model does not capture the ECDSA adaptor signature that underlies most real‑world systems. Second, we propose a relaxed definition and prove that it is satisfied by the ECDSA adaptor construction under the strong unforgeability of ECDSA. Finally, focusing on oracle‑based conditional payments, we formulate the first security model for adaptor‑based Discreet Log Contracts (DLCs) and show that our relaxed notion suffices for their security.
Jérémy Jean
Caicai Chen, Yuval Ishai, Aayush Jain, Tamer Mour, Alon Rosen, Chaoping Xing
We give the first candidate doubly-efficient secret-key PIR schemes that achieve a constant multiplicative storage overhead, asymptotically approaching 1 in natural regimes, together with $k^{o(1)}$ communication and online server work for a database of size $k$. The best previous online server work with constant storage overhead was $k/\textrm{polylog}(k)$.
Our constructions follow the permuted-code blueprint for doubly efficient sk-PIR (Boyle-Ishai-Pass-Wootters and Canetti-Holmgren-Richelson, TCC 2017), and are based on similar assumptions. The main novelty is that we instantiate this blueprint using new families of "$t$-smooth" locally decodable codes with improved tradeoffs between rate, locality, and smoothness. This includes a new $t$-smooth local decoder for Reed-Muller codes using concatenated curves, as well as a construction based on curve-lifted codes that has attractive concrete efficiency features.
We perform extensive cryptanalysis of the underlying assumptions and benchmark performance under realistic parameters, demonstrating the practicality of our schemes. A representative instantiation encodes a $37$ GB database of $18$-bit records with only $4.2$× storage overhead, while requiring the server to read less than $600$ KB from the encoded database per query.
Przemek Chojecki
Yiming Gao, Honggang Hu
Ivan Tjuawinata, Yann Fraboni, Darian Gunamardi, Jun Jie Sim, Zhenghao Wu, Hasventhran Baskaran, Chi-Hung Chi, Pu Duan, Kwok-Yan Lam
Qian Liu, Liwei Fang, Zhengbang Zha, Jing Zhang
22 July 2026
Austin, TX, USA, 26 October - 27 October 2026
Submission deadline: 1 August 2026
Notification: 1 September 2026
Taichung, Taiwan, 15 December - 17 December 2026
Submission deadline: 20 September 2026
Notification: 20 October 2026
Eindhoven University of Technology
We are looking for a PhD student, focusing on provable security. You will be part of a multidisciplinary team developing practical cryptographic standards for the post-quantum era, with implementation security in mind from the outset. Your research will combine cryptographic design with formal security analysis, helping to bridge the gap between theoretical security and secure real-world implementations.
You will be supervised by K. Hövelmanns, co-supervised by A. Hülsing.
What you can expect from us:
- The opportunity to work at the intersection of post-quantum, provable security, and implementation security.
- Weekly supervision meetings to help you stay on track.
- Guidance on writing, presentation, and career development.
- Flexible working hours.
- A shared interest in producing high-quality research results.
What we expect from you:
- An interest in cryptographic design and formal security analysis.
- A master's degree in computer science, mathematics, or related subjects.
- A solid background in cryptography, algorithms, discrete mathematics, or a related area.
- Strong analytical and problem-solving skills demonstrated in previous projects. Motivation to lead the projects.
- Research experience in the related areas is a plus but not required.
What you will like about Eindhoven:
- Being part of an internationally recognized research environment with strong expertise in cryptography and cybersecurity.
- The energy of an international technology hub (“Brainport”), combined with the convenience of a compact, easy-to-cycle-around city.
- A large international community—fortunately also reflected in the city’s food scene.
- Living in one of the Netherlands’ leading design hubs, home to Dutch Design Week and a lively creative scene.
Closing date for applications:
Contact: Please apply via https://www.tue.nl/en/working-at-tue/vacancy-overview/phd-in-post-quantum-cryptography
More information: https://www.tue.nl/en/working-at-tue/vacancy-overview/phd-in-post-quantum-cryptography
S. Venkitesh
Building upon Nguyen's dichotomy, we present a partial derandomization of evaluation places, improving upon the Maji et al. result for a restricted regime of parameters. We replace the random choice of $n$ independent evaluation places by the iterates $x_j = \Phi^j(x_0)$ of a simple fixed rational function $\Phi$, where the initial point $x_0 \in \mathbb{F}_{p^d}^*$ is randomly chosen. The randomness in the evaluation places thus drops from $nd \log p$ bits to $d\log p$ bits. Our construction is valid for the regime $n = O(d/\log_p d)$, and any reconstruction threshold $k \ge 2$; in fact, the scheme attains perfect security (statistical distance exactly zero) against single-block leakage. Our technique is a partial fraction nondegeneracy argument that exploits the distinct poles of the rational iterates.
Nouhou Abdou Idris, Mustapha Hedabou
Chengcheng Chang, Kai Hu, Shuo Peng, Haoyang Wang
We propose an exact 4-wise geometric framework for boomerang cryptanalysis that is a \emph{strict generalization} of the 3-wise framework: it recovers the 3-wise framework as the equal-difference $a=a',\,b=b'$ specialization, and at the same computational cost additionally covers the unequal-difference boomerangs and impossible boomerang distinguishers that the 3-wise representation cannot reach. By choosing bases adapted to the two value coordinates and two difference coordinates of a boomerang quartet, our framework removes the 3-wise assumption and gives a unified transition-matrix description for both impossible boomerang distinguishers and fixed-key boomerang probabilities.
The framework has two concrete applications. First, it yields a positive (satisfiability) model for searching for impossible boomerang distinguishers from the difference coordinates in the 4-wise representation. Using this model, we find new impossible boomerang distinguishers for \present, \ascon, \skinny, and \gift. Second, it computes fixed-key boomerang probabilities as sums of \emph{quasi-boomerang quartet characteristic} correlations. For the 13- and 17-round boomerang distinguishers of \skinny-64-128 and \skinny-64-192, respectively, the resulting probabilities match the experimental results and explain the gap left by the 3-wise framework through contributions from unequal-difference boomerangs.
Nirajan Koirala, Kevin Vuong, Micah Brody, Jihye Kim, Hyunok Oh, Taeho Jung
We present Vordr, a framework that removes the CVM owners from the end-user's trust domain across the full CVM lifecycle while still allowing workload-level updates/installations with auditability. We introduce a novel architecture that establishes an exclusive administrative binding between a process-based TEE (Warden Enclave (WEN)) and the CVM. This binding strictly blocks the CVM owners (or cloud) from directly manipulating the CVM. Vordr continuously tracks runtime integrity via a hardware-rooted Linux IMA event log anchored to PCR 10, serving time-bounded, platform-unlinkable cached or audit-ready quotes for independent end-user auditing. We optimize the costly IMA-log extraction via a novel incremental attestation design leveraging the IMA log's append-only structure and the WEN's sealed state. We implement Vordr, validate it across several workloads, and show that it provides up to 60.8x speedup for runtime monitoring with huge communication reductions in steady-state incremental rounds compared to prior methods. Vordr delivers highly scalable and verifiable runtime attestation, providing substantially stronger guarantees for runtime integrity and platform unlinkability.