International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

11 March 2026

Anasuya Acharya, Carmit Hazay, Rahul Satish
ePrint Report ePrint Report
Reusability is a recurring theme in cryptography, appearing in various contexts where a one-time setup produces an encoded program that can be applied to multiple inputs. Prominent examples include indistinguishability obfuscation (iO), functional encryption (FE), laconic function evaluation (LFE), homomorphic secret-sharing (HSS), and function secret-sharing (FSS), each offering different trade-offs in efficiency and functionality. A particularly clean setting for reusability arises in garbling schemes: a garbler publishes a garbled circuit that can be evaluated on multiple inputs chosen by an evaluator. While one-time garbling has become a central and widely applicable primitive, its reusable variant has received comparatively little attention, typically studied only as a consequence of FE.

In this work, we revisit the foundations of reusable garbling and develop a framework that clarifies its relationship to other reusable primitives. We first show that reusable garbling is equivalent to a single-key private-key variant of FE, capturing exactly the guarantees required for reusability and isolating it as a primitive in its own right. This equivalence further implies a black-box separation between reusable garbling and public-key FE, establishing that reusability can be realized entirely within the private-key setting without invoking public-key mechanisms. Building on this perspective, we demonstrate direct constructions from several inherently reusable primitives, including LFE, iO, HSS, and FSS, broadening the foundations of reusable garbling and revealing how reusability naturally emerges across diverse cryptographic paradigms.
Expand
Yuntian Chen, Tianpei Lu, Zhanyong Tang, Bingsheng Zhang, Zhiying Shi, Yuxiang Luan, Zhuzhu Wang
ePrint Report ePrint Report
The growing demand for privacy-preserving Transformer inference has led to the emergence of numerous protocols designed to protect sensitive data and model parameters. These protocols utilize diverse cryptographic tools under varying assumptions, each presenting unique characteristics and trade-offs between computation, communication, and accuracy. In this paper, we conduct a systematic and in-depth analysis of existing approaches from diverse performance perspectives, identifying their limitations and research gaps. We further evaluate the reproducibility of prior systems and re-benchmark representative solutions under standardized configurations. Our results yield a principled guideline for balancing protocol trade-offs under different deployment settings.
Expand
Klaas Ole Kürtz
ePrint Report ePrint Report
We undertake a comprehensive and structured synthesis of the drivers of human behavior in cybersecurity, focusing specifically on people within organizations (i.e., especially employees in companies), and integrate key concepts such as awareness, security culture, and usability into a coherent theoretical framework. This model is then compared with several relevant behavioral models that fundamentally represent drivers of human behavior.

Additionally, we discuss how this theoretical framework can help the domain of agentic AI security: We argue that as AI systems increasingly act as autonomous agents within organizations and based on natural language processing, they also exhibit vulnerabilities analogous to human behavioral risks. Consequently, we propose that this human-centric model offers a blueprint for developing additional security strategies against manipulation attacks targeting AI agents.
Expand
Robi Pedersen
ePrint Report ePrint Report
We present a new verifiable oblivious pseudorandom function (VOPRF) from isogeny group actions. Our construction is twice as fast as the previous state of the art of Delpech de Saint Guilhem and Pedersen at a slightly higher communication cost. One major contribution is the realization of a new proof protocol that is integrated as a two-party computation into the OPRF protocol, making the output verifiable. The main design choice behind our construction and this new proof system is to enable an easy transformation into a threshold protocol, something previous designs have not achieved. To this end, we present our VOPRF in a modular way based on different subroutines. We show how to replace these subroutines with their threshold counterparts, using simulation-based arguments. This results in the first threshold VOPRF from isogenies and one of the first threshold VOPRFs in the post-quantum literature. In contrast to other post-quantum threshold VOPRF designs, our construction has input and output size independent of the number of server parties and furthermore is robust, while other designs rely on aborts in the presence of malicious parties.
Expand
Akshaya Kumar, Carolina Ortega Pérez, Joseph Jaeger, Thomas Ristenpart, Michael A. Specter
ePrint Report ePrint Report
Offline finding (OF) protocols---such as Apple's Find My, Google's Find Hub, Samsung’s SmartThingsFind, and Tile---enable hundreds of millions of users to track their belongings via Bluetooth-based tracker tags. However, their scale and tracking capabilities give rise to privacy risks for tag owners and bystanders, as well as safety risks for victims of tag-facilitated stalking. In response, academics and practitioners have suggested cryptographic and non-cryptographic mitigations to improve privacy and anti-stalking protections, working to navigate complex and subtle tensions between these goals. The result is a large landscape of privacy goals, threat models, protocol designs, implementations, and analyses.

In this work, we systematize the OF protocol landscape. We gather and analyze a corpus of 49 research papers and OF protocol technical specifications, and use it to develop a taxonomy capturing the functionality, security, and privacy goals of OF protocols. We use the taxonomy to guide a focused assessment of the four major OF deployments along with six academic constructions, comparing design choices, consolidating known attacks, and analyzing the designs' trade-offs between privacy, security, abusability, and efficiency. We provide a simple OF protocol that achieves most security goals, and which clarifies the essential cryptographic components underlying OF protocols. We also provide a survey of physical layer attacks and usability issues that undermine protections in practice. Finally, we discuss open problems and potential research directions towards secure, interoperable, and abuse-resistant OF systems.
Expand
Kexi Huang, Yanpei Guo, Wenjie Qu, Jiaheng Zhang
ePrint Report ePrint Report
In this work, we construct a new and highly efficient blind polynomial commitment scheme (PCS) over non-binary fields. Our scheme is specifically designed to handle encrypted coefficients without requiring expensive bootstrapping operations, achieving a breakthrough in the "complexity-depth" trade-off.

The proposed scheme features an extremely efficient prover both asymptotically and concretely. The commitment and evaluation phases are dominated by a strictly linear $O(n)$ number of field operations. Furthermore, the construction maintains a constant multiplicative depth, which is a critical requirement for efficiency in homomorphic encryption settings. Concretely, for large-scale circuit sizes, our prover is significantly faster than prior state-of-the-art schemes such as phalanx and laminate.

Our underlying technique is the Generalized RAA code, an extremely efficient error-correcting code that extends the binary RAA code structure to arbitrary non-binary prime fields $\mathbb{F}_{p}$. We analyze the bounds over non-binary fields, which demonstrate that this code maintains a linear minimum distance property with high probability. By combining Ligero’s IOPP framework, we obtain the first asymptotically and concretely good blind PCS that achieves strictly linear $O(n)$ encoding complexity for the prover while avoiding the expensive bootstrapping operations.
Expand
Maxime Deryck, Diane Leblanc-Albarel, Bart Preneel
ePrint Report ePrint Report
?ℎ?????? is a widely deployed perceptual hash function used for the detection of illicit content such as Child Sexual Abuse Material (CSAM). This paper presents the first mathematical description of ??????? ?ℎ??????, a new function which has identical outputs to that of ?ℎ?????? for a large database of test images. From this description, several design weaknesses are identified: the algorithm is piece-wise linear and differentiable, the hash value only depends on the sum of the RGB values of each pixel, and it is trivial to find images with hash value equal to all zeroes. The paper further demonstrates that gradient-based optimization techniques and quadratic programming can exploit the mathematical weaknesses of ??????? ?ℎ?????? and ?ℎ?????? to produce visually appealing exact collisions and second preimages; for near-collisions and near-second-preimages the image quality can be further improved. The same techniques can be used to recover the rough shapes of an image from its hash value, disproving the claim from the designer that ?ℎ?????? is irreversible. Finally, it is also shown that it is easy to produce high-quality perceptually identical images with a hash value that is far from the original image allowing to avoid detection. We have implemented our attacks on a large set of varied images and we have tested them on both ??????? ?ℎ?????? and ?ℎ??????. Our attacks have success rates close or equal to 100% and run in seconds or minutes on a personal laptop; they present a substantial improvement over earlier work that requires hours on parallel machines and that results only in near-collisions. We believe that with additional optimization of the parameters, the image quality and/or the attack performance can be further improved. Our work demonstrates that ?ℎ?????? is unreliable for the detection of illicit content: it is easy to incriminate someone by sending them false content with a hash value close to illicit content (a false positive) and to avoid detection of illicit content with minimal modifications to an image (a false negative). False positives and leakage of information are particularly problematic in a Client Side Scanning (CSS) scenario as envisaged by several countries, where large hash databases would be stored on every user device and billions of images would be hashed with ?ℎ?????? every day. Overall, our research cast serious doubts on the suitability of ?ℎ??????for the large-scale detection of illicit content.
Expand
Jaehyung Kim, Hanjun Li, Huijia Lin, Zeyu Liu
ePrint Report ePrint Report
Primitives enabling homomorphic computation over secret-shared values--Homomorphic Secret Sharing (HSS) and algebraic Homomorphic MACs (aHMAC)--have recently emerged as efficient alternatives to ciphertext-based primitives such as fully homomorphic encryption (FHE) and attribute-based encryption (ABE). Leveraging the distributed nature of secret sharing, direct constructions of HSS and aHMAC are simple, lightweight, avoid costly bootstrapping, and have many applications including one-bit-per-gate garbled circuits.

Despite encouraging progress, all existing direct schemes still lack one key feature: efficient Single Instruction Multiple Data (SIMD) evaluation, a capability that has been critical to the efficiency of FHE. This gap leaves the potential of substantial efficiency improvements untapped.

We present the first SIMD evaluation techniques for HSS and aHMAC, based on variants of the RLWE assumption. Using a new interval coefficient encoding, our approach embeds $\sqrt{n}$ integer-valued slots per ring element and supports $\sqrt{n}$-fold batch addition and multiplication in just $O(\log n)$ ring operations, achieving a multiplicative $\tilde O(\sqrt{n})$ improvement in amortized efficiency over prior direct constructions. Building on top of these improvements, we show a streamlined one-bit-per-gate SIMD garbling scheme with similar efficiency gains in the online phase.

Our efficiency gains are concrete. Concrete operation counts and microbenchmark based estimates show $6\times$--$10\times$ improvements in amortized multiplication cost over prior non-SIMD constructions, with up to $25\times$--$50\times$ speedups for aggregation-heavy workloads such as matrix--vector multiplication. These results demonstrate the practical potential of SIMD techniques for secret-sharing-based homomorphic computation.
Expand

10 March 2026

Algarve, Portugal, 23 June - 26 June 2026
Event Calendar Event Calendar
Event date: 23 June to 26 June 2026
Submission deadline: 31 March 2026
Notification: 15 April 2026
Expand
Seagate Technology; Shakopee, Minnesota
Job Posting Job Posting

Seagate Technology is a global leader in data storage. We design and manufacture the next generation of hard drives, offering high-performance, sustainable options with the capacity to support a massively expanding demand for data. Our Data Trust research vector is a global team of scientists focused on innovative ways to protect data privacy, reliability, and verifiability for current and future customers.

We’re seeking a research intern with interests in cryptography, systems security, or related areas of computer science. Alongside our cryptographic and systems security researchers, you'll do a deep dive into the development and analysis of emerging security tech. We carefully design our projects to help each intern best utilize their individual expertise, develop new skills, and simultaneously progress towards their scientific goals and Seagate's. You’ll work on an interdisciplinary team of engaging researchers, discuss the future of data handling with engineers across the company, and develop connections with our local and global networks that will last beyond the initial internship period.

In this role, you will:

• Perform fundamental research in data security and write peer-reviewed scientific papers

• Create formal analyses, new algorithm designs, or prototype implementations that advance the field of data security.

• Learn about and contribute to an understudied but fundamental pillar of the Internet, AI, and data science fields.

• Join an exciting cohort of students in a wide array of fields, including computer science, chemical & mechanical engineering, and biology

Our desired intern candidate is

• A current MS or PhD student in computer science or a closely related subject

• Familiar with principles of cryptography and systems security

• Experienced programming skills using one or more languages such as Rust, Go, C, C++, or Python.

• Able to work and communicate effectively with a diverse group of people

• Knowledgeable about formal verification, theorem provers, or provable security analysis

Closing date for applications:

Contact: Hannah Davis

More information: https://seagatecareers.com/job/Shakopee-Research-Intern-Security-and-Cryptography-MN/1343136000/

Expand
University of Kent
Job Posting Job Posting
The School of Computing at the University of Kent invites applications for 3 fully-funded 3.5-year PhD (GTA) scholarships for UK students. You can apply to study for a PhD in any topic that falls within our range of expertise. Alongside completing your PhD programme of research and development, as a Graduate Teaching Assistant (GTA) you will normally be expected to work for 200 hours per annum in years 1 to 3, including teaching (maximum 96 contact hours per year) or demonstrating (maximum 130 contact hours per year) and related duties such as marking, preparation and examination. For preliminary discussions to work on cryptology-related topics, please contact Sanjay Bhattacherjee ([email protected]). More general enquiries should be directed to the PGR Admissions team ([email protected]). Details here: https://www.kent.ac.uk/scholarships/search/FN15COMPGR01

Closing date for applications:

Contact: Sanjay Bhattacherjee ([email protected])

More information: https://www.kent.ac.uk/scholarships/search/FN15COMPGR01

Expand
Torino, Italia, 21 May - 22 May 2026
Event Calendar Event Calendar
Event date: 21 May to 22 May 2026
Expand
Hamburg, Deutschland, 21 September - 25 September 2026
Event Calendar Event Calendar
Event date: 21 September to 25 September 2026
Expand
Rome, Italy, 10 May -
Event Calendar Event Calendar
Event date: 10 May to
Expand
Royal Holloway, University of London
Job Posting Job Posting

PhD Studentship in Cryptography

Applications are invited for a PhD studentship in Cryptography within the Information Security Group (https://cryptography.isg.rhul.ac.uk/) at Royal Holloway, University of London.

The studentship is available for a start in September 2026 and may be undertaken full-time or part-time.

The successful candidate will work on the design, development, and analysis of cryptographic protocols, with a particular focus on privacy and end-to-end verifiability. The project forms part of a broader research programme exploring how cryptographic systems can be designed to be both secure and understandable.

Eligibility Criteria

We seek applicants with a strong background in mathematics and/or computer science. Familiarity with cryptography, number theory, probability theory, or computational algebra would be advantageous.

This 3.5-year studentship is open to UK Home fee-status students only. The award covers Home-rate tuition fees and provides a tax-free stipend at the UKRI rate, which increases annually in line with UKRI guidance. For the 2026/27 academic year, the stipend will be £23,805, including £2,000 London Weighting.

How to Apply

Interested candidates should send:

  • a CV
  • a motivation letter

to Dr Elizabeth Quaglia at [email protected] by 17 April 2026.

Additional Information

This studentship is part of Dr Elizabeth Quaglia’s EPSRC-funded Open Plus Fellowship on Understandable Cryptography. The fellowship also funds postdoctoral researchers, meaning the successful candidate will join an active research team and a broader programme dedicated to advancing impactful cryptographic research.

Closing date for applications:

Contact: Elizabeth Quaglia, [email protected]

Expand
University of Tartu, Tartu, Estonia
Job Posting Job Posting
The zero-knowledge group, a subgroup of the cryptography group, at the Institute of Computer Science of the University of Tartu, seeks up to 3 Ph.D. students and one postdoc (up to three persons in total) on the topic of contemporary zero-knowledge proofs and zk-SNARKs. The existing zero-knowledge group comprises of Helger Lipmaa, Matteo Campanelli (part-time position), Janno Siim, Roberto Parisella, and Ph.D students.

Our current research interests include the provable security of zk-SNARKs (including stronger security notions and more realistic cryptographic assumptions), the design of pairing-based, code-based, and lattice-based zk-SNARKs and related primitives (polynomial commitment schemes, folding schemes, etc), and the design of zk-SNARKs for applications such as zkVM and zkML. We collaborate actively with local groups on coding theory and machine learning to further our aims. While primarily focused on academic publishing in top conferences, we are interested in collaborating with ZK companies and staying abreast of developments in practice.

The Ph.D. student must have an MSc or equivalent by this spring, a strong background in mathematics and/or theoretical computer science, and prior background in cryptography. For postdoc candidates, we especially welcome those with a background in the theoretical aspects of proof systems, zk-SNARKs (pairing-based, hash-based, or lattice-based), or applications such as zkML. We expect the postdoc candidate to have published a few papers at IACR conferences or venues of equivalent renown. However, we welcome all exceptional candidates. Some positions will be filled only when we receive strong candidates. Our salaries are competitive with living costs: they are higher than in Southern Europe in absolute terms, while our costs are significantly lower than in Northern Europe. A postdoc/Ph.D. student will receive around 2,600/1,900 euros (depending on qualifications) per month after taxes. See https://crypto.cs.ut.ee/Main/ZKPositions2026 for information on our group and department, and for an application link. (Email applications not possible.)

Closing date for applications:

Contact: Helger Lipmaa ([email protected])

More information: https://crypto.cs.ut.ee/Main/ZKPositions2026

Expand
Nanyang Technological University, Singapore
Job Posting Job Posting

The Symmetric Key and Lightweight Cryptography Lab (SyLLab) at NTU Singapore is looking for candidates for a Research Fellow/Post-Doc position (from fresh Post-Doc to Senior Research Fellow, flexible contract duration) on leakage-resilient modes for symmetric-key cryptography.

Postdoc candidates are expected to have a proven record of publications in top cryptography/security venues, with good experience in provable security.

The position will be funded by a 3-year national research grant. Salaries are competitive and are determined according to the successful applicant's accomplishments, experience and qualifications. We offer an excellent research environment with a highly international team, with flexible working conditions, budget for conferences/equipment, etc.

Interested applicants should send their detailed CVs and references to Prof. Thomas Peyrin ([email protected]). The review of applications starts immediately and will continue until positions are filled.

Closing date for applications:

Contact: [email protected]

Expand
Technical University of Denmark, DTU Compute; Copenhagen Area, Denmark
Job Posting Job Posting
We are looking for an associate professor or tenure-track assistant professor to extend and/or strengthen current research and teaching at the Cybersecurity Engineering Section at DTU Compute, Technical University of Denmark. You could be our new colleague if you are a talented and ambitious researcher with a strong passion for cybersecurity and a genuine drive to create societal impact through collaboration with partners across both the private and public sectors. You are expected to embrace and actively contribute to our mission which is to strengthen, advance and integrate foundational and applied research in cybersecurity and cryptography in order to anticipate and respond to evolving scientific, technological, and societal challenges. We are committed to academic excellence within a highly international environment defined by collegial respect, intellectual curiosity, and academic freedom grounded in responsibility. We value intellectual independence and offer you the autonomy to pursue research topics that truly interest you. We recognize and promote diverse forms of talent, supporting your individual interests and strengths. At the same time, we appreciate the importance of balance: for example, we ensure a reasonable teaching load, enabling you to dedicate significant time and energy to advancing your research. The university is located in the greater Copenhagen area, which is acknowledged for its excellent standards of living, childcare and welfare system. The list of special focus areas includes "Cryptogaphy, incuding post-quantum cryptography" among a broad list of cybersecurity sub-areas. The application deadline is 04/30/2026, 11:59 PM Copenhagen Time. For more information, see https://efzu.fa.em2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_2001/job/6948

Closing date for applications:

Contact: Nicola Dragoni ([email protected])

More information: https://efzu.fa.em2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_2001/job/6948

Expand
University of Amsterdam
Job Posting Job Posting
The Theory of Computer Science Group from the Informatics Institute of the University of Amsterdam is seeking a PhD student to carry out cutting-edge research in cryptography, with an expected focus on Secure Multi-Party Computation. For more information and to apply, please visit https://werkenbij.uva.nl/en/vacancies/phd-position-in-secure-multi-party-computation-netherlands-14874. The closing date for the applications is 1 May 2026 (for full consideration, you are encouraged to apply on or before 30 March 2026).

Closing date for applications:

Contact: Divya Ravi ([email protected])

More information: https://werkenbij.uva.nl/en/vacancies/phd-position-in-secure-multi-party-computation-netherlands-14874

Expand
University of Tartu, Estonia
Job Posting Job Posting

The Cryptography Group at the Institute of Computer Science at the University of Tartu invites applications for a PhD position in lattice-based cryptography.

The successful candidate will work on the mathematics of lattices, with a particular focus on their applications in lattice-based cryptography, including discrete Gaussian sampling, digital signature schemes, and cryptographic reductions. Our group includes researchers with expertise in post-quantum cryptography, zk-SNARKs, and coding theory, fostering a collaborative and research-driven environment.

This position offers the chance to work on topics that are both theoretically interesting and practically relevant in modern cryptography. Details about the position and the ideal candidate profile can be found on the application website (link in the headline).

For any inquiries or to apply for the position, submit a letter of motivation, a CV, and the names of two references to Maiara Bollauf (maiara.bollauf at ut.ee).

The PhD position starts on September 1, 2026, and lasts four years. The candidate may later seek further employment, but this is not guaranteed in advance.

Closing date for applications:

Contact: Maiara Bollauf (maiara.bollauf at ut.ee)

More information: https://sites.google.com/view/maiarabollauf/research/phd-in-lattice-based-cryptography

Expand
◄ Previous Next ►