IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
29 May 2026
Bengaluru , India, 13 December - 16 December 2026
Submission deadline: 15 August 2026
Notification: 10 October 2026
Jeju Island, South Korea, 26 August - 28 August 2026
Submission deadline: 13 June 2026
Notification: 18 July 2026
Antalya, Turkey, 11 October 2026
Amiens, France, 22 June - 25 June 2026
Jeju, South Korea, 26 August - 28 August 2026
Submission deadline: 13 June 2026
Notification: 18 July 2026
Simula UiB, Bergen, Norway
We are currently hiring at Simula UiB for a permanent Research Scientist or Senior Research Scientist position [*] in the Department of Cryptography, specialising in post-quantum cryptography.
We are seeking candidates with a PhD in cryptography, computer science, applied mathematics, or a related discipline. The successful candidate should be able to conduct both independent and collaborative, high-impact research and have experience in the design, analysis or implementation of post-quantum cryptographic schemes, demonstrated through publications in leading international venues. Expertise in related areas, such as cryptographic engineering, implementation security, side-channel analysis or applied cryptography more broadly will be an advantage.
Application deadline: 28 June 2026
For more information and how to apply: https://www.simula.no/careers/job-openings/research-scientist-in-cryptography-at-simula-uib
About Simula UiB: Simula UiB (simula-uib.com) is a research institute in Cryptography and Information Theory based in Bergen, Norway. The Department of Cryptography conducts research on the design and analysis of cryptographic algorithms, side-channel analysis and privacy-enhancing technologies. It currently comprises 13 members, including permanent staff, postdoctoral researchers and PhD students, and is led by Dr Martijn Stam. Simula UiB also hosts the Centre for Quantum Communication Networks and Applications (QCNA), one of Norway’s four national centres for quantum technology research, launched in May 2026.
[*] The Research Scientist and Senior Research Scientist levels at Simula UiB are broadly equivalent to Assistant Professor and Associate Professor positions in the university sector, respectively.
Closing date for applications:
Contact: Martijn Stam ([email protected])
More information: https://www.simula.no/careers/job-openings/research-scientist-in-cryptography-at-simula-uib
ENS Lyon, France
- The candidate should hold a PhD degree in Mathematics or Computer Science
- They should have a strong record related to some of the following topics: number theory, computational number theory, lattice-based cryptography, isogeny-based cryptography
Closing date for applications:
Contact: Benjamin Wesolowski, https://emploi.cnrs.fr/Offres/CDD/UMR5669-BENWES-004/Default.aspx?lang=EN
Department of Information Security and Communication Technology at NTNU in Trondheim, Norway
The role entails a balanced portfolio of research, teaching, and academic leadership. The successful applicant will be expected to develop and lead research projects, obtain external funding, and publish in top-tier international venues (such as IACR CHES, IACR CRYPTO, IACR EUROCRYPT, ACM CCS, IEEE S&P). The position also involves contributing to the department’s educational mission through research-based teaching, supervision, and curriculum development at bachelor, master, and PhD levels.
The successful candidate is expected to conduct advanced research in cryptographic engineering, with emphasis on areas such as high‑assurance and performance‑optimized implementations of cryptographic primitives, formal verification techniques, and resistance against side‑channel, fault‑injection, and microarchitectural attacks. Research activities may also involve system‑level integration and deployment of cryptographic mechanisms in resource‑constrained or security‑critical environments, including wireless and embedded communication systems. The position further offers opportunities for interdisciplinary collaboration with researchers in adjacent domains within the department and across the university.
Closing date for applications:
Contact: Tjerand Silde
More information: https://www.jobbnorge.no/en/available-jobs/job/300865/associate-professor-in-cryptographic-engineering
University College Cork, Ireland
Cybersecurity is an area of strategic research importance to the School, and a focus area of teaching with a new MSc in Cybersecurity due to start in September 2026. The post will support the further development and delivery of this new MSc, engage in research that spans cybersecurity, cyber-physical security, data privacy, and security of AI.
We are looking for a world-class scientist with expertise in cybersecurity and specifically the intersection of AI and cybersecurity. The candidate requires expertise in cybersecurity, a track record of applying AI methods to cybersecurity problems and the ability and desire to:
- develop and lead research and teaching activities in Cybersecurity;
- establish and manage a significant world-class research team supported by competitively won research funding;
- supervise research students at PhD level;
- publish in leading conferences and journals in the cybersecurity domain;
- develop and strengthen links between the School of Computer Science and key industry organisations working in Cybersecurity;
- take leadership roles in cybersecurity across the University, nationally and internationally;
- contribute to the overall strategic development of the School;
- represent the School at internal and external events.
Closing date for applications:
Contact: Prof Dirk Pesch at [email protected]
More information: https://my.corehr.com/pls/uccrecruit/erq_jobspec_version_4.jobspec?p_id=094546
27 May 2026
Jiawei Bao, Tibor Jager, Eike Kiltz, Aysan Nishaburi, Samin Nooripoor, Jiaxin Pan
Full Key Recovery of Masked PRESENT on an Out-of-Order RISC-V Processor: A First Reported Case Study
Siddhartha Chowdhury, Nimish Mishra, Sarani Bhattacharya, Debdeep Mukhopadhyay
We present \texttt{OoOLyzer}, a trace-driven analysis framework that reconstructs physical-register reuse and backend execution interactions from OoO RISC-V pipeline traces. Using \texttt{OoOLyzer}, we identify leakage arising from backend physical-register reuse and transient overlap of masked-share operations inside OoO execution structures.
We evaluate the framework on a masked PRESENT implementation and composable PINI gadgets. Our analysis shows that although rotated-share computations protect selected nonlinear operations, affine share pairs remain directly represented in the architectural execution state. OoO register renaming can therefore induce physical-register transitions of the form \[ \operatorname{HW}_{\mathrm{bit}}(a_0[b]\oplus a_1[b]), \] which reconstruct affine PRESENT intermediates and create key-dependent leakage.
We validate the leakage experimentally in two stages. First, using a modified gem5 OoO RISC-V model, we attribute the dominant leakage source to backend physical-register reuse and demonstrate first-round PRESENT subkey recovery from masked execution traces. Second, on a real SiFive P550-class OoO RISC-V processor, we perform a temperature-based side-channel experiment using Linux-accessible thermal telemetry and recover 60 out of 80 key bits from the masked PRESENT implementation.
The results establish a complete cross-layer leakage path from masked software execution to OoO backend interactions, physical-register transitions, thermal behavior, and practical key recovery on real hardware. Our findings demonstrate that masking schemes appearing secure under software-level analysis may still leak on OoO processors, motivating hardware-aware verification of masked software deployments.
Alex Davidson, Nuno Nogueira, Samuel Pearson, João Ribeiro
This work explores the possibility of deriving SPIR from PIR directly, utilising noise flooding to maintain the privacy of the database. While the common analysis based on the statistical distance leads to impractical parameters, we instead utilise arguments based on the Rényi divergence to obtain significantly improved parameters. We obtain simple single-server SPIR from state-of-the-art LWE-based PIR schemes with polynomial noise dimension and ciphertext modulus (concretely of 64 bits in size). Along the way, we note that practical schemes that utilise preprocessing via client-downloaded offline hints require extra protections for the database.
Overall, via an implementation of our approach, we show that post-quantum, round-optimal SPIR schemes can be constructed requiring online communication of 8 MB and server computation costs of 302 ms for a database of 1 million 1 kB elements.
Liyuan Tang, Lingyue Qin, Shiqi Hou, Xiaoyang Dong
Takakazu Satoh
Yechen Li, Qunxiong Zheng
26 May 2026
Behzad Abdolmaleki, Suvradip Chakraborty, Shahram Khazaei, Lorenzo Magliocco, Nahid Roustaeifar, Behzad Vahdani, Daniele Venturi
- We introduce so-called malleable trapdoor smooth projective hash functions (M-TSPHF), as an enhancement of trapdoor smooth projective hash functions (Benhamouda et al., CRYPTO 2013). Our extension incorporates new properties including key malleability and element rerandomizability. - We give a generic construction of subversion-resilient UC PAKE based on M-TSPHF and other standard cryptographic primitives. As we demonstrate, our PAKE protocol can be instantiated efficiently yielding an improved round and communication complexity with respect to the previous protocol of Chakraborty et al. In particular, our PAKE protocol achieves round optimality, as it concludes in a single round.
Ge Gao, Haining Yu, Jinbo Yang, Dongyang Zhan, Xiaohua Jia
Robert Schädlich, Linda Scheu-Hachtel, Erkan Tairi, Yuejun Wang
Apart from defining these new primitives and establishing their security in the indistinguishability-based setting, we provide various constructions with different trade-offs. Concretely, we provide a generic transformation from plain ABE to unidirectional and single-hop CU-ABE using only (inner-product) functional encryption (IPFE), which can be instantiated from plain LWE. Then, we show how to combine this CU-ABE with lockable obfuscation to obtain unidirectional and single-hop CU-PE from LWE. These constructions support bounded number of update tokens.
While unidirectional and single-hop updates with bounded number of tokens are sufficient for practical applications, we show that we can extend our results to multi-hop and unbounded token setting by constructing both key-policy and ciphertext-policy CU-ABE schemes for all bounded-depth circuits. Proving security of these multi-hop constructions turned out to be non-trivial, which required us to develop novel techniques and rely on public-coin evasive LWE assumption.