International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

29 May 2026

Bengaluru , India, 13 December - 16 December 2026
Event Calendar Event Calendar
Event date: 13 December to 16 December 2026
Submission deadline: 15 August 2026
Notification: 10 October 2026
Expand
Jeju Island, South Korea, 26 August - 28 August 2026
Event Calendar Event Calendar
Event date: 26 August to 28 August 2026
Submission deadline: 13 June 2026
Notification: 18 July 2026
Expand
Antalya, Turkey, 11 October 2026
Event Calendar Event Calendar
Event date: 11 October 2026
Expand
Amiens, France, 22 June - 25 June 2026
Event Calendar Event Calendar
Event date: 22 June to 25 June 2026
Expand
Jeju, South Korea, 26 August - 28 August 2026
Event Calendar Event Calendar
Event date: 26 August to 28 August 2026
Submission deadline: 13 June 2026
Notification: 18 July 2026
Expand
Simula UiB, Bergen, Norway
Job Posting Job Posting

We are currently hiring at Simula UiB for a permanent Research Scientist or Senior Research Scientist position [*] in the Department of Cryptography, specialising in post-quantum cryptography.

We are seeking candidates with a PhD in cryptography, computer science, applied mathematics, or a related discipline. The successful candidate should be able to conduct both independent and collaborative, high-impact research and have experience in the design, analysis or implementation of post-quantum cryptographic schemes, demonstrated through publications in leading international venues. Expertise in related areas, such as cryptographic engineering, implementation security, side-channel analysis or applied cryptography more broadly will be an advantage.

Application deadline: 28 June 2026

For more information and how to apply: https://www.simula.no/careers/job-openings/research-scientist-in-cryptography-at-simula-uib

About Simula UiB: Simula UiB (simula-uib.com) is a research institute in Cryptography and Information Theory based in Bergen, Norway. The Department of Cryptography conducts research on the design and analysis of cryptographic algorithms, side-channel analysis and privacy-enhancing technologies. It currently comprises 13 members, including permanent staff, postdoctoral researchers and PhD students, and is led by Dr Martijn Stam. Simula UiB also hosts the Centre for Quantum Communication Networks and Applications (QCNA), one of Norway’s four national centres for quantum technology research, launched in May 2026.

[*] The Research Scientist and Senior Research Scientist levels at Simula UiB are broadly equivalent to Assistant Professor and Associate Professor positions in the university sector, respectively.

Closing date for applications:

Contact: Martijn Stam ([email protected])

More information: https://www.simula.no/careers/job-openings/research-scientist-in-cryptography-at-simula-uib

Expand
ENS Lyon, France
Job Posting Job Posting
The candidate will be working on algorithmic and mathematical aspects of lattice-based and isogeny-based cryptography, in the context of to the ERC project AGATHA CRYPTY.
  • The candidate should hold a PhD degree in Mathematics or Computer Science
  • They should have a strong record related to some of the following topics: number theory, computational number theory, lattice-based cryptography, isogeny-based cryptography
The starting date is flexible, and applications should be submitted here: https://emploi.cnrs.fr/Offres/CDD/UMR5669-BENWES-004/Default.aspx?lang=EN

Closing date for applications:

Contact: Benjamin Wesolowski, https://emploi.cnrs.fr/Offres/CDD/UMR5669-BENWES-004/Default.aspx?lang=EN

Expand
Department of Information Security and Communication Technology at NTNU in Trondheim, Norway
Job Posting Job Posting
We are seeking a highly motivated and internationally recognized scholar to join our department as an Associate Professor in Cryptographic Engineering. The position offers an exceptional opportunity to contribute to cutting edge research and education in a rapidly evolving field crucial to modern digital infrastructure, secure communications, and trusted computing. The successful candidate will play a key role in strengthening our research profile, fostering collaboration with national and international partners, and shaping the next generation cryptographic engineering experts.

The role entails a balanced portfolio of research, teaching, and academic leadership. The successful applicant will be expected to develop and lead research projects, obtain external funding, and publish in top-tier international venues (such as IACR CHES, IACR CRYPTO, IACR EUROCRYPT, ACM CCS, IEEE S&P). The position also involves contributing to the department’s educational mission through research-based teaching, supervision, and curriculum development at bachelor, master, and PhD levels.

The successful candidate is expected to conduct advanced research in cryptographic engineering, with emphasis on areas such as high‑assurance and performance‑optimized implementations of cryptographic primitives, formal verification techniques, and resistance against side‑channel, fault‑injection, and microarchitectural attacks. Research activities may also involve system‑level integration and deployment of cryptographic mechanisms in resource‑constrained or security‑critical environments, including wireless and embedded communication systems. The position further offers opportunities for interdisciplinary collaboration with researchers in adjacent domains within the department and across the university.

Closing date for applications:

Contact: Tjerand Silde

More information: https://www.jobbnorge.no/en/available-jobs/job/300865/associate-professor-in-cryptographic-engineering

Expand
University College Cork, Ireland
Job Posting Job Posting
The School of Computer Science & Information Technology at UCC invites applications for a permanent Associate Professor (Senior Lecturer) in Cybersecurity.
Cybersecurity is an area of strategic research importance to the School, and a focus area of teaching with a new MSc in Cybersecurity due to start in September 2026. The post will support the further development and delivery of this new MSc, engage in research that spans cybersecurity, cyber-physical security, data privacy, and security of AI.
We are looking for a world-class scientist with expertise in cybersecurity and specifically the intersection of AI and cybersecurity. The candidate requires expertise in cybersecurity, a track record of applying AI methods to cybersecurity problems and the ability and desire to:
  • develop and lead research and teaching activities in Cybersecurity;
  • establish and manage a significant world-class research team supported by competitively won research funding;
  • supervise research students at PhD level;
  • publish in leading conferences and journals in the cybersecurity domain;
  • develop and strengthen links between the School of Computer Science and key industry organisations working in Cybersecurity;
  • take leadership roles in cybersecurity across the University, nationally and internationally;
  • contribute to the overall strategic development of the School;
  • represent the School at internal and external events.
Appointment may be made on the Senior Lecturer Salary Scale: €84,749 - €120,082 (scale B). Candidates should apply before 12:00 noon (Irish time) on Tuesday, 9th June 2026. For an information package including full details of the post, selection criteria and application process see https://ore.ucc.ie/ (job ID: 094546).

Closing date for applications:

Contact: Prof Dirk Pesch at [email protected]

More information: https://my.corehr.com/pls/uccrecruit/erq_jobspec_version_4.jobspec?p_id=094546

Expand

27 May 2026

Jiawei Bao, Tibor Jager, Eike Kiltz, Aysan Nishaburi, Samin Nooripoor, Jiaxin Pan
ePrint Report ePrint Report
Can a relevant cryptographic primitive, when instantiated over the NIST P-256 elliptic curve, achieve a bit-security level exceeding $128$ bits? Yes. We formally prove that the well-known password-authenticated key exchange protocol $\mathsf{EKE}$, introduced by Bellovin and Merritt (S&P 1992), achieves a generic security level of $128+\frac{1}{2}\log_2(N)$ bits, where $N$ denotes the size of the password space. To prove this result, we introduce and develop a new approach for showing that breaking a cryptosystem with a prescribed advantage requires solving many instances of an underlying computational assumption. To this end, we formulate the Hidden-Target Diffie-Hellman assumption. In this assumption, the adversary is given a set of $N$ Diffie-Hellman challenge instances. The Diffie-Hellman key of one uniformly random instance is designated as the hidden target. The adversary does not know which instance is the target, but may output an arbitrary subset of candidate solutions and succeeds only if this subset contains the target. We formally prove that breaking the Hidden-Target Diffie-Hellman assumption with probability greater than $(k-1)/N$ requires solving at least $k$ of the $N$ Diffie-Hellman instances. We then show that the security of $\mathsf{EKE}$ in the ideal-cipher model is equivalent to the Hidden-Target Diffie-Hellman assumption. A somewhat surprising consequence of this equivalence is that $\mathsf{EKE}$ achieves the claimed generic security level of $128+\frac{1}{2}\log_2(N)$ bits. Moreover, the equivalence implies that $\mathsf{EKE}$ remains secure even in settings where the hardness of $\mathsf{DLOG}$ or $\mathsf{CDH}$ is weaker than expected: an adversary may still need to solve on the order of hundreds or thousands of discrete logarithm instances in order to succeed, a task that may remain infeasible even for powerful attackers, including those equipped with early quantum computers.
Expand
Siddhartha Chowdhury, Nimish Mishra, Sarani Bhattacharya, Debdeep Mukhopadhyay
ePrint Report ePrint Report
Masking-based countermeasures such as Threshold Implementations and Probe-Isolating Non-Interference (PINI) are commonly assumed to protect cryptographic software against side-channel leakage by maintaining isolation between secret shares. In this work, we show that this assumption can break on modern out-of-order (OoO) processors due to backend microarchitectural effects that are not visible at the ISA level.

We present \texttt{OoOLyzer}, a trace-driven analysis framework that reconstructs physical-register reuse and backend execution interactions from OoO RISC-V pipeline traces. Using \texttt{OoOLyzer}, we identify leakage arising from backend physical-register reuse and transient overlap of masked-share operations inside OoO execution structures.

We evaluate the framework on a masked PRESENT implementation and composable PINI gadgets. Our analysis shows that although rotated-share computations protect selected nonlinear operations, affine share pairs remain directly represented in the architectural execution state. OoO register renaming can therefore induce physical-register transitions of the form \[ \operatorname{HW}_{\mathrm{bit}}(a_0[b]\oplus a_1[b]), \] which reconstruct affine PRESENT intermediates and create key-dependent leakage.

We validate the leakage experimentally in two stages. First, using a modified gem5 OoO RISC-V model, we attribute the dominant leakage source to backend physical-register reuse and demonstrate first-round PRESENT subkey recovery from masked execution traces. Second, on a real SiFive P550-class OoO RISC-V processor, we perform a temperature-based side-channel experiment using Linux-accessible thermal telemetry and recover 60 out of 80 key bits from the masked PRESENT implementation.

The results establish a complete cross-layer leakage path from masked software execution to OoO backend interactions, physical-register transitions, thermal behavior, and practical key recovery on real hardware. Our findings demonstrate that masking schemes appearing secure under software-level analysis may still leak on OoO processors, motivating hardware-aware verification of masked software deployments.
Expand
Alex Davidson, Nuno Nogueira, Samuel Pearson, João Ribeiro
ePrint Report ePrint Report
Private Information Retrieval (PIR) protocols allow a client to recover items from a server-held database without revealing the locations of requested items. In Symmetric PIR (SPIR), the client also learns nothing about the database beyond the requested items. Such schemes are critical for maintaining security in applications such as compromised credential checking, where database elements are considered as sensitive as queries. Existing approaches to building SPIR schemes require running multiple cryptographic primitives in parallel. Moreover, they do not naturally translate to the post-quantum setting, even though practical PIR schemes are typically post-quantum due to their reliance on learning with errors (LWE).

This work explores the possibility of deriving SPIR from PIR directly, utilising noise flooding to maintain the privacy of the database. While the common analysis based on the statistical distance leads to impractical parameters, we instead utilise arguments based on the Rényi divergence to obtain significantly improved parameters. We obtain simple single-server SPIR from state-of-the-art LWE-based PIR schemes with polynomial noise dimension and ciphertext modulus (concretely of 64 bits in size). Along the way, we note that practical schemes that utilise preprocessing via client-downloaded offline hints require extra protections for the database.

Overall, via an implementation of our approach, we show that post-quantum, round-optimal SPIR schemes can be constructed requiring online communication of 8 MB and server computation costs of 302 ms for a database of 1 million 1 kB elements.
Expand
Liyuan Tang, Lingyue Qin, Shiqi Hou, Xiaoyang Dong
ePrint Report ePrint Report
At CRYPTO 2025, Qin et al. introduced the guess-and-determine (GD) rebound attack, which integrates the guess-and-determine approach by Bouillaguet, Derbez, and Fouque and the rebound attack by Mendel et al. Taking the GD rebound as a building block, this paper introduces several classical and quantum models to convert the semi-free-start (SFS) collision attack or free-start (FS) collision attack into collision attacks on DM hashing mode with AES. As an application, the first full quantum collision attack on AES-256-DM is proposed. Despite numerous round-reduced quantum or classical attacks proposed against the three popular hash modes MMO/MP/DM with AES over the past two decades, this is the first full attack that targets one of the three fundamental security requirements: collision, (2nd) preimage resistance. Our full attack on AES-256-DM improves the best previous attack by Taiyama et al. at ASIACRYPT 2024 by 5 rounds. Besides, some improved results on AES-128-DM and AES-192-DM are also given, which have been verified partially or fully by experiments.
Expand
Takakazu Satoh
ePrint Report ePrint Report
In this note, we study decomposition of the Ate pairing on certain elliptic curves defined over finite fields. As an application, we reduce a generalized pairing inversion to root findings of an element of the affine coordinate ring appearing in the decomposition. For a supersingular curve $E / {\bf F}_q$ satisfying $\sharp E( {\bf F}_q ) = q+1$, heuristic observation suggests that a number of calls to a root finding algorithm seems to $O( N )$ where $N$ is the maximal power of $2$ dividing $q+1$. It is remarkable that the resulting algorithm does not utilize fixed argument pairing inversions. An underlying key observation is that the Miller function forms a factor system.
Expand
Yechen Li, Qunxiong Zheng
ePrint Report ePrint Report
The Learning with Errors (LWE) problem underpins many post-quantum cryptosystems, including the NIST-selected CRYSTALS-KYBER and CRYSTALS-DILITHIUM. Recent dual attacks have demonstrated remarkable effectiveness against concrete LWE-based schemes, with some claims suggesting that the security of CRYSTALS-KYBER may be reduced below the NIST threshold. However, the analysis of the score distribution for the correct guess in dual attacks has consistently relied on a flawed independence assumption, leading to variance estimates that are far smaller than the true score variance. This issue has been highlighted in several studies. For instance, Bashiri and Wiemers (JMC 2025) proposed an estimate of the variance, yet our experiments reveal that their approach performs poorly in medium-to-high dimensions. On the other hand, many works have characterized the success probability of dual attacks, but these are either based on the BDD problem or limited to specific attack types, lacking a unified analytical framework for dual attacks on LWE. These theoretical gaps motivate us to develop a unified estimation of the expectation and variance of the score in dual attacks. In this paper, we propose a unified predictive model for the expectation and variance of the score, covering three types of dual attacks: the original dual attack, the dual attack with modulus switching, and the dual attack with decoding (Crypto 2025). Our key observation is that the cosine of the angle between different short vectors follows a normal distribution, which we use to estimate the covariance between individual scores. By decomposing the score expression into a combination of simple distributions, we obtain estimates for the expectation and variance of individual scores, and combine these with the covariance to derive closed-form estimates for the total variance. Experiments show that our estimates achieve high accuracy and outperform previous work in medium-to-high dimensions. We also extend the prediction method of Ducas and Pulles (JOC 2026) for the score of incorrect guesses to a more general setting and, together with our predictive model, provide an extended characterization of the tail behavior.
Expand

26 May 2026

Behzad Abdolmaleki, Suvradip Chakraborty, Shahram Khazaei, Lorenzo Magliocco, Nahid Roustaeifar, Behzad Vahdani, Daniele Venturi
ePrint Report ePrint Report
Password-Authenticated Key Exchange (PAKE) allows two parties to establish a common high-entropy secret from a possibly low-entropy pre-shared secret such as a password. In this paper, we revisit the question of constructing PAKE protocols with subversion resilience in the framework of universal composability (UC), where the latter roughly means that UC security still holds even if one of the two parties is malicious and the honest party's code has been subverted (in an undetectable manner). The latter goal was recently achieved by Chakraborty, Magliocco, Magri and Venturi (ASIACRYPT 2024), based on sanitation of oblivious transfer protocols and dual-mode cryptosystems via cryptographic reverse firewalls (Mironov and Stephens-Davidowitz, EUROCRYPT 2015). Our contributions are as follows:

- We introduce so-called malleable trapdoor smooth projective hash functions (M-TSPHF), as an enhancement of trapdoor smooth projective hash functions (Benhamouda et al., CRYPTO 2013). Our extension incorporates new properties including key malleability and element rerandomizability. - We give a generic construction of subversion-resilient UC PAKE based on M-TSPHF and other standard cryptographic primitives. As we demonstrate, our PAKE protocol can be instantiated efficiently yielding an improved round and communication complexity with respect to the previous protocol of Chakraborty et al. In particular, our PAKE protocol achieves round optimality, as it concludes in a single round.
Expand
Ge Gao, Haining Yu, Jinbo Yang, Dongyang Zhan, Xiaohua Jia
ePrint Report ePrint Report
Anonymous whistleblowing systems allow insiders to report organizational misconduct while preserving confidentiality and anonymity. Existing systems often use Tor-based submission and encryption under a recipient public key, so the mailbox does not learn the submitter’s network address or report contents. This protection does not remove reliance on the parties that authenticate insiders or open reports. Two corruption risks remain: (1) token-issuance records held by an authentication server can be correlated with a submission to link the report to a registered insider; and (2) a recipient with unilateral plaintext access may suppress, selectively disclose, or influence the report before any accountable opening process. We present AWARE, a non-interactive whistleblowing protocol for anonymous report submission by eligible insiders and threshold opening of reports. AWARE separates identity authentication from submission: after scheduled token refresh, an eligible insider can submit a report with a locally finalized token, without contacting the authentication server at submission time. AWARE also replaces single-recipient opening with committee threshold opening: report recovery requires a threshold of committee decryption shares that pass verification. Under the stated corruption and leakage assumptions, we prove the corresponding anonymity, token unforgeability, report confidentiality before opening, and opening integrity properties. A Java implementation shows practical costs in the tested settings.
Expand
Robert Schädlich, Linda Scheu-Hachtel, Erkan Tairi, Yuejun Wang
ePrint Report ePrint Report
We present a novel variant of attribute-based encryption (ABE) and predicate encryption (PE) which supports ciphertext updates, called ciphertext-updatable ABE (CU-ABE) and PE (CU-PE). Such a feature enhances the usability of the fine-grained encryption paradigm by allowing controlled updates to the ciphertexts. Updating ciphertexts is carried out via update tokens, which can only be generated by the master secret key holder, yet any party with access to the token can convert the ciphertexts.

Apart from defining these new primitives and establishing their security in the indistinguishability-based setting, we provide various constructions with different trade-offs. Concretely, we provide a generic transformation from plain ABE to unidirectional and single-hop CU-ABE using only (inner-product) functional encryption (IPFE), which can be instantiated from plain LWE. Then, we show how to combine this CU-ABE with lockable obfuscation to obtain unidirectional and single-hop CU-PE from LWE. These constructions support bounded number of update tokens.

While unidirectional and single-hop updates with bounded number of tokens are sufficient for practical applications, we show that we can extend our results to multi-hop and unbounded token setting by constructing both key-policy and ciphertext-policy CU-ABE schemes for all bounded-depth circuits. Proving security of these multi-hop constructions turned out to be non-trivial, which required us to develop novel techniques and rely on public-coin evasive LWE assumption.
Expand
Xinyu Mao
ePrint Report ePrint Report
We study distributional collision resistance for random degree-2 functions over prime fields. Let $p$ be a prime and let \[ h:\mathbb{F}_p^N\to \mathbb{F}_p^M, \ x \mapsto (h_1(x), \dots, h_M(x)) \qquad M
Expand
Afshin Hassani, Mehran Alidoost Nia, Reza Ebrahimi Atani
ePrint Report ePrint Report
This systematic literature review investigates recent advancements in machine learning techniques aimed at ensuring safety and security in autonomous systems. By analyzing 129 scholarly articles published between 2018 and 2024, we identify dominant methodologies, prominent machine learning techniques, and key application domains. As the paper illustrates, Reinforcement Learning (RL) and Deep Learning (DL) have emerged as leading approaches, especially in contexts requiring real-time adaptation such as autonomous vehicles, Unmanned Aerial Vehicles (UAVs) and robotics. Our analysis reveals significant research trends, including a strong emphasis on safe motion, prediction, vulnerability detection, and security assurance. We highlight current research gaps, notably the need for standardized benchmarks and improved model robustness under adversarial conditions. This review provides valuable insights and future research directions, serving as a comprehensive guide for young researchers entering the field of safe and secure autonomy.
Expand
◄ Previous Next ►