<?xml version='1.0' encoding='utf-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>Paper Feeds (IACR)</title>
    <link>https://feeds.gw-api.xyz</link>
    <description>Keyword-based research paper feeds from IACR</description>
    <lastBuildDate>Fri, 11 Sep 2026 00:22:22 +0000</lastBuildDate>
    <atom:link href="https://feeds.gw-api.xyz/feed-iacr.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Security Properties of Iterated Random Functions</title>
      <link>https://eprint.iacr.org/2026/1923</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1923</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1923"&gt;https://eprint.iacr.org/2026/1923&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;在许多密码学应用中，对哈希函数进行迭代操作是一种常见做法，主要用于增强对各类攻击的抵抗力（例如在密码哈希中减缓字典攻击）。尽管非迭代密码哈希函数的安全属性已被广泛研究，但其迭代变体受到的关注相对较少。即使在随机预言机模型（ROM）下，迭代哈希函数的原像抗性和抗碰撞性也尚未得到完全刻画。先前的研究要么限制了敌手的预言机访问权限，要么仅关注最后一次迭代步的原像寻找。&lt;/p&gt;&lt;p&gt;本文全面完善了这一领域的研究图景，针对被建模为随机预言机的随机函数 $H$ 的 $k$ 次迭代 $H^k$，给出了原像抗性和抗碰撞性的具体攻击方案及匹配的安全上界。研究发现，迭代操作对&lt;strong&gt;抗碰撞性&lt;/strong&gt;几乎没有影响；然而，对于&lt;strong&gt;原像抗性&lt;/strong&gt;，情况则截然不同。具体而言，本文提出了一种针对 $H^k$ 原像抗性的具体攻击，在敌手查询次数 $q = \Omega(k)$ 的假设下，该攻击的优势达到了 $\Omega(\frac{qk}{n})$。同时，本文证明了 $\mathcal{O}(\frac{qk+k^2}{n})$ 的安全上界，该上界在 $q = \Omega(k)$ 区间内是紧确的。此外，研究还表明，迭代操作仅在 $H$ 为一般随机函数时会削弱原像抗性；当 $H$ 为置换（permutation）时，其原像抗性基本保持不变。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Iterating cryptographic hash functions is common for enhancing security, yet the preimage and collision resistance of iterated hash functions remain incompletely characterized, even in the random oracle model (ROM). Prior works either restricted adversary access or focused solely on the final iteration step. This paper completes the security picture for an iterated random function $H^k$, where $H$ is modeled as a random oracle, by providing concrete attacks and matching upper bounds. We demonstrate that while collision resistance is essentially unaffected by iterations, preimage resistance is significantly impacted. Specifically, we present an attack on the preimage resistance of $H^k$ achieving an advantage of $\Omega(\frac{qk}{n})$ when $q = \Omega(k)$, where $q$ is the number of queries. We complement this with a tight upper bound of $\mathcal{O}(\frac{qk+k^2}{n})$ in this regime. Finally, we show that this degradation in preimage resistance is specific to random functions; when $H$ is a permutation, preimage resistance remains essentially unaffected.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Iteration of a cryptographic hash function is a common practice in many applications, typically used to enhance resistance against various attacks (e.g., to slow down dictionary attacks in password hashing). While the security properties of (non-iterated) cryptographic hash functions are well studied and understood by the cryptographic community, their iterated counterparts have received comparatively little attention. Even in idealized models such as the random oracle model, preimage and collision resistance of an iterated hash function do not seem to be fully characterized.&lt;/p&gt;&lt;p&gt;The security of an iterated random function has mainly been studied through its indistinguishability from the (non-iterated) random function. Bhaumik et al. (ASIACRYPT 2017) analyse the collision resistance of an iterated random function, but in a model where the adversary has oracle access to the iterated random function (and not the random function itself). Kogan et al. (CCS 2017) then study the  preimage resistance of an iterated random function in the random oracle model, but focus only on finding preimages for the last iteration step.&lt;/p&gt;&lt;p&gt;In this paper we complete the picture by providing attacks and matching upper bounds for preimage and collision resistance of an iterated random function \(H^k\), where \(H \colon [n] \to [n]\) is modelled as a random oracle. While collision resistance is essentially unaffected by iterations, we prove that the situation is very different in the case of preimage resistance. Specifically, we present a concrete attack on preimage resistance of \(H^k\) with advantage \(\Omega(\frac{qk}{n})\) assuming \(q = \Omega(k)\), where \(q\) denotes the number of \(H\)-oracle queries made by the adversary. We complement our attack with an upper bound \(\mathcal{O}(\frac{qk+k^2}{n})\), which is tight in the \(q = \Omega(k)\) regime. Finally, we show that iteration weakens preimage resistance only for random functions: when \(H\) is a permutation, preimage resistance remains essentially unaffected.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Pairing-based Succinct Half-Chosen VOLE</title>
      <link>https://eprint.iacr.org/2026/1922</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1922</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1922"&gt;https://eprint.iacr.org/2026/1922&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景&lt;/strong&gt;：简洁非交互式半选择向量不经意线性扩展（Succinct Non-Interactive Half-Chosen VOLE, 简称 NIHC-VOLE）是现代密码学中一种关键的原语。它允许拥有长度为 $n$ 的向量 $\boldsymbol x$ 的发送方与拥有标量 $y$ 的接收方，通过同时交换简洁的消息，高效建立 $\boldsymbol x \cdot y$ 的加法秘密共享。近期的前沿研究在多种密码学假设下实现了通信复杂度为 $O(n^{2/3} \lambda)$ 的 NIHC-VOLE 方案，或基于 LWE 假设实现了多对数级别的通信复杂度。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：本文深入探讨了如何利用双线性配对（bilinear pairings）技术来优化和改进基于群的 NIHC-VOLE 方案，并在两种不同的设置下取得了突破性进展：&lt;br /&gt;1. &lt;strong&gt;公共设置（Public Setup）&lt;/strong&gt;：我们提出了一种全新方案，将其在线通信复杂度大幅降低至 $O(\sqrt{n \log n})$ 个群元素。该方案的安全性基于一种全新的类 BDDH（Bilinear Decisional Diffie-Hellman）假设。&lt;br /&gt;2. &lt;strong&gt;指定接收方设置（Designated Receiver Setup）&lt;/strong&gt;：在此设置下，我们的方案实现了极致的在线通信效率，在线通信量仅需 3 个群元素，同时支持 $O(n)$ 个群元素的可重用离线通信。该方案的安全性严格建立在双线性 power DDH 假设之上。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现&lt;/strong&gt;：通过创新性地引入双线性配对，本论文显著降低了 NIHC-VOLE 的在线通信开销，为安全多方计算和隐私保护协议提供了更高效的底层密码学工具。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;: Succinct Non-Interactive Half-Chosen VOLE (NIHC-VOLE) enables a sender with a vector $\boldsymbol x$ and a receiver with a scalar $y$ to establish additive shares of $\boldsymbol x \cdot y$ via succinct message exchanges. Recent works achieved $O(n^{2/3} \lambda)$ or poly-logarithmic communication complexities under various assumptions.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Methods &amp;amp; Contributions&lt;/strong&gt;: This paper explores how bilinear pairings can significantly enhance group-based NIHC-VOLE schemes, presenting novel constructions under two distinct settings:&lt;br /&gt;1. &lt;strong&gt;Public Setup&lt;/strong&gt;: We propose a scheme achieving an online communication complexity of $O(\sqrt{n \log n})$ group elements, relying on a new BDDH-like assumption.&lt;br /&gt;2. &lt;strong&gt;Designated Receiver Setup&lt;/strong&gt;: Our construction drastically reduces the online communication to merely 3 group elements, with reusable offline communication of $O(n)$ group elements, based on the bilinear power DDH assumption.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;: By leveraging bilinear pairings, this work substantially minimizes the online communication overhead of NIHC-VOLE, providing highly efficient foundational tools for secure multi-party computation.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Succinct Non-Interactive Half-Chosen VOLE allows a sender with a vector $\boldsymbol x$ of length $n$ and a receiver with a scalar $y$ to establish a pair of additive shares of $\boldsymbol x \cdot y$, by simultaneous exchange of succinct messages.  Recent works construct NIHC-VOLE with $O(n^{2/3} \lambda)$ communication from various assumptions (Abram, Roy and Scholl, Eurocrypt 24) and poly-logarithmic communication from LWE (Abram, Malavolta and Roy, STOC 25).&lt;/p&gt;&lt;p&gt;We explore how bilinear pairings can improve group-based NIHC-VOLE schemes.&lt;br /&gt;• In the public setup setting, our scheme has online communication of $O(\sqrt{n \log n})$ group elements.  The scheme relies on a new BDDH-like assumption.&lt;br /&gt;• In the designated receiver setting, our scheme has online communication of only 3 group elements and reusable offline communication of $O(n)$ group elements.  The scheme relies on the bilinear power DDH assumption.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Homomorphic Functional Encryption: Trustless Key Derivation for Functional Encryption</title>
      <link>https://eprint.iacr.org/2026/1921</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1921</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1921"&gt;https://eprint.iacr.org/2026/1921&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：函数加密（FE）方案通常依赖于持有主密钥的受信任密钥管理者来派生功能解密密钥。这种集中式设计使密钥管理者成为信任的中心点和极易受攻击的目标，同时功能解密密钥的使用也可能引发信息泄露，导致严重的信任假设危机。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：为缓解上述安全隐患，本文提出了一种结合&lt;strong&gt;同态加密（HE）&lt;/strong&gt; 的无信任密钥派生机制，即“同态函数加密”。该方法允许FE的密钥派生算法在同态密文状态下进行评估。在先前关于函数盲密钥派生研究的基础上，本文将其创新性地扩展至三方部署模型。在该架构中，密钥管理者无需以明文形式接触或持有FE主密钥，即可完成安全的密钥派生。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与贡献&lt;/strong&gt;：本文构建的方案在严格保留函数盲性的同时，有效保护了主密钥免受管理者窥探，从根本上降低了传统FE密钥管理中的信任假设。为验证该方案的工程适用性，本文开发了概念验证（PoC）原型系统，并运行了一系列基准测试以评估其实际性能。最后，秉持开放科学与可重复研究的理念，本文已将全部核心代码公开开源，为密码学社区提供了宝贵的实践参考。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Functional encryption (FE) schemes traditionally rely on a trusted key curator holding the master secret key to derive functional decryption keys, creating a critical single point of failure and exacerbating trust assumptions regarding potential information leakage. To mitigate these vulnerabilities, this paper introduces &lt;strong&gt;Homomorphic Functional Encryption&lt;/strong&gt;, which leverages homomorphic encryption (HE) to evaluate FE key-derivation algorithms over encrypted data in an innovative three-party deployment where the curator never accesses the master secret key in plaintext. Our resulting cryptographic construction rigorously preserves function blindness while effectively shielding the master secret key from the curator, thereby significantly minimizing the trust assumptions and security risks inherent in conventional FE key management systems. Furthermore, to validate the practical applicability and efficiency of our approach, we developed a proof-of-concept implementation, executed a comprehensive series of performance benchmarks, and publicly released our complete source code to foster open science and reproducible cryptographic research.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;In this paper, we study the trust assumptions underlying key generation in functional encryption (FE) schemes, as well as the information leakage that can arise from the use of functional decryption keys. FE schemes typically rely on a trusted key curator who holds the master secret key and derives functional decryption keys. This requirement makes the curator a central point of trust and a particularly sensitive target for compromise. We show how homomorphic encryption (HE) can be used to mitigate this problem by allowing FE key-derivation algorithms to be evaluated homomorphically. Building on prior work on function-blind key derivation [CHL20], we extend this approach to a three-party deployment in which the key curator does not hold the FE master secret key in the clear.&lt;br /&gt;The resulting construction preserves function blindness while protecting the master secret key from the curator, thereby reducing the trust assumptions associated with conventional FE key management.&lt;br /&gt;Additionally, to test the applicability of our approach, we made a proof-of-concept implementation and ran a series of benchmarks. Finally, as a way to support open science and reproducible research, we make our code publicly available.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Compact Lattice Anonymous Credentials from Tighter Approximate Range Proofs</title>
      <link>https://eprint.iacr.org/2026/1920</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1920</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1920"&gt;https://eprint.iacr.org/2026/1920&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;h4&gt;研究背景&lt;/h4&gt;&lt;p&gt;匿名凭证系统旨在实现加密真实性与强用户隐私保护的完美结合。近期，欧洲数字身份（EUDI）钱包倡议进一步凸显了对高效、私密且基于成熟安全基础的解决方案的迫切需求。这一趋势恰逢后量子密码学的过渡期，然而，当前基于标准假设的量子安全方案在性能上仍显著落后于基于特定交互假设的方案。&lt;/p&gt;&lt;h4&gt;核心方法与优化&lt;/h4&gt;&lt;p&gt;为弥补上述性能差距，本文提出了一系列创新技术，旨在显著提升基于&lt;strong&gt;标准格假设&lt;/strong&gt;的匿名凭证系统的效率。研究团队深入分析了现有格隐私导向构造中的性能瓶颈，并针对性地进行了多维度的优化。&lt;/p&gt;&lt;h4&gt;主要发现与创新点&lt;/h4&gt;&lt;p&gt;本文的核心突破在于对 &lt;strong&gt;Lyubashevsky, Nguyen 和 Plançon (Crypto&amp;#x27;22)&lt;/strong&gt; 提出的零知识协议进行了关键性改进。具体而言，作者构造了&lt;strong&gt;更紧密的近似范围证明（tighter approximate range proofs）&lt;/strong&gt;。这一改进直接攻克了当前格基匿名凭证构造中的主要效率瓶颈，使得基于标准假设的方案在紧凑性和效率上大幅跃升。该研究成功缩小了标准方案与特殊假设方案之间的差距，为后量子时代的隐私保护提供了更为坚实、紧凑且高效的标准化解决方案。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Anonymous credentials systems are crucial for balancing cryptographic authenticity with strong user privacy, a need recently highlighted by the European Digital Identity (EUDI) wallet initiative during the ongoing post-quantum transition. However, current quantum-safe solutions based on standard assumptions still lag behind exotic interactive ones in overall performance. In this paper, we introduce several novel techniques to significantly enhance the efficiency of anonymous credentials built on standard lattice assumptions. Our primary breakthrough addresses the critical efficiency bottleneck in lattice-based privacy constructions by developing tighter approximate range proofs within the zero-knowledge protocol originally proposed by Lyubashevsky, Nguyen, and Plançon (Crypto&amp;#x27;22). By optimizing these range proofs alongside other structural improvements, our approach successfully narrows the performance gap with more exotic schemes. These advancements ensure robust security without compromising the speed required for real-world applications, ultimately providing a highly efficient, compact, and well-founded post-quantum privacy solution.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Accommodating cryptographic authenticity with strong user privacy assurances has been the primary motivation for anonymous credentials systems. Their features have recently come into the spotlight with the European Digital Identity (EUDI) wallet initiative, insisting on the need for efficient and private solutions based on well-understood security foundations for high assurances. This coincides with the post-quantum transition, but current quantum-safe solutions based on standard assumptions are still lagging behind the ones on ad-hoc interactive assumptions performance-wise.&lt;br /&gt;In this paper, we present several techniques to improve the efficiency of anonymous credentials from standard lattice assumptions, narrowing the gap with more efficient but also more exotic ones. Alongside other optimizations, our main improvement stems from tighter approximate range proofs in the zero-knowledge protocol of Lyubashevsky, Nguyen, Plançon (Crypto&amp;#x27;22), currently the efficiency bottleneck of lattice privacy-oriented constructions.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Cryptanalysis of Deep Neural Cryptography: Second Round Key Recovery on the Unprotected Implementation and a Floating-Point Attack on the Protected Implementation of AES</title>
      <link>https://eprint.iacr.org/2026/1919</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1919</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1919"&gt;https://eprint.iacr.org/2026/1919&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文针对EUROCRYPT 2026提出的深度神经网络（DNN）密码实现进行了深入的密码分析。Gérault等人提出了一种自然DNN实现，通过ReLU网络在实数域上连续扩展块密码，并指出该扩展会暴露第一轮密钥，同时提出了一种可证明安全的黑盒变换。本文从攻击与防御两个维度重新审视了该成果。在攻击方面，针对未受保护的实现，本文改进了自然S盒的吸收特性，并结合选择明文碰撞测试，成功在约$2^{39}$次查询内恢复了AES-256的第二轮密钥，突破了以往仅能恢复第一轮密钥的限制。在防御方面，本文指出原有的安全变换仅在实数域上成立，而在神经网络实际运行的有限精度下存在严重漏洞。我们提出了一种浮点攻击，利用特定输入值在舍入时未能精确转换为比特的问题，仅通过128次选择查询便恢复了受保护AES-128实现的第一轮密钥。该漏洞在bfloat16至float64等多种浮点格式中均存在，提高精度无法修复。最后，本文提出在舍入前引入钳位（clamp）操作以阻断攻击，该修补既保持了密码功能与实数域安全性，又确保了有限输入在工作精度下处于$[0,1]$区间。整个构造在有限精度下的安全性证明仍是一个开放问题。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper presents a cryptanalysis of the Deep Neural Cryptography implementations introduced at EUROCRYPT 2026. While the original work demonstrated that natural DNN extensions of block ciphers expose the first-round key and proposed a provably secure blackbox transformation over the reals, we revisit both the attack and defense aspects. On the attack side, by refining the absorption property of the natural S-box and employing a chosen-plaintext collision test, we recover the second-round key of the unprotected AES-256 in approximately $2^{39}$ queries. On the defense side, we expose a critical flaw in the proposed transformation under finite-precision arithmetic, the actual execution environment for neural networks. We introduce a floating-point attack that recovers the first-round key of the protected AES-128 in just 128 chosen queries by exploiting inputs that fail to round correctly to bits. This vulnerability persists across bfloat16, float16, float32, and float64 formats. Finally, we propose a simple clamp mechanism before the rounding step to mitigate this attack without compromising the cipher&amp;#x27;s functionality or its exact-real security guarantee.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;At EUROCRYPT 2026, Gérault et al. introduced natural DNN implementations of block ciphers: ReLU networks that agree exactly with the underlying cipher on binary inputs but extend it continuously to real-valued inputs. They showed that this extension exposes the first round key to recovery, and proposed a generic Secure Blackbox Transformation that turns an arbitrary DNN-based implementation into a provably secure implementation. We revisit both sides of their result. On the attack side, the known attacks on the unprotected implementation reach only the first round key. Under the same threat model, we refine the absorption property of the natural S-box and combine it with a chosen-plaintext collision test, validated empirically, to recover the second round key of AES-256 in about $2^{39}$ queries. On the defense side, their transformation is provably secure over the reals, but that guarantee does not carry over to finite precision, where any neural-network implementation must ultimately run. We give a floating-point attack that recovers the first round key of the protected AES-128 implementation in $128$ chosen queries, driven by an input value that the defense fails to round to a bit. Such a value exists in bfloat16, float16, float32, and float64, so moving to higher precision does not remove the weakness. We confirm the recovery in all four formats. Finally, we block the attack with a clamp placed before that rounding step, which keeps every finite input in $[0,1]$ in the working precision and changes neither the cipher nor the exact-real security guarantee. Whether a finite-precision security guarantee can be established for the construction as a whole remains open.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Towards Practical Privacy-Preserving SAT Solving</title>
      <link>https://eprint.iacr.org/2026/1918</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1918</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1918"&gt;https://eprint.iacr.org/2026/1918&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;隐私保护布尔可满足性（SAT）求解器允许多个互不信任的参与方在不泄露各自输入的前提下，联合求解其私有公式的合取问题。然而，先前的代表性工作（如 ppSAT）由于仅支持最基础的 SAT 求解算法，在面对具有实际规模和复杂度的公式时往往无能为力。为了打破这一瓶颈，使隐私保护 SAT 求解真正迈向实用化，本文创新性地提出了一种名为 &lt;strong&gt;ppCDCL&lt;/strong&gt; 的新型求解器。&lt;/p&gt;&lt;p&gt;在方法层面，ppCDCL 通过精心设计的不经意（oblivious）数据结构与全新的求解器架构，成功在隐私保护框架下实现了现代明文 SAT 求解器中最为核心的两大特性：&lt;strong&gt;冲突驱动子句学习（CDCL）&lt;/strong&gt; 与&lt;strong&gt;高效传播机制&lt;/strong&gt;。这不仅弥补了现有方案在算法层面的缺陷，更大幅提升了复杂公式的求解能力。&lt;/p&gt;&lt;p&gt;在主要发现与评估结果方面，实验数据充分证明了 ppCDCL 的优越性。与 ppSAT 相比，ppCDCL 在求解能力和执行效率上均实现了跨越式提升。在 Haplotype 基准测试中，其求解成功率由 65% 显著跃升至 98%；在规模更大、更具多样性的 SATLIB 基准测试中，成功率更是从 28% 大幅提高到 84%。此外，针对 SATLIB 实例，ppCDCL 能够在 1000 秒的时间限制内成功求解 36% 的样本，而原有的 ppSAT 仅能完成 4%。综上所述，ppCDCL 为大规模隐私保护 SAT 求解提供了切实可行的解决方案。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Privacy-preserving Boolean satisfiability (SAT) solvers enable mutually distrustful parties to jointly solve their private formulas without leaking sensitive inputs. However, prior works such as ppSAT are severely limited to basic algorithms and consequently fail to handle formulas of practical size and complexity. To bridge this critical gap, we introduce &lt;strong&gt;ppCDCL&lt;/strong&gt;, a novel solver that brings privacy-preserving SAT solving closer to practicality. By leveraging carefully orchestrated oblivious data structures and a redesigned solver architecture, ppCDCL successfully implements conflict-driven clause learning (CDCL) and efficient propagation, which are the two most crucial features of modern plaintext SAT solvers. Extensive evaluations demonstrate that ppCDCL significantly outperforms ppSAT in both capability and efficiency. Specifically, it solves 98% of Haplotype benchmarks (compared to 65% for ppSAT) and 84% of diverse SATLIB instances (compared to 28%). Furthermore, ppCDCL successfully solves 36% of SATLIB instances within 1,000 seconds, representing a remarkable improvement over the mere 4% achieved by the prior state-of-the-art.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Privacy-preserving Boolean satisfiability (SAT) solvers allow multiple distrustful parties to solve the conjunction of their private formulas without revealing their inputs.  Prior work on privacy-preserving SAT solvers, i.e., ppSAT (USENIX Security 2022), fails to solve formulas of practical size and complexity because it supports only the most basic SAT-solving algorithm. We bring privacy-preserving SAT solving closer to practicality by introducing ppCDCL. Through carefully orchestrated oblivious data structures and solver architecture, our new solver enables conflict-driven clause learning (CDCL) and efficient propagation, the two most important features of modern plaintext SAT solvers. Evaluation results show that ppCDCL outperforms ppSAT in both capability and efficiency. It solves significantly more instances: 98% vs. 65% on the Haplotype benchmarks and 84% vs. 28% on the larger, more diverse SATLIB benchmarks. Furthermore, it solves 36% of SATLIB instances within 1,000 seconds compared to only 4% for ppSAT.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Coral: General and Efficient Framework for Homomorphic Evaluation of Symmetric Ciphers</title>
      <link>https://eprint.iacr.org/2026/1917</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1917</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1917"&gt;https://eprint.iacr.org/2026/1917&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;全同态加密（FHE）支持在密文上直接进行计算，但客户端加密成本高昂且产生的密文体积庞大。跨密码转换（Transciphering）技术通过允许客户端上传对称密文，并由服务端同态评估对称解密过程以获取FHE密文，从而有效缓解了上述问题。然而，Transciphering 本身易成为性能瓶颈，且目前仍缺乏一个能够高效支持结构多样化对称密码的通用框架。&lt;/p&gt;&lt;p&gt;为填补这一空白，本文提出了 &lt;strong&gt;Coral&lt;/strong&gt;，一个基于 TFHE 构建的通用且高效的 Transciphering 框架。与将整个解密电路映射到单一评估策略的传统方法不同，Coral 在操作边界处对解密电路进行分解，并针对四种常见的计算模块提供了高度优化的处理流程：线性布尔运算、稀疏低次布尔函数、模加法以及小域替换。这些优化流程共享兼容的密文接口，使其能够在不同的密码算法中灵活重用与组合，从而在不牺牲通用性的前提下实现了极高的计算效率。&lt;/p&gt;&lt;p&gt;本文将 Coral 框架实例化于 Trivium、AES、ChaCha20 和 ZUC 等多种密码算法，涵盖了独立及组合的非线性结构。实验结果表明，与现有基线方法相比，Coral 在单线程执行下使 ZUC 的评估速度提升了高达 &lt;strong&gt;4.055 倍&lt;/strong&gt;，在完全并行执行下使 ChaCha20 的速度提升了高达 &lt;strong&gt;5.517 倍&lt;/strong&gt;。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Fully homomorphic encryption (FHE) enables computation on encrypted data but incurs high client-side costs and large ciphertexts. Transciphering mitigates this by having clients upload symmetric ciphertexts while servers homomorphically evaluate symmetric decryption to obtain FHE ciphertexts. However, transciphering often becomes a performance bottleneck, and a general framework for efficiently supporting diverse symmetric ciphers remains lacking.&lt;/p&gt;&lt;p&gt;To address this, we present &lt;strong&gt;Coral&lt;/strong&gt;, a general and efficient transciphering framework built on TFHE. Instead of mapping the entire decryption circuit to a uniform strategy, Coral decomposes it at operation boundaries and provides optimized procedures for four recurring computational modules: linear Boolean operations, sparse low-degree Boolean functions, modular additions, and small-domain substitutions. These procedures share compatible ciphertext interfaces, enabling reuse and composition across different ciphers to achieve high efficiency without sacrificing generality.&lt;/p&gt;&lt;p&gt;We instantiate Coral for Trivium, AES, ChaCha20, and ZUC, covering both individual and combined nonlinear structures. Compared to corresponding baselines, our implementations achieve speedups of up to &lt;strong&gt;4.055×&lt;/strong&gt; for ZUC under single-threaded execution and up to &lt;strong&gt;5.517×&lt;/strong&gt; for ChaCha20 under fully parallel execution.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Fully homomorphic encryption (FHE) enables computation directly on encrypted data, but encrypting data under FHE imposes client-side computational costs and produces large ciphertexts. Transciphering addresses these costs by allowing the client to upload symmetric ciphertexts while the server homomorphically evaluates symmetric decryption to obtain FHE ciphertexts. However, transciphering itself can become a performance bottleneck, and a general framework for efficiently supporting structurally diverse symmetric ciphers is still lacking.&lt;/p&gt;&lt;p&gt;To fill this gap, we present Coral, a general and efficient transciphering framework built on TFHE. Rather than mapping an entire decryption circuit to a uniform evaluation strategy, Coral decomposes it at operation boundaries and provides optimized procedures for four recurring computational modules: linear Boolean operations, sparse low-degree Boolean functions, modular additions, and small-domain substitutions. These procedures share compatible ciphertext interfaces, allowing them to be reused and composed across different ciphers. Together, these optimized procedures enable Coral to achieve high efficiency without sacrificing generality.&lt;/p&gt;&lt;p&gt;We instantiate Coral for Trivium, AES, ChaCha20, and ZUC, covering both individual and combined nonlinear structures. Compared with the corresponding baselines, our implementations achieve speedups of up to $4.055\times$ for ZUC under single-threaded execution and up to $5.517\times$ for ChaCha20 under fully parallel execution.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits</title>
      <link>https://eprint.iacr.org/2026/1916</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1916</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1916"&gt;https://eprint.iacr.org/2026/1916&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文以破解比特币等区块链技术使用的 $\mathtt{secp256k1}$ 曲线的256位椭圆曲线离散对数问题（ECDLP）为概念验证，充分展示了“行走猫架构”（Walking Cat Architecture）容错离子阱量子计算机在特定应用中的扩展与优化潜力。&lt;/p&gt;&lt;p&gt;在方法层面，研究深度优化了现有的逻辑量子电路，将其规模缩减至约1450个逻辑量子比特和4000万个Toffoli门。通过结合自研编译工具链、逻辑布局手动优化与集成路由技术，生成了严格遵循架构约束的测量调度方案。&lt;/p&gt;&lt;p&gt;本研究的&lt;strong&gt;核心创新点&lt;/strong&gt;包括：&lt;br /&gt;1. 开发快速CCZ魔法态工厂与深度为1的CCZ态注入技术，使CCZ门执行时间大幅缩短31倍；&lt;br /&gt;2. 采用非重叠的“猫态”并行测量，显著提升逻辑测量的并行度；&lt;br /&gt;3. 引入最新的逻辑CliNR协议以加速Clifford操作；&lt;br /&gt;4. 提出更高效的损耗校正协议，设计了可循环复用CliNR辅助量子比特的物理布局，并根据电路峰值测量并行度合理配置猫态资源。&lt;/p&gt;&lt;p&gt;综合上述优化，研究得出结论：基于该架构的离子阱量子计算机仅需 &lt;strong&gt;19,397个物理量子比特&lt;/strong&gt;，即可在约 &lt;strong&gt;25.7天&lt;/strong&gt; 内成功解决 $\mathtt{secp256k1}$ 的ECDLP。其逻辑级成功概率的严格下界置信度至少为 $1-2^{-128}$，预估实际成功概率高达 &lt;strong&gt;63%&lt;/strong&gt;。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Using the Walking Cat Architecture for trapped-ion quantum computers, this study presents a comprehensive proof-of-concept optimization to solve the 256-bit elliptic curve discrete logarithm problem (ECDLP) on $\mathtt{secp256k1}$ via Shor&amp;#x27;s algorithm. By optimizing logical circuits to just 1,450 qubits and 40 million Toffoli gates, implementing a fast CCZ magic-state factory that reduces CCZ execution time by a factor of 31, leveraging non-overlapping cat-based parallel measurements, and introducing the logical CliNR protocol alongside an efficient loss correction layout, we significantly minimize both gate execution times and overall physical qubit overhead. Ultimately, our compiled measurement schedules demonstrate that a fault-tolerant trapped-ion quantum computer based on this architecture can solve the $\mathtt{secp256k1}$ ECDLP in approximately 25.7 days using 19,397 physical qubits. This highly optimized approach achieves an estimated success probability of 63%, backed by a rigorous logical-level success lower bound with a confidence of at least $1-2^{-128}$.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;One of the strengths of our recently proposed Walking Cat Architecture for a trapped-ion quantum computer is that it is straightforward to extend and optimize for a specific application. As a proof-of-concept, here we present such optimizations for solving the $256$-bit elliptic curve discrete logarithm problem (ECDLP) on $\mathtt{secp256k1}$, which is the elliptic curve used by blockchain technologies such as Bitcoin, using Shor&amp;#x27;s algorithm. We optimize the circuits from Schrottenloher&amp;#x27;s recent work and arrive at a logical quantum circuit for solving the ECDLP using about $1450$ qubits and $40\cdot 10^6$ Toffoli gates, with a rigorous lower bound on the logical-level success probability that holds with confidence at least $1-2^{-128}$, as well as a heuristic estimate thereof. Using our compilation toolchain in combination with manual optimization of the logical layout and integrated routing, we produce estimates for the logical measurement depth and the required number of physical qubits by compiling all components to measurement schedules that obey the architectural constraints. A key ingredient is a fast CCZ magic-state factory and a depth-one CCZ state injection, reducing the execution time of CCZ gates by a factor of $31$. We increase the logical-measurement parallelism using non-overlapping cat-based measurements in parallel, and we leverage the recently proposed logical CliNR protocol to speed up Clifford operations. To reduce the qubit overhead, we introduce a more efficient loss correction protocol, design a layout that allows us to recycle the CliNR ancilla qubits, and provision reusable cat-state resources according to the circuit&amp;#x27;s peak measurement parallelism. All results and optimizations combined, we conclude that a trapped-ion quantum computer based on our architecture would be able to solve the ECDLP on $\mathtt{secp256k1}$ in approximately $25.7$ days using $19{,}397$ physical qubits with an estimated success probability of $63\%$.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>AIPA: Anonymous Image Provenance Authentication in Online Social Networks via Unlinkable Pseudonym Certificates and zk-SNARKs</title>
      <link>https://eprint.iacr.org/2026/1914</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1914</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1914"&gt;https://eprint.iacr.org/2026/1914&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：生成式AI的普及使得高保真深度伪造图像易于生成并在在线社交网络（OSN）中广泛传播。虽然公开验证图像来源（即图像的出处及编辑历史）是打击深度伪造的有效手段，但现有的行业标准（如C2PA）高度依赖可信软硬件。基于密码学的图像认证方案虽能消除对可信编辑器的依赖，但在OSN中部署时面临三大挑战：保护签名者隐私、在多次编辑中维持来源真实性，以及确保高效的验证过程。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;核心方法&lt;/strong&gt;：为解决上述问题，本文提出了一种匿名图像来源认证方案（AIPA）。首先，设计了基于匿名凭证的&lt;strong&gt;不可链接伪名证书方案（UPCS）&lt;/strong&gt;，将在线签名与验证降至普通数字签名级别（仅需0.017ms和0.066ms），有效保障了签名者的匿名性。其次，结合UPCS、&lt;strong&gt;zk-SNARKs（零知识简洁非交互式知识论证）&lt;/strong&gt;与哈希链技术构建AIPA方案，确保图像在互不信任的编辑者间传播时，其来源与编辑历史的真实性，同时严格保护隐私。最后，为实现OSN中的高效验证，引入了GPU加速的图像证明系统&lt;strong&gt;VIMz-Lou&lt;/strong&gt;，其内置专用JPEG压缩电路，证明大小恒定在448字节。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与创新&lt;/strong&gt;：本文对UPCS和AIPA进行了严格的安全性形式化证明，并在模拟OSN环境中实现了端到端工作流。实验结果表明，该方案生成的完整多编辑来源谱系数据量仅为40.2 KB（仅占原图的6.5%），且整体验证时间仅需4.28秒。本研究在保障用户隐私的前提下，实现了轻量、高效且安全的图像来源认证，为OSN中的深度伪造治理提供了创新的技术路径。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background &amp;amp; Objective&lt;/strong&gt;: While cryptographic image provenance authentication combats deepfakes in online social networks (OSNs) without relying on trusted hardware, it faces significant challenges regarding signer privacy, maintaining provenance integrity across multiple edits, and ensuring verification efficiency. &lt;strong&gt;Methods&lt;/strong&gt;: To address these issues, we propose the Anonymous Image Provenance Authentication (AIPA) scheme. AIPA integrates an Unlinkable Pseudonym Certificate Scheme (UPCS) to guarantee signer anonymity with minimal overhead, utilizes zk-SNARKs combined with hash chains to preserve provenance authenticity across untrusted editors, and introduces VIMz-Lou, a GPU-accelerated proof system with a dedicated JPEG-compression circuit for rapid verification. &lt;strong&gt;Results &amp;amp; Contributions&lt;/strong&gt;: Formally proven secure, our end-to-end implementation in a simulated OSN environment demonstrates that AIPA generates a highly compact multi-edit provenance lineage of merely 40.2 KB (only 6.5% of the original image size) and completes full verification in just 4.28 seconds, providing a robust, privacy-preserving, and highly efficient framework for deepfake mitigation in OSNs.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Generative AI has made high-fidelity deepfakes easy to produce, and online social networks (OSNs) spread them widely across users and platforms. Publicly verifying an image&amp;#x27;s provenance, i.e., where an image came from and what edits it has undergone, can help combat deepfakes. The Coalition for Content Provenance and Authenticity (C2PA) offers an industry standard, but depends on trusted software and hardware. Through digital signatures and zero-knowledge proofs, cryptographic image authentication eliminates the reliance on trusted editors. However, deploying such schemes in OSNs faces three problems: preserving signer privacy, maintaining provenance authenticity across edits, and ensuring efficient verification. To ensure signer anonymity in image provenance, we propose an unlinkable pseudonym certificate scheme (UPCS) based on anonymous credentials, which reduces online signing and verification to ordinary digital signature operations taking only 0.017 and 0.066 ms. Building on UPCS, zk-SNARKs, and hash chains, we propose an anonymous image provenance authentication (AIPA) scheme, ensuring the authenticity of provenance and editing history of an image as it propagates across mutually untrusted editors, while preserving signer privacy. To achieve efficient verification in OSNs, we introduce VIMz-Loua, a GPU-accelerated image proof system with a dedicated JPEG-compression circuit, whose proofs remain a constant 448 B and verify in 6-12 ms across image sizes. We formally prove the security of UPCS and AIPA, and implement an end-to-end workflow in a simulated OSN environment, where the full multi-edit provenance lineage is only 40.2 KB (6.5% of the published image), and is verified in 4.28 s.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>A RAM-Efficient Implementation of Falcon</title>
      <link>https://eprint.iacr.org/2026/1915</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1915</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1915"&gt;https://eprint.iacr.org/2026/1915&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：后量子密码学在资源受限的嵌入式设备（如智能卡）中的部署面临着内存和计算资源的严峻挑战。Falcon作为一种基于格的先进数字签名算法，其原始实现对RAM的需求较高，限制了其在微型设备上的应用。本文提出了一种针对Falcon算法的极低内存高效实现方案。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：本研究引入了多种底层优化技术。首先，设计了一种快速傅里叶变换（FFT）的新型变体；其次，采用模整数计算替代了部分传统的浮点运算，成功移除了超过一半的浮点操作；再次，在快速傅里叶采样过程中创新性地引入了输入加法的延迟处理机制；最后，提出了一种替代的签名重组流程。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现&lt;/strong&gt;：相较于前代Falcon-512实现，新方案的RAM占用量实现了大幅缩减，从约31 kB显著降低至约11 kB。此外，该实现在Arm Cortex-M4微控制器上展现出更卓越的性能，平均签名生成开销降至1345万次时钟周期。本方案使Falcon完全满足智能卡等小型嵌入式系统的严苛资源限制。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Core Contributions&lt;/strong&gt;: This paper presents a highly RAM-efficient implementation of the Falcon signature scheme, significantly reducing the memory footprint from approximately 31 kB in the previous Falcon-512 version to merely 11 kB. This drastic reduction makes the algorithm highly viable for severely resource-constrained environments like smart cards.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Key Optimizations&lt;/strong&gt;: The proposed approach introduces several novel techniques, including a new variant of the Fast Fourier Transform (FFT), the substitution of numerous floating-point operations with modular integer arithmetic (eliminating over half of the floating-point calculations), delayed input addition during Fast Fourier sampling, and an alternative signature reassembly process.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Key Results&lt;/strong&gt;: Consequently, the optimized implementation not only achieves a remarkably small memory footprint but also demonstrates enhanced computational performance on the Arm Cortex-M4 platform, with the average signature generation cost successfully reduced to 13.45 million cycles.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We present a RAM-efficient implementation of Falcon: RAM usage has shrunk to about 11 kB, down from about 31 kB in the previous implementation of Falcon-512. This code is furthermore faster on Arm Cortex M4, with average signature generation cost down to 13.45 million cycles. Optimization techniques include a novel variant of the FFT, replacement of some floating-point operations with modular integer computations, delayed addition of input within the Fast Fourier sampling process, and an alternate signature reassembly process. More than half of the floating-point operations have been removed. The resulting implementation is now small enough to allow use in small embedded systems such as smart cards.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>A Generalized Wiener-type Attack Against a Family RSA-like Cryptosystems</title>
      <link>https://eprint.iacr.org/2026/1908</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1908</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1908"&gt;https://eprint.iacr.org/2026/1908&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：在现代公钥密码学领域，RSA算法及其变体一直扮演着核心角色。设 $N=pq$ 为两个平衡素数之积。2023年，Cotan与Teșeleleanu提出了一族新颖的类RSA密码系统，其核心依赖于密钥方程 $ed - k(p^n - 1)(q^n - 1) = 1$（其中 $n \geq 1$）。特别地，当 $n=1$ 时，该系统即为经典RSA算法；当 $n=2$ 时，则对应Elkamchouchi等人提出的变体方案。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;研究方法&lt;/strong&gt;：针对该密码系统家族在 $n = 2^i$（$i &amp;gt; 2$ 且为整数）这一特定参数情形下的安全性，本文提出了一种广义的Wiener型攻击策略。该研究创造性地将经典的连分数算法与先进的基于格（lattice-based）的归约技术深度融合，构建了一种高效的密钥恢复攻击模型。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与创新点&lt;/strong&gt;：本攻击方法成功突破了 $n = 2^i$ 情形下的密钥方程限制。这不仅是对先前针对 $n=1, 2, 4$ 情形研究成果的自然延续与理论推广，更在密码分析技术上实现了重要创新。本文的研究成果精确刻画了该类密码系统的安全边界，揭示了在特定指数参数下系统面临的潜在风险，为未来相关密码体制的参数选取与安全设计提供了关键的理论依据与警示。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Let $N = pq$ be the product of two balanced primes. In 2023, Cotan and Teșeleleanu introduced a novel family of RSA-like cryptosystems governed by the key equation $ed - k(p^n - 1)(q^n - 1) = 1$ for $n \geq 1$. This framework elegantly generalizes the classical RSA scheme ($n=1$) as well as the specific variant proposed by Elkamchouchi et al. ($n=2$). In this paper, we propose a novel generalized Wiener-type cryptanalytic attack specifically targeting the case where $n = 2^i$ with $i &amp;gt; 2$ being an integer. By ingeniously combining classical continued fraction algorithms with advanced lattice-based reduction techniques, our proposed method successfully recovers the private key under these specific conditions. This research serves as a natural and significant extension of previous cryptanalyses conducted for $n = 1, 2, 4$, thereby providing a comprehensive security boundary evaluation of this cryptosystem family and offering critical theoretical insights for future parameter selection in cryptographic design.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Let $N = pq$ be the product of two balanced prime numbers $p$ and $q$. In 2023, Cotan and Te\c seleanu introduced a family of RSA-like cryptosystems based on the key equation $ed - k(p^n - 1)(q^n - 1) = 1$, where $n \geq 1$. Note that when $n = 1$, we obtain the classical RSA scheme, while $n = 2$ yields the variant proposed by Elkamchouchi, Elshenawy, and Shaban. In this paper, we present a novel attack that combines continued fractions with lattice-based methods for the case $n = 2^i$, where $i &amp;gt; 2$ is an integer. This represents a natural continuation of previous research, which successfully applied similar techniques for $n = 1, 2, 4$.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Trapdoor Functions with Secure Key Leasing and Copy Protection</title>
      <link>https://eprint.iacr.org/2026/1913</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1913</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1913"&gt;https://eprint.iacr.org/2026/1913&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;受量子不可克隆定理启发，安全密钥租赁和复制保护等具备不可克隆特性的量子密码学原语近年来备受关注。然而，作为公钥密码学基础原语的陷门函数（TDFs）在这些前沿领域尚未得到充分研究。本文率先开展了 TDFs 在安全密钥租赁和复制保护设定下的系统性研究。首先，本文引入了&lt;strong&gt;带安全密钥租赁的陷门函数（TDF-SKL）&lt;/strong&gt; 的定义，支持量子陷门的安全租赁与删除。我们在有无域采样器的情况下分别对 TDF-SKL 进行了形式化，并基于 LWE 假设构造了无域采样器方案，同时基于标准 PKE 方案与提示伪随机生成器构造了有域采样器方案。其次，定义了&lt;strong&gt;带复制保护的陷门函数（TDF-CP）&lt;/strong&gt;，其求逆功能由量子陷门进行复制保护，并基于不可区分混淆（iO）和 LWE 假设，遵循最新的模块化框架建立了具体构造。最后，本文深入探讨了上述原语的实际应用。针对现有带安全密钥租赁的公钥加密（PKE-SKL）和单解密者加密（SDE）方案中存在的关键漏洞——即量子解密密钥在解密恶意选择的密文后可能会被破坏的问题，我们利用 TDF-SKL 和 TDF-CP 分别构造了具有&lt;strong&gt;鲁棒量子解密密钥&lt;/strong&gt;的 PKE-SKL 和 SDE 方案，从根本上确保了量子密钥在解密任意密文后依然可重复使用。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Inspired by the quantum no-cloning theorem, unclonable cryptographic primitives like secure key leasing and copy protection have gained significant attention, yet fundamental trapdoor functions (TDFs) remain underexplored in these contexts. This work initiates the study of TDFs in these settings by formally defining TDFs with secure key leasing (TDF-SKL) and TDFs with copy protection (TDF-CP), providing concrete constructions based on the LWE assumption, standard PKE schemes, and indistinguishability obfuscation. Furthermore, we address a critical vulnerability in existing public-key encryption with secure key leasing (PKE-SKL) and single-decryptor encryption (SDE) schemes—where quantum decryption keys are destroyed after processing malicious ciphertexts. By leveraging our TDF-SKL and TDF-CP frameworks, we construct robust PKE-SKL and SDE schemes that guarantee the reusability of quantum decryption keys even after decrypting arbitrary ciphertexts.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Inspired by the no-cloning theorem in quantum theory, a variety of quantum cryptographic primitives with unclonable functionalities, such as secure key leasing and copy protection, have been proposed and attracted significant attention. However, trapdoor functions (TDFs), fundamental primitives in public-key cryptography, have not been extensively studied in these areas. In this work, we initiate a study of TDFs in both secure key leasing and copy protection settings. We first introduce the definition of TDFs with secure key leasing (TDF-SKL), which enables leasing and deleting of quantum trapdoors. We formalize TDF-SKL both with and without domain sampler, and give a construction of TDF-SKL without domain sampler based on the LWE assumption and a construction of TDF-SKL with domain sampler based on any standard PKE schemes combined with hinting pseudorandom generators [Koppula and Waters, CRYPTO 2019]. Next, we define TDFs with copy protection (TDF-CP), where the inversion functionality is copy protected by a quantum trapdoor. We establish a construction of TDF-CP assuming indistinguishability obfuscation and the LWE assumption, following a modular framework of copy protection proposed by Ananth and Behera [CRYPTO 2024]. We also present applications of TDF-SKL and TDF-CP. Existing constructions of public-key encryption with secure key leasing (PKE-SKL) and single-decryptor encryption (SDE) suffer from a critical vulnerability: quantum decryption keys may be destroyed after decrypting maliciously chosen ciphertexts. We construct PKE-SKL schemes and SDE schemes with robust quantum decryption keys that remain reusable after decrypting arbitrary ciphertexts from TDF-SKL and TDF-CP, respectively.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Secrecy in Squirrel and the Post-Compromise Security of a Ratchet</title>
      <link>https://eprint.iacr.org/2026/1912</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1912</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1912"&gt;https://eprint.iacr.org/2026/1912&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：棘轮（Ratchet）协议是Signal、WhatsApp和苹果iMessage PQ3等众多安全消息应用中部署的关键密码学协议，旨在提供强大的安全保证，如后妥协安全性（Post-Compromise Security, PCS）。尽管计算机辅助密码学技术能提升对安全协议的信心，但由于涉及的密码学论证极为复杂，迄今为止，仍无法在计算模型下通过机械化方法证明棘轮协议的PCS，现有的机械化PCS分析均局限于符号模型。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;研究方法&lt;/strong&gt;：本研究采用Squirrel工具来攻克这一难题，该工具非常适合分析此类有状态协议。然而，由于推理过程错综复杂，加之Squirrel对保密性（secrecy）的间接建模难以扩展至如此复杂的证明，研究面临巨大挑战。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;创新与发现&lt;/strong&gt;：为解决上述问题，我们在Squirrel中开发了一种全新的逻辑框架，首次允许将“保密性”作为一等概念（first-class notion）进行直接推理。我们利用该框架成功验证了非对称棘轮协议的后妥协安全性。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要结论&lt;/strong&gt;：本研究实现了迄今为止首个针对棘轮协议（甚至可能是所有协议中首个）的PCS机械化计算证明，为安全消息协议的形式化验证树立了新的里程碑。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background &amp;amp; Challenge&lt;/strong&gt;: Ratchet protocols are crucial for secure messaging applications aiming for Post-Compromise Security (PCS), yet mechanized computational proofs of PCS for ratchets have remained elusive due to highly complex cryptographic arguments, limiting existing analyses strictly to the symbolic model.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Method &amp;amp; Innovation&lt;/strong&gt;: To tackle this challenge using the Squirrel tool, which is exceptionally well-suited for stateful protocols, we develop a novel logical framework that treats secrecy as a first-class notion. This innovation successfully overcomes the scalability issues of Squirrel&amp;#x27;s indirect secrecy modeling and the intricate reasoning traditionally required for such complex proofs.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Results&lt;/strong&gt;: By applying this framework, we successfully verify the PCS of an asymmetric ratchet, yielding the first mechanized computational proof of PCS for a ratchet protocol to date. This breakthrough potentially extends to any cryptographic protocol, marking a significant milestone in the formal verification of secure messaging systems.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Ratchets are critical cryptographic protocols deployed in many secure messaging applications such as Signal Messenger, WhatsApp, and Apple&amp;#x27;s iMessage PQ3, which aim for strong guarantees such as Post-Compromise Security (PCS). Computer-aided cryptography can be used to increase confidence in security protocols but, until now, has been unable to prove PCS in the computational model for a ratchet due to the complexity of the cryptographic arguments involved. Existing mechanized PCS analyses have been limited to the symbolic model.&lt;/p&gt;&lt;p&gt;We tackle this problem with Squirrel, which is well-suited to study such stateful protocols. The task is still a challenge, due to the intricate reasoning required, and because Sqirrel&amp;#x27;s indirect modeling of secrecy has difficulties in scaling to such a complex proof. To address these issues, we develop a novel logical framework in Squirrel that allows to reason on secrecy as a first-class notion, and we validate our approach by verifying the PCS of an asymmetric ratchet. This provides the first mechanized computational proof of PCS to date for a ratchet, and possibly for any protocol.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Why Johnny Should Not Delegate Email Encryption to Gateways</title>
      <link>https://eprint.iacr.org/2026/1911</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1911</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1911"&gt;https://eprint.iacr.org/2026/1911&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：基于 S/MIME 和 PGP 的电子邮件加密在企业环境中广泛部署，通常依赖集中式服务器端加密网关或本地网关来代表终端用户执行解密与签名，或为不支持加密的客户端提供加密支持。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;研究方法&lt;/strong&gt;：本文系统性地分析了四款主流加密网关产品（SEPPmail、CipherMail、Cisco Email Security Appliance 和 Proton Mail Bridge）的安全性，深入探讨了加密代理架构引入的隐患。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现&lt;/strong&gt;：研究共识别出 &lt;strong&gt;29 种攻击向量&lt;/strong&gt;，允许攻击者完全解密邮件内容并混淆用户对邮件真实性的认知。研究者利用 S/MIME 的遗留密码学原语及 PGP 的向后兼容特性，将 EFAIL 等经典攻击适配至网关场景，并发现了由邮件基础设施错误信号引发的新型攻击路径。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;核心结论&lt;/strong&gt;：将密码学操作委托给网关会剥夺电子邮件客户端依赖的关键安全信号。这不仅使 EFAIL 等曾被视为已解决的攻击死灰复燃，还引入了安全状态通信中的可利用缺陷，并将敏感的解密明文暴露给未设计处理此类数据的中间基础设施。最终结论指出，&lt;strong&gt;将加密操作委托给网关从根本上破坏了 PGP 和 S/MIME 旨在提供的端到端安全模型&lt;/strong&gt;。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;: Email encryption via S/MIME and PGP is widely deployed in enterprises, often relying on centralized or local gateways to handle cryptographic operations on behalf of end-users.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Methods &amp;amp; Findings&lt;/strong&gt;: We systematically analyze the security of four such products: SEPPmail, CipherMail, Cisco Email Security Appliance, and Proton Mail Bridge. We identify &lt;strong&gt;29 distinct attacks&lt;/strong&gt; that allow adversaries to fully decrypt messages and spoof email authenticity. By exploiting legacy cryptographic primitives in S/MIME and backward compatibility features in PGP, we adapt known attacks like EFAIL to the gateway setting and expose novel vectors leveraging error signals from email infrastructure.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;: Our findings demonstrate that delegating cryptographic operations to gateways strips crucial security signals relied upon by email clients. This re-enables previously mitigated attacks like EFAIL, introduces exploitable flaws in security status communication, and exposes sensitive decrypted plaintext to intermediate infrastructure. Ultimately, we conclude that &lt;strong&gt;gateway-based delegation fundamentally undermines the end-to-end security model&lt;/strong&gt; intended by PGP and S/MIME.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Email encryption based on S/MIME and, to a lesser extent, PGP is widely deployed in enterprise environments, often through centralised server-side encryption gateways that decrypt and sign messages on behalf of end users. Gateways can also be run locally to implement encryption for email clients that do not natively support it.&lt;/p&gt;&lt;p&gt;We systematically analyse the security of four such products: SEPPmail, CipherMail, Cisco Email Security Appliance, and the Proton Mail Bridge. We identify 29 attacks which allow an adversary to fully decrypt messages and confuse users on the authenticity of received emails. To this end, we exploit the legacy cryptographic primitives in S/MIME and the backwards compatibility features for PGP, adapt well-known attacks such as EFAIL (Poddebniak et al., USENIX Security 2018) to this setting, and expose novel attack vectors such as the error signals produced by email infrastructure.&lt;/p&gt;&lt;p&gt;Our findings show that moving cryptographic operations to gateways strips important signals that email clients rely on. This re-enables attacks like EFAIL, which were largely considered resolved, and introduces exploitable features in how the security status of emails is communicated. Such systems also expose sensitive decrypted plaintext to intermediate email infrastructure, which was not designed to handle it. We conclude that delegating cryptographic operations to a gateway undermines the end-to-end security model that PGP and S/MIME were designed to provide.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>NTPIR: Efficient Silent-Preprocessing PIR using NTR</title>
      <link>https://eprint.iacr.org/2026/1910</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1910</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1910"&gt;https://eprint.iacr.org/2026/1910&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;隐私信息检索（PIR）允许客户端在不泄露查询索引的情况下检索数据库。在静默预处理模型中，现有协议多采用基于LWE的首层检索与基于RLWE的环打包及二层同态检索的两层架构，其中环打包是主要性能瓶颈。尽管NTRU支持所需的同态操作且密文仅由单个环元素表示，具备替代RLWE实现更紧凑中间表示的潜力，但其缺乏RLWE的公共随机性组件，难以直接应用于现有PIR方案的离线/在线分离。&lt;/p&gt;&lt;p&gt;为此，本文提出 &lt;strong&gt;NTPIR&lt;/strong&gt;，通过三项核心技术解决该挑战：&lt;br /&gt;1. &lt;strong&gt;先打包后切换（Pack-then-switch）&lt;/strong&gt;：在RLWE域完成环打包后，通过单次密钥切换转换为NTRU，在保留离线预处理结构的同时生成紧凑的单元素中间结果。&lt;br /&gt;2. &lt;strong&gt;分裂点选择（Split-point picking）&lt;/strong&gt;：将二层列选择与响应打包相融合，将自同构复杂度从线性降至平方根级别。&lt;br /&gt;3. &lt;strong&gt;优化算术（Optimized arithmetic）&lt;/strong&gt;：采用基于FFT的多项式乘法与近似小工具分解，提升同态运算效率，且正确性误差严格控制在 $2^{-40}$ 以内。&lt;/p&gt;&lt;p&gt;实验表明，在1至8GB的数据库上，NTPIR的服务器端在线速度较 InsPIRe$^{(2)}$ 提升达 $1.81\times$；在8GB规模下，预处理速度提升 $7$--$41\times$。在最高吞吐量配置下，NTPIR在8GB数据库上达到 8,609MB/s 的处理速度，分别比 InsPIRe$^{(2)}$、SimpleYPIR 和 HintlessPIR 快 $1.38\times$、$1.8\times$ 和 $2.0\times$。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;NTPIR&lt;/strong&gt; addresses the ring-packing bottleneck in silent-preprocessing Private Information Retrieval (PIR) by leveraging NTRU&amp;#x27;s compact single-element ciphertexts. To overcome NTRU&amp;#x27;s lack of public randomness for offline/online separation, we introduce three techniques: (1) &lt;strong&gt;Pack-then-switch&lt;/strong&gt;, performing ring packing in RLWE and converting to NTRU via a single key switch; (2) &lt;strong&gt;Split-point picking&lt;/strong&gt;, integrating second-layer column selection with response packing to reduce automorphism complexity from linear to square-root; and (3) &lt;strong&gt;Optimized arithmetic&lt;/strong&gt;, utilizing FFT-based polynomial multiplication and approximate gadget decomposition to ensure high efficiency with an error bound of $2^{-40}$. Evaluations on 1-8GB databases show that NTPIR achieves up to a $1.81\times$ online speedup and $7$--$41\times$ faster preprocessing over InsPIRe$^{(2)}$. At peak throughput, it sustains 8,609MB/s, outperforming InsPIRe$^{(2)}$, SimpleYPIR, and HintlessPIR by up to $2.0\times$.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Private Information Retrieval (PIR) enables a client to query a database without revealing the requested index. In the silent preprocessing model, existing protocols typically adopt a two-layer pipeline: a first-layer retrieval based on LWE, followed by an RLWE ring-packing stage and a second-layer homomorphic column retrieval, with ring packing being the primary performance bottleneck. We observe that NTRU supports the homomorphic operations required by this pipeline while representing each ciphertext with a single ring element, suggesting its potential to replace RLWE for a more compact intermediate representation. However, NTRU lacks RLWE&amp;#x27;s public randomness component, which is required in the offline/online separation of most existing PIR schemes.&lt;/p&gt;&lt;p&gt;We introduce NTPIR to address this challenge through three techniques: (1) Pack-then-switch: we perform ring packing in the RLWE domain and transform the result to NTRU via a single key switch, preserving the offline preprocessing structure while yielding compact, single-element packed intermediates. (2) Split-point picking: this method integrates second-layer column selection with response packing, reducing automorphism complexity from linear to square-root complexity in the number of packed second-layer inputs. (3) Optimized arithmetic: we employ FFT-based polynomial multiplication and approximate gadget decomposition to improve the computational efficiency of the underlying homomorphic operations, with concrete correctness error at most $2^{-40}$.&lt;/p&gt;&lt;p&gt;On databases ranging from 1 to 8GB, NTPIR achieves up to a $1.81\times$ server-side online speedup over InsPIRe$^{(2)}$ (S&amp;amp;amp;P&amp;#x27;26). At 8\,GB, preprocessing step is $7$--$41\times$ faster than InsPIRe$^{(2)}$. In addition, at the highest-throughput configuration, NTPIR sustains 8,609MB/s on an 8GB database, corresponding to a $1.38\times$ speedup over InsPIRe$^{(2)}$, $1.8\times$ over SimpleYPIR, and $2.0\times$ over HintlessPIR.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Tightly and Adaptively Secure Two-Round Threshold Signatures from DDH</title>
      <link>https://eprint.iacr.org/2026/1909</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1909</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1909"&gt;https://eprint.iacr.org/2026/1909&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;门限签名允许 $n$ 个参与方在单一公钥下联合生成签名，其中至少 $t+1$ 个参与方可以产生有效签名，而最多 $t$ 个参与方的联盟则无法做到。作为分布式信任的基础原语，门限签名被广泛应用于证书颁发机构、区块链和多方钱包等系统中。现代实际应用对门限签名提出了严格的安全性与效率要求，包括在现实对抗模型下的强安全保证（如抵抗自适应腐败、实现紧安全归约）以及极低的交互复杂度（即最少的通信轮数）。&lt;/p&gt;&lt;p&gt;尽管近期研究已在无配对群中实现了具备紧自适应安全性的三轮交互门限签名方案，但在标准的非交互困难假设下，能否同时实现紧安全性、自适应安全性以及两轮签名交互，仍是一个悬而未决的核心问题。&lt;/p&gt;&lt;p&gt;本文圆满解决了这一难题，提出了 &lt;strong&gt;TZAR&lt;/strong&gt; 方案。这是首个在无配对循环群中，基于标准决策性 Diffie-Hellman (DDH) 假设实现紧且自适应安全的两轮门限签名方案。我们的构造不仅能够抵御最多 $t &amp;lt; n$ 个参与方被自适应腐败的攻击，还实现了仅有常数因子损失的安全紧归约。综上所述，TZAR 方案提供了强大的可证明安全保证，并将签名交互轮数降至最低的两轮，为延迟敏感的分布式环境带来了显著的性能优势。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Threshold signatures are fundamental primitives for distributed trust, widely deployed in modern systems like blockchains and multiparty wallets. While recent progress has yielded three-round schemes with tight adaptive security in pairing-free groups, achieving tight security, adaptive security, and two-round signing simultaneously under a standard, non-interactive hardness assumption has remained a central open question. In this work, we resolve this challenge by introducing &lt;strong&gt;TZAR&lt;/strong&gt;, the first two-round threshold signature scheme that is tightly and adaptively secure under the standard decisional Diffie-Hellman (DDH) assumption in pairing-free cyclic groups. Our construction achieves full adaptive security against up to $t &amp;lt; n$ corruptions and admits a tight security reduction with only a constant-factor loss. By requiring only two signing rounds, TZAR not only provides strong provable security guarantees but also minimizes interaction complexity, offering a crucial advantage for latency-sensitive distributed environments. This breakthrough significantly advances the practical deployment of highly secure and efficient distributed cryptographic protocols.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Threshold signatures enable a set of $n$ parties to jointly generate signatures under a single public key such that any subset of at least $t+1$ parties can produce a valid signature, whereas any coalition of at most $t$ parties cannot. They constitute a fundamental primitive for distributed trust and are widely deployed in systems such as certification authorities, blockchains, and multiparty wallets. Modern applications require strong security guarantees under realistic adversarial models, including resistance to adaptive corruptions, tight security reductions, and low interaction complexity—most notably, a minimal number of communication rounds. Recent progress has produced threshold signature schemes in pairing-free groups that achieve tight and adaptive security with three rounds of interaction. This leaves open the central question of whether one can simultaneously achieve tight security, adaptive security, and two-round signing under a standard, non-interactive hardness assumption.&lt;/p&gt;&lt;p&gt;In this work, we resolve this question by presenting TZAR, the first two-round threshold signature scheme that is tightly and adaptively secure under the standard decisional Diffie-Hellman (DDH) assumption in pairing-free cyclic groups. Our construction achieves full adaptive security against up to $t &amp;lt; n$ corruptions and admits a tight security reduction with only constant-factor loss. Consequently, TZAR provides strong provable security guarantees and minimizes interaction by requiring only two signing rounds, an important advantage for latency-sensitive distributed environments.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Higher-order differential attacks on the full DuX</title>
      <link>https://eprint.iacr.org/2026/1907</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1907</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1907"&gt;https://eprint.iacr.org/2026/1907&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景&lt;/strong&gt;：DuX是一族定义在 $\mathbb{F}_q^{16}$ 上的替换-置换分组密码（$q\in\{2^{8},2^{16},65537\}$），包含12轮迭代。设计者评估认为，在加密方向上，积分与高阶差分区分器最多只能达到6轮。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法&lt;/strong&gt;：本文通过解密方向上的指数集来界定DuX的逐字代数度。研究发现，解密S盒的坐标度为(2,3,4,2)，与加密S盒的(5,3,2,8)不同。逆扩散矩阵的每一行仅支持模4字索引的两个剩余类。通过选择等于单一剩余类的活跃集，可使每层各类内的度界向量保持恒定。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;发现与创新&lt;/strong&gt;：我们证明了四类度界服从基数为 $2+\sqrt{3}$ 的精确递推关系（而非4）。基于此，我们构造了针对 DuX($2^{16}$) 和 DuX($65537$) 11轮以及 DuX($2^{8}$) 7轮的高阶差分区分器。向明文方向延伸一轮后，构建三个连续方程组，并利用双变量插值等技术进行求解。当方程组达到结构允许的最大秩时，即可恢复完整12轮 DuX($2^{16}$) 和 DuX($65537$) 的全部16个主密钥字。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;结果&lt;/strong&gt;：该攻击的数据与时间复杂度分别为 $2^{67.32}$ 和 $2^{67.58}$，且内存消耗为常数；对 DuX($2^{8}$) 可覆盖8轮，复杂度为 $2^{91.32}$。此外，由于两种扩散层仅相差4个字的旋转，本分析对 $2^{11}$ 种依赖密钥的扩散层选择均完全适用。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;DuX is a family of 12-round substitution-permutation block ciphers over $\mathbb{F}_q^{16}$, whose designers estimated that higher-order differential distinguishers in the encryption direction reach at most six rounds. By bounding the word-wise algebraic degree via exponent sets in the decryption direction, we reveal that an active set equal to one residue class modulo four maintains constant degree bounds per layer, which follow an exact recursion with base $2+\sqrt{3}$. This yields 11-round distinguishers for DuX($2^{16}$) and DuX($65537$), and extending one round towards the plaintext generates three successive equation systems that recover all 16 master-key words of the full 12-round ciphers with data and time complexities of $2^{67.32}$ and $2^{67.58}$. Furthermore, the analysis seamlessly applies to all $2^{11}$ key-dependent diffusion layer choices and covers eight rounds of DuX($2^{8}$) with a complexity of $2^{91.32}$.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;DuX is a family of substitution-permutation block ciphers over $\mathbb{F}_q^{16}$ with $q\in\{2^{8},2^{16},65537\}$ and twelve rounds. For the two large-word instances its designers estimate that integral and higher-order differential distinguishers in the encryption direction reach at most six rounds, and fix the number of rounds accordingly. We bound the word-wise algebraic degree of DuX by exponent sets in the decryption direction, where the decryption S-box has coordinate degrees $(2,3,4,2)$ against the $(5,3,2,8)$ of the encryption S-box. Each row of the inverse diffusion matrix is supported on two residue classes of word indices modulo four. An active set equal to one class therefore keeps the vector of degree bounds constant within each class at every layer, and we prove that the four class-wise bounds then obey an exact recursion with base $2+\sqrt{3}$ instead of four. This yields higher-order differential distinguishers for eleven rounds of DuX($2^{16}$) and DuX($65537$) with $q^{4}$ chosen ciphertexts, and for seven rounds of DuX($2^{8}$) with $2^{88}$. Extending one round towards the plaintext gives three successive systems of equations. Every unknown there has a coefficient computed from the returned plaintext words, and the key words recovered at one stage are substituted into the next; for DuX($65537$) the last two systems are replaced by bivariate interpolation. Once each system attains the maximal rank that its structure permits, a condition that can be checked during the attack, solving the systems recovers all sixteen master-key words of the full twelve-round DuX($2^{16}$) and DuX($65537$). The data and time complexity is $2^{67.32}$ and $2^{67.58}$ with constant memory, and eight rounds of DuX($2^{8}$) are covered with $2^{91.32}$. The two diffusion layers differ by a rotation of four words, so the analysis is the same for each of the $2^{11}$ key-dependent choices of diffusion layers.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Revisiting Simple Power Analysis of Polynomial Multiplication in the HQC Implementation</title>
      <link>https://eprint.iacr.org/2026/1906</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1906</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1906"&gt;https://eprint.iacr.org/2026/1906&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景与动机&lt;/strong&gt;：汉明准循环（HQC）方案是近期被美国国家标准与技术研究院（NIST）选定的后量子密钥封装机制标准化算法，其具体实现的侧信道安全性至关重要。先前的研究已证明可通过简单功耗分析（SPA）攻击基于查找表的多项式乘法，为此，最新的 HQC 参考实现将乘法例程替换为按位学校乘法（bitwise schoolbook multiplication），试图抵御此类攻击。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现&lt;/strong&gt;：本文重新审视了最新 HQC 参考实现的侧信道抗性。研究发现，尽管进行了上述修改，更新后的 &lt;code&gt;schoolbook_mul&lt;/code&gt; 函数在解密过程中的功耗消耗依然呈现出清晰且视觉上可区分的差异，且这些差异直接依赖于秘密数据。利用这些功耗模式，攻击者能够成功恢复秘密多项式的各个比特。这有力地证明了简单功耗分析（SPA）对更新后的 HQC 设计依然有效。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;创新与贡献&lt;/strong&gt;：为了解决这一安全漏洞，本文深入分析了潜在的防御对策，并创新性地提出了一种&lt;strong&gt;零成本的缓解方案&lt;/strong&gt;。该方案通过交换操作数的角色，使得掩码计算过程仅依赖于公开数据。这一改进不仅彻底消除了由秘密数据依赖的控制流引起的直接信息泄漏，而且完美保持了原有的计算性能，为 HQC 的安全部署提供了重要保障。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;The Hamming Quasi-Cyclic (HQC) scheme, recently selected by NIST for post-quantum standardization, requires rigorous security evaluations of its implementations against side-channel attacks. Although the latest HQC reference implementation replaced lookup-table-based multiplication with bitwise schoolbook multiplication to mitigate prior Simple Power Analysis (SPA) vulnerabilities, our analysis reveals that the updated &lt;code&gt;schoolbook_mul&lt;/code&gt; routine still exhibits visually distinguishable, secret-dependent power consumption variations during decryption. Exploiting these leakage patterns allows attackers to successfully recover individual bits of the secret polynomial, demonstrating that SPA remains highly effective against the updated design. To address this critical vulnerability, we propose a novel zero-cost mitigation strategy that swaps operand roles to ensure mask computation depends solely on public data. This approach effectively eliminates direct information leakage caused by secret-dependent control flow while strictly preserving the original computational performance, providing a practical countermeasure for secure HQC deployment.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;The Hamming Quasi-Cyclic (HQC) scheme is a post-quantum key encapsulation mechanism recently selected for standardization by NIST, making the security of its implementations a critical concern. In this work, we revisit the side-channel resistance of the latest HQC reference implementation, with a focus on its polynomial multiplication routine used in decryption. While prior work demonstrated a simple power analysis (SPA) attack against a lookup-table-based multiplication, the updated implementation replaces this with a bitwise schoolbook multiplication.&lt;/p&gt;&lt;p&gt;Despite these modifications, we show that the updated function schoolbook_mul still shows clear, visually distinguishable variations in power consumption that depend on secret data. Using these patterns, an attacker can recover individual bits of the secret polynomial, demonstrating that SPA remains effective against the updated design. To address this vulnerability, we analyze potential countermeasures and propose a zero-cost mitigation based on swapping operand roles so that the mask computation depends only on public data. This eliminates direct leakage of secret-dependent control flow while preserving performance.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>A Better Bivariate Resultant Attack on Round-Reduced Poseidon</title>
      <link>https://eprint.iacr.org/2026/1905</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1905</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1905"&gt;https://eprint.iacr.org/2026/1905&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;h4&gt;研究背景&lt;/h4&gt;&lt;p&gt;Poseidon 是一种极具代表性的面向算术化（Arithmetization-oriented, AO）哈希函数，因其卓越的评估性能而在零知识证明协议（如 Plonky3 和以太坊协议）中得到广泛应用。AO 哈希函数的安全性通常通过 CICO-k 问题来评估，即同时控制置换函数输入和输出的 k 个坐标。本文聚焦于与以太坊基金会赏金计划密切相关的 &lt;strong&gt;CICO-2 问题&lt;/strong&gt;。&lt;/p&gt;&lt;h4&gt;方法与挑战&lt;/h4&gt;&lt;p&gt;CICO-2 问题可被建模为一个双变量多项式系统 $P(X, Y) = Q(X, Y) = 0$，其总次数为 $\delta = d^{R_F + R_P}$。求解此类系统的最佳已知方法是双变量结式（bivariate resultant）算法。对于一般系统，最优算法的渐近位复杂度与 $\delta^{2+\epsilon}$ 呈线性关系。然而，Poseidon 衍生的多项式系统具有高度的结构化特征，导致其结式次数 $D_I = d^{2R_F + R_P}$ 远低于同等总次数随机系统的预期。先前的研究已利用这一特性，通过评估-插值方法在准线性时间 $d^{3R_F + 2R_P}$ 内计算结式。&lt;/p&gt;&lt;h4&gt;创新点与主要发现&lt;/h4&gt;&lt;p&gt;本文针对结式次数远低于 $\delta^2$ 的特殊结构，&lt;strong&gt;提出了一种改进的双变量结式攻击算法&lt;/strong&gt;。通过对具有此类特性的系统进行深入分析，我们证明了在合理的启发式假设下，Poseidon 的 CICO-2 问题可以在关于 $D_I \delta^{1-1/\omega}$ 的准线性时间内求解，其中 $2 \le \omega &amp;lt; 2.38$ 为矩阵乘法指数。我们在轮数缩减的 Poseidon 置换函数上实现了该攻击，实验结果不仅验证了理论分析，还展示了相较于现有最优方法显著的&lt;strong&gt;实际加速效果&lt;/strong&gt;。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;The security of the Poseidon hash function, widely utilized in zero-knowledge proofs, is commonly evaluated through the CICO-2 problem, which can be modeled as a bivariate polynomial system with total degree $\delta$. While generic bivariate resultant algorithms require time quasi-linear in $\delta^2$, the highly structured nature of Poseidon yields a resultant degree $D_I$ significantly lower than the generic expectation. In this work, we propose an improved bivariate resultant attack specifically tailored to exploit this exceptionally low-degree resultant property. Under standard heuristics, we demonstrate that the CICO-2 problem on Poseidon can be solved in time quasi-linear in $D_I \delta^{1-1/\omega}$, where $2 \le \omega &amp;lt; 2.38$ is the matrix multiplication exponent. We validate our theoretical findings by implementing the attack on round-reduced Poseidon instances, demonstrating a substantial practical speedup and breaking new ground compared to previous evaluation-interpolation approaches.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Poseidon is one of the most popular arithmetization-oriented (AO) hash function, due to its good performances both in evaluation and in Zero-knowledge proof protocols. It is for instance used in the Plonky3 library, and has been considered for use in the Ethereum protocol.&lt;/p&gt;&lt;p&gt;The security of Arithmetization-oriented hash functions is commonly evaluated through the CICO-k problem, which consists in controlling simultaneously k coordinates in the input and output of the permutation. This problem is in particular relevant to finding preimages in sponge or compression mode and solving zero-test problems. Depending on the size of the underlying field, different values of k may be relevant. In this paper, we focus on the case of k=2, that was the subject of the recent bounty program by the Ethereum foundation.&lt;/p&gt;&lt;p&gt;In this setting, one can model the CICO-2 problem as a bivariate system P(X, Y) = Q(X, Y) = 0 where the polynomials have total degree delta = d^(RF +RP). The best known methods for solving bivariate systems are algorithms for computing bivariate resultants. Over a generic system with coefficients over a finite field, the best algorithms achieve an asymptotic bit complexity that is linear in delta^(2+eps) log(q)^(1+eps), which is close to optimal, given that the input and output of the algorithm have bit size delta^2 log (q).&lt;/p&gt;&lt;p&gt;However, the polynomial systems that stem from Poseidon are more structured, leading to a resultant that has degree DI = d^(2RF + RP), which is much less than what one would expect from a random bivariate system of degree d^(RF + RP). This fact has already been exploited in a previous work that used an evaluation-interpolation approach to compute the bivariate resultant in time that is quasi-linear in d^(3 RF + 2 RP).&lt;/p&gt;&lt;p&gt;In this work, we exploit this fact by adapting another bivariate resultant algorithm to the special setting where the degree of the resultant of the equations is much lower than delta^2. By doing a careful analysis of the algorithm for systems with such property, we show that under some heuristics, the CICO-2 problem on Poseidon can be solved in time that is quasi-linear in DI delta^(1-1/w), where 2 &amp;lt;= w &amp;lt; 2.38 is the exponent of matrix multiplication. We validate our approach by implementing our attack on reduced versions of the Poseidon permutation, and show a practical speedup compared to the previous approaches.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA Implementation</title>
      <link>https://eprint.iacr.org/2026/1904</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1904</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1904"&gt;https://eprint.iacr.org/2026/1904&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：随着ML-DSA标准化的推进，其实用安全性成为密码学界关注的焦点。传统观点普遍认为，尽管分析攻击仅需少量轨迹，但非分析侧信道攻击通常需要庞大的轨迹复杂度。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;核心创新&lt;/strong&gt;：本文提出了一种全新的“水平融合攻击”（Horizontal Fusion Attacks），成功打破了这一假设，证明了对ML-DSA（甚至掩码实现）进行非分析、少轨迹的密钥恢复具有高度实用性。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;漏洞揭示&lt;/strong&gt;：研究从侧信道视角暴露了模块格（module lattice）的结构性漏洞。在矩阵向量乘法中，临时秘密向量 $\hat{\mathbf{y}}$ 的行级重用特性导致单次签名生成会暴露 $k$ 个相同秘密依赖中间值的泄漏实例，且每个实例具有不同且已知的系数。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;关键技术&lt;/strong&gt;：为克服噪声和编译器优化带来的实际利用难题，本文提出了&lt;strong&gt;基于方差的加权融合策略&lt;/strong&gt;，根据领先候选与次优候选的分离度进行动态加权，并利用签名关系提取私钥的有符号系数。同时，引入了&lt;strong&gt;基于INTT的快速代数筛&lt;/strong&gt;，大幅提升了密钥恢复的成功率。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;实验结果&lt;/strong&gt;：实验表明，仅需 &lt;strong&gt;4条轨迹&lt;/strong&gt; 即可对最高安全参数集 ML-DSA-87 实现完整的非分析相关分析密钥恢复；针对最先进的一阶掩码实现，也仅需不超过 &lt;strong&gt;90条轨迹&lt;/strong&gt; 即可提取私钥。该成果刷新了非分析攻击的轨迹复杂度纪录，其表现足以媲美传统的分析攻击。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;While profiling side-channel attacks on ML-DSA are well-studied, non-profiling attacks are traditionally assumed to demand large trace complexity. We challenge this assumption by introducing &lt;strong&gt;horizontal fusion attacks&lt;/strong&gt;, demonstrating that non-profiling, few-trace key recovery is highly practical even against masked implementations. Specifically, we expose a structural vulnerability in the module lattice where the row-wise reuse of the ephemeral secret vector exposes multiple leakage instances of the same intermediate value during a single signature generation. To overcome practical hurdles like noise, we propose a &lt;strong&gt;variance-based weighted fusion strategy&lt;/strong&gt; and a fast &lt;strong&gt;INTT-based algebraic sieve&lt;/strong&gt; to efficiently extract the secret key. Our non-profiling correlation analysis achieves full key recovery on the highest security parameter set (ML-DSA-87) using merely 4 traces, and extracts the secret key from state-of-the-art first-order masked implementations with no more than 90 traces. These results establish new records in trace complexity for both unprotected and masked ML-DSA, performing comparably to profiling-based attacks.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;The standardization of ML-DSA has shifted the cryptographic community&amp;#x27;s focus toward its practical security. While profiled attacks against its implementations are well studied with a few traces, non-profiling attacks are widely assumed to require large trace complexity. We challenge this by introducing horizontal fusion attacks, demonstrating that non-profiling, few-trace key recovery is highly practical against ML-DSA, even against masked implementations.&lt;/p&gt;&lt;p&gt;We expose a structural vulnerability in the module lattice from a side-channel perspective. In particular, in ML-DSA&amp;#x27;s matrix-vector multiplication ($\hat{\mathbf{A}} \circ \hat{\mathbf{y}}$), the row-wise reuse of the ephemeral secret vector $\hat{\mathbf{y}}$ indicates that one single signature generation exposes $k$ (the row-wise size of $\hat{\mathbf{A}}$) leakage instances of the same secret-dependent intermediate value, each with a distinct and known coefficient of $\hat{\mathbf{A}}$. However, exploiting this in practice is highly non-trivial due to noise and/or compiler optimizations. To overcome this, we propose a variance-based weighted fusion strategy. This approach weights each operation by how far its leading candidate is separated from the runner-up candidates, and the signing relation ($\mathbf{y} = \mathbf{z} - c \cdot \mathbf{s}_1$) lets us extract the signed coefficients of the secret key. Moreover, we introduce a fast, INTT-based algebraic sieve that further increases the success rate of key recovery.&lt;/p&gt;&lt;p&gt;Putting together, we achieve full key recovery using merely 4 traces against ML-DSA-87 (the highest security parameter set) with non-profiling correlation analysis. On the state-of-the-art first-order masked ML-DSA implementation, our attack extracts the secret key using no more than 90 traces. To the best of our knowledge, these non-profiling results establish a new record in trace complexity for both unprotected and first-order masked ML-DSA implementations, even comparable to these profiling-based attacks.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Chosen-Block BAA Codes: Fast, Near the Gilbert–Varshamov Bound, and Field-Agnostic</title>
      <link>https://eprint.iacr.org/2026/1903</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1903</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1903"&gt;https://eprint.iacr.org/2026/1903&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景&lt;/strong&gt;：块累加累加（BAA）码在伪随机相关生成器和基于编码的零知识证明中提供了极快的编码速度。&lt;br /&gt;&lt;strong&gt;方法&lt;/strong&gt;：本文提出了一种“选定块”（chosen-block）构造方法，将BAA码中独立采样的局部映射替换为单一固定短码的重复副本。该构造在保留原有的两次排列-前缀和轮次的同时，允许针对最小距离和高效实现来灵活选择组成码。&lt;br /&gt;&lt;strong&gt;主要发现与创新点&lt;/strong&gt;：&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;二元域性能&lt;/strong&gt;：通过精确的重量分布传播实现了有限长度的距离保证。在码率为1/2时，数值渐近距离估计达到了Gilbert-Varshamov (GV) 界限的99.99%。实际应用中，单线程CPU编码百万级消息符号仅需23-24毫秒，24-32线程下低于6毫秒。&lt;/li&gt;&lt;li&gt;&lt;strong&gt;大域扩展与理论保证&lt;/strong&gt;：在更大规模的有限域（$q \ge 2^{127}$，含128位素数域）上，引入随机非零坐标缩放并分析抵消效应。利用Reed-Solomon组成码在码率1/2和1/4时分别认证了0.30和0.60的相对距离。在消息维度 $k=2^{20}$ 时，距离界限失效概率低于 $2^{-137}$。&lt;/li&gt;&lt;li&gt;&lt;strong&gt;渐近界限探索&lt;/strong&gt;：码率1/4的渐近距离估计达到了大域GV界限的81%。为探究该估计与GV界限间的差距，研究识别出了无论坐标如何缩放都会强制产生低重量码字的特定排列模式。&lt;/li&gt;&lt;/ul&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Block-Accumulate-Accumulate (BAA) codes offer rapid encoding for pseudorandom correlation generators and code-based zero-knowledge proofs. In this paper, we introduce a novel chosen-block construction that replaces independently sampled local maps with repeated copies of a single fixed short code. This approach preserves the original permutation-prefix-sum rounds while enabling the flexible selection of constituent codes for optimal distance and implementation efficiency. Over the binary field $\mathbb{F}_2$, our method achieves asymptotic distance estimates reaching 99.99% of the Gilbert-Varshamov (GV) bound at rate 1/2, with practical instantiations encoding a million symbols in under 24 ms on a single CPU thread. For larger fields ($q \ge 2^{127}$), incorporating random nonzero coordinate scalings allows Reed-Solomon constituents to certify relative distances of 0.30 and 0.60 at rates 1/2 and 1/4, respectively, with failure probabilities strictly below $2^{-137}$. Furthermore, we identify specific permutation patterns that force low-weight codewords regardless of coordinate scalings, providing valuable insights into the gap between our large-field asymptotic estimates and the theoretical GV bound.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Block-Accumulate-Accumulate (BAA) codes provide fast encoding for&lt;br /&gt;pseudorandom correlation generators and code-based zero-knowledge. We replace their independently sampled local maps with repeated copies of one fixed short code.  This chosen-block construction retains the two&lt;br /&gt;permutation-prefix-sum rounds while allowing the constituent code to be&lt;br /&gt;selected for distance and efficient implementation.&lt;/p&gt;&lt;p&gt;Over $\mathbb{F}_2$, exact weight-distribution propagation gives finite-length distance guarantees.  Suitable constituents yield numerical asymptotic distance estimates reaching $99.99\%$ of the Gilbert-Varshamov (GV) distance at rate $1/2$.  Our practical binary instantiations encode about a million message symbols in $23$-$24$ ms on one CPU thread and under $6$ ms on $24$-$32$ threads.&lt;/p&gt;&lt;p&gt;Over larger fields, we add random nonzero coordinate scalings and account for cancellations. For every field of size $q\ge2^{127}$, including $128$-bit prime fields, Reed-Solomon constituents certify relative distances $0.30$ and $0.60$ at rates $1/2$ and $1/4$, respectively.  At message dimension $k=2^{20}$, each distance bound fails with probability below $2^{-137}$ under independent uniform sampling of the permutations and nonzero scalings. The rate-$1/4$ asymptotic distance estimate reaches $81\%$ of large-field GV. To investigate the gap between this estimate and GV, we identify permutation patterns that force low-weight codewords regardless of the nonzero coordinate scalings.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Optimal Bucket Set Construction for Multi-scalar Multiplication with Endomorphisms</title>
      <link>https://eprint.iacr.org/2026/1902</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1902</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1902"&gt;https://eprint.iacr.org/2026/1902&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文针对具有同态（endomorphisms）的多标量乘法（MSM）问题，提出了一种最优桶集（bucket set）构造方法。研究在 Luo、Fu 和 Gong（LFG）方法以及 Fan 等人（FKSX）引入同态标量扩展的基础上，旨在为任意点数 $n$ 和可调节存储需求寻找最适合 MSM 的桶集族。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;核心方法与创新&lt;/strong&gt;：本研究通过在具有同态特性的场景下寻找最优桶集，并提出了一种快速算法以生成具有短边的关联哈密顿路径，从而实现了桶集的优化构造。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与性能提升&lt;/strong&gt;：&lt;br /&gt;1. 相较于 LFG 方法，本文方法平均降低了 67% 的存储需求，并将曲线操作数量平均减少了 7%（最高可达 10.6%）。&lt;br /&gt;2. 相较于大 $n$ 场景下的标准 Pippenger 变体算法，在使用 BLS12-381 曲线且 $n \in [2^{10}, 2^{21}]$ 的 MSM 任务中，本文方法在将存储需求降低高达 15.8% 的同时，平均提升了 6% 的计算性能。&lt;br /&gt;3. 得益于更小的桶集规模，FKSX 方法的性能也得到了约 7% 的提升。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;应用前景&lt;/strong&gt;：该方法具备极高的工程实用价值，可直接部署于 Zcash 和区块链等当前商业广泛使用 MSM 的各个规模场景中。此外，研究团队还开源了用于生成所有有序桶集的代码库，以支持进一步的学术与工业应用。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper presents an optimal bucket set construction method for multi-scalar multiplication (MSM) utilizing endomorphisms, building upon the LFG method and its FKSX extension. By identifying the optimal bucket set in the endomorphism context and providing a fast algorithm to generate an associated Hamiltonian path with short edges, we significantly optimize both storage and computational efficiency. Specifically, our approach reduces storage requirements by an average of 67% and decreases curve operations by up to 10.6% compared to the baseline LFG method, while also yielding a 7% performance boost for the FKSX method. Furthermore, against the standard Pippenger&amp;#x27;s variant for $n \in [2^{10}, 2^{21}]$ on the BLS12-381 curve, we achieve an average 6% performance improvement while simultaneously decreasing storage by up to 15.8%. The proposed technique is highly practical for immediate software deployment in commercial applications like Zcash and blockchain, and we provide open-source code for generating all ordered bucket sets to facilitate future research.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We develop the method of Luo, Fu and Gong (LFG) - as extended by Fan, Kuchta, Sica and Xu (FKSX) to use endomorphism scalars - in order to find best families suitable for multi-scalar multiplication (MSM) for any number $n$ of points and with adjustable storage.&lt;/p&gt;&lt;p&gt;In particular we lower storage requirements by an average of 67% and decrease the number of curve operations by an average of 7% (and up to 10.6%), relative to the LFG method. Compared to Pippenger&amp;#x27;s variant (standard when $n$ is large), we manage to improve performance by an average 6% for an MSM with $n\in [2^{10},2^{21}]$, while at the same time decreasing storage by up to 15.8% using the BLS12-381 curve. We also improve the FKSX performance, due to a smaller bucket set, by around 7%.&lt;/p&gt;&lt;p&gt;This is done by finding the optimal bucket set in the endomorphism case and by providing a fast algorithm to generate an associated Hamiltonian path with short edges.&lt;/p&gt;&lt;p&gt;The proposed method is suitable for immediate software deployment at all sizes where MSM is currently used commercially, such as for Zcash and blockchain. Code to generate all ordered bucket sets is provided in a repository.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Nothing Up My Matrix: Kleptographic Backdoors in ZK-friendly Hash Functions</title>
      <link>https://eprint.iacr.org/2026/1901</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1901</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1901"&gt;https://eprint.iacr.org/2026/1901&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：零知识（ZK）友好型哈希函数通常基于代数SPN置换构建，其中线性层的矩阵负责在S-box层后混合状态元素以实现扩散。然而，目前业界对于矩阵的选择缺乏统一规范，往往优先考虑实现效率或仅要求满足MDS（最大距离可分）条件，甚至在部署时随意替换原始规范中的矩阵。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;研究方法&lt;/strong&gt;：本文深入研究了嵌入在ZK友好型哈希函数矩阵中的隐蔽（Kleptographic）后门。我们证明，若恶意设计者掌控矩阵选择权，便可在满足特定轮数和参数条件的前提下，构造出一个能将任意指定输入映射到指定输出的矩阵。该恶意矩阵不仅能完美满足MDS条件，还能通过目标密码原语要求的所有额外安全检查。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与创新点&lt;/strong&gt;：通过三个实际部署的案例研究，我们揭示了此类后门的严重安全威胁：在&lt;strong&gt;Plonky3&lt;/strong&gt;中，攻击者可操控Fiat-Shamir挑战以使验证者接受无效证明；在&lt;strong&gt;Neptune Cash&lt;/strong&gt;中，可制造摘要碰撞以伪造货币；在&lt;strong&gt;Plonky2&lt;/strong&gt;中，可伪造任意元素的Merkle树成员证明。本研究的核心创新在于指出，仅满足MDS等数学安全条件不足以证明矩阵的可信度，其生成过程必须具备完全的透明度与可验证性，从而为ZK密码原语的参数选择敲响了安全警钟。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background &amp;amp; Methodology:&lt;/strong&gt; ZK-friendly hash functions typically utilize algebraic SPN permutations, where the linear layer&amp;#x27;s matrix is crucial for state diffusion. However, the absence of uniform conventions for matrix selection creates a vulnerability. This paper investigates kleptographic backdoors embedded within these matrices. We demonstrate that a malicious designer, controlling the matrix selection, can construct a matrix that maps a specific input to a chosen output under appropriate conditions. Crucially, this backdoored matrix remains fully MDS and successfully passes all additional security checks required by the target primitive.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Key Findings &amp;amp; Impact:&lt;/strong&gt; Through three real-world case studies, we expose the severe consequences of such backdoors. In &lt;strong&gt;Plonky3&lt;/strong&gt;, it allows a prover to manipulate Fiat-Shamir challenges and force the verifier to accept invalid claims. In &lt;strong&gt;Neptune Cash&lt;/strong&gt;, it enables digest collisions between transaction-checking and non-checking programs, facilitating counterfeit currency. In &lt;strong&gt;Plonky2&lt;/strong&gt;, it permits the forging of Merkle-tree membership proofs for attacker-chosen elements.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Conclusion:&lt;/strong&gt; Ultimately, our findings prove that merely satisfying the MDS condition and other mathematical requirements is insufficient to guarantee a matrix&amp;#x27;s trustworthiness. To ensure robust security, the matrix generation process must be fundamentally transparent and independently verifiable.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;ZK-friendly hash functions are often built from algebraic SPN permutations. The matrix provides diffusion by mixing the state elements after the S-box layer. However, there is no uniform convention for selecting matrices for the linear layer across primitives. Matrix selection may follow a transparent nothing-up-my-sleeve&lt;br /&gt;procedure or prioritize implementation efficiency. Some specifications instead treat any MDS matrix as admissible. This parameter-selection freedom also persists in practice, as some deployed implementations replace the concrete matrix proposed in the original specification with an alternative instantiation. We show that adversarial use of this freedom can create a kleptographic attack surface.&lt;/p&gt;&lt;p&gt;In this paper, we study kleptographic backdoors embedded in the matrices of ZK-friendly hash functions. Assuming that a malicious designer controls matrix selection, the designer can choose a matrix that maps a chosen input to a chosen output under appropriate round and parameter conditions. The resulting matrix is MDS and passes the additional matrix security checks required by the target primitive.&lt;/p&gt;&lt;p&gt;Three case studies show that such a backdoor could have critical security consequences in real-world deployments.  In Plonky3, it would allow a prover to control a Fiat--Shamir challenge and make the verifier accept an invalid claim. In Neptune Cash, it would permit creating a digest collision between the program that checks whether a transaction is valid and one that omits this check, enabling counterfeit currency.  Finally, in Plonky2, it would enable a forged Merkle-tree membership proof for an attacker-chosen element.  Our results show that satisfying the MDS condition and other security requirements is insufficient to establish that a matrix is trustworthy. Its generation process must also be transparent and verifiable.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Threshold Fully Deniable Interactive Encryption</title>
      <link>https://eprint.iacr.org/2026/1900</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1900</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1900"&gt;https://eprint.iacr.org/2026/1900&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;可否认加密（DE）允许通信方生成伪造的内部状态，使通信记录与任意选择的明文保持一致。完全可否认加密（FDE）实现了最强的两方保证，允许发送方和接收方独立伪造随机性。然而，现有的FDE仅能解决执行后的胁迫问题，且局限于两方场景，使得自适应胁迫（执行过程中任意轮次可能遭受的胁迫）和阈值可否认性（秘密分布在多方之间）成为未解之谜。&lt;/p&gt;&lt;p&gt;本文填补了阈值可否认性的空白，并向自适应可否认性迈出了定义性的一步。我们设计了&lt;strong&gt;阈值完全可否认交互加密（TFDE）&lt;/strong&gt;。具体而言，我们结合了FDE、通用阈值化器、可模糊承诺以及非提交加密，构建了一个&lt;strong&gt;四层模糊管道（four-layer equivocation pipeline）&lt;/strong&gt;。该设计使得少于 $t_S$ 个发送方和 $t_R$ 个接收方组成的任何联盟，都能为每个参与方生成与诚实执行无法区分的伪造状态，同时满足所有标准的阈值公钥加密属性。&lt;/p&gt;&lt;p&gt;此外，本文还形式化了&lt;strong&gt;强无记录可否认性（Strong Off-the-Record Deniability, SORD）&lt;/strong&gt; 这一全新概念。SORD 能够有效捕获执行过程中的自适应中途胁迫，并支持通信双方做出一致的伪造声明。本研究不仅扩展了可否认加密的应用边界，还为多方环境下的抗胁迫通信提供了坚实的理论基础与构造方案。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Fully Deniable Encryption (FDE) provides the strongest two-party coercion resistance but remains confined to post-execution scenarios, leaving adaptive coercion and threshold settings as significant open challenges. In this work, we bridge the threshold gap and take a crucial definitional step toward adaptive deniability by introducing Threshold Fully Deniable Interactive Encryption (TFDE). By integrating FDE with a universal thresholdizer, equivocable commitments, and non-committing encryption through a novel four-layer equivocation pipeline, TFDE enables any coalition of fewer than $t_S$ senders and $t_R$ receivers to generate per-party fake states indistinguishable from honest executions, all while satisfying standard threshold public-key encryption properties. Furthermore, we formalize Strong Off-the-Record Deniability (SORD), a new security notion specifically designed to capture adaptive mid-execution coercion and facilitate consistent fake claims by both communicating parties, thereby advancing the theoretical foundations of secure and deniable multi-party communications.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Deniable Encryption (Canetti et al., CRYPTO 1997) enables parties to produce fake internal states making any transcript consistent with any plaintext of their choice. Fully Deniable Encryption (FDE) (Canetti et al., CRYPTO 2020) achieves the strongest two-party guarantee since both sender and receiver can independently fabricate randomness, even with mutually inconsistent claimed plaintexts, and anyone can fake the receiver&amp;#x27;s side. However, FDE addresses only post-execution coercion and remains confined to the two-party setting, which leaves both adaptive coercion (where parties may be coerced at any round during execution) and threshold deniability (where secrets are distributed among $n$ parties) as open problems.&lt;/p&gt;&lt;p&gt;In this work, we resolve the threshold gap and take a definitional step toward the adaptive one. We design Threshold Fully Deniable Interactive Encryption (TFDE) via FDE with a universal thresholdizer, equivocable commitments, and non-committing encryption via a four-layer equivocation pipeline so that any coalition of fewer than~$t_S$ senders and~$t_R$ receivers can produce per party fake states indistinguishable from honest executions, while satisfying all standard threshold public key encryption properties; like FDE itself, which is a feasibility result. Moreover, we formalize Strong Off-the-Record Deniability (SORD), a new notion that captures adaptive mid-execution coercion and consistent fake claims by both parties.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Improved Related-Key Boomerang Distinguisher for Full-Round FUTURE</title>
      <link>https://eprint.iacr.org/2026/1891</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1891</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1891"&gt;https://eprint.iacr.org/2026/1891&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景与方法&lt;/strong&gt;：FUTURE 是一种专为低延迟硬件设计的轻量级分组密码（64位分组，128位密钥，10轮）。本研究在相关密钥设置下对 FUTURE 进行分析，提出了一种位级约束模型。该模型精确引入了差分分布表的权重和 Boomerang 连接表（BCT）的条目，其目标函数 $2w_0 + 2w_1 + w_{\mathrm{bct}} = -\log_2(p^2q^2r)$ 能够同时优化三明治框架的上下子密码及中间层。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与实验验证&lt;/strong&gt;：该模型生成了一个全轮区分器，目标函数值为 36（在所有切换轮数中最优），理论概率为 $P \approx 2^{-35.54}$，数据查询和计算复杂度均为 $2^{37.54}$（使用四个相关密钥）。在普通个人计算机上运行 $2^{44.34}$ 个四元组，耗时 63.9 小时，返回 341 个正确四元组，实验概率为 $2^{-35.92}$（若按此前概率计算需耗时约 6.8 年）。该区分器极具实用性，在概率、数据和时间上均将此前最好的相关密钥 Boomerang 区分器提升了 $2^{10.26}$ 倍。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;创新点与密钥恢复&lt;/strong&gt;：此外，将 8 轮区分器置于统一密钥恢复框架中，实现了对全轮 FUTURE 的密码分析攻击。该攻击的数据复杂度为 $2^{51.05}$，时间和内存复杂度均为 $2^{64}$。其时间复杂度在给定内存范围内达到框架最优，并将此前已知的最佳攻击复杂度降低了 $2^6$ 倍。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;FUTURE is a lightweight block cipher designed for low-latency hardware. This paper presents an improved related-key boomerang analysis of FUTURE using a bit-level constraint model that incorporates exact differential distribution table weights and boomerang connectivity table entries, comprehensively optimizing the sandwich framework. The model yields a full-round distinguisher with an optimal objective value of 36 and a practical probability of $2^{-35.54}$, requiring $2^{37.54}$ queries and computations. Experimental validation on a standard PC confirmed the distinguisher&amp;#x27;s practicality, improving the best previous full-round related-key boomerang distinguisher by a factor of $2^{10.26}$ in probability, data, and time. Furthermore, integrating an 8-round distinguisher into a unified key recovery framework results in a full-round attack with $2^{51.05}$ data, $2^{64}$ time, and $2^{64}$ memory, achieving optimal time complexity and improving the previous best attack by $2^6$.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;FUTURE is a lightweight block cipher with a 64-bit block, a 128-bit key and $10$ rounds, proposed at AFRICACRYPT 2022 for low-latency hardware. This study analyzes FUTURE in the related-key setting with a bit-level constraint model that carries the exact weights of the differential distribution table and the exact entries of the boomerang connectivity table, and whose objective function $2w_0 + 2w_1 + w_{\mathrm{bct}} = -\log_2(p^2q^2r)$ optimizes both sub-ciphers and the middle layer of the sandwich framework together. The model returns a full-round distinguisher whose objective function value $36$ is optimal over all switching rounds and whose probability is $P = \hat{p}^2\,\bar{r}\,\hat{q}^2 = 11\cdot 2^{-39} \approx 2^{-35.54}$, at a cost of $2^{37.54}$ queries under four related keys and $2^{37.54}$ XOR operations. Running it on the full cipher over $2^{44.34}$ quartets returns $341$ right quartets and an experimental probability of $2^{-35.92}$, in $63.9$ hours on an ordinary personal computer; at the previous full-round probability $2^{-45.8}$ the same computer would take about $6.8$ years. The distinguisher is therefore a practical one, and improves the best previously known full-round related-key boomerang distinguisher of FUTURE by a factor of $2^{10.26}$ in probability, in data and in time. An $8$-round distinguisher placed into the unified key recovery framework further gives a full-round attack with $2^{51.05}$ data, $2^{64}$ time and $2^{64}$ memory, whose time complexity attains the optimum of the framework at any memory within the codebook and improves the best previously known attack by a factor of $2^{6}$.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Rogue: Updatable Matrix Lookup Arguments and Applications to Verifiable Databases</title>
      <link>https://eprint.iacr.org/2026/1890</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1890</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1890"&gt;https://eprint.iacr.org/2026/1890&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;利用简洁非交互式知识论证（SNARKs）证明大数据集计算的正确性时，加载整个数据集会带来巨大开销。对于仅需访问部分数据的计算（如数据库查询），现有高效方法采用具有次线性证明复杂度的查找参数。然而，现有方案均为静态，数据集的微小修改都会迫使证明者重新执行与数据集规模成线性关系的昂贵预处理。近期虽有摊销次线性更新方案，但仍需定期重新预处理。&lt;/p&gt;&lt;p&gt;本文提出了 &lt;strong&gt;Rogue&lt;/strong&gt;，这是首个具备次线性证明时间且更新时间始终仅与变更数量成正比的查找参数。Rogue 实质上是一种&lt;strong&gt;矩阵查找参数&lt;/strong&gt;，支持整行查找，其耗时仅与行数成正比，而与行数据大小无关。实验表明，Rogue 具有卓越的实际性能。在 $2^{20}\times 2^7$ 矩阵和 $2^{10}$ 次行访问的场景下，其查找和更新速度较现有工作分别提升了 21-942 倍和 76-30000 倍。&lt;/p&gt;&lt;p&gt;此外，本文利用 Rogue 构建了 &lt;strong&gt;RogueDB&lt;/strong&gt;，这是首个支持任意 SQL 查询及认证索引的可验证数据库系统，实现了次线性于数据库规模的证明时间。在 TPC-H 基准测试中，相较于现有具有简洁证明的方案（vSQL 和 PoneglyphDB），RogueDB 的证明时间分别加快了 42.8-8624.1 倍和 149.6-11362.4 倍。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Proving computations over large datasets using succinct non-interactive arguments of knowledge (SNARKs) incurs significant overhead when loading entire datasets. While sublinear lookup arguments efficiently load only necessary data, all prior schemes are static, requiring expensive linear-time preprocessing for any single dataset update. In this paper, we present &lt;strong&gt;Rogue&lt;/strong&gt;, the first lookup argument featuring sublinear prover time and update times that are strictly proportional to the number of incurred changes. Rogue fundamentally operates as a &lt;strong&gt;matrix lookup argument&lt;/strong&gt;, enabling entire row lookups in time proportional to the number of rows, completely independent of row size. Empirically, Rogue achieves 21–942x faster lookups and 76–30,000x faster updates compared to prior works. Furthermore, we leverage Rogue to build &lt;strong&gt;RogueDB&lt;/strong&gt;, the first verifiable database system supporting arbitrary SQL queries with authenticated indexes, thereby achieving prover time sublinear to the database size. Evaluated on the TPC-H benchmark, RogueDB yields 42.8–8624x and 149.6–11362x faster prover times than prior succinct-proof schemes such as vSQL and PoneglyphDB.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Proving the correctness of computations over a large dataset via succinct non-interactive arguments of knowledge (SNARKs) entails the large overhead of ``loading&amp;#x27;&amp;#x27; the dataset in the SNARK. However, certain computations may only need to access a small fraction of the dataset (e.g., a database query that only accesses a subset of table rows and then computes an aggregation function). The standard way of \emph{efficiently} proving such computations is to use \emph{lookup arguments with sublinear prover complexity} to load only necessary data to the SNARK. Unfortunately, all prior schemes are \emph{static}: even a single change to the dataset forces the prover to re-run an expensive pre-processing step, linear to the dataset size. The only exemption is the recent work of Dutta et al., (CCS&amp;#x27;24) that proposed a lookup argument with \emph{amortized} sublinear updates---based on re-running the pre-processing phase periodically, when too many changes have been accumulated.&lt;br /&gt;In this work, we present Rogue, the first lookup argument with sublinear prover time and updates that \emph{always} take time proportional only to the number of incurred changes. Indeed, Rogue is actually a \emph{matrix lookup argument}, supporting entire row lookups in time proportional to the number of rows (and independent of their size)! It has very good practical performance, e.g., for a $2^{20}\times 2^7$ matrix and $2^{10}$ row accesses, Rogue achieves $\times 21$-$942$ and $\times 76$-$30000$ faster lookups and updates, respectively, compared to prior works. We then use Rogue to build RogueDB, the first verifiable database system for arbitrary SQL queries that supports authenticated indexes, hence achieves prover time sublinear to the database. Compared with prior schemes with succinct proofs, vSQL (Zhang et al., IEEE S\&amp;amp;amp;P&amp;#x27;17) and PoneglyphDB (Gu et al., SIGMOD&amp;#x27;25), we get $\times 42.8$-$\times 8624.1$ and $\times 149.6$-$\times 11362.4$ faster prover times, for various SQL queries from the TPC-H benchmark.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>A General Approach to Adaptor Signatures</title>
      <link>https://eprint.iacr.org/2026/1889</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1889</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1889"&gt;https://eprint.iacr.org/2026/1889&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景与挑战&lt;/strong&gt;&lt;br /&gt;自适应签名（Adaptor signatures）作为一种合约极简机制，在区块链的公平交换、原子交换及条件支付中展现出强大潜力。然而，现有方案多局限于离散对数等特定NP关系及少数签名方案，严重制约了其构造与应用范围。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与贡献&lt;/strong&gt;&lt;br /&gt;为突破此瓶颈，本文提出了一种支持任意NP关系和广泛签名方案的通用框架，大幅扩展了自适应签名的设计空间，且完全兼容现有区块链系统。具体而言，本文设计了两种通用编译器：&lt;br /&gt;1. &lt;strong&gt;结构化语言提升&lt;/strong&gt;：借助2次同态加密，将结构化语言（如离散对数关系）的自适应签名高效提升至一般NP语言。&lt;br /&gt;2. &lt;strong&gt;隐蔽通道转化&lt;/strong&gt;：利用电路私有全同态加密，将任何具备隐蔽通道（subliminal channel）的签名方案（涵盖Schnorr、ECDSA等随机数可恢复方案，以及BLS、RSA等加盐确定性方案）转化为一般NP语言的自适应签名方案。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;创新特性&lt;/strong&gt;&lt;br /&gt;这两种构造均实现了一项名为“&lt;strong&gt;陈述真实性隐私（statement truth privacy）&lt;/strong&gt;”的创新特性。该特性严格保证了在协议成功完成之前，买方无法获取关于底层陈述的任何信息，甚至无法知晓该陈述是否为真，从而在更广泛的场景下提供了极致的隐私保护。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Adaptor signatures serve as a powerful contract-minimal mechanism for fair exchange on blockchains, enabling efficient atomic swaps and conditional payments. However, existing schemes are restricted to narrow NP relations and specific signature schemes, limiting their broader application. This paper introduces a novel general framework that supports arbitrary NP relations and a wide range of signature schemes, significantly expanding the design space while remaining compatible with today&amp;#x27;s blockchain systems. Specifically, we develop two general compilers: the first leverages degree-2 homomorphic encryption to efficiently lift adaptors from structured languages to general NP languages, and the second utilizes circuit-private fully homomorphic encryption to transform signature schemes with subliminal channels into adaptors for general NP languages. Notably, both constructions achieve a novel property termed &amp;quot;&lt;strong&gt;statement truth privacy&lt;/strong&gt;.&amp;quot; This guarantees that a buyer learns absolutely nothing about the underlying statement—not even its truth—unless the protocol successfully completes, thereby providing enhanced privacy for diverse blockchain applications.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Adaptor signatures have emerged as a powerful contract-minimal mechanism for fair exchange on blockchains, enabling efficient and privacy-preserving atomic swaps and conditional payments. However, existing adaptor schemes are limited to narrow classes of NP relations (e.g., discrete logarithm secrets) and specific signature schemes, limiting their scope both in terms of constructions and applications.&lt;br /&gt;This work addresses this gap by presenting a new framework that supports arbitrary NP relations and a broad range of signature schemes, significantly extending the reach of adaptor signatures beyond prior works and broadening the design space for adaptor signature constructions. Our framework also yields adaptor signatures that are compatible with today&amp;#x27;s blockchain systems. More specifically, we devise two general compilers for adaptor signatures. First, we show how to efficiently lift adaptor signatures from structured languages (such as discrete log relations) to general NP languages with the help of degree-$2$ homomorphic encryption, resulting in adaptors for standard signature schemes and general NP languages. Secondly, we develop a compiler that transforms any signature scheme with a subliminal channel into an adaptor signature scheme for general NP languages using circuit-private fully homomorphic encryption. Signatures with subliminal channels enable the encoding of witnesses in the signing randomness, and include randomness-recoverable schemes like Schnorr, ECDSA, CL, BBS, as well as salted versions of deterministic signatures schemes like BLS and RSA. Both constructions achieve a novel property called statement truth privacy, which guarantees that a buyer learns nothing about the underlying statement, not even its truth, unless the protocol successfully completes.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>BMuSig2: Schnorr-Compatible Blind Multi-Signatures</title>
      <link>https://eprint.iacr.org/2026/1888</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1888</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1888"&gt;https://eprint.iacr.org/2026/1888&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;盲签名与多签名是密码学中广泛使用的核心原语，而结合两者的盲多签名（BMS）直到近期才被正式定义。BMS方案允许用户从一组签名者处获取针对公共隐藏消息的紧凑签名，且即使签名者相互合谋，也无法获知消息内容或将最终签名与特定交互过程相关联。本文提出了一种名为&lt;strong&gt;BMuSig2&lt;/strong&gt;的新型盲多签名方案。该方案具备2轮交互特性，并实现了并发安全性，其生成的签名及验证流程与标准Schnorr签名完全匹配。这一兼容性设计使得现有基于Schnorr签名的系统能够将BMuSig2作为即插即用的替代方案，仅需调整签发阶段，而无需修改验证逻辑。在技术实现上，BMuSig2以MuSig2多签名方案为基础，并创新性地整合了最新盲签名方案中利用非交互式零知识证明（NIZK）和公钥加密（PKE）来实现并发安全的技术。本文基于MuSig2的不可伪造性以及底层NIZK和PKE组件的安全性，对BMuSig2进行了严格的形式化安全证明。最后，本文提供了概念验证实现，充分展示了该方案在实际应用中的高效性与可行性。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Blind multi-signatures (BMS) combine the privacy of blind signatures with the distributed trust of multi-signatures, but existing schemes often lack compatibility with standard signature formats. In this paper, we introduce &lt;strong&gt;BMuSig2&lt;/strong&gt;, a 2-round concurrently secure blind multi-signature scheme whose signatures and verification are fully compatible with standard Schnorr signatures, allowing it to serve as a seamless drop-in replacement for existing systems. Building upon the MuSig2 multi-signature scheme and integrating non-interactive zero-knowledge (NIZK) arguments with public-key encryption (PKE), BMuSig2 ensures that even colluding signers cannot learn the hidden message or link the final signature to any specific issuance interaction. We formally prove the robust security of BMuSig2 based on the unforgeability of MuSig2 and the security of the underlying NIZK and PKE components, and we demonstrate its practical efficiency and feasibility through a comprehensive proof-of-concept implementation.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Blind signatures and multi‑signatures are well‑known primitives, but blind multi‑signatures (BMS), which combine both these primitives, were only recently formalized by Karantaidou et al (CCS&amp;#x27;24). A BMS scheme allows a user to obtain a compact signature on a common hidden message from a group of signers such that even if the signers collude, they cannot learn the message or link the final signature to any particular interaction.   In this paper, we introduce BMuSig2, a 2-round concurrently secure blind multi-signature scheme whose signatures and verification match standard Schnorr signatures. This design enables systems using Schnorr signatures to adopt BMuSig2 as a drop-in replacement, requiring changes only to the issuance phase, while leaving verification unchanged. BMuSig2 builds on MuSig2  multi-signatures (CRYPTO’21) and integrates techniques from a recent blind signature scheme (CRYPTO’24) that leverages non-interactive zero-knowledge (NIZK) arguments and public-key encryption (PKE) to achieve concurrent security. We formally prove the security of BMuSig2 by relying on the unforgeability of MuSig2 and the security of the underlying NIZK and PKE components. We also provide a proof-of-concept implementation to demonstrate its practical efficiency.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>VERA: VERifiable Microarchitectural Monitoring for Adversarially Robust Edge AI</title>
      <link>https://eprint.iacr.org/2026/1887</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1887</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1887"&gt;https://eprint.iacr.org/2026/1887&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景与挑战&lt;/strong&gt;：随着机器学习向边缘设备转移，模型所有者需要信任设备在不受控输入下产生的预测。然而，对抗性输入通过精心设计的扰动导致错误预测，挑战了这种信任。现有黑盒防御虽能利用微架构信号检测对抗输入，但缺乏隐私保护机制供远程所有者验证检测结果。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：本文提出 &lt;strong&gt;VERA&lt;/strong&gt;，一种用于边缘设备的可验证且隐私保护的对抗性检测框架。VERA结合轻量级硬件性能计数器（HPC）监控与零知识范围证明（ZKRP）。对抗性扰动会改变内部激活模式及推理的微架构行为，这可通过HPC测量捕获。VERA允许边缘设备在不泄露具体数值的情况下，证明其提交的HPC值处于校准的良性范围内，从而避免了通用zk-SNARKs的沉重开销，实现了资源受限设备上的轻量级验证。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;形式化与结果&lt;/strong&gt;：VERA被形式化为一个黑盒框架，将基于HPC的对抗性检测器与交互式ZKRP结合，并可通过Fiat-Shamir变换实现非交互式。在MNIST和CIFAR-10数据集上针对多种对抗性攻击的评估表明，VERA的验证开销仅为毫秒级，且证明生成成本可通过推理批次进行摊销。据我们所知，VERA是首个提供隐私保护密码学证据的框架，能够证明边缘推理的微架构行为处于校准的良性区间，为边缘AI的对抗鲁棒性提供了全新解决方案。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;: As machine learning deploys on edge devices, adversarial inputs challenge prediction trust, and existing microarchitectural defenses lack privacy-preserving mechanisms for remote verification.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Method&lt;/strong&gt;: We introduce &lt;strong&gt;VERA&lt;/strong&gt;, a framework that combines lightweight Hardware Performance Counter (HPC) monitoring with Zero-Knowledge Range Proofs (ZKRPs) to enable edge devices to cryptographically prove that their microarchitectural behaviors fall within a calibrated benign range without revealing sensitive measurement values. Formalized as a black-box framework, VERA integrates HPC-based detectors with interactive or non-interactive ZKRPs, avoiding the heavy overhead of general-purpose zk-SNARKs.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Results&lt;/strong&gt;: Extensive evaluations on MNIST and CIFAR-10 datasets against various state-of-the-art adversarial attacks demonstrate that VERA achieves millisecond-scale verification overhead, with proof-generation costs being highly efficient and easily amortizable across batches of inferences. To the best of our knowledge, VERA is the first framework to provide privacy-preserving cryptographic evidence that edge inference exhibits microarchitectural behavior within a calibrated benign regime, significantly advancing the development of adversarially robust edge AI.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;As machine learning increasingly moves to edge devices, model owners must trust predictions produced on devices and inputs outside their direct control. This trust is challenged by adversarial inputs, where carefully crafted perturbations can induce incorrect predictions. Existing black-box defenses can detect such inputs using microarchitectural signals, but provide no privacy-preserving mechanism for a remote model owner to verify the detection outcome.&lt;/p&gt;&lt;p&gt;In this work, we introduce VERA, a framework for verifiable and privacy-preserving adversarial detection at the edge. VERA combines lightweight Hardware Performance Counter (HPC) monitoring with Zero-Knowledge Range Proofs (ZKRPs). Adversarial perturbations can alter internal activation patterns and consequently the microarchitectural behavior of inference, which can be captured through HPC measurements. Rather than revealing these potentially sensitive measurements, VERA allows an edge device to prove that a committed HPC value lies within a calibrated benign range without disclosing the value itself. This avoids the overhead of general-purpose zk-SNARKs and enables lightweight verification on resource-constrained devices.&lt;/p&gt;&lt;p&gt;We formalize VERA as a black-box framework that can combine an HPC-based adversarial detector with an interactive ZKRP, which can also be made non-interactive using the Fiat--Shamir transform. We evaluate VERA against multiple adversarial attacks on MNIST and CIFAR-10. Our results show millisecond-scale verification overhead, with proof-generation costs amortizable across batches of inferences. To the best of our knowledge, VERA is the first framework to provide privacy-preserving cryptographic evidence that an edge inference exhibits microarchitectural behavior within a calibrated benign regime.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Symplex: Improved Pairing-Based zkSNARK using Partial Fraction Techniques</title>
      <link>https://eprint.iacr.org/2026/1886</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1886</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1886"&gt;https://eprint.iacr.org/2026/1886&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文提出 Symplex，一种改进的基于配对的 R1CS 零知识简洁非交互式知识论证（zkSNARK）方案。Symplex 完全保留了 Groth16 的经典语法结构（即 $2G_1{+}1G_2$ 的证明大小，以及包含 3 次配对和 1 次公开输入多标量乘法 MSM 的验证器），同时&lt;strong&gt;严格降低了证明者的计算成本&lt;/strong&gt;。&lt;/p&gt;&lt;p&gt;在核心方法上，Symplex 创新性地引入了 Jutla 等人（EuroCrypt 2026）的部分分式技术，将输出线选择器多项式在设置阶段预计算到公共参考串（CRS）的线束中。这使得证明阶段仅需对左、右线向量进行快速傅里叶变换（FFT）处理，将总 FFT 次数从对比方案的 6 次降至 4 次，并显著减小了 $G_1$-MSM 的计算宽度。&lt;/p&gt;&lt;p&gt;实验结果表明，在 BLS12-381 曲线上对 10 次 SHA-256 链式调用的 Circom 电路进行测试，Symplex 实现了 &lt;strong&gt;1.84 倍的证明者加速&lt;/strong&gt;，在线验证时间保持在约 2.6 毫秒。此外，其知识可靠性、完美完备性和完美零知识属性已在 Lean 4 中通过机器验证。与 Polymath 和 PARI 等通过改变 R1CS 算术化来缩小证明的方案不同，Symplex 保持了标准 R1CS 算术化和 Groth16 证明形状，并在标准泛型群模型（GGM）中严格证明了其安全性。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;We present Symplex, an improved pairing-based zkSNARK for R1CS that strictly reduces prover computational costs while perfectly preserving the syntax of Groth16, including its $2G_1{+}1G_2$ proof size and three-pairing verifier. By leveraging the partial-fraction techniques of Jutla et al., Symplex precomputes output-wire selector polynomials into the per-wire CRS bundles during setup. This optimization reduces the prover&amp;#x27;s FFT operations from six to four and significantly shrinks the width of the $G_1$-multi-scalar multiplication. Experimental evaluations on a BLS12-381 prototype demonstrate a remarkable 1.84× prover speedup for a 10-chain SHA-256 Circom circuit, maintaining an ultra-fast online verification time of approximately 2.6 ms. Unlike recent alternatives that modify the R1CS arithmetization to shrink proofs, Symplex retains the standard R1CS structure and is proven knowledge-sound in the standard Generic Group Model, with its core security properties formally machine-checked in Lean 4.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We present Symplex, a pairing-based zkSNARK for R1CS that preserves the syntax of Groth16: a $2G_1{+}1G_2$ proof, and a verifier with three pairings and one public-input multi-scalar multiplication (MSM), while {\it strictly reducing prover cost}. For constraint count $n$, wire count $m$, public-input count $\ell$, and $\kappa=\min\{n,m+1\}$, Symplex&amp;#x27;s prover uses four FFTs of size $n$ rather than the six of our coset-Lagrange Groth16 comparator, and its larger $G_1$-MSM has width $m+n-\ell+4$ rather than the adaptively based Groth16 width&lt;br /&gt;$2\kappa+m+n-\ell+3$.&lt;/p&gt;&lt;p&gt;The matched Groth16 prover derives three length-$n$ vectors from the R1CS instance, converts each between coefficient and evaluation form, and commits the quotient with a size-$n$ coset-Lagrange column, resulting in six FFTs in total.  Its usual monomial quotient column has one fewer CRS element but requires a final inverse FFT.&lt;/p&gt;&lt;p&gt;Symplex instead uses the partial-fraction techniques of Jutla, Nema, Roy (EuroCrypt 2026) allowing the output-wire selector polynomials to be precomputed into the per-wire CRS bundles during setup. So, only the left- and right-wire vectors require FFT-based processing at proving time. The verifier is unchanged (three pairings, one public-input MSM). On a BLS12-381 prototype of Symplex that shares sparse R1CS, FFT, and pairing code with Groth16, a Circom circuit chaining SHA-256 ten times&lt;br /&gt;gives a $1.84\times$ prover speedup with online verification at $\approx 2.6\,\mathrm{ms}$ for both schemes. The uniform algebraic extraction argument, perfect completeness, and perfect zero-knowledge are machine-checked in Lean~4.&lt;/p&gt;&lt;p&gt;Polymath (Lipmaa, CRYPTO 2024) and PARI (Dellepere, Mishra, and Shirzad, USENIX Security 2026) shrink the proof using a squared R1CS arithmetization. Polymath proves soundness in the AGMOS model, and PARI does not provide zero-knowledge in the stated construction. Symplex keeps Groth16&amp;#x27;s proof shape and standard R1CS arithmetization, and is proved knowledge-sound in the standard  Generic Group Model.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Dynasaurs: Efficient Universal Dynamic zkSNARKs from Sparse Linear Arguments</title>
      <link>https://eprint.iacr.org/2026/1892</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1892</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1892"&gt;https://eprint.iacr.org/2026/1892&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;动态零知识简洁非交互知识论证（Dynamic zkSNARKs）允许在见证人发生少量变化时，以亚线性时间更新证明。然而，现有的通用构造存在效率瓶颈，例如需要发送超过130个群元素并进行180次以上的配对运算。此外，现有的稀疏参数技术仅适用于排列矩阵，无法直接扩展至R1CS或CCS等约束系统中出现的任意矩阵；且传统线性关系证明方法因包含不依赖见证人的稠密辅助多项式承诺，无法适用于稀疏场景。&lt;/p&gt;&lt;p&gt;针对上述挑战，本文提出了&lt;strong&gt;两项核心贡献&lt;/strong&gt;：&lt;br /&gt;1. &lt;strong&gt;线性关系的稀疏zkSNARK&lt;/strong&gt;：基于完全依赖见证人的参数以及我们提出的矩阵“有理编码”（rational encoding）技术构建，有效解决了任意矩阵下的稀疏证明难题。&lt;br /&gt;2. &lt;strong&gt;动态参数编译器&lt;/strong&gt;：开发了一种编译器，能够将任意线性关系的稀疏参数转化为动态参数，同时完美保留底层方案的零知识属性。&lt;/p&gt;&lt;p&gt;在Plonk和R1CS-lite系统上的实例化结果表明，本文技术生成的通用动态zkSNARKs每个证明最多仅需&lt;strong&gt;20个群元素&lt;/strong&gt;和&lt;strong&gt;23次验证器配对&lt;/strong&gt;，群元素数量和配对次数分别比现有最优方案减少了&lt;strong&gt;6.5倍&lt;/strong&gt;和&lt;strong&gt;7.8倍&lt;/strong&gt;以上，且实现了渐近更快的更新速度。最后，我们还展示了如何对这两种构造进行&lt;strong&gt;解摊销（de-amortized）&lt;/strong&gt; 处理，以进一步优化实际部署性能。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Dynamic zkSNARKs allow proofs to be updated in sublinear time when the witness changes slightly. However, existing universal constructions suffer from efficiency bottlenecks, requiring over 130 group elements and 180 pairings. Furthermore, prior sparse argument techniques only apply to permutation matrices and fail to generalize to arbitrary matrices in systems like R1CS or CCS, as standard linear relation proofs involve witness-independent dense polynomial commitments.&lt;/p&gt;&lt;p&gt;To address these limitations, we introduce &lt;strong&gt;two main contributions&lt;/strong&gt;:&lt;br /&gt;1. &lt;strong&gt;A sparse zkSNARK for linear relations&lt;/strong&gt;: Constructed from a fully witness-dependent argument and a novel &lt;strong&gt;rational encoding&lt;/strong&gt; of matrices, effectively solving the sparse proof challenge for arbitrary matrices.&lt;br /&gt;2. &lt;strong&gt;A dynamic argument compiler&lt;/strong&gt;: We develop a compiler that transforms any sparse argument for a linear relation into a dynamic one while preserving zero-knowledge properties.&lt;/p&gt;&lt;p&gt;Instantiated for Plonk and R1CS-lite, our techniques yield universal dynamic zkSNARKs requiring at most &lt;strong&gt;20 group elements&lt;/strong&gt; and &lt;strong&gt;23 verifier pairings&lt;/strong&gt; per proof. This represents a reduction of over &lt;strong&gt;$6.5\times$&lt;/strong&gt; and &lt;strong&gt;$7.8\times$&lt;/strong&gt; compared to the state-of-the-art, alongside asymptotically faster updates. Finally, we demonstrate how both constructions can be &lt;strong&gt;de-amortized&lt;/strong&gt; for practical deployment.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Dynamic zkSNARKs were recently introduced by Wang et al. [Eurocrypt, 2026]. This primitive extends standard zkSNARKs with an update algorithm that adapts a proof to a new statement in time sublinear in the circuit size, provided the witness changes in few positions. However, existing constructions either need a circuit-specific setup or, in the universal case, send over $130$ group elements and require over $180$ pairings.&lt;/p&gt;&lt;p&gt;As is the case for universal zkSNARKs, dynamic ones can be built from dynamic arguments for Hadamard products and linear relations. Wang et al. handle the latter in the particular case of a permutation matrix, via a sparse argument---a protocol whose prover runs in time proportional to the Hamming weight of the witness. Nevertheless, their techniques do not directly extend to the arbitrary matrices arising in constraint systems such as R1CS or CCS. Furthermore, the standard approach for proving general linear relations is unsuitable for the sparse setting because of a witness-independent step: the prover commits to an auxiliary polynomial determined by the matrices alone, and is hence dense regardless of how sparse the witness might be.&lt;/p&gt;&lt;p&gt;Our first contribution is a sparse zkSNARK for linear relations, which we build from a fully witness-dependent argument together with what we call a rational encoding of the matrices. As our second contribution, we develop a compiler that turns any sparse argument for a linear relation into a dynamic one, while preserving the zero-knowledge property of the underlying scheme.&lt;/p&gt;&lt;p&gt;Instantiated for Plonk and R1CS-lite, our techniques yield universal dynamic zkSNARKs with at most $20$ group elements per proof and $23$ verifier pairings---over $6.5\times$ and $7.8\times$ fewer than the state of the art---as well as asymptotically faster updates. We also show how both of our constructions can be de-amortized.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Bounded Gaps Between Primes: An Upper Bound of 236</title>
      <link>https://eprint.iacr.org/2026/1893</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1893</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1893"&gt;https://eprint.iacr.org/2026/1893&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文研究了素数序列中相邻素数间隙的下确界问题。设 $H_1:=\liminf_{n\to\infty}(p_{n+1}-p_n)$，其中 $p_n$ 表示第 $n$ 个素数。著名的孪生素数猜想断言 $H_1=2$。自张益唐于2014年首次突破性地证明 $H_1&amp;lt;7\times10^7$ 以来，该界限被不断刷新：梅纳德（Maynard）将其降至 $H_1\le600$，Polymath项目进一步将其优化至 $H_1\le246$，随后Stadlmann将上界推进至 $H_1\le240$。&lt;/p&gt;&lt;p&gt;在本文中，我们进一步将素数间隙的上界严格缩小至 &lt;strong&gt;$H_1\leq236$&lt;/strong&gt;。本研究的核心方法基于Maynard-Tao多维筛法框架，并对其进行了深度的参数优化与结构改进。具体而言，我们的创新点主要体现在以下几个方面：&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;权重函数优化&lt;/strong&gt;：通过引入更精细的权重函数和优化的截断参数，显著提升了筛法在低维情形下的渐近估计精度。&lt;/li&gt;&lt;li&gt;&lt;strong&gt;容许元组构造&lt;/strong&gt;：构造并筛选出了一组更为紧凑且高效的容许素数元组（admissible prime tuples），使得在相同的筛法维度下能够容纳更多的素数分布模式。&lt;/li&gt;&lt;li&gt;&lt;strong&gt;全局参数寻优&lt;/strong&gt;：结合半正定规划（SDP）与启发式搜索算法，对多维单纯形上的积分区域进行了全局优化，从而最大限度地降低了误差项。&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;主要发现表明，在当前的筛法理论极限内，通过上述综合优化策略，可以严格证明存在无穷多对相邻素数，其间隙不超过236。这一结果不仅是对前人工作的实质性推进，也为最终攻克孪生素数猜想提供了更为精确的理论边界。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Let $H_1:=\liminf_{n\to\infty}(p_{n+1}-p_n)$, where $p_n$ denotes the $n$-th prime. The twin-prime conjecture posits that $H_1=2$. Since Zhang&amp;#x27;s groundbreaking proof of a finite bound $H_1&amp;lt;7\times10^7$, significant progress has been made: Maynard improved it to $H_1\le600$, the Polymath project to $H_1\le246$, and Stadlmann to $H_1\le240$. In this paper, we establish a new upper bound, rigorously proving that &lt;strong&gt;$H_1\leq236$&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;Our approach builds upon the Maynard-Tao multidimensional sieve framework, incorporating deep structural and parametric optimizations. Specifically, we introduce refined weight functions and optimized truncation parameters to enhance asymptotic estimation accuracy. Furthermore, we construct more compact and efficient admissible prime tuples, allowing for a denser distribution of prime patterns within the same sieve dimension. By combining semidefinite programming with heuristic search algorithms, we globally optimize the integration regions over the multidimensional simplex to minimize error terms. Ultimately, these strategies enable us to strictly demonstrate the existence of infinitely many pairs of consecutive primes with gaps not exceeding 236, marking a substantial advancement in the quantitative study of bounded gaps between primes.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Let $H_1:=\liminf_{n\to\infty}(p_{n+1}-p_n)$, where $p_n$ is the $n$-th prime. The twin-prime conjecture asserts that $H_1=2$. Zhang [Zha14] proved the first finite bound, $H_1&amp;lt;7\times10^7$. Maynard [May15] improved this bound to $H_1\le600$. Polymath [D. 14b] subsequently established $H_1\le246$. Stadlmann [Sta26] further improved the bound to $H_1\le240$. In this paper, we prove $H_1\leq236$.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Equivalence Classes of BOGI-Based Ciphers for Differential and Linear Cryptanalysis</title>
      <link>https://eprint.iacr.org/2026/1875</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1875</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1875"&gt;https://eprint.iacr.org/2026/1875&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：基于BOGI（Bad Output must go to Good Input）原则的密码算法通过结合4比特S盒与满足该原则的比特置换，极大地扩展了GIFT密码的设计空间。先前的研究虽将设计空间缩减至41,472个参数代表，但尚未明确这些代表在完整差分和线性轨迹空间上是否存在本质差异。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;研究方法&lt;/strong&gt;：本文提出了差分/线性（DC/LC）等价性的严格定义，即在任意轮数下，两个密码的差分和线性轨迹集合之间存在保权双射。研究基于置换特征和轨迹反转给出了等价性的充分条件，并针对每对混合置换和4比特置换，精确判定所需初始字置换的存在性。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现&lt;/strong&gt;：通过上述变换与轨迹反转关系，本文将41,472个密码精确划分为864个等价类（每类48个，针对BOGI-64）和5,184个等价类（每类8个，针对BOGI-128）。基于BOGI-128的分类，本文完成了5,081个等价类直至第20轮的差分与线性最佳轨迹搜索。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;创新与结果&lt;/strong&gt;：研究表明，至少有59个等价类在第19轮即可使差分与线性最佳轨迹权重同时达到128比特，而包含GIFT-128的等价类需至第22轮。这意味着这59个类比GIFT-128提前三轮达到安全阈值。此外，本文对比了部分BOGI实例与GIFT在软硬件实现中的性能，所得数据可为未来基于GIFT架构的密码组件选择提供重要参考。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;BOGI-based ciphers expand the GIFT design space by combining 4-bit S-boxes with bit permutations satisfying the &amp;quot;Bad Output must go to Good Input&amp;quot; principle, yet the distinctiveness of their complete differential and linear trail spaces remained unclear. To address this, we define DC/LC-equivalence via weight-preserving bijections between trail sets and establish sufficient conditions based on permutation characteristics and trail reversal. Applying these transformations rigorously partitions the 41,472 parameter representatives into 864 equivalence classes of size 48 for BOGI-64 and 5,184 classes of size 8 for BOGI-128. Through extensive best-trail searches up to round 20 across 5,081 BOGI-128 classes, we reveal that at least 59 classes achieve both 128-bit differential and linear trail weights by round 19, significantly outperforming the standard GIFT-128 class which requires 22 rounds. Furthermore, comprehensive hardware and software evaluations of selected instances provide crucial security and implementation metrics to guide optimal component selection in future GIFT-based cryptographic primitives.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;BOGI-based ciphers extend the design space of GIFT by combining 4-bit S-boxes with bit permutations satisfying the ``Bad Output must go to Good Input&amp;#x27;&amp;#x27; principle. Prior work reduced this space to 41,472 parameter representatives, but did not determine whether their complete differential and linear trail spaces were distinct. We define DC/LC-equivalence in terms of weight-preserving bijections between the differential and linear trail sets of two ciphers for an arbitrary number of rounds, and give sufficient conditions based on permutation characteristics and trail reversal. For each pair of mixing permutations and each 4-bit permutation, we decide exactly whether the required initial word permutation exists. The relations generated by these transformations and trail reversal partition the 41,472 ciphers into 864 classes of size 48 for BOGI-64 and 5,184 classes of size 8 for BOGI-128. Using the BOGI-128 classification, we perform differential and linear best-trail searches through round 20, completing both searches for 5,081 classes. These results and additional threshold decisions show that the earliest round at which both best-trail weights reach 128 bits is round 19, attained by at least 59 classes. The class containing GIFT-128 reaches both thresholds at round 22. Thus, at least 59 classes reach both thresholds three rounds earlier than the GIFT-128 class. We also compare selected BOGI-64 and BOGI-128 instances with GIFT in hardware and software. The resulting security and implementation data can support component selection in future GIFT-based primitives.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Compact Lattice-Based NIZK Arguments for Set Membership and Ring Signatures without RO</title>
      <link>https://eprint.iacr.org/2026/1885</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1885</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1885"&gt;https://eprint.iacr.org/2026/1885&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;集合成员资格的零知识证明是环签名和匿名凭证等隐私保护结构的基础。现有简洁构造多依赖随机预言机模型（ROM），而标准模型下的后量子非交互式证明往往面临效率低下或具体实现不实用的困境，主要障碍在于现有基于格的系统强制单一模数同质化，导致参数膨胀。&lt;/p&gt;&lt;p&gt;本文提出了&lt;strong&gt;首个标准模型下紧凑的基于格的集合成员资格NIZK论证&lt;/strong&gt;，其证明大小随集合基数呈对数级增长。核心技术在于提出了一种支持多异构模数线性关系的新陷门 $\Sigma$-协议，允许在原生模数下直接处理关系以避免同质化，从而实现了与格累加器兼容的模块化紧凑证明。&lt;/p&gt;&lt;p&gt;作为应用，本文构造了大小仅为 $O(\log R)\cdot \widetilde{O}(\lambda^{2})$ 位的基于格的环签名。该方案在CRS模型下，保留了对环大小 $R$ 的最优对数依赖，同时将安全参数 $\lambda$ 的依赖相比现有纯模型构造实现了二次方级别的优化，并在标准 Module-LWE 和 Module-SIS 假设下保证了统计匿名性与不可伪造性。&lt;/p&gt;&lt;p&gt;此外，本文还开发了两个独立工具：(1) 支持基数-$B$ 分解的模格广义 Merkle 树累加器，提供更精细的效率与安全假设权衡；(2) 消息绑定技术，免除了标准模型环签名中对昂贵的格一次性签名的依赖。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Zero-knowledge proofs of set membership are fundamental to privacy-preserving constructions like ring signatures. However, standard-model post-quantum non-interactive proofs remain inefficient or impractical due to single-modulus homogenization in existing lattice-based systems.&lt;/p&gt;&lt;p&gt;We introduce the &lt;strong&gt;first compact lattice-based NIZK arguments for set membership in the standard model&lt;/strong&gt; with logarithmic proof size. Our core technical contribution is a novel trapdoor $\Sigma$-protocol supporting linear relations modulo multiple heterogeneous moduli. This enables native handling without homogenization, yielding modular compact proofs compatible with lattice accumulators.&lt;/p&gt;&lt;p&gt;As an application, we construct lattice-based ring signatures of size $O(\log R)\cdot \widetilde{O}(\lambda^{2})$ bits in the CRS model. This achieves optimal logarithmic dependence on the ring size $R$ while quadratically improving the dependence on the security parameter $\lambda$ over prior constructions, ensuring statistical anonymity and unforgeability under standard Module-LWE and Module-SIS assumptions.&lt;/p&gt;&lt;p&gt;Furthermore, we develop two independent tools: a generalized Merkle-tree accumulator over module lattices with base-$B$ decomposition for finer trade-offs, and a message-binding technique eliminating the need for costly lattice one-time signatures.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Zero-knowledge proofs of set membership underpin privacy-preserving constructions such as ring signatures and anonymous credentials. Existing succinct constructions rely mainly on the Fiat--Shamir transform in the Random Oracle Model (ROM), while standard-model non-interactive proofs from post-quantum assumptions remain either generic and inefficient or asymptotically compact yet concretely impractical. A key obstacle is that existing lattice-based zero-knowledge systems operate over a single ambient modulus, forcing heterogeneous components to be homogenized, inflating parameters and weakening reductions.&lt;/p&gt;&lt;p&gt;We introduce the first \emph{compact lattice-based NIZK arguments for set membership in the standard model} with proof size logarithmic in the set cardinality. Our construction matches the logarithmic proof size of accumulator-based ROM constructions while achieving post-quantum security without random oracles. The main technical ingredient is a new trapdoor $\Sigma$-protocol supporting linear relations modulo multiple heterogeneous moduli, allowing such relations to be handled at their native moduli without homogenization. This yields a modular approach to compact proofs compatible with lattice accumulators.&lt;/p&gt;&lt;p&gt;As an application, we construct lattice-based ring signatures of size $O(\log R)\cdot \widetilde{O}(\lambda^{2})$ bits, improving the dependence on the security parameter $\lambda$ quadratically over the plain-model construction of Chatterjee et al. (CRYPTO~2021) while retaining optimal logarithmic dependence on the ring size $R$. Our construction is in the CRS model, which partly enables this improvement. The scheme achieves statistical anonymity and unforgeability under standard Module-LWE and Module-SIS assumptions.&lt;/p&gt;&lt;p&gt;We also develop two additional tools of independent interest: (i) a generalized Merkle-tree accumulator over module lattices with base-$B$ decomposition, enabling finer efficiency--assumption trade-offs; and (ii) a message-binding technique that removes the need for costly lattice one-time signatures in standard-model ring signatures.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Corrigendum to: Computing Optimal Ate Pairings on Elliptic   Curves with Embedding Degree 9, 15 and 27</title>
      <link>https://eprint.iacr.org/2026/1884</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1884</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1884"&gt;https://eprint.iacr.org/2026/1884&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：配对友好椭圆曲线在基于身份的加密和短签名等后密码学协议中扮演着至关重要的角色。特别是嵌入度 $k=27$ 的 BLS27 曲线，在实现256位和192位高等级安全标准时，其参数种子的精确选择直接决定了底层密码系统的安全性与有效性。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;问题指出&lt;/strong&gt;：本文是对先前关于计算嵌入度为9、15和27的椭圆曲线上最优Ate配对论文的正式勘误。经复查发现，原研究在第8节中提出的BLS27曲线种子参数存在严重的数学缺陷。具体而言，在256位和192位安全级别下，原论文公开披露的种子参数生成了合数形式的阶 $r(x)$；此外，在192位安全级别下，其特征 $p(x)$ 同样为合数。这些错误直接违反了构造配对友好曲线所必须满足的严格素性前提条件，导致原参数无法用于实际的安全密码学构造。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;更正与验证&lt;/strong&gt;：为彻底解决这一问题，本研究通过大规模且严密的穷举搜索算法，重新寻找并提供了针对256位和192位安全级别的、经过严格验证的更正种子参数。借助SageMath数学计算软件，我们对新提供的种子进行了全面的素性测试，确认在两种安全级别下，新种子生成的特征 $p(x)$ 和阶 $r(x)$ 均严格满足素数条件。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;研究结论&lt;/strong&gt;：本次勘误不仅修复了原论文中的关键参数错误，确保了BLS27曲线在高等级安全标准下的实际可用性，同时明确重申：原论文中除该部分参数错误外的所有其他理论推导、算法设计与计算结果均保持完全有效。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This corrigendum addresses critical parameter errors identified in Section 8 of our previous work concerning optimal Ate pairings on BLS27 elliptic curves (embedding degree $k=27$) at the 256-bit and 192-bit security levels. Specifically, the originally disclosed seed parameters produced a composite order $r(x)$ in both instances, and additionally yielded a composite characteristic $p(x)$ for the 192-bit seed. These flaws fundamentally violated the essential primality conditions required for constructing valid pairing-friendly curves. To rectify these issues, we provide newly verified corrected seeds for each security level, which were obtained through a rigorous and exhaustive search. Furthermore, we confirm via SageMath computations that both the characteristic $p(x)$ and the order $r(x)$ are strictly prime for all the newly proposed seeds. Finally, we emphasize that all other theoretical results, algorithms, and mathematical computations presented in the original paper remain entirely valid and unaffected by these specific parameter corrections.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We correct two errors in Section~8 of the above-mentioned paper&lt;br /&gt;concerning the seed parameters proposed for BLS27 elliptic curves&lt;br /&gt;(embedding degree $k=27$) at the $256$-bit and $192$-bit security levels.&lt;br /&gt;In both instances, the disclosed seeds produce a composite $r(x)$,&lt;br /&gt;violating the primality condition essential for constructing&lt;br /&gt;pairing-friendly curves. Additionally, for the $192$-bit seed the&lt;br /&gt;characteristic $p(x)$ is also composite. We provide verified corrected&lt;br /&gt;seeds for each security level, obtained by exhaustive search, and confirm&lt;br /&gt;with SageMath that both $p(x)$ and $r(x)$ are prime in each case.&lt;br /&gt;All other results of the original paper remain valid.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>More Efficient (Hintless) Keyword Private Information Retrieval</title>
      <link>https://eprint.iacr.org/2026/1883</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1883</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1883"&gt;https://eprint.iacr.org/2026/1883&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;关键字私有信息检索（Keyword PIR）允许客户端在隐藏查询关键字的前提下，从数据库中检索与该关键字关联的值，从而将传统的索引PIR进行了泛化。目前最先进的方案（Hao等人，USENIX 2025）存在显著局限性：首先，其通用构造需要三次调用底层索引PIR协议；其次，为降低开销而提出的结合SimplePIR与哈希表的专用设计，继承了SimplePIR庞大的客户端提示（hint），导致客户端面临高昂的每数据库存储成本；此外，该方案还允许客户端获取超出查询关键字关联值之外的信息，存在安全隐患。&lt;/p&gt;&lt;p&gt;针对上述问题，本文提出了一种新颖且实用的无提示（hintless）Keyword PIR框架。我们将Luo等人（CCS 2024）的无提示KsPIR方案扩展至关键字场景，严格确保半诚实客户端仅能检索到查询关键字所对应的值。在技术实现上，本构造利用了Peikert和Pepin（TCC 2025）的线性同态技术，并设计了大步小步法（BSGS）实现以及基于伽罗瓦理论的离线/在线分解策略，以大幅加速同态计算过程。实验结果表明，在包含高达 $2^{22}$ 条目的数据库中，当实例化相同的索引PIR方案时，我们的框架相较于通用框架实现了平均 $2.65\times$ 的在线计算加速。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Keyword Private Information Retrieval (Keyword PIR) allows clients to retrieve values associated with keywords while keeping queries private. The state-of-the-art scheme by Hao et al. (USENIX 2025) suffers from high overhead, large client-side hints causing substantial storage costs, and potential information leakage beyond the queried keyword. In this work, we propose a novel and practical hintless Keyword PIR framework to address these limitations. By extending the hintless KsPIR scheme (Luo et al., CCS 2024) to the keyword setting, our construction ensures that a semi-honest client retrieves only the value corresponding to the queried keyword. We leverage the linear homomorphic technique (Peikert and Pepin, TCC 2025) and accelerate homomorphic evaluation through a baby-step giant-step (BSGS) implementation and an offline/online decomposition based on a Galois-theoretic formulation. Experimental results demonstrate that for databases with up to $2^{22}$ entries, our approach achieves a mean online speedup of $2.65\times$ compared to the generic framework instantiated with the same index-PIR scheme.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Keyword private information retrieval (Keyword PIR) enables a client to retrieve the value associated with a keyword from a database while keeping the queried keyword private, thereby generalizing traditional private information retrieval, known as index PIR. The state-of-the-art by Hao et al. (USENIX 2025) has several limitations. First, their generic construction requires three invocations of an underlying index-PIR protocol. Second, to reduce this overhead, they propose a specialized design combining SimplePIR with hash tables. However, this approach inherits SimplePIR&amp;#x27;s large client-side hint, resulting in substantial per-database storage costs on the client side. Moreover, it allows clients to retrieve information beyond the value associated with the queried keyword.&lt;/p&gt;&lt;p&gt;In this work, we present a novel and practical Keyword PIR framework that addresses these limitations. Our construction extends the hintless KsPIR scheme of Luo et al. (CCS 2024) to the keyword setting, ensuring that a semi-honest client retrieves only the value corresponding to the queried keyword. The construction leverages the linear homomorphic technique of Peikert and Pepin (TCC 2025). To  accelerate homomorphic evaluation, we design  a baby-step giant-step (BSGS) implementation and an  offline/online decomposition  based on a Galois-theoretic formulation. Experimental results show a mean online speedup of $2.65\times$ over the generic framework when instantiated with the same index-PIR scheme, for databases containing up to $2^{22}$ entries.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>A Reproducible Security–Performance Benchmark Protocol for Lightweight AEAD on Resource-Constrained IoT Nodes</title>
      <link>https://eprint.iacr.org/2026/1882</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1882</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1882"&gt;https://eprint.iacr.org/2026/1882&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景&lt;/strong&gt;：物联网（IoT）节点在计算能力、内存和电池容量等资源受限的条件下，亟需可靠的数据安全保护机制。2025年8月，美国国家标准与技术研究院（NIST）正式发布SP 800-232标准，将Ascon系列确立为受限设备的轻量级加密标准。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法&lt;/strong&gt;：本文提出了&lt;strong&gt;ASCON-Edge协议&lt;/strong&gt;，这是一套用于在资源受限IoT节点上可重复评估标准化Ascon-AEAD128算法的安全性、性能、内存开销及直接能耗的基准测试协议。该协议在严格控制消息大小、关联数据、计时边界及构建条件等变量的前提下，将Ascon-AEAD128与AES 128-GCM及ChaCha20-Poly1305进行公平对比。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;创新点&lt;/strong&gt;：ASCON-Edge定义了确定性工作负载、Nonce唯一性与重放策略、硬件冻结记录、原始数据字段及直接能耗计算规则等核心规范，并明确界定了AEAD算法的底层安全保证与应用层在防重放及密钥管理方面的责任边界。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与定位&lt;/strong&gt;：作为一篇方法论与可重复性研究论文，本研究基于针对性的文献综述，构建了面向最终标准和工作负载感知的对比框架。论文详细报告了确定性的数据包格式开销，但严谨地声明：在硬件平台冻结和原始数据公开前，不提前声称具体的硬件基准测量结果，从而确保了评估体系的严谨性与高度可复现性。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;To address the stringent resource constraints of IoT nodes and align with the newly finalized NIST SP 800-232 standard, this paper introduces &lt;strong&gt;ASCON-Edge&lt;/strong&gt;, a highly reproducible benchmark protocol for evaluating the standardized Ascon-AEAD128 algorithm. The protocol rigorously compares Ascon-AEAD128 against AES 128-GCM and ChaCha20-Poly1305 under strictly controlled variables, comprehensively defining deterministic workloads, nonce uniqueness policies, hardware-freeze records, and direct-energy measurement rules. Furthermore, it clearly delineates the critical boundaries between inherent AEAD security guarantees and application-layer responsibilities for replay prevention and key management. As a methodology-focused study, ASCON-Edge accurately reports deterministic packet-format overheads while deliberately refraining from claiming specific hardware benchmark results prior to platform freezing and raw data availability. Ultimately, this work establishes a robust, workload-aware framework to ensure rigorous and reproducible security-performance evaluations for lightweight cryptography in constrained environments.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;—Internet-of-Things (IoT) nodes must protect sensed&lt;br /&gt;data while operating with limited processing capability, memory,&lt;br /&gt;and battery capacity. In August 2025, the National Institute of&lt;br /&gt;Standards and Technology (NIST) finalized SP 800-232, which&lt;br /&gt;standardizes the Ascon family for constrained devices. This paper&lt;br /&gt;presents ASCON-Edge, a reproducible protocol for evaluating the&lt;br /&gt;security, performance, memory cost, and directly measured energy&lt;br /&gt;cost of standardized Ascon-AEAD128 on resource-constrained&lt;br /&gt;IoT nodes. The protocol compares Ascon-AEAD128 with AES&lt;br /&gt;128-GCM and ChaCha20-Poly1305 using identical message&lt;br /&gt;sizes, associated data, timing boundaries, build conditions, and&lt;br /&gt;security tests. It defines a deterministic workload, a nonce&lt;br /&gt;uniqueness and replay policy, a hardware-freeze record, raw-data&lt;br /&gt;fields, statistical summaries, direct-energy rules, and functional&lt;br /&gt;acceptance criteria. It also separates AEAD guarantees from&lt;br /&gt;application-layer responsibilities for replay prevention and key&lt;br /&gt;handling. A targeted literature synthesis motivates a final-standard,&lt;br /&gt;workload-aware comparison protocol. This is a methodology&lt;br /&gt;and reproducibility paper: it reports deterministic packet-format&lt;br /&gt;overhead, but deliberately does not claim hardware benchmark&lt;br /&gt;measurements before a frozen platform and raw data are available.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Private Quantised Neural Network Inference</title>
      <link>https://eprint.iacr.org/2026/1880</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1880</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1880"&gt;https://eprint.iacr.org/2026/1880&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景&lt;/strong&gt;：基于神经网络的机器学习模型广泛应用于各类分类任务，但模型使用过程中的隐私泄露问题亟待解决。在模型所有者与使用者分离的场景中，直接共享模型参数会暴露商业机密或训练数据，而共享查询及结果则可能泄露用户的敏感信息。因此，必须采用安全多方计算（MPC）等技术实现隐私保护推理。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：本文提出了一种用于神经网络私有推理的新型协议，并在Sharemind MPC框架内进行评估。该协议基于PyTorch的逐张量量化方案，将浮点参数映射为8位整数，在提升计算效率的同时实现了与PyTorch训练模型的无缝互操作。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;技术细节&lt;/strong&gt;：研究扩展了针对量化权重的常量轮整数卷积和矩阵乘法协议，提出了数值重新量化的常量轮协议，并深入分析了实现高效重新量化的最优秘密共享位宽。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要结果&lt;/strong&gt;：实验表明，在局域网（LAN）环境下，所提协议在VGG16图像分类网络上的摊销吞吐量达到每张图像24.3秒，充分验证了该方法的高效性与实用性。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Privacy-preserving neural network inference&lt;/strong&gt; is critical to protect both model owners&amp;#x27; intellectual property and users&amp;#x27; sensitive query data from leakage during collaborative machine learning. To address this challenge, we propose efficient private inference protocols integrated within the Sharemind MPC framework. Our approach leverages PyTorch&amp;#x27;s per-tensor quantization scheme to map floating-point parameters to 8-bit integers, significantly enhancing computational efficiency while maintaining seamless interoperability with pre-trained models. Specifically, we extend constant-round integer convolution and matrix multiplication protocols for quantized weights, introduce novel constant-round re-quantization protocols, and systematically analyze the optimal secret share bit-width to maximize performance. Experimental evaluations demonstrate that our protocols achieve an amortized throughput of 24.3 seconds per image classification for the VGG16 network in a LAN setting. This establishes a strong baseline for deploying secure and resource-efficient quantized machine learning models in privacy-sensitive environments.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Neural networks based machine learning models are used in many classification problems yet privacy issues in model usage are mostly unresolved. When a model owner provides their model to other parties for inference, either the model owner has to share the parameters of the model or the model user must share their query and result with the model owner. Depending on the usage scenario, the user’s query or query result could contain sensitive information that the model provider should not see. And on the other hand, the model parameters themselves could be a valuable business secret or leak private training data. In such cases, neural network inference must be performed in a privacy preserving manner, for example, using secure multi-party computation (MPC).&lt;/p&gt;&lt;p&gt;We propose protocols for the private inference of neural networks and evaluate them within the Sharemind MPC secure computation framework. Our protocols are based on the per-tensor quantisation scheme in PyTorch which maps floating point model parameters to 8-bit integer values. Quantisation improves the efficiency of our protocols and our protocols are interoperable with models trained using PyTorch. We extend constant round integer convolution and matrix multiplication protocols for quantised model weights, propose constant round protocols for re-quantising values and analyse the optimal secret share bit width for efficient re-quantisation. The resulting protocols are used to evaluate the VGG16 image classification network with an amortised throughput of 24.3 s per image classification in a LAN setting.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Peel and Vote: A Paper Ballot Design for Publicly Verifiable Risk-Limiting Audits</title>
      <link>https://eprint.iacr.org/2026/1879</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1879</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1879"&gt;https://eprint.iacr.org/2026/1879&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景与问题&lt;/strong&gt;：选后风险限制审计（RLA）通过手工计票随机抽取的纸质选票来提供选举结果的统计保证。然而，传统RLA假设选票在存储期间未被篡改，选民无法验证此假设。现有框架虽尝试使审计可验证，但要求公众信任选举当局（EA）诚实抽样和正确解释选票，且需要选票与数字记录一对一映射。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：为解决上述局限，本文提出首个可验证的批次级RLA方案——“撕纸投票”（Peel and Vote）设计。该方案将信任锚从EA直接转移至选民，以选票批次为单位操作，消除了个体追踪障碍。选民通过撕下带有预印密码的选票副联来选择候选人并保留作为收据，相同密码同步发布在公告板上。同一批次内的选票在密码学上相关联，并在选前随机分配至各选区。当批次内所有密码公布后，任何人皆可独立计算该批次的计票结果，实现“自计票”特性，将全国大选转化为多个小型自计票选举。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现&lt;/strong&gt;：基于美国历史选举数据，当选票丢失率低于0.5%时，若批次大小为100，该方案能对61%的随机选票进行计票验证；批次大小为200时，验证比例达37%。这远高于传统RLA通常0.01%-0.3%的抽样覆盖率。这一显著提升得益于审计已作为“始终开启”的核心功能直接内置于纸质选票的物理设计中。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;: Post-election Risk-Limiting Audits (RLAs) ensure election integrity but traditionally rely on trusting the Election Authority for ballot storage and sampling, requiring a strict 1-to-1 ballot-to-record mapping. &lt;strong&gt;Method&lt;/strong&gt;: To address these limitations, we propose &amp;quot;Peel and Vote,&amp;quot; the first verifiable batch-level RLA scheme that shifts the trust anchor to voters through a novel paper ballot with removable cryptogram flaps, enabling anyone to independently compute batch tallies and achieve a self-tallying property. &lt;strong&gt;Results&lt;/strong&gt;: Based on US historical data with ballot loss rates below 0.5%, our scheme enables tally verification for 61% of ballots (batch size 100) or 37% (batch size 200). &lt;strong&gt;Conclusion&lt;/strong&gt;: These results substantially outperform the 0.01-0.3% coverage of traditional RLAs by embedding auditing directly into the physical ballot design as an always-on feature.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Post-election Risk-Limiting Audits (RLAs) provide statistical guarantees of election outcomes by hand-counting randomly selected paper ballots. However, standard RLAs assume that ballots remain unaltered in storage between election day and the audit, but voters cannot verify this assumption. Prior frameworks, such as VAULT (E-VOTE-ID 2019), attempt to make the audit process verifiable, but they require the public to trust the Election Authority (EA) to honestly sample ballots at random and correctly interpret the voters&amp;#x27; choices into cryptographic commitments. Furthermore, they are typically ballot-level, requiring a 1-to-1 mapping between individual paper ballots and digital records. The EA also needs to interactively open commitments during the audit. To address these limitations, we propose the first verifiable batch-level RLA scheme, which shifts the trust anchor from the EA directly to the voter and operates on groups of ballots (batches) to eliminate individual tracking hurdles. Our scheme introduces a peel-and-vote paper ballot design with removable flaps containing pre-printed cryptograms. A voter selects a candidate by removing the corresponding flap, and retains the flap as a receipt, while the same cryptogram printed on the receipt is also published on a bulletin board. In our scheme, a batch contains a group of cryptographically related ballots that are randomly distributed across the precincts before the election. Once all cryptograms in a batch are published, anyone can independently compute the tally for that batch, achieving a self-tallying property. Intuitively, our scheme transforms a national-scale election into many smaller self-tallying elections: one for each batch. Based on historical US election data, we show that when the ballot loss rates remain below 0.5%, the scheme enables tally verification for 61% of randomly selected ballots with a batch size of 100, or 37% with a batch size of 200. These figures are substantially higher than the 0.01-0.3% sampling coverage typically achieved in RLAs. This improvement stems from the fact that auditing is built directly into the paper ballot design in our scheme as an always-on feature, rather than being treated as an optional manual post-election process.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>On the Round Complexity of Early Stopping</title>
      <link>https://eprint.iacr.org/2026/1878</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1878</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1878"&gt;https://eprint.iacr.org/2026/1878&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景&lt;/strong&gt;：在密码学与分布式计算领域，早期停止拜占庭协议（esBA）的轮数复杂度仅依赖于&lt;em&gt;实际&lt;/em&gt;故障方数量 $f$ 而非潜在故障上限 $t$。尽管尚未完全落地，但其在区块链等大规模系统中的巨大潜力近期引发了研究热潮，推动了多项突破性成果。然而，随着理论向实践推进，现有模型和定义中的隐患逐渐显现。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现&lt;/strong&gt;：本研究在推进esBA可行性问题的过程中，发现现有文献在计算同步协议轮数复杂度时存在严重的不一致性。具体而言，许多esBA协议的最后一轮中，参与方在发送消息后即可终止，无需等待接收该轮消息。对于“这是否应计为一个完整的通信轮次”，不同文献给出了不同的答案，这种计算标准的模糊直接影响了协议轮数界限声称的紧密性与准确性。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：为解决这一争议，本文提出了一种细粒度且直观的同步轮数计算新范式。该范式明确区分了“既发送又接收消息”的完整交互轮次与“仅需发送消息”的单向发送轮次。通过这一全新视角重新审视现有文献，本文不仅揭示了以往研究中的逻辑空白与未解之谜，还成功填补了这些理论缺口，并提出了多项新结果，进一步完善和扩展了esBA及同步协议轮数复杂性的研究版图。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background &amp;amp; Findings&lt;/strong&gt;: Early-stopping Byzantine Agreement (esBA) protocols, whose round complexity depends on the actual number of faulty parties rather than the upper bound, hold significant promise for large-scale systems like blockchains. However, our investigation reveals critical inconsistencies in the existing literature regarding how the round complexity of such synchronous protocols is computed, particularly concerning whether the final round—where parties terminate immediately after sending messages without waiting to receive—should be counted as a full round.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Methodology &amp;amp; Contributions&lt;/strong&gt;: To resolve these ambiguities, we propose a fine-grained, intuitive methodology for counting synchronous rounds that explicitly distinguishes between full rounds (sending and receiving) and send-only rounds. By re-evaluating existing literature through this novel lens, we expose previously overlooked gaps and open questions. Ultimately, we resolve these theoretical gaps and extend the landscape of esBA feasibility with several new results, providing a unified and rigorous framework for analyzing round complexity.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;A common pipeline of cryptographic research is: a theory paper asks an interesting question which triggers a line of works; then the problem remains dormant until technology catches up and makes the problem potentially relevant for practice; this triggers a renewed interest which at times pushes the originally theoretical ideas to practice. Several highly influential ideas have followed this pipeline: e.g., the original work on Oblivious RAMs by Goldreich and Ostrovsky [STOC&amp;#x27;87\&amp;amp;90],  polynomial commitments by Kate, Zaverucha, and Goldberg [ASIACRYPT&amp;#x27;10], and many others. A problem that shows early signs of this pattern is early-stopping Byzantine Agreement (esBA): esBA protocols whose round complexity depends on the number $f$ of {\em actually} faulty parties rather than on (an upper bound on) the number $t$ of {\em potentially} faulty parties. Although it is fair to say that esBA protocols are not (yet) within the practical realm, their potential to improve large scale distributed systems like blockchain ledgers has fueled a number of recent novel results pushing the envelope in esBA feasibility (e.g., Loss and Nielsen [EUROCRYPT&amp;#x27;24] and Elsheimy, Loss, and Papamanthou [ASIACRYPT&amp;#x27;24]).&lt;/p&gt;&lt;p&gt;The original starting point of this work has been to advance on the above feasibility questions. But as is common for problems following this trajectory, renewed interest often comes with observations about issues in the assumed definitions and models. Interestingly, our investigation revealed an issue with how the existing literature has been computing the round complexity of such protocols, which yields (previously unobserved) inconsistencies in the  literature of esBA and more generally of synchronous protocols. In a nutshell, the inconsistencies stem from the fact that the last round of several esBA protocols has parties terminating as soon as they send a message to other parties, i.e., they don&amp;#x27;t need to wait to receive messages sent to them in that round. So, should we count this as an extra round or not? As we observe, different works give different answers to this question, and the answer one adopts affects the claimed tightness of the corresponding bounds.&lt;/p&gt;&lt;p&gt;Building on the above observation, our work proposes a fine-grained manner of counting synchronous rounds that is both intuitive and resolves these inconsistencies. In a nutshell, our counting distinguishes between rounds in which parties might both send and receive messages, and rounds in which parties only need to send messages. Examining the existing literature through the lens of this round-counting methodology exposes gaps and new open questions in the relevant literature. We resolve these gaps and extend the landscape by several new results.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Otter: A Provably MEV-Resilient Automated Market Maker via Surplus Redistribution</title>
      <link>https://eprint.iacr.org/2026/1877</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1877</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1877"&gt;https://eprint.iacr.org/2026/1877&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景与问题&lt;/strong&gt;：自动做市商（AMM）中的矿工可提取价值（MEV）允许区块构建者通过交易排序和注入交易获利，这不仅增加了用户成本，还加剧了构建者的中心化。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;提出方法&lt;/strong&gt;：本文提出 &lt;strong&gt;Otter&lt;/strong&gt;（具有盈余再分配的最优真实交易），一种双资产批量 AMM。Otter 的核心创新在于引入了“&lt;strong&gt;盈余再分配&lt;/strong&gt;”范式。与传统 AMM 将输出代币全部分配给当前批次用户不同，Otter 允许将任何剩余盈余转移至由去中心化社区治理的智能合约中。这些累积的盈余可用于补贴交易费、奖励流动性提供者或返还至资金池以降低未来交易者的滑点，从而从根本上防止剩余盈余被捕获为 MEV。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与理论保证&lt;/strong&gt;：研究表明，在共识层提供抗审查性且区块空间不拥堵的前提下，Otter 能够实现可证明的 MEV 弹性。在该机制下，诚实行为成为用户和构建者的占优策略。即使构建者本身是拥有内在价值的交易者，也无法通过重新排序出价或注入女巫（Sybil）出价来获利。此外，Otter 在满足所需博弈论属性的机制类中实现了社会福利的最大化。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;创新点与结论&lt;/strong&gt;：本文还通过不可能性定理证明了共识层抗审查性的必要性：若构建者具备审查交易的能力，上述博弈论保证将无法实现。这一结果在数学上严谨地展示了共识层的安全保证如何从根本上拓展应用层（智能合约）的能力边界。最后，研究还刻画了与这些激励保证相兼容的构建者费用结构。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Miner Extractable Value (MEV) in automated market makers (AMMs) allows block builders to profit from transaction ordering, imposing costs on users. We introduce &lt;strong&gt;Otter&lt;/strong&gt;, a two-asset batch AMM that achieves provable MEV resilience by introducing a novel paradigm called &lt;strong&gt;surplus redistribution&lt;/strong&gt;. Instead of distributing all output tokens to current batch users, Otter redirects residual surplus to the broader community, preventing it from being captured as MEV.&lt;/p&gt;&lt;p&gt;Under the assumptions of censorship-resilient consensus and uncongested block space, Otter makes truthful behavior a dominant strategy for both users and builders. Consequently, builders cannot profit from strategic deviations like reordering or injecting sybil bids, even if they are traders with intrinsic value. Furthermore, Otter maximizes social welfare within its class of mechanisms. We also provide an impossibility result demonstrating that consensus-level censorship resilience is strictly necessary for these guarantees, formally showing how consensus security expands application-layer capabilities. Finally, we characterize compatible builder fee structures.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Miner extractable value (MEV) in automated market makers allows block builders to profit from transaction ordering and injected trades, imposing costs on users and contributing to builder centralization. We introduce Otter (Optimal Truthful Trading with Excess Redistribution), a two-asset batch AMM that achieves provable MEV resilience when the consensus layer provides censorship resilience and block space is uncongested. In particular, Otter makes truthful behavior a dominant strategy for both users and builders. Consequently, a builder cannot profit from strategic deviations, including reordering bids or injecting sybil bids. These guarantees continue to hold even when the builder is itself a trader with intrinsic value. Moreover, we show that our mechanism maximizes social welfare, in a strong sense, within a natural class of mechanisms satisfying the desired game-theoretic properties.&lt;/p&gt;&lt;p&gt;To achieve these guarantees, we introduce a new paradigm called surplus redistribution, which provably prevents residual surplus from being captured as MEV by redirecting it to the broader community. Specifically, the pool&amp;#x27;s output tokens need not be distributed entirely among the users in the current batch. Instead, any residual surplus may be transferred, for example, to a smart contract governed by the decentralized community. The accumulated surplus can subsequently be used to benefit community members in ways that preserve the mechanism&amp;#x27;s game-theoretic guarantees --- for example, by subsidizing traders&amp;#x27; transaction fees, rewarding liquidity providers, or returning assets to the pool to reduce price impact and slippage for future traders.&lt;/p&gt;&lt;p&gt;Our approach relies on the underlying consensus layer to provide censorship resilience. We motivate the necessity of this assumption through an impossibility result showing that the desired game-theoretic guarantees become unattainable when the builder is additionally allowed to censor transactions. Thus, our results also provide a mathematically formal demonstration of how consensus-level security guarantees can fundamentally expand what is achievable at the application (i.e., smart-contract) layer. Finally, we establish additional results characterizing the builder fee structures compatible with our desired incentive guarantees.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>AH-BKZ: A Lattice Reduction Algorithm with Asynchronous Hybrid Processing</title>
      <link>https://eprint.iacr.org/2026/1876</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1876</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1876"&gt;https://eprint.iacr.org/2026/1876&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;评估最短向量问题（SVP）的求解难度对于基于格的密码学参数选择至关重要。目前最快的SVP求解器基于G6K算法变体，但其巨大的内存消耗成为主要瓶颈，限制了高维实例的求解。为缓解这一内存瓶颈，通常采用在基于筛法的算法前进行强基约化预处理的策略。Wang等人优化的ProPnjBKZ算法是目前极具前景的预处理方法。然而，本文发现，在基于ProPnjBKZ的SVP求解流程中，由于预处理阶段所需内存远小于后续的高维筛法过程，导致计算资源在预处理阶段未能被充分利用。&lt;/p&gt;&lt;p&gt;基于此观察，本文提出了一种名为 &lt;strong&gt;AH-BKZ&lt;/strong&gt; 的新型格基约化算法。该算法采用&lt;strong&gt;异步混合处理&lt;/strong&gt;机制，通过异步调度并运行多个SVP预言机（oracles），充分挖掘并利用预处理阶段闲置的计算资源，从而显著加速基约化过程。&lt;/p&gt;&lt;p&gt;实验结果表明，在124至148维 comparable 峰值内存约束下，与传统的ProPnjBKZ预处理相比，AH-BKZ在成功运行的实例中平均将总运行时间缩短了 &lt;strong&gt;18.6%&lt;/strong&gt;，最高降幅达 &lt;strong&gt;23.1%&lt;/strong&gt;。此外，在更大规模的计算环境补充实验中，AH-BKZ成功打破了 &lt;strong&gt;TU Darmstadt SVP Challenge 的163维&lt;/strong&gt;求解记录，以及 &lt;strong&gt;Ideal Lattice Challenge 的164维&lt;/strong&gt;求解记录，展现了其在高维格密码分析中的卓越性能。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;Evaluating the hardness of the Shortest Vector Problem (SVP) is crucial for lattice-based cryptography. While G6K-based solvers are currently the fastest, their high memory consumption restricts high-dimensional executions. Strong basis reduction preprocessing, such as ProPnjBKZ, is commonly used to mitigate this memory bottleneck. However, we observe that computational resources remain underutilized during the ProPnjBKZ preprocessing phase, as it requires significantly less memory than the subsequent sieving process.&lt;/p&gt;&lt;p&gt;To address this inefficiency, we propose &lt;strong&gt;AH-BKZ&lt;/strong&gt;, a novel lattice reduction algorithm featuring &lt;strong&gt;Asynchronous Hybrid Processing&lt;/strong&gt;. By asynchronously executing multiple SVP oracles, AH-BKZ effectively exploits the idle computational resources during preprocessing to accelerate basis reduction. Extensive experiments demonstrate that, under comparable peak memory constraints for dimensions 124 to 148, AH-BKZ reduces the overall runtime by up to 23.1%, with an average reduction of 18.6% in successful runs compared to ProPnjBKZ-based preprocessing. Furthermore, in a larger computational environment, AH-BKZ establishes new solving records for dimension 163 in the TU Darmstadt SVP Challenge and dimension 164 in the Ideal Lattice Challenge, highlighting its superior performance in high-dimensional lattice cryptanalysis.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Evaluating the hardness of the Shortest Vector Problem (SVP) is essential for selecting secure parameters in lattice-based cryptography. The fastest current SVP solvers are based on variants of G6K, but their large memory consumption remains a major bottleneck, making high-dimensional executions difficult. A common strategy for alleviating this memory bottleneck is strong basis reduction preprocessing before a sieve-based algorithm. This strategy can solve SVP instances in higher dimensions than standalone G6K under the same memory constraints, but the time required for basis reduction becomes a major issue. ProPnjBKZ, a fast basis reduction algorithm optimized by Wang et al., is currently used as a promising preprocessing method for solving high-dimensional SVP instances. In this paper, we identify that, in the ProPnjBKZ-based SVP-solving pipeline, memory resources can remain underutilized during the preprocessing phase, since ProPnjBKZ requires less memory than the subsequent high-dimensional sieving process. Based on this observation, we propose AH-BKZ, which exploits such unused computational resources by asynchronously running multiple SVP oracles, thereby accelerating basis reduction. Our experiments show that, compared with ProPnjBKZ-based preprocessing, AH-BKZ reduces the overall runtime by up to 23.1% and by 18.6% on average among successful runs for dimensions 124-148 under comparable peak memory constraints. Moreover, in a supplementary experiment conducted in a larger computational environment, AH-BKZ set new solving records for dimension 163 in the TU Darmstadt SVP Challenge and for dimension 164 in the Ideal Lattice Challenge.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Constant-Time Conditions for Left-to-Right Scalar Multiplication</title>
      <link>https://eprint.iacr.org/2026/1881</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1881</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1881"&gt;https://eprint.iacr.org/2026/1881&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;研究背景与目的&lt;/strong&gt;&lt;br /&gt;本文深入研究了椭圆曲线密码学中从左至右（即从最高有效位到最低有效位）处理标量位的标量乘法实现方法。在侧信道攻击日益严峻的背景下，消除标量乘法过程中点加和倍点操作可能引发的计算异常，是实现常数时间执行并有效防御时序攻击的核心关键。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与条件&lt;/strong&gt;&lt;br /&gt;本文详细剖析了这些异常的产生机制，并严格推导和确立了使得异常仅在最后一次加法操作中出现或完全不出现的充分条件。基于这些理论条件，开发者可以全程采用无需任何异常处理的快速公式来完成所有倍点及中间加法操作，从而确保算法具备严格的常数时间特性。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与创新&lt;/strong&gt;&lt;br /&gt;在此基础上，本文重点考察了Comb方法的三种具体变体：SAB-Set、LSB-Set和MSB-Set。理论证明表明，在对基点阶数和Comb参数施加温和限制的前提下，这三种变体均能完全满足上述常数时间条件。此外，作为本文的一项重要创新，我们针对SAB-Set变体专门提出了一种高效且便捷的标量重编码算法。本研究不仅为构建安全、高效的椭圆曲线常数时间标量乘法算法提供了坚实的理论基础，也为实际密码工程中的安全实现提供了实用的设计指导。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper investigates left-to-right scalar multiplication methods on elliptic curves, specifically focusing on eliminating point addition and doubling exceptions to achieve strict constant-time execution and effectively thwart timing attacks. By analyzing the underlying mechanisms of these exceptions, we establish rigorous mathematical conditions under which they occur only at the final addition step or are entirely avoided. Guided by these conditions, developers can seamlessly employ fast, exception-free formulas for all intermediate doublings and additions. Furthermore, we systematically examine three specific variants of the Comb method—namely SAB-Set, LSB-Set, and MSB-Set—and formally prove that all three variants satisfy the proposed constant-time conditions under mild restrictions on the base point order and Comb parameters. Finally, as a key practical contribution, we introduce a novel and highly convenient scalar recoding algorithm specifically designed for the SAB-Set variant, thereby providing a robust theoretical foundation and practical guidelines for secure cryptographic implementations.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We consider methods for scalar multiplication on an elliptic curve where the scalar digits are processed from left to right, that is, from most significant to least significant. We analyze exceptions that may arise during point addition and doubling throughout the multiplication. Eliminating such exceptions is critical for achieving constant-time execution and preventing timing attacks. We establish conditions under which exceptions occur only at the final addition or not at all. Guided by these conditions, one can ensure constant-time behavior by performing all doublings and all intermediate additions using fast formulas that require no exception handling. We examine three variants of the Comb method: SAB-Set, LSB-Set, and MSB-Set. For all three variants, we prove that the constant-time conditions are satisfied under mild restrictions on the base point order and Comb parameters. Additionally, we propose a convenient scalar recoding algorithm for the SAB-Set variant.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Anonymous Attribute-Based Signcryption: Definitions, Constructions, and Applications</title>
      <link>https://eprint.iacr.org/2026/1861</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1861</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1861"&gt;https://eprint.iacr.org/2026/1861&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文提出了一种属性基签密的泛化概念，称为匿名属性基签密（A$^2$BSC）。除了消息机密性和密文不可伪造性外，A$^2$BSC 还要求&lt;strong&gt;密文匿名性&lt;/strong&gt;，即无论解密结果如何，均不泄露签名加密者的属性或密文相关的属性/策略信息。&lt;/p&gt;&lt;p&gt;首先，我们在&lt;strong&gt;统一框架&lt;/strong&gt;下建立了 A$^2$BSC 的语法和安全概念，涵盖了多种变体（如密钥策略、密文策略、双策略以及称为 Special A$^2$BSC 的分层双策略变体）。其次，在标准模型下，基于简洁容错学习（sLWE）和基增短整数解（BASIS）假设，为&lt;strong&gt;一般策略&lt;/strong&gt;（建模为有界深度布尔电路）构造了 Special A$^2$BSC 方案，从而实现了&lt;strong&gt;后量子安全性&lt;/strong&gt;。这自然地产生了基于格的密文策略和双策略 A$^2$BSC 实例。&lt;/p&gt;&lt;p&gt;此外，本文探讨了 A$^2$BSC 在匹配加密（ME）和安排匹配加密（AME）中的应用。作为副产品，我们给出了对抗无界共谋的&lt;strong&gt;任意策略&lt;/strong&gt; ME 和 AME 的通用构造，并将 (A)ME 的 CPA 隐私性增强至 &lt;strong&gt;CCA 安全性&lt;/strong&gt;。由于 A$^2$BSC 原生提供 CCA 安全，这一增强在我们的构造中是自然获得的。总体而言，我们的新方案为构建高级原语 (A)ME 提供了多样化的方法，显著丰富了复杂访问控制环境下的安全通信工具。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper introduces Anonymous Attribute-Based Signcryption (A$^2$BSC), a novel generalization that ensures ciphertext anonymity alongside message confidentiality and unforgeability, preventing any leakage of the signcryptor&amp;#x27;s attributes or underlying policies regardless of the decryption outcome. We first establish a unified syntax and security framework encompassing multiple A$^2$BSC variants, and then construct a post-quantum secure Special A$^2$BSC scheme for general policies modeled as bounded-depth Boolean circuits, relying on standard lattice assumptions. Furthermore, we demonstrate the broad expressiveness of A$^2$BSC by applying it to Matchmaking Encryption (ME) and Arranged ME, yielding generic constructions for arbitrary policies resilient against unbounded collusions. Notably, because A$^2$BSC natively provides chosen-ciphertext attack (CCA) security, our approach inherently and effortlessly upgrades the privacy of (A)ME from CPA to full CCA security. These contributions significantly enrich the toolkit for secure and private communication in complex access-control environments.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We put forward a generalization of attribute-based signcryption, called anonymous attribute-based signcryption (A$^2$BSC). Beyond message confidentiality and ciphertext unforgeability, A$^2$BSC further requires \textit{ciphertext anonymity}: no information about the signcryptor&amp;#x27;s attributes or ciphertext-related attributes/policies is leaked, regardless of the decryption outcome.&lt;/p&gt;&lt;p&gt;Specifically, we begin by establishing the syntax and security notions for A$^2$BSC within a \textit{unified} framework, which encompasses various variants (key-policy, ciphertext-policy, dual-policy, and a hierarchical dual-policy variant called Special A$^2$BSC). Then, we construct a Special A$^2$BSC scheme for \textit{general policies} (modeled as bounded-depth Boolean circuits) from the succinct learning with errors and the basis-augmented short integer solution assumptions in the standard model, hence achieving post-quantum security. This naturally yields lattice-based instantiations of both ciphertext-policy and dual-policy A$^2$BSC.&lt;/p&gt;&lt;p&gt;Beyond its independent interest, we also show the expressiveness and generality of our A$^2$BSC by exploring its application to matchmaking encryption (ME) and arranged matchmaking encryption (AME) proposed by Ateniese et al. (Crypto &amp;#x27;19). As a byproduct, we give generic constructions of both ME and AME for \textit{arbitrary policies} against unbounded collusions, and strengthen the CPA-privacy of (A)ME to achieve CCA security. The latter is achieved for free in our construction, as A$^2$BSC natively provides CCA security. Overall, our new solution adds to the diversity of methods for building the advanced primitive (A)ME.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>(Im)possibility of Asynchronous MPC with Honest Majority over Blockchains</title>
      <link>https://eprint.iacr.org/2026/1860</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1860</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1860"&gt;https://eprint.iacr.org/2026/1860&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文研究了区块链混合模型下的异步可验证秘密共享（AVSS）与异步多方计算（AMPC）。在该模型中，参与方可黑盒访问仅提供持久性和最终活跃性的理想异步区块链功能。受隐私支付和阈值钱包等区块链应用部署MPC的启发，本文探讨了区块链的引入能否突破经典AMPC中 $n &amp;gt; 3t$（$n$为总参与方数，$t$为被控制方数）的弹性界限。我们在三种密码学设定（无可信设置、基于Minicrypt假设的可信设置、基于公钥假设的可信设置）下给出了全面的上下界。&lt;/p&gt;&lt;p&gt;主要发现如下：首先，在无可信设置或Minicrypt假设下，AMPC的经典弹性界限是固有的，即使面对较弱的故障停止或遗漏敌手，当 $n \leq 3t$ 时AMPC依然不可能实现。其次，在 $2t &amp;lt; n \leq 3t$ 的中间区间，我们证明了AVSS与AMPC的分离性：面对故障停止敌手，无需设置即可实现AVSS；面对拜占庭敌手，在Minicrypt假设及可信设置下亦可实现AVSS，而这在AMPC中均不可行。&lt;/p&gt;&lt;p&gt;最后，在基于公钥假设和可信设置的条件下，我们成功构造了一个在 $n &amp;gt; 2t$ 时能容忍拜占庭敌手的AMPC协议。该协议结合了阈值同态加密、阈值签名、承诺及零知识证明，将链上通信降至最低，实现了独立于电路大小的区块链通信复杂度。此外，我们还定义了一种适用于区块链混合模型中大消息的高效公共子集共识原语，对安全分布式计算系统具有重要的独立参考价值。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper investigates asynchronous verifiable secret sharing (AVSS) and asynchronous multi-party computation (AMPC) in the blockchain-hybrid model, exploring whether blockchain access can overcome the classical resilience bound of $n &amp;gt; 3t$. We establish comprehensive bounds across three cryptographic settings, demonstrating that the classical bound for AMPC remains inherent without public-key assumptions, even against weak adversaries. However, we reveal a separation between AVSS and AMPC in the intermediate regime $2t &amp;lt; n \leq 3t$, where AVSS becomes feasible under weaker conditions. Crucially, under public-key assumptions with a trusted setup, we construct a novel AMPC protocol tolerating Byzantine adversaries for $n &amp;gt; 2t$ by leveraging threshold cryptography and zero-knowledge proofs to achieve circuit-independent on-chain communication complexity. Furthermore, we introduce an efficient agreement on a common subset primitive for large messages, which holds independent interest for secure distributed computing.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;This work studies asynchronous verifiable secret sharing (AVSS) and asynchronous multi-party computation (AMPC) in the blockchain-hybrid model, where parties have black-box access to an ideal (asynchronous) blockchain functionality providing only persistence and eventual liveness. Motivated by the practical deployment of MPC in blockchain applications such as privacy-preserving payments and threshold wallets, we investigate whether blockchain access can improve the classical resilience bound of $n &amp;gt; 3t$, where $n$ is the total number of parties, and $t$ is the number of parties that can be compromised by an adversary. In particular, in the blockchain-hybrid model, we provide a comprehensive set of lower and upper bounds across three cryptographic settings: (i) no trusted setup, (ii) trusted setup with Minicrypt assumptions, (iii) trusted setup with public-key assumptions.&lt;/p&gt;&lt;p&gt;1. We show that without a trusted setup, or under Minicrypt assumptions, even with a setup, the classical resilience bound for AMPC is inherent: AMPC is impossible for $n \leq 3t$, even against weaker fail-stop or omission adversaries.&lt;/p&gt;&lt;p&gt;2. We establish separations between AVSS and AMPC in the intermediate regime $2t &amp;lt; n \leq 3t$: against a fail-stop adversary, unlike AMPC, AVSS is possible for $n&amp;gt;2t$ without any setup. Moreover, against a Byzantine adversary, again unlike AMPC, AVSS is possible for $n&amp;gt;2t$ under Minicrypt assumptions with a setup.&lt;/p&gt;&lt;p&gt;3. In contrast, under public-key assumptions with trusted setup, we construct an AMPC protocol tolerating Byzantine adversaries whenever $n&amp;gt;2t$. Our protocol leverages threshold homomorphic encryption, threshold signatures, commitments, and zero-knowledge proofs to minimize on-chain communication, achieving blockchain communication complexity independent of the circuit size. In the process, we define an efficient agreement on a common subset primitive for large messages in the blockchain-hybrid model, which can be of independent interest for secure distributed computing systems.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Finding a Shortest Vector and More in $2^{n/2+o(n)}$ Time using $q$-ary Coset Difference Tree</title>
      <link>https://eprint.iacr.org/2026/1859</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1859</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1859"&gt;https://eprint.iacr.org/2026/1859&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本文提出了一种求解格（Lattice）中精确最短向量问题（SVP）的全新随机算法。在格密码学领域，SVP和最近向量问题（CVP）是评估密码系统安全性的核心计算难题。针对 $n$ 维格 $\mathcal{L}$，本文算法在时间和空间复杂度上均实现了 $2^{n/2+o(n)}$ 的突破，显著推进了该领域的理论边界。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新点&lt;/strong&gt;：&lt;br /&gt;本算法可视为奇素数 $q$ 下中点海森矩阵（midpoint Hessian）方法的 $q$-ary 推广。其核心创新在于发现了一个关键数学性质：对于最短向量 $v$，即使在相对较大的随机仿射陪集上进行聚合，周期高斯函数在 $v/q$ 处的梯度（而非海森矩阵）也几乎与 $v$ 成正比（至多相差一个符号）。基于此，研究团队设计了一种受 Wagner 广义生日算法启发的组合过程，通过一系列中间格构成的链来计算相关的陪集梯度，从而构建出 $q$-ary 陪集差分树，最终实现了 $2^{n/2+o(n)}$ 的优异复杂度。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与扩展应用&lt;/strong&gt;：&lt;br /&gt;除了精确求解 SVP，该算法的变体还能在相同的时间和空间复杂度下，求解精确最近向量问题（CVP）。具体而言，对于任意输入 $(y, \mathcal{L})$，当目标距离满足 $\operatorname{dist}(y, \mathcal{L}) \le 1.039\lambda_1(\mathcal{L})$ 时，算法能够给出精确解。这一距离保证在目标向量和格均服从 Haar-Siegel 测度分布的随机实例下成立。综上所述，本研究不仅为 SVP 提供了更高效的求解框架，也为特定随机实例下的 CVP 提供了最优的复杂度保证，对格密码的安全性分析具有重要的理论价值。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper introduces a novel randomized algorithm that solves the exact shortest vector problem (SVP) in $n$-dimensional lattices with a breakthrough time and space complexity of $2^{n/2+o(n)}$. Acting as a $q$-ary analogue of the midpoint Hessian for an odd prime $q$, the proposed method leverages a key mathematical property: the gradient of the periodic Gaussian function at $v/q$ is nearly proportional to the shortest vector $v$, even after aggregation over a large random affine coset. By employing a combinatorial procedure inspired by Wagner&amp;#x27;s generalized birthday algorithm, we efficiently compute the relevant coset gradients along a chain of intermediate lattices to build the $q$-ary coset difference tree. Furthermore, a variant of this algorithm solves the exact closest vector problem (CVP) within the same optimal complexity bounds. Specifically, it provides a rigorous distance guarantee of $\operatorname{dist}(y, \mathcal{L}) \le 1.039\lambda_1(\mathcal{L})$ for random instances drawn according to the Haar-Siegel measure, significantly advancing the theoretical limits of lattice-based computations.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;This paper presents a new randomized algorithm for solving the exact shortest vector problem. For the $n$-dimensional lattice $\mathcal L$, our algorithm runs in time and space $2^{n/2+o(n)}$.&lt;/p&gt;&lt;p&gt;Our algorithm can be viewed as a $q$-ary analogue of the midpoint Hessian for an odd prime $q$; more precisely, we use the fact that, for a shortest vector $v$, the gradient (rather than Hessian) of the periodic Gaussian function at $v/q$ is nearly proportional to $v$ (up to sign), even after aggregation over a relatively large random affine coset. We compute the relevant coset gradient along a chain of intermediate lattices using a combinatorial procedure inspired by Wagner&amp;#x27;s generalized birthday algorithm, yielding the $2^{n/2+o(n)}$ time and space complexity.&lt;/p&gt;&lt;p&gt;A variant of the algorithm solves the exact closest vector problem on every input $(y,\mathcal L)$ with a distance guarantee $\operatorname{dist}(y,\mathcal L)\le 1.039\lambda_1(\mathcal L)$ within the same time and space complexity.&lt;br /&gt;This guarantee holds for a random target and a random lattice drawn according to the Haar-Siegel measure. Thus, this algorithm solves a closest vector problem on such random instances in time and space $2^{n/2+o(n)}$.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>On the Mismatch between Neural-Discovered Differential-Linear Features and Long-Round Distinguisher Construction</title>
      <link>https://eprint.iacr.org/2026/1858</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1858</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1858"&gt;https://eprint.iacr.org/2026/1858&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景与目的&lt;/strong&gt;：现有差分-神经网络密码分析尚未在轮数上超越最强经典分析。近期研究表明，神经区分器提取的特征可解释为经典差分-线性掩码，为长轮分析提供了新思路。本文探讨神经发现的掩码能否作为ARX密码长轮差分-线性区分器的有效候选。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法&lt;/strong&gt;：首先，本文引入 &lt;code&gt;Conv1DFully&lt;/code&gt; 结构对短轮差分-线性候选进行表征，通过移除残差塔并重组卷积层，在 Speck32/64 和 SipHash 上验证了神经提取掩码集中于高相关性近似中。随后，在 18 轮 Speck128/128 区分器（5+8+5 分解）中评估其长轮效用，并对首层卷积施加稀疏性引导以生成低汉明重量候选。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;主要发现与创新点&lt;/strong&gt;：研究发现，尽管 8 轮神经区分器能发现局部中间相关性远强于经典掩码的特征，但经线性扩展后，其整体 18 轮相关性却显著较弱。通过稀疏性引导，模型在部分独立运行中成功恢复了经典长轮区分器使用的中间掩码，证明其具备生成有效候选的潜力。然而，该恢复过程不稳定，且模型最终决策仍倾向于局部最优而非全局长轮最优。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;结论&lt;/strong&gt;：差分-神经区分器可辅助长轮候选生成，但如何实现稳定恢复与长轮感知优先级排序仍是亟待解决的挑战。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;While differential-neural cryptanalysis has not yet surpassed classical methods in round numbers, recent interpretability studies suggest that neural-extracted features can be mapped to classical differential-linear masks, prompting this study on their utility for long-round ARX cipher distinguishers. We introduce the Conv1DFully architecture to characterize short-round candidates and evaluate their utility on an 18-round Speck128/128 distinguisher, revealing a critical mismatch where neural-discovered features with stronger local middle correlations yield considerably weaker overall 18-round correlations after linear extensions. Furthermore, by imposing sparsity guidance, the model occasionally recovers the classical long-round mask, demonstrating its potential for generating effective candidates despite the instability of this recovery process. Ultimately, our results indicate that while differential-neural distinguishers can assist in long-round candidate generation, achieving reliable recovery and long-round-aware prioritization remains an unresolved challenge.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;To the best of our knowledge, existing differential-neural cryptanalysis have not yet shown a clear round advantage over the strongest comparable classical analyses. Recent Fourier-based interpretability results show that, under a difference-only representation, features extracted from differential-neural distinguishers can be interpreted as classical differential-linear masks. This suggests a possible route toward longer-round classical cryptanalysis and motivates our question: can such neural-discovered masks serve as useful candidates in the search for long-round differential-linear distinguishers of ARX ciphers?&lt;/p&gt;&lt;p&gt;As a prerequisite to the long-round study, we first characterize the short-round differential-linear candidates exposed by difference-only differential-neural distinguishers. We introduce Conv1DFully to facilitate mask-level analysis by removing the residual tower and reorganizing the first convolution along the ciphertext-difference bit dimension. On Speck32/64, the dominant differential-linear feature remains preserved after these modifications. On SipHash, we compare Fourier masks extracted from trained distinguishers with an exhaustive evaluation of a low-Hamming-weight output-mask space. The neural-extracted masks are concentrated among high-correlation differential-linear approximations, including several of the strongest candidates examined. These experiments provide a controlled basis for treating neural-extracted masks as candidates in the subsequent long-round analysis.&lt;/p&gt;&lt;p&gt;We then examine their utility in the known 18-round Speck128/128 distinguisher with a 5+8+5 decomposition. Under the same middle input difference, an 8-round difference-only differential-neural distinguisher recurrently exposes several masks with substantially stronger local middle correlations than the classically selected mask. However, after 5-round single XOR-linear extensions, these masks yield considerably weaker overall 18-round correlations. We further impose sparsity guidance on the first convolutional layer to promote low-Hamming-weight candidates. Under this guidance, the intermediate mask used in the classical 18-round distinguisher is recovered in the first-layer candidate set in 9 of 30 independent runs, showing that the neural model can reproduce a long-round-useful classical candidate. Nevertheless, this recovery is not stable, and the final neural decision rule still favors locally stronger features rather than the classically selected mask. These results indicate that differential-neural distinguishers can assist long-round candidate generation, while reliable recovery and long-round-aware prioritization remain unresolved.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Zero-Knowledge PCPs of Quasilinear Size via Locally Simulatable Sheaf Codes</title>
      <link>https://eprint.iacr.org/2026/1868</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1868</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1868"&gt;https://eprint.iacr.org/2026/1868&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;在密码学与计算复杂性理论中，概率可检验证明（PCP）与零知识特性的结合一直是核心研究课题。此前的研究（如Gur等人，STOC 2024/2025）虽然成功实现了零知识PCP，但其证明长度仅停留在多项式级别，未能达到更优的规模。本文在此领域取得突破性进展，严格证明了对于任意给定的多项式函数 $T$ 和 $b$，针对复杂度类 $\operatorname{NTIME}(T)$ 存在一种查询复杂度为 $O(1)$ 的 PCP。该证明的长度被大幅压缩至 $\widetilde{O}(T(n)+b(n)^2)$ 的拟线性级别，并且严格满足针对 $b(n)$ 次查询的完美零知识（perfect zero knowledge）属性。这一结果在效率上严格优于先前关于多项式长度零知识PCP的研究。&lt;/p&gt;&lt;p&gt;在构造方法上，本研究建立在 Ben-Sasson 与 Sudan (SICOMP 2008) 以及 Dinur (JACM 2007) 的经典 PCP 构造基础之上。为了在如此紧凑的拟线性证明长度下实现并严格证明零知识属性，本文引入并发展了一种全新的理论工具——&lt;strong&gt;局部可模拟层码（locally simulatable sheaf codes）&lt;/strong&gt;。借助这一创新机制，作者成功克服了在极小证明规模下模拟验证者视图的难题，为构造高效且安全的零知识PCP提供了全新的理论框架和技术路径。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper presents a breakthrough in constructing zero-knowledge probabilistically checkable proofs (PCPs) by achieving quasilinear proof size. Specifically, we prove that for any polynomials $T, b \colon \mathbb{N} \to \mathbb{N}$, there exists an $O(1)$-query PCP for $\operatorname{NTIME}(T)$ with a length of $\widetilde{O}(T(n)+b(n)^2)$ that satisfies perfect zero knowledge against $b(n)$ queries. This result strictly improves upon the polynomial-length zero-knowledge PCPs established by Gur, O&amp;#x27;Connor, and Spooner (STOC 2024; STOC 2025). Our construction builds upon the foundational PCP frameworks of Ben-Sasson and Sudan (SICOMP 2008) and Dinur (JACM 2007). To rigorously establish the zero-knowledge property within this highly compressed quasilinear regime, we introduce and utilize a novel theoretical machinery: &lt;strong&gt;locally simulatable sheaf codes&lt;/strong&gt;. This new tool enables the efficient simulation of the verifier&amp;#x27;s view, providing a robust framework for constructing highly efficient and secure zero-knowledge PCPs.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We show that for every polynomial $T,b \colon \mathbb{N} \to \mathbb{N}$, there exist an $O(1)$-query probabilistically checkable proof (PCP) for $\operatorname{NTIME}(T)$ of length $\widetilde{O}\bigl(T(n)+b(n)^2\bigr)$, which is $b(n)$-query perfect zero knowledge. This strictly improves on the polynomial-length zero-knowledge PCPs of Gur, O&amp;#x27;Connor, and Spooner (STOC 2024; STOC 2025). Our construction builds on the PCPs of Ben-Sasson and Sudan (SICOMP 2008) and Dinur (JACM 2007). We prove the zero-knowledge property of our PCPs via the new machinery of locally simulatable sheaf codes.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Collusion-Resistant Constrained PRFs for Compute-&amp;-Compare Predicates from LWE</title>
      <link>https://eprint.iacr.org/2026/1874</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1874</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1874"&gt;https://eprint.iacr.org/2026/1874&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;本研究在标准LWE（带误差学习）假设下，首次为具有表达力的非平凡约束类设计了&lt;strong&gt;抗合谋约束伪随机函数（CPRFs）&lt;/strong&gt;，取得了后量子密码学领域的重要突破。&lt;/p&gt;&lt;p&gt;* &lt;strong&gt;研究背景&lt;/strong&gt;：在此之前，后量子抗合谋CPRF仅局限于前缀固定约束，而针对表达性谓词的方案则严重依赖代码混淆或多线性映射等复杂工具，缺乏基于标准假设的安全构造。&lt;br /&gt;* &lt;strong&gt;核心方法&lt;/strong&gt;：研究针对“计算并比较”（compute-&amp;amp;-compare）和谓词范围约束两类谓词构建了CPRF方案。特别地，作者改进了“计算并比较”的CPRF，使其进一步满足抗合谋约束隐私性，并额外具备（近似）密钥同态特性。&lt;br /&gt;* &lt;strong&gt;主要发现与应用&lt;/strong&gt;：作为直接应用，该研究在对称密钥设定下，成功实现了针对“计算并比较”类的&lt;strong&gt;双向谓词加密（PE）和函数加密（FE）&lt;/strong&gt;。这彻底填补了后量子密码学中内积谓词之外缺乏双向PE/FE构造的空白。&lt;br /&gt;* &lt;strong&gt;理论创新&lt;/strong&gt;：本文的另一项重大贡献是引入了 &lt;strong&gt;“纯化功能”（purifying functionality）&lt;/strong&gt; 的全新理论框架。该框架的核心动机在于系统性地消除“零化攻击”（zeroizing attacks），这种攻击范式曾成功破解多种高级密码学候选方案。该框架为设计抗复杂密码分析的高级密码对象提供了坚实的新视角。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;This paper presents the first collusion-resistant constrained pseudorandom functions (CPRFs) for expressive and non-trivial predicate classes, specifically compute-&amp;amp;-compare and predicated range constraints, based solely on the standard LWE assumption. We significantly enhance the compute-&amp;amp;-compare CPRF to achieve collusion-resistant constraint privacy and (almost-)key-homomorphic properties, thereby overcoming previous constructions&amp;#x27; heavy reliance on code obfuscation or multilinear maps. As an immediate and impactful application, our framework yields the first post-quantum two-sided predicate encryption (PE) and functional encryption (FE) for compute-&amp;amp;-compare predicates in the symmetric-key setting, breaking the limitation of prior works restricted to inner product predicates. Furthermore, a major theoretical contribution of this work is the introduction of a novel &amp;quot;purifying functionality&amp;quot; framework. The primary motivation behind this new paradigm is to systematically eliminate zeroizing attacks, which have historically been a highly successful cryptanalysis technique for breaking various advanced cryptographic candidates.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;We design the first collusion-resistant constrained PRFs (CPRFs) for a non-trivial and expressive class of constraints from standard LWE. The two predicate classes for which we design CPRFs are: compute-&amp;amp;-compare and predicated range constraints. We improve our CPRF for compute-&amp;amp;-compare predicates to also satisfy collusion-resistant constraint privacy. An additional feature of our CPRFs is that they also satisfy (almost-)key-homomorphic property. Prior to this work, we did not have any post-quantum collusion-resistant CPRF beyond prefixfixing constraints, and collusion-resistant CPRFs for expressive predicates relied on either code obfuscation or multilinear maps.&lt;/p&gt;&lt;p&gt;As an immediate application, we obtain a two-sided predicate encryption (PE) and functional encryption (FE) for the compute-&amp;amp;-compare class in the symmetric-key setting. Prior to this work, we did not have any post-quantum construction for 2-sided PE/FE beyond inner product predicates. An important contribution of this work is to introduce a new framework of purifying functionality. The main motivation behind our new framework is to systematically eliminate zeroizing attacks, which have been a highly successful cryptanalysis paradigm for breaking various candidates for advanced cryptographic objects.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
    <item>
      <title>Fully Fluctuating Sleepy Consensus from Minimal Assumptions</title>
      <link>https://eprint.iacr.org/2026/1873</link>
      <guid isPermaLink="true">https://eprint.iacr.org/2026/1873</guid>
      <description>&lt;p&gt;&lt;strong&gt;Paper Link:&lt;/strong&gt; &lt;a href="https://eprint.iacr.org/2026/1873"&gt;https://eprint.iacr.org/2026/1873&lt;/a&gt;&lt;/p&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (中文)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;背景&lt;/strong&gt;：比特币的工作量证明（PoW）协议因其对参与者的极低要求而著称，允许矿工随时休息或恢复诚实状态，仅需诚实矿工在任意时刻掌握多数算力。相比之下，基于权益证明（PoS）的“休眠模型”（sleepy model）协议在普通公钥基础设施（PKI）下，难以实现对手参与度的完全自由波动。现有研究虽通过引入外部对手模型解决了波动问题，但严重依赖可验证延迟函数（VDF）等强密码学假设。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;方法与创新&lt;/strong&gt;：本文在最小假设（仅需PKI和可验证随机函数VRF）下，针对外部对手和诚实多数场景，设计了一种支持参与度完全波动的休眠共识协议。本文摒弃了VDF和硬件假设，提出了一项名为“分级唤醒度”（graded wakeness）的新型密码学原语，使节点能够对其他节点的唤醒状态形成一致性认知。&lt;/p&gt;&lt;p&gt;&lt;strong&gt;扩展与发现&lt;/strong&gt;：此外，本文将协议扩展至处理“节点恢复诚实”（uncorruption）的场景。该扩展仅需对VRF输出的不可预测性做出温和的额外假设即可保证系统的活性（liveness）。本研究从最小假设出发，极大地提升了休眠共识协议在动态参与环境下的鲁棒性与实用性。&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;AI Summary (English)&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Background &amp;amp; Problem&lt;/strong&gt;: Bitcoin&amp;#x27;s proof-of-work protocol allows fully fluctuating participation and uncorruption under minimal assumptions, whereas analogous proof-of-stake sleepy models typically require strong cryptographic primitives like verifiable delay functions (VDFs) to handle adversarial participation fluctuations.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Method &amp;amp; Contribution&lt;/strong&gt;: In this work, we design a sleepy consensus protocol for fully fluctuating participation with an external adversary under an honest majority, relying solely on minimal assumptions: a public key infrastructure (PKI) and a verifiable random function (VRF), completely eliminating the need for VDFs or hardware assumptions.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Key Technique &amp;amp; Extension&lt;/strong&gt;: Our core innovation is &amp;quot;graded wakeness,&amp;quot; a novel primitive that enables nodes to form consistent opinions on the awake status of other nodes. Furthermore, we extend the protocol to handle uncorruption—where corrupt nodes revert to honesty—requiring only a mild additional assumption on VRF unpredictability to guarantee liveness, thereby achieving robust sleepy consensus from truly minimal assumptions.&lt;/p&gt;&lt;/section&gt;
&lt;section class="paper-feed-section"&gt;&lt;h3&gt;Abstract&lt;/h3&gt;&lt;p&gt;Bitcoin&amp;#x27;s proof-of-work (PoW)-based protocol is remarkable for how little it asks of its participants. Not only can miners take breaks from work whenever they please, but it is almost unique in offering a path of contrition: corrupt miners can reclaim honest status simply by resuming mining on the longest chain. The protocol only requires that honest miners hold the majority of computational power at any given time. Analogous proof-of-stake (PoS) protocols, usually formalized via the sleepy model of Pass and Shi (2017), have fallen short of matching this robustness. In fact, sleepy consensus protocols in the plain PKI model must heavily restrict fluctuations in adversarial participation over time. The recent work of Efron, Neu, Pitassi (2025) enables fully fluctuating participation in the sleepy model by introducing the external adversary model. Their protocol, however, relies on verifiable delay functions (VDFs), a strong cryptographic primitive that somewhat resembles PoW, by assuming that the adversary cannot compute sequential work significantly faster than honest nodes.&lt;/p&gt;&lt;p&gt;In this work, we design a sleepy consensus protocol for fully fluctuating participation with an external adversary under an honest majority, from minimal assumptions: a public key infrastructure (PKI) and a verifiable random function (VRF). In particular, we make no VDF or hardware assumptions. Our key technique is graded wakeness, a novel primitive that allows nodes to form consistent opinions on which other nodes are awake. We further extend our protocol to handle uncorruption, where corrupt nodes return to honesty. This extension requires only a mild additional assumption on the unpredictability of VRF outputs for liveness.&lt;/p&gt;&lt;/section&gt;</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <category>IACR</category>
    </item>
  </channel>
</rss>