Dates are inconsistent

Dates are inconsistent

5084 results sorted by ID

2026/2370 (PDF) Last updated: 2026-10-06
Extract-Amplify-Measure: Single-Sided and Tight O2H with Applications to CCA Security in the Quantum Random Oracle Model
Jiangxia Ge, Kang Yang, Yu Yu
Public-key cryptography

The One-Way-to-Hiding (O2H) theorem is a useful tool for analyzing reprogramming in the quantum random oracle model (QROM). It bounds the distinguishing advantage by the probability $\epsilon$ that a one-wayness attacker finds the reprogrammed point. A sequence of works has improved the tightness of this theorem. Currently, the Measure-Rewind-Extract O2H (MRE-O2H) theorem proved by Ge et al. (ASIACRYPT 2024) achieves the tightest known upper bound of $O(\sqrt{q}\cdot\epsilon)$, where $q$ is...

2026/2365 (PDF) Last updated: 2026-10-05
On the Instantiability of the Fujisaki–Okamoto Transform for Trapdoor Functions
Carter Luck, Xinyu Mao, Adam O'Neill
Public-key cryptography

The Fujisaki--Okamoto (FO) transform (Journal of Cryptology, 2013) is the standard route from weakly secure public-key encryption to chosen-ciphertext security, and it underlies many practical post-quantum key-encapsulation schemes, including ML-KEM. Security proofs for FO are set in the (quantum) random oracle models. FO uses two hash functions: the derandomization hash~$H$, which turns the base scheme into a deterministic trapdoor function (TDF) by Encrypt-with-Hash, and the...

2026/2362 (PDF) Last updated: 2026-10-05
The Geometry of Witness-Update Tradeoffs in Additive Positive Accumulators
Wei Qi
Public-key cryptography

An additive positive accumulator represents a growing set by a short public digest. Each inserted element has a membership witness, which may have to be refreshed after later insertions. An execution of $n$ insertions therefore defines a labeled update vector $d=(d_1,\ldots,d_n)$, where $d_i$ is the number of strict post-insertion refreshes of the witness created at time $i$. Previous lower bounds concern scalar quantities such as $\max_i d_i$ and $\sum_i d_i$. Even when both are known, they...

2026/2332 (PDF) Last updated: 2026-10-04
Rotate Once, Read Many Times: on the Output Noise of Multi-Value Bootstrapping
Philippe Chartier, Michel Koskas, Mohammed Lemou
Public-key cryptography

In FHEW/TFHE, a programmable bootstrap evaluates an arbitrary function of the encrypted message, encoded as the \emph{test polynomial} of a blind rotation. We work in a prime-power cyclotomic ring whose prime is the plaintext modulus $p$ (a \emph{design choice} that leaves the ring degree free as a security parameter) and compare the \emph{Single-Value Mode} (SVM), one rotation per function, with the \emph{Multi-Value Mode} (MVM), one \emph{function-independent} rotation shared by...

2026/2328 (PDF) Last updated: 2026-10-04
Automorphism-Compatible NTT and its Application to Homomorphic Encryption
Charanjit S. Jutla, Nathan Manohar, Guy Moshkowich
Public-key cryptography

For $N$ a power of $2$, the negacyclic number-theoretic transform (NTT) maps a degree $N-1$ polynomial to its evaluations at the $N$ primitive $2N$th roots of unity. In-place butterfly algorithms such as Cooley-Tukey and Gentleman-Sande compute the negacyclic NTT in $O(N\log N)$ time and output the evaluations in a specific, standard order. We give in-place butterfly algorithms for the negacyclic NTT and its inverse that instead output the evaluations in an automorphism-compatible order....

2026/2327 (PDF) Last updated: 2026-10-04
The Humbert Form of Discriminant 36, and What It Says About Splitting Detection
Tony Shaska
Public-key cryptography

Explicit equations for the locus $\mathcal{L}_n$ of genus-two curves with a maximal degree-$n$ elliptic subcover have been computed only for $n \le 5$, and by elimination, whose cost is not predictable in advance. The degree formula of [22] changes this. It gives $\deg_w F_n = k(H_{n^2}) - 10\,\nu(n)$ in closed form, and with it a reduced monomial support for the associated Humbert modular form $G_{n^2}$, so that the reconstruction becomes a determined linear problem whose every...

2026/2323 (PDF) Last updated: 2026-10-03
ATLAS: A Compact Module-LWR Signature Scheme
Karthick Srivatsan, Debranjan Pal, Anindya Ganguly, Suparna Kundu, Abhinava De, Puja Mondal, Harry Hart, Quinten Norga, Prajna Mahadev, Supriya Adhikary, Debayan Das, Chaoyun Li, Angshuman Karmakar
Public-key cryptography

We present $\mathsf{ATLAS}$, a lattice-based digital signature scheme built on the Fiat--Shamir with aborts paradigm, with security based on the hardness of the Module Learning with Rounding ($\mathsf{MLWR}$) problem. Unlike $\mathsf{Dilithium}$'s $\mathbf{t} = \mathbf{As}_1 + \mathbf{s}_2$ construction or $\mathsf{HAETAE}$'s bimodal, hyperball-uniform instantiation, $\mathsf{ATLAS}$ derives its public key via deterministic rounding, $\mathbf{t} = \lfloor \tfrac{p}{q}\mathbf{As}_1 \rceil$,...

2026/2318 (PDF) Last updated: 2026-10-06
Beyond Mosca’s Heuristic: Supported Is Not Protected in Post-Quantum Migration
Abdoul Ahad FALL
Public-key cryptography

Post-quantum (PQ) migration is usually tracked per asset, with Mosca’s inequality and a share of “migrated” systems. For a flow of sensitive data, the relevant questions are different: is every session that carries it keyed by a quantum-safe secret, what evidence supports that claim, and what can an assessor establish from outside? We propose an assessment method whose unit is the data path and whose verdicts are tied to evidence. Key lineage is an algebra on break dates: a derived key falls...

2026/2309 (PDF) Last updated: 2026-10-02
Three-Move Blind Signatures from DL
Rutchathon Chairattana-Apirom, Michael Reichle, Stefano Tessaro
Public-key cryptography

This paper considers the problem of building blind signatures in pairing-free groups. We provide the first three-move blind signature which is provably one-more unforgeable, in the random-oracle model, under the minimal assumption that the discrete logarithm (DL) problem is hard. Our construction in fact achieves one-more strong unforgeability, and also supports partial blindness. Blindness is statistical, also in the ROM. Our construction makes black-box use of the underlying group and does...

2026/2305 (PDF) Last updated: 2026-10-02
Revisiting Partitioning: Output-Adaptive ABE for Circuits from LWE
Jiaqi Cheng, Rishab Goyal
Public-key cryptography

We introduce Output-Adaptive Security, a new intermediate security notion for Attribute-Based Encryption (ABE) that bridges the gap between selective and full adaptive security. In our model, the adversary selectively commits to a policy function structure $f$ but adaptively chooses a long target output value $y$ during the challenge phase. We construct the first Output-Adaptive ABE scheme for general circuits from the standard Learning With Errors (LWE) assumption by revisiting classical...

2026/2292 (PDF) Last updated: 2026-10-01
Nonstop Multihop? Constructions and Lower Bounds for Re-Aggregatable Multisignatures
Lucjan Hanzlik, Julian Loss, Omar Renawi
Public-key cryptography

Multisignatures compress many signatures on a common message into a single aggregate. In large distributed systems, aggregation occurs over multiple hops, where partial aggregates may overlap. The recent hint-free multisignatures of Hofheinz, Reichle, and Wagner (TCC~2026) eliminate aggregation-topology hints, but verification still requires the complete set of participating public keys. This leaves open whether the signer-set information itself can be eliminated. We answer this question...

2026/2277 (PDF) Last updated: 2026-09-30
Non-Interactive Atomic Swaps from Standard Signatures: Lower Bounds and Constructions
Xiangyu Liu, Riccardo Zanotto, Vassilis Zikas
Public-key cryptography

Atomic swaps are the prototypical application of adaptor signatures. Practical constructions settle with two ordinary on-chain signatures and require no scripting, but they need two sequential online rounds: Alice samples a hard statement and sends its pre-signature, and Bob follows with his own pre-signature using the same statement. We ask whether the protocol can be compressed into a single online round (from Bob to Alice), which we call a non-interactive atomic swap, without relying on...

2026/2276 (PDF) Last updated: 2026-09-30
Concurrently secure variants of blind (Okamoto-)Schnorr signatures
Georg Fuchsbauer, Fabian Regen, Levente Sulyok
Public-key cryptography

We present variants of blind Schnorr and blind Okamoto-Schnorr signatures that are not susceptible to ROS-style attacks. We prove the schemes unforgeable in the algebraic group model and the random oracle model: the Okamoto-Schnorr variant under the discrete-logarithm assumption; the Schnorr variant under the algebraic one-more discrete-logarithm assumption. Our Schnorr variant improves on the communication complexity of Snowblind (CRYPTO 2023), the state-of-the-art "pairing-free" blind...

2026/2272 (PDF) Last updated: 2026-09-30
Attacking UOV-based Signatures over divided power algebras
Peigen Li, Siyong Tao
Public-key cryptography

Merz and Ran derive additional equations from divided powers of the public polar forms in characteristic two. We extend this construction to finite fields of arbitrary characteristic and apply it to the security analysis of QR-UOV.

2026/2268 (PDF) Last updated: 2026-09-29
Kopis: A KEM for Obfuscation
Andrea Basso, Michael Rosenberg
Public-key cryptography

Password-authenticated key exchange (PAKE) and obfuscated key exchange (OKEX) are widely used protocols, appearing in passport access control, Tor's censorship evasion, and more. As quantum threats grow nearer, there have been an increasing number of proposals for post-quantum PAKE and OKEX. All such protocols are similar in that they build on a KEM, obfuscating public keys and/or ciphertexts sent over the wire, e.g., by adding a random mask or applying an ideal cipher. Many propose...

2026/2263 (PDF) Last updated: 2026-09-29
Levis: Extension-Free Multi-Key Fully Homomorphic Encryption in the Plain Model
Baoyu Li, Binwu Xiang, Kang Yang
Public-key cryptography

Multi-key fully homomorphic encryption (MKFHE) enables computation over ciphertexts encrypted under keys independently generated by different parties. Recently, Min, Park, and Song (MPS, CRYPTO 2026) constructed the first RLWE-based MKFHE scheme in the plain model, i.e., without trusted or interactive setup. Their construction requires each local compact Gentry-Sahai-Waters (GSW) ciphertext to be extended to a joint-key GSW-like ciphertext before evaluation, incurring $O(dk^2)$ gadget...

2026/2260 (PDF) Last updated: 2026-09-29
PQMZ: Formally Verified Falcon-PKR for Post-Quantum Cryptographic Migration in Zcash
Hannes Hacker, Shekoufeh Neisarian, Sara Zain, Elif Bilge Kavun
Public-key cryptography

Migrating blockchain systems to Post-Quantum Cryptography (PQC) requires not only replacing classical primitives, but also analysing transformations that change how signatures are represented and verified. We study Falcon-PKR, a public-key-recovery variant of Falcon, motivated by Zcash-like transparent transaction workflows. Falcon-PKR replaces explicit storage of the full Falcon public key with a compact stored digest and reconstructs a candidate public key from the signature during...

2026/2259 (PDF) Last updated: 2026-09-29
Supersingularity and Superspeciality Verification of Abelian Surfaces
Maria Corte-Real Santos, Gioella Lorenzon, Krijn Reijnders
Public-key cryptography

Supersingular abelian surfaces are essential in isogeny-based cryptography. Despite this, we have no efficient algorithm to verify if a given abelian surface is supersingular. In this work, we initiate this research topic by giving an efficient Monte Carlo algorithm to verify if an abelian surface over $\mathbb{F}_p$ is supersingular in $O(\log p)$ with negligible failure probability, and an efficient conclusive algorithm if the order is smooth. We derive this algorithm by a careful analysis...

2026/2252 (PDF) Last updated: 2026-09-28
Batch Decryption from New Standard Assumptions
Nico Döttling, Bernardo Magri, Benjamin Marsh, Mahesh Sreekumar Rajasree
Public-key cryptography

Batch decryption allows an authority to release a short key that enables public decryption of a selected batch of ciphertexts. Motivated by encrypted mempools, we study this capability through two constructions with different authorization semantics and assumptions. First, we provide a simple and compact epochless construction in an RSA group based on Fiat's Batch RSA [CRYPTO'89]. Its batch-decryption hint is just one group element, and its keys and ciphertexts have size independent of...

2026/2250 (PDF) Last updated: 2026-09-28
Decryption Failures in NGCC Lattice KEMs: Correlated Blocks, Omitted Compression Noise, and Failure Boosting under a Query Cap
Yuyang Xiao
Public-key cryptography

The Chinese NGCC post-quantum competition received a family of lattice KEMs whose decryption failure rates (DFRs) are certified by their designers with models that differ in detail. We recompute the failure probability of the first-round lattice KEMs whose claimed DFR, or a simple recomputation of it, lies near or below the nominal level, and we estimate the offline search for weak ciphertexts under a cap of $2^{64}$ or $2^{80}$ decapsulation queries. Three distinct mechanisms are...

2026/2243 (PDF) Last updated: 2026-09-28
TPOKÉ: Threshold Public-Key Encryption from POKÉ via Isogeny Sharing
Toshiki Takatera, Hiroshi Onuki, Tsuyoshi Takagi
Public-key cryptography

POKÉ, introduced by Basso and Maino, is one of the most efficient isogeny-based public-key encryption schemes. The generic parallel-encryption approach yields a $(t,n)$-threshold variant by running $n$ independent POKÉ instances and secret-sharing the message, but this multiplies the public-key and ciphertext sizes by roughly $n$. We present S-TPOKÉ, a POKÉ-based $(t,n)$-threshold construction for every $1\le t\le n$, and Ch-TPOKÉ, an $(n,n)$ variant that arranges the parties' secret...

2026/2232 (PDF) Last updated: 2026-10-01
Cryptanalysis of the ICCS NGCC Round-1 Public-Key Candidates
Zhenyu Xiong, Mingsheng Wang
Public-key cryptography

The ICCS Next-Generation Commercial Cryptography (NGCC) round-1 call received 84 public-key candidates for public evaluation. We present a design-level assessment that targets weaknesses no local code fix can close, identifying eight such flaws. Each recurs a pitfall already known from NIST PQC standardization: reducible-ring sub-ring projections that break IND-CPA below the claimed level; public data that fixes a value meant to remain secret, enabling public-key-only forgery or keyless...

2026/2226 (PDF) Last updated: 2026-09-26
FALCON++: Shorter Signatures without NTRU Smoothing Estimates
Hao Yan, Nicholas Zhao
Public-key cryptography

\Falcon{} is a digital signature scheme based on NTRU lattices, known for its compact signatures. Its weak-smoothness variant, \FalconWS{} (ASIACRYPT 2025), reduces signature sizes by allowing narrower Gaussian sampling distributions. Further reductions require efficient sampling at narrower widths and a security analysis that accounts for the resulting distributions. We analyze the distribution of accepted preimages directly, without estimating the smoothing parameter of the NTRU...

2026/2223 (PDF) Last updated: 2026-09-26
Linear Key Recovery in the BAG-Loong Reference Implementation
Zihan Liu
Public-key cryptography

The BAG-Loong reference implementation samples its secret matrices X and Y from fixed, publicly known subspaces, although the specification calls for secret random supports. This makes the public-key relation S = HX + Y , with public H, amenable to Gaussian elimination. Expanding the relation over F2 and projecting away the support of Y leaves a linear system for X. We prove an exact recovery criterion based on its column rank. All 40 supplied known-answer-test records, covering four...

2026/2216 (PDF) Last updated: 2026-09-25
On the Multi-User Security of CSI-FiSh with Tight Reductions
Seunghoon Lee, Maher Mamah, Bruno Sterner
Public-key cryptography

The security of isogeny-based signatures is almost exclusively studied in the single-user setting, leaving a gap for realistic multi-user deployments. This gap is especially crucial for CSI-FiSh, where the small challenge space and parameter sensitivity directly impacts security estimates. We address the multi-user security of CSI-FiSh and obtain tight concrete classical multi-user bounds in the random-oracle model (ROM) plus generic group-action model (GGAM). Crucially, our analysis only...

2026/2211 (PDF) Last updated: 2026-09-25
Structural Cryptanalysis of Polar-KEM: Direct Recovery of the Secret Isometry
Yuyang Xiao, Long Chen, Zhenfeng Zhang
Public-key cryptography

Polar-KEM is a lattice-based key encapsulation mechanism submitted to the Next-generation Commercial Cryptographic Algorithms Program. Its security is claimed to rely on a lattice isomorphism problem over polar-code-defined Construction-D lattices. In its core key-generation algorithm, a polar lattice basis is constructed from a polar-code chain, reduced using LLL, and left-multiplied by a secret orthogonal matrix. The resulting matrix is published as the public key. We show that...

2026/2195 (PDF) Last updated: 2026-09-23
Multi-Key FHE Almost as Fast as Single-Key FHE
Abtin Afshar, Rishab Goyal
Public-key cryptography

Multi-key fully homomorphic encryption (MKFHE) supports homomorphic computation over ciphertexts encrypted under independently generated keys. Known constructions accommodate independent keys by expanding every ciphertext under the concatenation of the participating secret keys, and then evaluating the circuit in that expanded dimension. A concatenated key is $N$ times longer than an individual key, so the ciphertext on each wire and the running time of each gate grow with $N$, the number of...

2026/2190 (PDF) Last updated: 2026-09-26
Stay in Your Lane: Fast Arithmetic over Large Finite Rings with CKKS
Hyeongmin Choe, Robin Köstler, Tim Seuré
Public-key cryptography

Recent CKKS-based constructions support homomorphic arithmetic modulo powers of two and more general moduli. We explore a complementary tradeoff: using polynomial rings native to CKKS simplifies arithmetic and refreshing but restricts the message spaces. Building on Kim's interpretation of GBFV ciphertexts as CKKS ciphertexts, we use the decomposition $\mathbb{R}[X]/\langle X^N+1\rangle \cong(\mathbb{R}[X]/\langle X^n+1\rangle)^{N/n}$ into $N/n$ polynomial lanes, where $2\leq n\leq N$ is a...

2026/2167 (PDF) Last updated: 2026-09-23
New Applications of RSA
Yao-Ching Hsieh, Abhishek Jain, Brent Waters
Public-key cryptography

We present new constructions of the following primitives featuring succinct communication: - Batch threshold encryption: Assuming RSA and DCR, we construct a threshold encryption scheme in which a batch of ciphertexts can be decrypted via short hints from a quorum of decryptors. Previously, this was known only from bilinear maps. - Aggregate signatures: Assuming RSA, we construct a signature scheme where signatures on different messages from an arbitrary number of signers can be...

2026/2164 (PDF) Last updated: 2026-09-22
On the Limits of LWE and PCE based UPKE
Martin R. Albrecht, Benjamin Benčina, Russell W. F. Lai
Public-key cryptography

Updatable Public-Key Encryption (UPKE) enables forward secrecy in asynchronous settings like secure group messaging. At EC'25, Albrecht, Benčina and Lai proposed the first plausibly post-quantum UPKE scheme supporting unlimited updates, based on permutation code equivalence (PCE) over finite fields and hollow lattice problems. However, it has impractically large public keys (4.8MiB) and ciphertexts (1.5MiB). In this work, we first replace the information-theoretic Hollow LHL with a...

2026/2154 (PDF) Last updated: 2026-09-22
Recovering SNOVA Secret Keys from Biased Vinegar Sampling
Ward Beullens , Basil Hess
Public-key cryptography

The Round-3 SNOVA signer samples vinegar variables, which are elements of $\mathbb{F}_q$, by reducing uniform byte strings modulo a power of $q$. We show that the resulting bias leaks secret-key information for the six odd-characteristic alternative parameter sets. Even though the leakage is small (the most leaky variables leak at most $0.086$ bits of information), this still leads to efficient key-recovery attacks which we demonstrate in practice. Key recovery becomes a $q$-ary LPN problem...

2026/2143 (PDF) Last updated: 2026-09-21
SAK: Sparse Arguments of Knowledge, from Sparse Lookup Arguments
Abhiram Kothapalli, Sriram Sridhar, Arantxa Zapico
Public-key cryptography

We formalize and construct $sparse$ arguments of knowledge, where given a length $N$ witness that contains $n$ non-zero values the prover time is $O(n) \circ o(N)$. In particular, we achieve a sparse argument of knowledge for the customizable constraint system relation, which generalizes circuit-satisfiability. We achieve this by first utilizing $sublinear$ lookup arguments to provably select only the subset of the constraint system that touches the non-zero entries of...

2026/2136 (PDF) Last updated: 2026-09-21
MAMBA-Frost: A Lattice KEM from Learning With Quantization
Shanxiang Lyu, Ke Ma, Junzuo Lai
Public-key cryptography

The Learning With Errors (LWE) problem provides a conservative and well-established security foundation for lattice-based cryptography, while Learning With Rounding (LWR) improves bandwidth efficiency through deterministic rounding. However, the rounding noise in LWR is inherently correlated with the hidden linear term, preventing tight and sample-preserving reductions to standard LWE for polynomial moduli. Prior work on the Learning With Quantization (LWQ) problem established a tight...

2026/2134 (PDF) Last updated: 2026-09-21
ANSA-IBS: Identity-Based Signatures from Annular NTRU Trapdoors and Bimodal Fiat-Shamir with Aborts
Zhaohui Cheng, Hengfu Yang, Kaixin Xiong
Public-key cryptography

We give a lattice identity-based signature scheme from annular NTRU trapdoors and Fiat--Shamir with aborts (FSwA). Countered hashing maps each identity to its first invertible DLP/NTRU syndrome $a$. Extraction returns a short witness to $s_0+s_1h=a\bmod q$, and signing normalizes this relation to a fixed-target two-response equation with public commitment recovery. Gärtner's iterative rejection method fits naturally into this signing layer: processing the challenge monomials separately...

2026/2128 (PDF) Last updated: 2026-09-20
Schnorr Signatures and MuSig2 Are Jointly Secure, Even in Deterministic Wallets
Renas Bacho, Yanbo Chen, Poulami Das, Julian Loss, Tim Ruffing, Benedikt Wagner
Public-key cryptography

Modern cryptocurrency wallets use Schnorr signatures together with public, deterministic key derivation: by repeatedly rerandomizing a single master public key, an unlimited number of public keys for incoming payments can be derived without access to secret data. Moreover, some wallets support multi-signature schemes such as MuSig2 for optionally aggregating derived public keys from $n$ distinct parties into "$n$-of-$n$" public keys, so that funds received on such aggregated keys can be...

2026/2121 (PDF) Last updated: 2026-09-20
Lattice-Based Synchronous Signatures: Efficiently Aggregatable and Thresholdizable
Dan Boneh, Binyi Chen, Trisha Datta
Public-key cryptography

Aggregate signatures play an important role in proof-of-stake systems, where many validators sign a block. There is a strong desire to aggregate all these signatures into one short signature that is fast to verify. Since all validators know the block number they are signing, this setting is well suited for synchronous (a.k.a stateful) signatures. Boneh and Kim (2019) showed that lattice-based one-time signatures (OTS) can be aggregated very efficiently. The Chipmunk and Lemur signature...

2026/2119 (PDF) Last updated: 2026-09-20
CKKS Bootstrapping in less than 10ms
Rending Ouyang, Jian Liu, Peimin Gao, Pan Xiao, Heng Zhang, Man Ho Au, Cong Zhang, Kui Ren, Chun Chen
Public-key cryptography

Bootstrapping enables deep homomorphic computation in CKKS by replenishing multiplicative levels. It remains one of the scheme's most expensive operations. HEAAN reports a bootstrapping latency of 6.97ms, substantially faster than other publicly documented alternatives. However, the algorithmic and implementation techniques underlying this result have not been disclosed, leaving it unclear how such performance is achieved. In this work, we present a fully specified CKKS bootstrapping...

2026/2113 (PDF) Last updated: 2026-09-19
Post-Quantum PKE and More from a Noisy Unstructured Linear Algebraic Assumption: Beyond LWE and LPN
Riddhi Ghosal, Paul Lou, Amit Sahai
Public-key cryptography

Noisy linear algebraic assumptions (NLAs), such as $\mathsf{LWE}$ and Alekhnovich’s $\mathsf{LPN}$, have long served as the most reliable sources of post-quantum hardness. However, a series of recent classical attacks on assumptions once believed to be quantum-secure, coupled with the rapid progress in quantum technology, underscores the urgent need for assumptions that are plausibly hard even if both $\mathsf{LWE}$ and $\mathsf{LPN}$ turn out to be broken. A fascinating recent work of...

2026/2096 (PDF) Last updated: 2026-09-18
Perpetual Encryption
Yevgeniy Dodis, Daniel Jost
Public-key cryptography

Traditional public-key encryption (PKE) schemes have a static secret key. This means that the secret key owner can decrypt any old ciphertext in perpetuity. Schemes with changing secret keys, supporting so-called epochs, have been considered for a variety of reasons, such as post-compromise security or more simply supporting communication among a dynamically changing group. This complicates perpetuity, especially in settings where the epoch number itself is supposed to be confidential....

2026/2094 (PDF) Last updated: 2026-09-18
Tree Encodings IV: Depth-Unbounded Attribute-Based Encryption and Delay Encryption
Damiano Abram, Giulio Malavolta, Lawrence Roy
Public-key cryptography

Assuming the polynomial-time hardness of Decomposed LWE, a variant of the learning with errors (LWE) problem, we construct ciphertext-policy attribute-based encryption for depth-unbounded (but bounded-space) predicates. Previously, attribute-based encryption for depth-unbounded predicates was only known from an insecure version of evasive LWE, or by additionally assuming the cryptographic hardness of discrete logarithms, which makes such schemes quantum-insecure. Adapting these...

2026/2088 (PDF) Last updated: 2026-09-18
Detecting split surfaces, RM surfaces, and minimum walks on isogeny graphs
Eda Kırımlı, Gaurish Korpal
Public-key cryptography

We study the detectability of split surfaces in isogeny graphs of principally polarized superspecial abelian surfaces, a question relevant to the security analysis of dimension-$2$ isogeny-based cryptography. Our approach uses refined Humbert invariants to replace explicit isogeny computations with primitive representation problems for positive definite quadratic forms in five variables. We develop algorithms to detect $(N,N)$-splittings and to compute the minimum $(N,N)$-splitting level of...

2026/2087 (PDF) Last updated: 2026-09-18
Batched and Weighted Threshold Encryption with Silent Setup
Amit Agarwal, Rutchathon Chairattana-Apirom, Sourav Das, Babak Poorebrahim Gilkalaye
Public-key cryptography

Batched Threshold Encryption (BTE) enables a committee of parties to jointly decrypt any subset of ciphertexts from a large set, while all other ciphertexts remain private. BTE has applications in blockchains, particularly in designing encrypted mempools, where transactions are encrypted until included into a block to prevent maximal extractable value (MEV) attacks. Existing BTE constructions, however, encounter one of the following usability downsides: (a) reliance on expensive...

2026/2078 (PDF) Last updated: 2026-09-18
Radical Ring-LWR: Efficient Key Encapsulation and Signatures from Structured Rounding
Joost Renes, Joppe W. Bos, Haochen Huang, Selim Kirbiyik, Alberto Ovena, Sujoy Sinha Roy, Frederik Vercauteren, Peng Wang, Fangyu Zheng, Chenxin Zhong
Public-key cryptography

State-of-the-art lattice-based cryptography requires a power-of-two cyclotomic field that limits the attainable security levels, or a module structure for which the cost grows quadratically in the module rank. Radical rings were recently proposed as a solution in the context of Learning With Errors (LWE) based Key Encapsulation Mechanisms (KEMs) with heuristic hardness arguments for the Ring-LWE security and failure probability. We develop the Learning With Rounding counterpart, Radical...

2026/2077 (PDF) Last updated: 2026-09-18
Practical Group Signatures from Tag-Based NTRU Sampler
Corentin Jeudy
Public-key cryptography

The post-quantum migration for key agreements and signatures being well underway, the focus naturally shifts to other properties and primitives that still lack efficient solutions. One such area is that of privacy-enhanced primitives, with a growing number of post-quantum constructions. Among the most fundamental are group signatures, which represent an important milestone of anonymity and accountability towards more involved designs. However, despite recent progress, most compact lattice...

2026/2076 (PDF) Last updated: 2026-09-20
Symmetry-Graded Digit Extraction Framework for Faster BGV Bootstrapping
Zhenyu Xiong, Mingsheng Wang, Zhedong Wang, Han Wang
Public-key cryptography

Bootstrapping is the bottleneck of BGV/BFV homomorphic encryption, and for large plaintext primes $p$ its cost is dominated by digit extraction. Recently, this stage has been accelerated along two separate routes. The first lowers the degree of the digit-extraction polynomial: the bounded-support construction of Ma et al. (Eurocrypt'24) confines its support, and the order-four filter of Xiong et al. (to appear in Asiacrypt'26) removes three quarters of its monomials. The second lowers the...

2026/2069 (PDF) Last updated: 2026-09-17
Default Correct: A New Fault Surface in the Comparison Booleanisation of Kyber-KEM
Anirudh Jaiswal, Abhilash Kumar Das, Dhiman Saha
Public-key cryptography

The Fujisaki–Okamoto (FO) transform protects Kyber-KEM against chosen- ciphertext attacks and is based on a ciphertext comparison step. This comparison is usually treated as a single atomic check. However, in every mainstream implementation it is a short pipeline of independently faultable stages. It comprises a byte-wise mismatch accumulation, a two’s-complement Booleanisation, and a conditional move (cmov). In this work, we expose a previously unexamined stage of this pipeline, the...

2026/2054 (PDF) Last updated: 2026-09-16
Lemur+: Compact Post-Quantum Synchronized Multi-Signatures and Multi-Hop Aggregation
Yini Lin, Hongxiao Wang, Muhammed F. Esgin, Amin Sakzad, Ron Steinfeld
Public-key cryptography

In this work, we introduce Lemur+, a compact post-quantum synchronized multi-signature scheme based on standard lattice assumptions (namely, Module LWE and Module SIS). Lemur+ builds on Lemur (CCS 2026) and targets large-scale, long-term distributed applications such as blockchain consensus while supporting non-interactive aggregation. Lemur+ maintains an almost constant signature size of about 56 KB even for one million signers and a 42-year key lifetime, compared to 491 KB in Lemur,...

2026/2053 (PDF) Last updated: 2026-09-15
Weighted Batch Threshold Encryption with Efficient DKG
Alexander Frolov, Aditi Partap, Max Resnick, Ertem Nusret Tas
Public-key cryptography

Batch threshold encryption allows a committee to decrypt a selected batch of ciphertexts using one short pre-decryption key per party, while ciphertexts outside the batch remain private. This makes batch threshold encryption attractive for building encrypted mempools for blockchains, where validators reveal transactions selected for a block while pending transactions remain private. However, in proof-of-stake systems like Solana or Ethereum, authorization depends on each validator's stake,...

2026/2049 (PDF) Last updated: 2026-09-15
Tighter and Friendlier Integer Bounds for Quaternion Algorithms - Application to SQIsign
Maciej Czuprynko, Anisha Mukherjee, Sujoy Sinha Roy
Public-key cryptography

The digital signature scheme SQIsign, currently under consideration in NIST's call for additional post-quantum signatures, offers the smallest key and signature sizes among all candidates. Its signing procedure, however, relies on an involved arithmetic layer over quaternions, in which the objects are represented by small-dimensional integer lattices. In this layer, the intermediate integers can grow significantly larger than the final outputs. Controlling this growth is essential for...

2026/2044 (PDF) Last updated: 2026-09-15
On Sparkle+ and its Security Claims
Andrea Gangemi, Massimiliano Sala, Lorenzo Viganò
Public-key cryptography

We revisit the security bounds of Sparkle+, the threshold Schnorr signature scheme which first appeared in 2023. This scheme has been updated and corrected in several versions and papers (also of other authors). However, no version or paper has checked in detail the final bounds of Theorem 1 and 2 of the June 2025 version, which have therefore, to the best of our knowledge, been taken for granted in the related literature. There, the derivation of the final bounds of its Theorems 1 and 2,...

2026/2003 (PDF) Last updated: 2026-09-13
NP-Hardness of Ideal Lattice Problems
Daniel E. Martin
Public-key cryptography

We establish the worst-case hardness of several ideal lattice problems (including SVP and CVP) in the $\ell_2$ norm by providing a dimension-preserving, deterministic polynomial time reduction from their generic lattice versions. The reduction constructs an ideal lattice in the canonical embedding of a number field that approximates some input lattice up to scaling and orthogonal transformation. The integers defining the ideal and the ambient number ring, in particular its discriminant, are...

2026/1991 (PDF) Last updated: 2026-09-12
Towards Practical Iterative Rejection Sampling: A Compact and Efficient Signature over Module Lattices
Yifan Ming, Jipeng Zhang, Zihan Liu, Guofeng Tang, Pengfei Chen, Yutao Sun, Si Gao, Cong Zhang, Long Chen
Public-key cryptography

Lattice signatures face a strict trade-off among compactness, implementation simplicity, and reliance on standard lattice assumptions: ML-DSA-44 requires a 2420-byte signature (3732 bytes combined) and HAETAE-120 takes 1474 bytes (2466 bytes combined), while Falcon-512 achieves 555 bytes but relies on complex floating-point arithmetic. We propose SHUTTLE, a compact Fiat–Shamir signature built on a standard MLWE public-key structure with unforgeability bound to MSIS in the random oracle...

2026/1977 (PDF) Last updated: 2026-09-11
Lattice-based Secret-Key Functional Encryption for Constant-Degree Polynomials
Valerio Cini, Russell W. F. Lai, Akin Ünal, Ivy K. Y. Woo
Public-key cryptography

We present a lattice-based construction of secret-key functional encryption (FE) for low-norm polynomials of any constant degree $d$, hence also for $\mathsf{NC}^{0}$ circuits. We rely on two core ingredients: 1. New trapdoor and preimage sampling algorithms for certain degree-$d$ tensor-structured matrices, used to generate functional secret keys. 2. A new $k$-LWE-style assumption where short preimages of non-zero images with respect to the above tensor-structured matrix are given as...

2026/1974 (PDF) Last updated: 2026-09-20
Filtered Supersingular Isogeny Counts and Exact-Coset Response Existence
Ti-Hong Qin, Hong-Yu Tang, Zong-Bin Wang, Wen-Lun Pan
Public-key cryptography

We study the existence of bounded-degree supersingular isogenies under prescribed degree filters and exact torsion constraints. In characteristic $p$, a second-moment argument using the Brandt trace formula gives asymptotically positive coverage of independent uniform endpoints at $D=\lfloor c\sqrt{p}\rfloor$, for every fixed $c>0$ and every endpoint-independent binary filter retaining $\Omega(D^2)$ cyclic kernels. This avoids the logarithmic loss of a maximum-Petersson-norm estimate, but...

2026/1968 (PDF) Last updated: 2026-09-16
The Closest-Vector Problem over Cyclotomics and its Application to Homomorphic Encryption
Natalie Lang, Dana Dachman-Soled
Public-key cryptography

Rounding error plays a key role in approximate homomorphic encryption (HE), as it determines the noise level and affects the achievable precision. While rounding is typically performed coordinate-wise in the coefficient basis, an alternative is to perform lattice-based rounding in the canonical embedding. These two approaches coincide for power-of-two (PoT) cyclotomics, but can differ for non-PoT cyclotomics. This difference opens the possibility of new parameter tradeoffs for approximate HE...

2026/1966 (PDF) Last updated: 2026-09-10
Design and Analysis of Isogeny-Based Strong Designated Verifier Signature
Abhinav Sharma, Vikas Srivastava
Public-key cryptography

Strong designated-verifier signatures provide authentication while restricting verification to a chosen verifier and protecting the signer from transferable evidence. Designing such signatures in the post-quantum setting is challenging because authentication, signer privacy, simulation, and efficiency must be achieved simultaneously. Recently, Renan proposed CSI-SDVS, a compact post-quantum strong designated-verifier signature scheme built from CSIDH-style commutative isogeny class-group...

2026/1965 (PDF) Last updated: 2026-09-10
Lattice-based Threshold Traitor Tracing with Public Traceability
Sébastien Canard, Nathan Papon, Duong Hieu Phan
Public-key cryptography

Since the introduction of Threshold Traitor Tracing by Boneh, Partap and Rotem at CRYPTO '24, several works have extended the functionalities within the framework or improved the parameters. However, most of the existing solution fall short in providing post quantum security guarantees. The only lattice-based construction, due to Das et al. from EUROCRYPT '26, achieves post-quantum security but is limited to private tracing: a dedicated tracing authority holds a secret tracing key. In a...

2026/1960 (PDF) Last updated: 2026-09-10
Unbounded Broadcast and KP-ABE with Sublinear Ciphertext from Pairings
Junichi Tomida, Hoeteck Wee
Public-key cryptography

We present the first pairing-based unbounded broadcast encryption and key-policy attribute-based encryption (KP-ABE) with sublinear ciphertext size. Here, unbounded means set-up and the public parameters do not impose a bound on the size of the broadcast set, attribute length, or policy size. - Our broadcast encryption scheme supports an unbounded number of users, and achieves \[ |mpk| = O(1), |ct| = O(\sqrt{N}), |sk| = O(\sqrt{N})\] where $N$ denotes an upper...

2026/1958 (PDF) Last updated: 2026-09-29
Arithmetic for Large-Characteristic Finite Fields in CKKS
Daehyun Jang, Junho Lee
Public-key cryptography

Seur\'e and Suvanto (ePrint 2026/1102) recently showed that, for small-characteristic primes $p$, arithmetic over $\mathbb{F}_{p^r}$ can be homomorphically evaluated in CKKS via a technique they call \emph{spectral encoding}. Their construction is, however, restricted to small characteristic: ciphertext multiplication amplifies the error by the operator norm of the multiplied plaintext. Under the spectral encoding, a field element in $\mathbb F_{p^r}$ is encoded to a plaintext with...

2026/1951 (PDF) Last updated: 2026-09-09
OAEP† Transform in the Post-Quantum World
You Lyu, Shengli Liu, Shuai Han, Bohang Chen
Public-key cryptography

We provide a new variant of OAEP called OAEP†, which converts an almost trapdoor injective function (ATIF) to a public-key encryption (PKE) scheme. The resulting PKE not only has CCA security but also enjoys pseudo-randomness, anonymity, and robustness under chosen-ciphertext attacks in the quantum random oracle (QRO) model. Compared with the plain OAEP and its variants whose structure does not serve the quantum world very well, our OAEP† is designed with a new structure, admitting more...

2026/1944 (PDF) Last updated: 2026-09-09
Fault Injection Attacks on Torsion Masking
Valerie Gilchrist, Yi-Fu Lai, Michael Meyer
Public-key cryptography

In 2022, a string of attacks on SIDH was released that made use of the now infamous Kani's Lemma. Since then, several new and exciting isogeny-based protocols have emerged that both avoid the attacks, while at the same time, leverage the power of Kani's Lemma to improve their efficiency. One common technique to do so has been the inclusion of masked torsion points. This is when a protocol publishes information about how a secret isogeny acts on a large torsion subgroup, but masks the exact...

2026/1928 (PDF) Last updated: 2026-09-08
Two-Round Threshold Signatures with Adaptive TS-UF-1 Security from MDDH
Wenzhong Li, Shengli Liu, You Lyu
Public-key cryptography

In this paper, we construct threshold signatures (TS) to achieve adaptive TS-UF-1 security and identifiable abort. Our TS construction has two rounds. We prove its adaptive TS-UF-1 security in the random oracle model (ROM) under the MDDH (covering DDH) assumption in pairing-free groups. To the best of our knowledge, there are only two TS schemes, namely GLRS26 (Gerhart et al., Eurocrypt 2026) and Dazzle (Chen, PKC 2025), enjoying two rounds, identifiable abort and adaptive security from DDH...

2026/1926 (PDF) Last updated: 2026-09-08
Symmetric and Asymmetric Anonymous Authenticated KEM
Benedikt Auerbach, Doreen Riepel, Paul Rösler, Lea Thiemt, Julian Thomas
Public-key cryptography

The terms Signcryption, Split KEM, and Authenticated Key-Encapsulation Mechanism (AKEM) are often used synonymously to capture the amalgamation of a KEM and a Digital Signature Scheme in a single primitive. This means that a sender Alice can encapsulate a symmetric secret to the public key of receiver Bob, and Bob can use Alice's public key to verify that Alice was indeed the sender. Some constructions of AKEM additionally use symmetric pre-shared key material between Alice and Bob to...

2026/1924 (PDF) Last updated: 2026-09-08
Decryption-Failure Rate with Multidimensional Lattice Decoders: Unified Framework, Theory Refinement, and More Accurate Evaluation
Boyue Fang, Songlin Li, Yunlei Zhao
Public-key cryptography

Using a multidimensional lattice block code complicates decryption-failure analysis in two distinct ways. A norm or BDD certificate need not equal the implemented message-failure event, and structured polynomial products can make the residual coordinates dependent. We record every estimate by its decoder event, residual law, tail engine, and ciphertext/key aggregation. This event-aligned framework yields finite directional bounds for arbitrary residual laws and a finite Gaussian reference...

2026/1921 (PDF) Last updated: 2026-09-08
Homomorphic Functional Encryption: Trustless Key Derivation for Functional Encryption
Camille Nuoskala, Hossein Abdinasibfar, Mélina Hadjeres, Antonios Michalas
Public-key cryptography

In this paper, we study the trust assumptions underlying key generation in functional encryption (FE) schemes, as well as the information leakage that can arise from the use of functional decryption keys. FE schemes typically rely on a trusted key curator who holds the master secret key and derives functional decryption keys. This requirement makes the curator a central point of trust and a particularly sensitive target for compromise. We show how homomorphic encryption (HE) can be used to...

2026/1908 (PDF) Last updated: 2026-09-10
A Generalized Wiener-type Attack Against a Family RSA-like Cryptosystems
George Teseleanu
Public-key cryptography

Let $N = pq$ be the product of two balanced prime numbers $p$ and $q$. In 2023, Cotan and Te\c seleanu introduced a family of RSA-like cryptosystems based on the key equation $ed - k(p^n - 1)(q^n - 1) = 1$, where $n \geq 1$. Note that when $n = 1$, we obtain the classical RSA scheme, while $n = 2$ yields the variant proposed by Elkamchouchi, Elshenawy, and Shaban. In this paper, we present a novel attack that combines continued fractions with lattice-based methods for the case $n = 2^i$,...

2026/1895 (PDF) Last updated: 2026-09-11
Large-Universe (Multi-Authority) ABE from LWE
Pratish Datta, Yannis Rouselakis, Junichi Tomida, Nikhil Vanjani
Public-key cryptography

An attribute-based encryption (ABE) scheme is "large-universe" if its attribute universe is superpolynomial and is not enumerated during setup. In the multi-authority setting, we further require that each authority can independently manage a superpolynomial set of attributes and dynamically issue an arbitrary polynomial number of secret keys per user. Although large-universe (multi-authority) ABE from pairings is well studied, explicit lattice-based constructions have remained elusive. In...

2026/1892 (PDF) Last updated: 2026-09-04
Dynasaurs: Efficient Universal Dynamic zkSNARKs from Sparse Linear Arguments
Martí Batista, Álvaro Montes, Nikitas Paslis, Carla Ràfols
Public-key cryptography

Dynamic zkSNARKs were recently introduced by Wang et al. [Eurocrypt, 2026]. This primitive extends standard zkSNARKs with an update algorithm that adapts a proof to a new statement in time sublinear in the circuit size, provided the witness changes in few positions. However, existing constructions either need a circuit-specific setup or, in the universal case, send over $130$ group elements and require over $180$ pairings. As is the case for universal zkSNARKs, dynamic ones can be built...

2026/1886 (PDF) Last updated: 2026-09-04
Symplex: Improved Pairing-Based zkSNARK using Partial Fraction Techniques
Charanjit S. Jutla, Arnab Roy
Public-key cryptography

We present Symplex, a pairing-based zkSNARK for R1CS that preserves the syntax of Groth16: a $2G_1{+}1G_2$ proof, and a verifier with three pairings and one public-input multi-scalar multiplication (MSM), while {\it strictly reducing prover cost}. For constraint count $n$, wire count $m$, public-input count $\ell$, and $\kappa=\min\{n,m+1\}$, Symplex's prover uses four FFTs of size $n$ rather than the six of our coset-Lagrange Groth16 comparator, and its larger $G_1$-MSM has width...

2026/1874 (PDF) Last updated: 2026-09-02
Collusion-Resistant Constrained PRFs for Compute-&-Compare Predicates from LWE
Jiaqi Cheng, Rishab Goyal
Public-key cryptography

We design the first collusion-resistant constrained PRFs (CPRFs) for a non-trivial and expressive class of constraints from standard LWE. The two predicate classes for which we design CPRFs are: compute-&-compare and predicated range constraints. We improve our CPRF for compute-&-compare predicates to also satisfy collusion-resistant constraint privacy. An additional feature of our CPRFs is that they also satisfy (almost-)key-homomorphic property. Prior to this work, we did not have any...

2026/1869 (PDF) Last updated: 2026-09-02
High-Precision Homomorphic ALU over Arbitrary Moduli with $O(1)$ Bootstrapping
Jiaming Liu, Shihe Ma, Anyu Wang, Xiaoyun Wang
Public-key cryptography

Homomorphic computation on large integers requires both arithmetic and non-arithmetic (e.g., Boolean) operations. The radix-based method by Cha et al. (EUROCRYPT'26) supports both operation types over arbitrary $n$-bit integers with a complexity of \(O(\log n)\) and \(O(1)\) bootstrapping, respectively. Meanwhile, the triangle encoding method by Gao and Zheng (CRYPTO'26) has a complexity of \(O(1)\) bootstrapping in arithmetic mode, but is restricted to power-of-two integers. Its...

2026/1847 (PDF) Last updated: 2026-08-31
Order-Four Symmetry in BGV Bootstrapping: Faster Digit Extraction for Large Primes
Zhenyu Xiong, Mingsheng Wang, Zhedong Wang, Han Wang
Public-key cryptography

Bootstrapping is the computational bottleneck of BGV/BFV fully homomorphic encryption, scaling particularly poorly with large plaintext primes. Its two dominant stages: digit extraction and linear transforms. Recent work has reduced the digit-extraction polynomial degree via null-polynomial lattices and bounded-support constructions, but both evaluate the reduced polynomial via generic Paterson--Stockmeyer at cost $O(\sqrt{d})$ . We present two algebraic optimizations that address both...

2026/1846 (PDF) Last updated: 2026-08-31
Covert Federated Learning under Regulation based on Threshold Anamorphic Encryption
Wenxuan Xu, Huaqun Wang, Debiao He
Public-key cryptography

When communication systems are subject to strict external control, a powerful authority may monitor all transmitted messages and compel users to surrender their secret keys, thereby undermining user autonomy and the confidentiality of keys in encrypted communication. Anamorphic encryption (AE) enables covert communication under such surveillance by embedding hidden messages into innocent-looking ciphertexts. However, existing lattice-based AE constructions remain limited and typically rely...

2026/1840 (PDF) Last updated: 2026-09-23
Efficient Homomorphic Arithmetic Logical Units with \texorpdfstring{$O(1)$}{O(1)} Bootstrapping
Xuan Shen, Zhihao Li, Ruida Wang, Xianhui Lu
Public-key cryptography

Arithmetic logic units (ALU) combine word-level arithmetic with bitwise operations over encrypted data. The state-of-the-art scheme, GZ26 (CRYPTO'26), constructs an ALU in CKKS via triangle encoding, but has two limitations: the radix-$2$ design restricts packing capacity, while the arithmetic-to-Boolean (A2B) conversion requires $O(\ell)$ functional bootstrappings for $\ell$-bit message without batching independent ciphertexts. In this paper, we first generalize triangle encoding to...

2026/1836 (PDF) Last updated: 2026-09-18
FHE for ALU over Large Prime Moduli and Application to One-Round Threshold ECDSA
Yuchen Wei, Kaisheng Ma, Mingyu Gao, Hongren Zheng
Public-key cryptography

Fully Homomorphic Encryption (FHE) has served as a theoretical building block for cryptographic primitives, but concrete instantiations remain limited by the cost of generic homomorphic computation. One example is the universal thresholdizer that compiles any (deterministic) signature scheme into a multi-party threshold signature scheme with a one-round signing protocol (Boneh et al., Crypto'18), where the signing algorithm is homomorphically evaluated without communication with other...

2026/1831 (PDF) Last updated: 2026-08-29
Silent-Share: Decoupling Hidden Threshold Matching from Pairing Operations via Group-Valued Oblivious Key-Value Stores
Jie Zhang, Xiaohong Li, Ruitao Feng, Guangdong Bai
Public-key cryptography

Matchmaking encryption (ME) enables bilateral access control with private policies, but existing pairing-based constructions tie receiver-side authorization cost to the policy size. This is especially problematic when one party holds a large hidden policy while the other holds only a small attribute set. We present Silent-Share, a bilateral hidden-policy threshold access-control protocol that decouples policy representation from pairing-based authorization. The construction combines a...

2026/1826 (PDF) Last updated: 2026-09-07
Threshold Encryption with Internally Motivated Corruptions
Jan Bormet, Hussien Othman, Benedikt Wagner
Public-key cryptography

In recent years, threshold encryption has gained a lot of interest, particularly due to its potential use in encrypted mempools in blockchains. Standard security models allow the adversary to corrupt parties either statically (i.e., fixed at the onset of the game) or adaptively (i.e., via an oracle one-by-one, depending on keys and ciphertexts). In this work, we observe that neither of these models captures the case in which a party decides to become corrupted based on secret...

2026/1820 (PDF) Last updated: 2026-09-10
Practical Silent Threshold Signatures and Silent Threshold Encryption for Dynamic Committees
Yifei He, Zheng Zhou, Yu Chen, Zhi Guan, Zhong Chen
Public-key cryptography

Silent threshold signatures (STS) and encryption (STE) enable threshold cryptography without interactive distributed key generation, allowing a group of $N$ parties to non-interactively generate a joint public signature verification key or an encryption key. However, modern distributed systems (such as Ethereum) rely on small, dynamically changing committees of size $n \ll N$ for efficiency, and existing silent threshold schemes either fail to support this dynamic setting or suffer from...

2026/1789 (PDF) Last updated: 2026-08-24
HRFPRE: Fast Proxy Re-encryption for Multi-RSU Outsourcing and Hardware-assisted Revocation in the IoV.
Tingting Li, Leyou Zhang, Qing Wu, Fei Zhou, Yuxing Wei
Public-key cryptography

In the Internet of Vehicles (IoV), content-centric data sharing is essential for driving safety and user experience. However, the highly dynamic and distributed IoV network raises challenges such as unauthorized data access and inefficient information dissemination. Although existing proxy re-encryption (PRE) schemes with revocation partially mitigate these concerns, they still have key shortcomings: (i) computational costs that grow linearly with the number of attributes; (ii) heavy...

2026/1779 (PDF) Last updated: 2026-09-13
Bootstrapping via Ring Switching without Slot Recovery
Zhaoyang Liang, Dan Ding
Public-key cryptography

Ring switching provides a natural way to reduce bootstrapping cost in ring-based fully homomorphic encryption by moving computation to smaller rings. For SIMD-packed ciphertexts, however, ring switching changes the slot layout, so conventional approaches apply slot recovery to ensure correct computation on the original slot values, consuming capacity and requiring synchronization across ciphertexts. In this paper, we show that slot recovery is not indispensable: CKKS and BGV/BFV...

2026/1775 (PDF) Last updated: 2026-09-23
A Note on the Security Proof of SQIsign
Maher Mamah, David Jao
Public-key cryptography

Aardal et al. (CRYPTO 2025) provided the first complete security proof of SQIsign; however, their reduction incurs a square-root loss in the prime characteristic due to the application of a loose bound on the min-entropy. For instance, at NIST security level I, an adversary making $2^{64}$ signing queries renders the security proof vacuous. In this note, we show that the min-entropy of SQIsign is optimal, namely $\mathcal{O}(1/p)$. Although this improvement does not yield full $\lambda$-bit...

2026/1761 (PDF) Last updated: 2026-08-21
Lightweight Lattice-based Single-Party Public-Key Authenticated Key Exchange
Alex Aïdan, Sébastien Canard, Emmanuel Fouotsa, Nyiang Melchisedech Mbeng
Public-key cryptography

Authenticated Key Exchange (AKE) is a cornerstone of secure communication, especially in resource-constrained IoT environments where lightweight and post-quantum security are paramount. While lattice-based cryptography offers promising solutions, existing post-quantum AKE protocols often prioritize strong security notions, such as the use of an IND-CCA encryption scheme, incurring overheads incompatible with IoT devices. This raises a critical question: Can one-way security (OW), a weaker...

2026/1756 (PDF) Last updated: 2026-08-21
Fully Homomorphic Encryption with Chosen-Ciphertext Security from LWE
Rupeng Yang, Zuoxia Yu, Willy Susilo
Public-key cryptography

We construct (1-hop) fully homomorphic encryption (FHE) schemes with chosen-ciphertext (CCA) security from the learning with errors (LWE) assumption in the standard model. Security of our construction only relies on the circular-secure LWE, which matches the assumptions needed for FHE with the basic chosen-plaintext security. Besides, the scheme achieves a security notion that is strictly stronger than the CCA1 security. Prior FHE schemes with even just CCA1 security require either the...

2026/1746 (PDF) Last updated: 2026-08-20
Chasing QuOCCAs in a Quantum World: Type-2 Oracles for CCA-Secure PKE
Barbara Jiabao Benedikt, Tommaso Gagliardoni, Patrick Struck
Public-key cryptography

In the context of PKE schemes, Gagliardoni et al. proposed at PQCrypto 2021 a qIND-qCPA security notion (a superposition-based analogue of the classical IND-CPA security notion), by using the theory of so-called type-2 unitary operators. On one hand, this notion is very natural, closely mirrors the classical intuition, and can be handled without relying on complex techniques such as Zhandry’s compressed oracles. On the other hand, it is restricted to a certain class of PKE schemes (so-called...

2026/1732 (PDF) Last updated: 2026-08-19
Indifferentiability of Public-Key Encryption: Theory Meets Practice
Taiyu Wang, Cong Zhang, Hong-Sheng Zhou, Jiayi Ai, Zhihong Jia, Wenli Wang, Jian Liu, Xin Wang, Li Lin, Kui Ren, Chun Chen
Public-key cryptography

Public-key encryption (PKE) is a fundamental primitive in modern cryptography, and many PKE schemes have been standardized and widely deployed. To reason about security in complex and highly compositional environments, Zhandry and Zhang (CRYPTO 2020) initiated the study of indifferentiability for public-key cryptosystems. However, their construction for PKE departs substantially from the design paradigms used in practice, and to date no practical public-key encryption schemes are known to...

2026/1731 (PDF) Last updated: 2026-09-08
Generic Ring-Signature Transforms for Fiat-Shamir with Aborts and Hash-and-Sign with Retry
Haruhisa Kosuge, Koutarou Suzuki
Public-key cryptography

Ring signatures provide signer anonymity for ad hoc sets of public keys. Generic Abe-Ohkubo-Suzuki (AOS) transforms are well understood for plain Fiat--Shamir and hash-and-sign signatures, but not for their rejection-sampling variants: Fiat--Shamir with aborts (FSwA) and hash-and-sign with retry (HSwR). We formalize AOS ring transforms for FSwA and HSwR and analyze their security in the quantum random-oracle model. For unforgeability, we reduce security under adaptive ring-signing queries to...

2026/1722 (PDF) Last updated: 2026-08-18
Elementary-Vector Modeling for Shorter VOLE-Based Signatures from SD and PKP
Boyuan Gao, Zongyang Zhang, Weihan Li, Jianwei Liu, Jianting Ning
Public-key cryptography

Zero-knowledge proofs based on VOLE have recently become a promising approach for designing post-quantum signature schemes. Such schemes are constructed by having a signer prove knowledge of a secret input for a prescribed one-way function. In this work, we optimize VOLE-based signature schemes from syndrome decoding (SD) and the permuted kernel problem (PKP). Despite relying on different one-way functions, these schemes share a common modeling method. Elementary vectors are compressed into...

2026/1716 (PDF) Last updated: 2026-08-17
Silent Threshold Encryption from Lattices
Jeffrey Champion, David J. Wu, Shota Yamada
Public-key cryptography

Silent threshold encryption is a generalization of threshold encryption where the public encryption key associated with a group of users is a deterministic function of their individual public keys. The main efficiency requirement is that the ciphertext size should be sublinear in (and ideally, independent of) the size of the decryption quorum $N$. Existing constructions of silent threshold encryption for arbitrary threshold policies have either relied on bilinear maps or on heavyweight tools...

2026/1715 (PDF) Last updated: 2026-08-19
How Compact Can NTRU Encryption Be? Heuristic Frontiers and Practical Schemes
Yijian Liu, Yu Zhang, Xianhui Lu, Yao Cheng, Yongjian Yin
Public-key cryptography

NTRU is one of the longest-tested lattice-based public-key encryption families and is often viewed as a compact alternative to (R/M)-LWE. Yet, after three decades of research, its potential for compactness remains an open area for further exploration: recent designs such as NEV (Asiacrypt 2023) and DAWN (Asiacrypt 2025) suggest that there is still room for improvement. This raises a natural question: Has NTRU reached its compactness limit? If not, how compact can it be while still remaining...

2026/1709 (PDF) Last updated: 2026-08-17
Ring Signatures with Personalized Anonymity
Kyosuke Yamashita, Keisuke Hara
Public-key cryptography

Ring signatures have long struggled to balance absolute anonymity with traceability. While various extensions, such as traceable and accountable ring signatures, have been proposed, they typically apply a uniform anonymity or traceability rule to all potential signers. This paper introduces personalized-anonymity ring signatures (PARS), a novel primitive in which users are certified with different anonymity rights according to their roles or authority. Unlike ordinary ring signatures,...

2026/1708 (PDF) Last updated: 2026-08-17
Prepared Episodes for Short Online Hash Based Signatures
Chongxu Ren, Kaiyi Zhang, Haorui Cui, Hongbo Yu
Public-key cryptography

SPHINCS+ provides stateless signing and self-contained verification, but its signatures are large: every message carries a FORS signature and a complete WOTS+/Merkle authentication chain to the long-term root. This cost is repeated even when messages arrive in a bounded episode whose maximum size is known in advance. We introduce prepared-episode signatures and instantiate them as SPHINCS-PE. The construction splits a globally addressed hypertree at an episode boundary into upper and...

2026/1701 (PDF) Last updated: 2026-08-16
DTRU: A Versatile, Compact, Simple, and Robust NTRU KEM with Double $E_8$ Encoding
Hengchuan Zou, Songlin Li, Jieyu Zheng, Xiaowen Hu, Hanyu Wei, Weizhi Ao, Yifan Dong, Wenbo Guo, Yunlei Zhao
Public-key cryptography

Responding to China's 2025 call for commercial cryptographic standards mandating 128-bit, 256-bit, and 512-bit security (optional 384-bit), we propose DTRU, a versatile, compact, simple, and robust NTRU-based key encapsulation mechanism (KEM). Our principal design contribution is double $E_8$ encoding, which constructs 16-dimensional lattice codes from $E_8$ with low decoding complexity. We further provide a detailed analysis of decryption-failure probability under this encoding mechanism....

2026/1700 (PDF) Last updated: 2026-08-15
Qlapoty: Improved analysis and efficiency for quaternionic ideal to isogeny transformation
Max Duparc, Antonin Leroux, Sina Schaeffler
Public-key cryptography

The quaternionic ideal-to-isogeny translation is a central building block of SQIsign. While the Qlapoti algorithm by Borin, Invernizzi, Corte-Real Santos, Eriksen, Mula, Schaeffler and Vercauteren significantly simplified and accelerated this step, it does not treat several technical details in sufficient depth, resulting in a flawed analysis of its failure probability. Additionally, several discrepancies between the implementation of Qlapoti and the paper's pseudocode were never analyzed...

2026/1694 (PDF) Last updated: 2026-08-15
Relations Between the Uniform MQ Assumption and Other Multivariate Assumptions
Zijun Zhuang, Yingjie Zhang, Jintai Ding
Public-key cryptography

The uniform multivariate quadratic (UMQ) assumption states that it is hard to find a zero of a uniformly generated MQ function. It is the average-case hardness assumption about the MQ problem. In this paper, we investigate the relations among the UMQ assumption, the MQ one-wayness (MQOW) assumption, and the MQ second-preimage resistance (MQSPR) assumption. We show that UMQ and MQSPR tightly imply each other, and MQOW tightly implies UMQ. Then, we show that UMQ implies MQOW when $m\leq...

2026/1683 (PDF) Last updated: 2026-08-13
Fully-Succinct Multi-Key FHE & Rate-1 Simulatable Threshold Decryption from LWE
Abtin Afshar, Rishab Goyal
Public-key cryptography

We construct the first multi-key fully homomorphic encryption (MKFHE) scheme where the ciphertext size, public key size, and secret key size remain independent of the number of users, $N$. Our construction is leveled and relies on the standard Learning with Errors (LWE) assumption. All prior MKFHE schemes incur at least linear growth in ciphertext size with the number of users ($|\mathsf{ct}| \propto N$), a limitation that has persisted across more than a decade of research. Our results...

2026/1679 (PDF) Last updated: 2026-08-13
Critical-Round Special Soundness for Multi-Round Proofs
Masayuki Abe, David Balbás, Dung Bui, Miyako Ohkubo, Zehua Shang, Akira Takahashi, Mehdi Tibouchi
Public-key cryptography

In this work, we revisit multi-round public-coin proof systems by enabling the use of their simulators and extractors within other cryptographic protocols. Although research on multi-round public-coin proofs has rapidly progressed, their simulators and extractors typically differ from the 3-move (e.g., Sigma protocols) setting in interface and behavior, and are rarely studied from this viewpoint. Prior work [Abe et al., Eurocrypt ’26] introduced the notion of critical-round...

2026/1676 (PDF) Last updated: 2026-09-14
Simple and Efficient SKL-IBE with Classical Revocation from LWE
Ho Nguyen Pham, Duong Hieu Phan, Quoc-Huy Vu, Weiqiang Wen
Public-key cryptography

Secure key leasing (SKL) is a quantum cryptographic primitive that enables the leasing of decryption keys to delegated users with the guarantee that, once revoked, the lessees irreversibly lose decryption capability. A key feature that makes SKL practically relevant is classical revocation: the ability to revoke keys at any time and from anywhere, without relying on a quantum channel. In this work, we revisit SKL schemes for public-key encryption (PKE) and identity-based encryption...

2026/1660 (PDF) Last updated: 2026-10-06
Transient Quantum Resistance, with Application to Ethereum Consensus
Pranay Anchuri, Matteo Campanelli, Rosario Gennaro
Public-key cryptography

Candidates for post-quantum migration carry additional costs compared to their pre-quantum counterparts, especially for signatures, and they lose attractive properties of schemes such as BLS: homomorphism, and hence direct signature aggregation. We propose a methodology through which a pre-quantum primitive may still be securely used past Q-day (the advent of quantum computers) in settings where forgery of signatures or cryptographic proofs need only be prevented for a bounded lifespan...

2026/1650 (PDF) Last updated: 2026-10-07
D-James: Ultra Short Multivariate Signatures
Jacques Patarin, Alexandre Roullet
Public-key cryptography

Multivariate signature schemes are among the few post-qua-\allowbreak ntum candidates capable of providing very short signatures, but designing secure constructions has proven challenging. HFE-based schemes such as G$e$MSS were compromised by algebraic MinRank attacks. This motivates the HFE$_\text{IP}^-$ framework, which combines IP and minus modifiers to address these attacks. We introduce James and \D-James, the latter achieving signatures of only 156 bits at the 128-bit classical...

2026/1641 (PDF) Last updated: 2026-08-08
Design and Analysis of Four-State Quantum Public-Key Encryption Scheme
Rahul Kumar, Vikas Srivastava
Public-key cryptography

Quantum public-key encryption (QPKE) is an important direction for secure communication in the presence of quantum adversaries. In this paper, we analyze the four-state QPKE scheme of Liu et al. and show that its ciphertext structure leaks information about computational-basis plaintexts. We present a ciphertext-leakage attack in which an adversary, without knowing the private key, measures the quantum ciphertext component and combines the result with the exposed classical correction bit to...

Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.