Dates are inconsistent

Dates are inconsistent

2000 results sorted by ID

2026/2402 (PDF) Last updated: 2026-10-07
Revisiting Lattice-based Blind Signatures Again
Yi-Fu Lai, Yu Yu
Public-key cryptography

We show an attack on a lattice-based blind signature proposed in Crypto'20. Formally it is a linear hash function based framework with a lattice-based instantiation. We first notice a bug in their security proof of blindness, which is overlooked these years. Then, we develop an attack under the honest key and the honest-but-curious signer setting against the blindness notion of the schemes by exploiting the coorelations between the leaves of the tree. We also discuss how to repair the scheme.

2026/2400 (PDF) Last updated: 2026-10-07
Simple Byzantine Lattice Agreement in $O(\frac{\log f}{\log \log f})$ Rounds
Yuval Efron, Jovan Komatovic
Applications

Lattice agreement is a relaxed version of the standard consensus problem: correct processes need not decide the same value, but their decisions must be ``comparable''. Namely, every process proposes a value from a join semi-lattice, and correct processes decide values that (1) lie on a single chain, (2) include their own proposals, and (3) include nothing beyond what was proposed. Lattice agreement has important practical applications, as it underpins atomic snapshot objects and replicated...

2026/2381 (PDF) Last updated: 2026-10-06
The Lattice Isomorphism Problem with Hints
Mélissa Rossi
Attacks and cryptanalysis

The Lattice Isomorphism Problem (LIP) is a relatively new problem that has gained increasing attention in the field of lattice-based cryptography. It is the underlying hard problem of the Hawk signature scheme, which has been submitted to the second NIST call for post-quantum signatures. In this paper, we propose to study the security of LIP in the presence of partial information on the secret solution, which can be obtained through side-channel attacks or by design. We propose a new...

2026/2334 (PDF) Last updated: 2026-10-04
Trapdoor Projective Sampling and Identity-Based Anonymous Broadcast
Gaspard Meunier, Duong Hieu Phan
Cryptographic protocols

In anonymous broadcast encryption, a ciphertext hides both the message and the set of recipients. In the general case, a lower bound of Kiayias and Samari forces the ciphertext to grow linearly with the number of recipients, a bound already met by the trivial per-recipient solution. The bounded universe is the setting where anonymous broadcast becomes concise, even asymptotically optimal and as efficient as the underlying public-key encryption. Far from a mere restriction, it is the building...

2026/2329 (PDF) Last updated: 2026-10-04
What Makes Lattice Key Generation Expensive? Controlled Cost Attribution with Structured LWR, ML-KEM, and HAETAE on Cortex-M4
Yan Zhang, Meizi Li, Liang Tan
Implementation

End-to-end cycle counts quantify lattice key-generation time on a microcontroller, but not which implementation decisions create that cost. We develop a controlled attribution method for public structure, candidate admission, and transform lifetime: how public data are organised, when candidate acceptance is checked, and whether transformed secret state is retained or reconstructed. On a fixed STM32L476RG Cortex-M4 target, paired runs within one executable keep the relevant secret, accepted...

2026/2325 (PDF) Last updated: 2026-10-03
On the hull attacks against Construction A lattices
Jean-François Biasse, Alexandra V. Hostetler, Anuvrat Jaindungarwal
Attacks and cryptanalysis

In this paper, we present an algorithm for solving the Lattice Isomorphism Problem between input lattices that are isometric to the Construction A lattice of a certain code C. Our algorithm is a direct extension of a method due to Ducas and Gibbons (PKC 2023). We prove that the run time of our algorithm is $2^{O(n)}$ and that its success probability is $1+o(1)$ over a random choice of C. Crucially, our method works when the hull of C has arbitrary dimension while the method of Ducas and...

2026/2323 (PDF) Last updated: 2026-10-03
ATLAS: A Compact Module-LWR Signature Scheme
Karthick Srivatsan, Debranjan Pal, Anindya Ganguly, Suparna Kundu, Abhinava De, Puja Mondal, Harry Hart, Quinten Norga, Prajna Mahadev, Supriya Adhikary, Debayan Das, Chaoyun Li, Angshuman Karmakar
Public-key cryptography

We present $\mathsf{ATLAS}$, a lattice-based digital signature scheme built on the Fiat--Shamir with aborts paradigm, with security based on the hardness of the Module Learning with Rounding ($\mathsf{MLWR}$) problem. Unlike $\mathsf{Dilithium}$'s $\mathbf{t} = \mathbf{As}_1 + \mathbf{s}_2$ construction or $\mathsf{HAETAE}$'s bimodal, hyperball-uniform instantiation, $\mathsf{ATLAS}$ derives its public key via deterministic rounding, $\mathbf{t} = \lfloor \tfrac{p}{q}\mathbf{As}_1 \rceil$,...

2026/2288 (PDF) Last updated: 2026-10-04
Kettle: Short Post-Quantum Threshold Signatures from the HAWK Signature Scheme
Calvin Abou Haidar, Daniel Escudero, Thomas Espitau, Clément Hoffmann, Kaoru Takemure, Mehdi Tibouchi, Hernán Darío Vanegas Madrigal
Cryptographic protocols

HAWK is a lattice-based hash-and-sign signature scheme that was a third round candidate in the NIST additional call for post-quantum signatures. It has short signatures and keys, as well as fast and portable signing and verification. However, in response to a highly-publicized AI-driven cryptanalytic result that reduced its security (roughly doubling the required dimension to achieve a given security level), the authors de- cided to withdraw from the competition. The need to...

2026/2287 (PDF) Last updated: 2026-10-01
Knuth–Yao masked (Gaussian) sampling
Calvin Abou Haidar, Clément Hoffmann
Implementation

Discrete Gaussian sampling remains one of the most delicate operations to protect against side-channel attacks in lattice-based cryptography. In this work, we present the first masked evaluation of the Knuth-Yao sampler, a generic building block for lattice-based schemes. Its random-walk formulation might seem fundamentally at odds with masking, since the walk's control flow depends precisely on the secret sample being produced. We show instead that its underlying tree structure is...

2026/2281 (PDF) Last updated: 2026-09-30
Poisoned Cryptography: Solving Direct-Sum LIP in Half the Dimension
Artyom Kuninets, Aleksandr Bakharev
Attacks and cryptanalysis

We analyse the Lattice Isomorphism Problem framework of Ducas and van Woerden when it is instantiated with the direct sum of two rescaled integral Barnes-Wall lattices, $\Lambda_{\mathbf{S}}=gBW^{\mathbb{Z}}_{m}\oplus(g+1)BW^{\mathbb{Z}}_{m}$. All primitives of the framework share the same key pair, a public form $\mathbf{P}=\mathbf{U}^{\top}\mathbf{S}\mathbf{U}$ and a secret unimodular matrix $\mathbf{U}$, so recovering $\mathbf{U}$ from $\mathbf{P}$ breaks each of them. We take the...

2026/2278 (PDF) Last updated: 2026-09-30
Masked CROSS: Masking the CROSS Digital Signature Scheme at Arbitrary Order
Khan Keren Mengwi, Puja Mondal, Achille Ecladore Tchahou Tchendjeu, Emmanuel Fouotsa, Suparna Kundu
Implementation

CROSS is a code-based signature scheme built on the Restricted Syndrome Decoding Problem and is a second-round candidate in NIST's additional digital signature standardization process. Recent work shows that its reference implementation is vulnerable to side-channel analysis, allowing an attacker to recover the long-term secret key from a single power trace. No masking countermeasure has so far been designed for CROSS's restricted-syndrome framework, leaving its practical side-channel...

2026/2268 (PDF) Last updated: 2026-09-29
Kopis: A KEM for Obfuscation
Andrea Basso, Michael Rosenberg
Public-key cryptography

Password-authenticated key exchange (PAKE) and obfuscated key exchange (OKEX) are widely used protocols, appearing in passport access control, Tor's censorship evasion, and more. As quantum threats grow nearer, there have been an increasing number of proposals for post-quantum PAKE and OKEX. All such protocols are similar in that they build on a KEM, obfuscating public keys and/or ciphertexts sent over the wire, e.g., by adding a random mask or applying an ideal cipher. Many propose...

2026/2250 (PDF) Last updated: 2026-09-28
Decryption Failures in NGCC Lattice KEMs: Correlated Blocks, Omitted Compression Noise, and Failure Boosting under a Query Cap
Yuyang Xiao
Public-key cryptography

The Chinese NGCC post-quantum competition received a family of lattice KEMs whose decryption failure rates (DFRs) are certified by their designers with models that differ in detail. We recompute the failure probability of the first-round lattice KEMs whose claimed DFR, or a simple recomputation of it, lies near or below the nominal level, and we estimate the offline search for weak ciphertexts under a cap of $2^{64}$ or $2^{80}$ decapsulation queries. Three distinct mechanisms are...

2026/2226 (PDF) Last updated: 2026-09-26
FALCON++: Shorter Signatures without NTRU Smoothing Estimates
Hao Yan, Nicholas Zhao
Public-key cryptography

\Falcon{} is a digital signature scheme based on NTRU lattices, known for its compact signatures. Its weak-smoothness variant, \FalconWS{} (ASIACRYPT 2025), reduces signature sizes by allowing narrower Gaussian sampling distributions. Further reductions require efficient sampling at narrower widths and a security analysis that accounts for the resulting distributions. We analyze the distribution of accepted preimages directly, without estimating the smoothing parameter of the NTRU...

2026/2222 (PDF) Last updated: 2026-09-26
SoK: The Landscape of Post-Quantum Multi-Party Signature Aggregation
Gaurav Kumar
Cryptographic protocols

Post-quantum signature schemes such as ML-DSA, FN-DSA (Falcon), and SLH-DSA have significantly larger keys and signatures than their classical counterparts, making compact multiparty signing an increasingly important research problem. We survey more than 30 schemes published between 2021 and 2026, covering threshold and dis tributed signing, proof-based aggregation, and algebraic half-aggregation. Our survey shows that most existing work is designed around blockchain and...

2026/2211 (PDF) Last updated: 2026-09-25
Structural Cryptanalysis of Polar-KEM: Direct Recovery of the Secret Isometry
Yuyang Xiao, Long Chen, Zhenfeng Zhang
Public-key cryptography

Polar-KEM is a lattice-based key encapsulation mechanism submitted to the Next-generation Commercial Cryptographic Algorithms Program. Its security is claimed to rely on a lattice isomorphism problem over polar-code-defined Construction-D lattices. In its core key-generation algorithm, a polar lattice basis is constructed from a polar-code chain, reduced using LLL, and left-multiplied by a secret orthogonal matrix. The resulting matrix is published as the public key. We show that...

2026/2201 (PDF) Last updated: 2026-09-24
Dance with Noise: Safely Trade Minor Decryption Failures for More Compact KEMs with Applications to IKEv2
Zidi Zhuang, Yuyang Xiao, Long Chen, Qiang Tang, Zhenfeng Zhang
Cryptographic protocols

The standardization of post-quantum cryptography, notably ML-KEM, introduces a severe network bottleneck: large public keys and ciphertexts often exceed the Maximum Transmission Unit (MTU) limits of UDP-based protocols. This size explosion inevitably leads to unreliable IP-layer fragmentation or forces complex protocol workarounds. To overcome this, we propose a novel design philosophy for post-quantum Authenticated Key Exchange (AKE). We challenge the rigid cryptographic paradigm that...

2026/2180 (PDF) Last updated: 2026-09-23
Gaussian Kernel Lattices and Smoothing Bounds from Theta Integrals
Samed Düzlü, Nihar Gargava, Erkan Tairi
Foundations

A Gaussian leftover hash lemma (LHL) states that, for a matrix $\mathbf{X}$ with discrete Gaussian columns and a sufficiently wide Gaussian vector $\mathbf{v}$, the product $\mathbf{X}\mathbf{v}$ is close to a discrete Gaussian. Over the integers this is a classical tool, and Albrecht-Felderhoff-Lai-Lapiha-Woo (EUROCRYPT'26) recently extended it to modules over a number field $K$ of degree $d$. In every version, the lemma rests on two facts about the kernel lattice of $\mathbf{X}$: that...

2026/2170 (PDF) Last updated: 2026-09-23
Swing the Lure: How to Cheaply Mitigate Sign Leakage in Falcon
Xiuhan Lin, Mehdi Tibouchi, Yang Yu
Attacks and cryptanalysis

Falcon is one of the three post-quantum signature schemes selected by NIST for standardization so far. It is efficient and has particularly short signatures, but has the drawback of being difficult to implement correctly and securely, owing to its use of floating point arithmetic and secret-dependent lattice Gaussian sampling. In particular, obtaining implementations of Falcon that are protected against side-channel attacks seems to be a tremendous challenge that has no satisfactory solution...

2026/2167 (PDF) Last updated: 2026-09-23
New Applications of RSA
Yao-Ching Hsieh, Abhishek Jain, Brent Waters
Public-key cryptography

We present new constructions of the following primitives featuring succinct communication: - Batch threshold encryption: Assuming RSA and DCR, we construct a threshold encryption scheme in which a batch of ciphertexts can be decrypted via short hints from a quorum of decryptors. Previously, this was known only from bilinear maps. - Aggregate signatures: Assuming RSA, we construct a signature scheme where signatures on different messages from an arbitrary number of signers can be...

2026/2149 (PDF) Last updated: 2026-09-22
Identify Post-Quantum Cryptographic Algorithms for Automotive Security: Performance-Driven Guidance for Secure Boot, OTA, and V2X Communication
Dileep Singh Kushwaha, Parneet Kaur
Cryptographic protocols

The rapid expansion of quantum computing threatens the security foundations of classical public-key cryptography, including RSA and ECC, both vulnerable to Shor's algorithm. For the automotive industry, where secure communication underpins critical functions such as over-the-air (OTA) updates, secure boot, firmware signing, PKI validation, and vehicle-to-everything (V2X) connectivity, this threat demands early and informed migration planning. This paper presents a cross-platform performance...

2026/2146 (PDF) Last updated: 2026-09-22
Succinct Shortness Check Under a Few Kilobytes via Tensor Train Random Projections
Zhiyuan Geng, Maxime Plançon
Cryptographic protocols

Range proofs are a fundamental building block of lattice-based proof systems. Existing approaches relying on standard Johnson-Lindenstrauss (JL) struggle to provide succinctness: unstructured JL incurs linear verifier complexity, while structured JL introduced in RoK and Roll [ASIACRYPT'25] produce large projection vectors that need to be sent in costly committed form. For a witness of dimension $m$ and a security parameter $\lambda$, the JL projection vector is $O(\lambda),$ but the...

2026/2136 (PDF) Last updated: 2026-09-21
MAMBA-Frost: A Lattice KEM from Learning With Quantization
Shanxiang Lyu, Ke Ma, Junzuo Lai
Public-key cryptography

The Learning With Errors (LWE) problem provides a conservative and well-established security foundation for lattice-based cryptography, while Learning With Rounding (LWR) improves bandwidth efficiency through deterministic rounding. However, the rounding noise in LWR is inherently correlated with the hidden linear term, preventing tight and sample-preserving reductions to standard LWE for polynomial moduli. Prior work on the Learning With Quantization (LWQ) problem established a tight...

2026/2134 (PDF) Last updated: 2026-09-21
ANSA-IBS: Identity-Based Signatures from Annular NTRU Trapdoors and Bimodal Fiat-Shamir with Aborts
Zhaohui Cheng, Hengfu Yang, Kaixin Xiong
Public-key cryptography

We give a lattice identity-based signature scheme from annular NTRU trapdoors and Fiat--Shamir with aborts (FSwA). Countered hashing maps each identity to its first invertible DLP/NTRU syndrome $a$. Extraction returns a short witness to $s_0+s_1h=a\bmod q$, and signing normalizes this relation to a fixed-target two-response equation with public commitment recovery. Gärtner's iterative rejection method fits naturally into this signing layer: processing the challenge monomials separately...

2026/2125 (PDF) Last updated: 2026-09-20
A Survey of Constraint-Based Side-Channel Analysis: From Algebraic Attacks to Exact Probabilistic Inference
Gaurav Kumar
Attacks and cryptanalysis

Over the last fifteen years, side-channel analysis (SCA) against implementations of both classical and post quantum cryptography has undergone a quiet but fundamental change of paradigm: from treating leakage as evidence to be combined with an algorithm’s structure into a system of exact equations to be solved, to treating it as evidence to be combined into a joint probability distribution to be queried. This survey gives a systematic account of that evolution through four paradigms:...

2026/2124 (PDF) Last updated: 2026-09-20
Every Signing Leaks: Breaking Falcon via Floating-Point Conversion Leakage
Yuanyuan Zhou, Weijia Wang, Yiteng Sun, Yu Yu
Attacks and cryptanalysis

Falcon offers compact signatures and well-studied mathematical security, but its side-channel security remains a critical challenge. In particular, its floating-point Gaussian sampler constitutes a major source of side-channel leakage, while protecting it efficiently is difficult because of its reliance on floating-point arithmetic. However, existing attacks targeting the sampler under realistic noisy-leakage conditions typically require thousands of traces and are evaluated on unoptimized...

2026/2121 (PDF) Last updated: 2026-09-20
Lattice-Based Synchronous Signatures: Efficiently Aggregatable and Thresholdizable
Dan Boneh, Binyi Chen, Trisha Datta
Public-key cryptography

Aggregate signatures play an important role in proof-of-stake systems, where many validators sign a block. There is a strong desire to aggregate all these signatures into one short signature that is fast to verify. Since all validators know the block number they are signing, this setting is well suited for synchronous (a.k.a stateful) signatures. Boneh and Kim (2019) showed that lattice-based one-time signatures (OTS) can be aggregated very efficiently. The Chipmunk and Lemur signature...

2026/2117 (PDF) Last updated: 2026-09-20
Provable dual attack on LWE via lattice projection
Hongyuan Qu, Chengliang Tian, Geng Wang, Guangwu Xu
Attacks and cryptanalysis

The Learning with Errors (LWE) problem is a cornerstone of post-quantum cryptography, and the dual attack is a central tool for evaluating its concrete hardness. In provable dual attacks, a major bottleneck is the large number of discrete Gaussian samples required over the dual lattice. While recent works have focused on accelerating the guessing step via modulus switching, the sampling bottleneck has remained largely unoptimized. In this paper, we address this issue from a new perspective....

2026/2094 (PDF) Last updated: 2026-09-18
Tree Encodings IV: Depth-Unbounded Attribute-Based Encryption and Delay Encryption
Damiano Abram, Giulio Malavolta, Lawrence Roy
Public-key cryptography

Assuming the polynomial-time hardness of Decomposed LWE, a variant of the learning with errors (LWE) problem, we construct ciphertext-policy attribute-based encryption for depth-unbounded (but bounded-space) predicates. Previously, attribute-based encryption for depth-unbounded predicates was only known from an insecure version of evasive LWE, or by additionally assuming the cryptographic hardness of discrete logarithms, which makes such schemes quantum-insecure. Adapting these...

2026/2093 (PDF) Last updated: 2026-09-18
Tree Encodings III: Time/Space Hardness from Lattice Problems
Damiano Abram, Giulio Malavolta, Lawrence Roy
Foundations

Assuming the polynomial-time hardness of a variant of the short integer solution (SIS) problem, we show the existence of sequential and memory-hard functions. Such an assumption postulates the hardness of a problem against polynomial-time algorithms, regardless of their memory and depth. Yet, we show that this assumption implies that $\mathsf{P} \neq \mathsf{NC}$, that $\mathsf{P} \neq \mathsf{L}$, and that the $\mathsf{NC}$ hierarchy is proper, i.e., that $\mathsf{NC}^1 \subsetneq...

2026/2082 (PDF) Last updated: 2026-09-18
Incremental Keyword Private Information Retrieval from d-ary Segmented Cuckoo Filters
Bao Ninh
Cryptographic protocols

We introduce RisePIR, the first preprocessing keyword private information retrieval (PIR) scheme that absorbs insert, update, and delete on its key-value store at a cost proportional to the number of mutations alone. Where the static state-of-the-art schemes ChalametPIR and $\mathsf{KPIR}^{\mathsf{index}}$ re-run their preprocessing from scratch on every change, RisePIR patches its preprocessing in place and stays as practical as both in the online phase. We give a generic construction of...

2026/2078 (PDF) Last updated: 2026-09-18
Radical Ring-LWR: Efficient Key Encapsulation and Signatures from Structured Rounding
Joost Renes, Joppe W. Bos, Haochen Huang, Selim Kirbiyik, Alberto Ovena, Sujoy Sinha Roy, Frederik Vercauteren, Peng Wang, Fangyu Zheng, Chenxin Zhong
Public-key cryptography

State-of-the-art lattice-based cryptography requires a power-of-two cyclotomic field that limits the attainable security levels, or a module structure for which the cost grows quadratically in the module rank. Radical rings were recently proposed as a solution in the context of Learning With Errors (LWE) based Key Encapsulation Mechanisms (KEMs) with heuristic hardness arguments for the Ring-LWE security and failure probability. We develop the Learning With Rounding counterpart, Radical...

2026/2077 (PDF) Last updated: 2026-09-18
Practical Group Signatures from Tag-Based NTRU Sampler
Corentin Jeudy
Public-key cryptography

The post-quantum migration for key agreements and signatures being well underway, the focus naturally shifts to other properties and primitives that still lack efficient solutions. One such area is that of privacy-enhanced primitives, with a growing number of post-quantum constructions. Among the most fundamental are group signatures, which represent an important milestone of anonymity and accountability towards more involved designs. However, despite recent progress, most compact lattice...

2026/2055 (PDF) Last updated: 2026-09-16
A Locality-Sensitive Hashing Framework for Reducing Bounded Distance Decoding to EDCP
Ryann Cartor, Felice Manganiello, William Youmans
Foundations

Bounded Distance Decoding (BDD) is a fundamental primitive in both code- and lattice-based post-quantum cryptography. Prior work of Regev (FOCS~2002) and Brakerski, Kirshanova, Stehl\'e and Wen (PKC~2018) connected lattice BDD and Learning With Errors (LWE) to the Extrapolated Dihedral Coset Problem (EDCP), but these reductions rely heavily on geometric structure and do not naturally extend to coding-theoretic metrics. We present a general quantum reduction from BDD over finite Abelian...

2026/2049 (PDF) Last updated: 2026-09-15
Tighter and Friendlier Integer Bounds for Quaternion Algorithms - Application to SQIsign
Maciej Czuprynko, Anisha Mukherjee, Sujoy Sinha Roy
Public-key cryptography

The digital signature scheme SQIsign, currently under consideration in NIST's call for additional post-quantum signatures, offers the smallest key and signature sizes among all candidates. Its signing procedure, however, relies on an involved arithmetic layer over quaternions, in which the objects are represented by small-dimensional integer lattices. In this layer, the intermediate integers can grow significantly larger than the final outputs. Controlling this growth is essential for...

2026/2042 (PDF) Last updated: 2026-09-15
On Solving Ideal-SVP and Ideal-BDD with Group Representations
Hongyuan Qu, Guangwu Xu
Attacks and cryptanalysis

Ideal lattices over number fields play a central role in post-quantum cryptography, as evidenced by the NIST-standardized schemes Kyber and Dilithium. Understanding the hardness of ideal-lattice problems such as the Unique Shortest Vector Problem (Id-uSVP) and Bounded Distance Decoding (Id-BDD) is therefore essential. Recent works have shown that certain algebraic symmetries can significantly reduce the dimension of the Ideal-SVP problem. In particular, subfield attacks exploit the...

2026/1991 (PDF) Last updated: 2026-09-12
Towards Practical Iterative Rejection Sampling: A Compact and Efficient Signature over Module Lattices
Yifan Ming, Jipeng Zhang, Zihan Liu, Guofeng Tang, Pengfei Chen, Yutao Sun, Si Gao, Cong Zhang, Long Chen
Public-key cryptography

Lattice signatures face a strict trade-off among compactness, implementation simplicity, and reliance on standard lattice assumptions: ML-DSA-44 requires a 2420-byte signature (3732 bytes combined) and HAETAE-120 takes 1474 bytes (2466 bytes combined), while Falcon-512 achieves 555 bytes but relies on complex floating-point arithmetic. We propose SHUTTLE, a compact Fiat–Shamir signature built on a standard MLWE public-key structure with unforgeability bound to MSIS in the random oracle...

2026/1983 (PDF) Last updated: 2026-09-18
Akita: A High-Performance Lattice-Based Polynomial Commitment Scheme
Quang Dao, Omid Bodaghi, Amirhossein Khajehpour, Giuseppe Vitto, Mohammadtaghi Badakhshan, Markos Georghiades, Fengrun Liu, Jiapeng Zhang, Justin Thaler
Cryptographic protocols

Lattice-based polynomial commitment schemes (PCSs) promise post-quantum SNARKs with two properties that elliptic curves provide and hash-based schemes, today's deployed post-quantum default, do not: concretely small proofs and commitment time proportional to the number of nonzero entries in the committed polynomial rather than its length. The second property is essential to Twist and Shout (CRYPTO 2026), the fastest known memory-checking arguments and a core component of the Jolt...

2026/1965 (PDF) Last updated: 2026-09-10
Lattice-based Threshold Traitor Tracing with Public Traceability
Sébastien Canard, Nathan Papon, Duong Hieu Phan
Public-key cryptography

Since the introduction of Threshold Traitor Tracing by Boneh, Partap and Rotem at CRYPTO '24, several works have extended the functionalities within the framework or improved the parameters. However, most of the existing solution fall short in providing post quantum security guarantees. The only lattice-based construction, due to Das et al. from EUROCRYPT '26, achieves post-quantum security but is limited to private tracing: a dedicated tracing authority holds a secret tracing key. In a...

2026/1951 (PDF) Last updated: 2026-09-09
OAEP† Transform in the Post-Quantum World
You Lyu, Shengli Liu, Shuai Han, Bohang Chen
Public-key cryptography

We provide a new variant of OAEP called OAEP†, which converts an almost trapdoor injective function (ATIF) to a public-key encryption (PKE) scheme. The resulting PKE not only has CCA security but also enjoys pseudo-randomness, anonymity, and robustness under chosen-ciphertext attacks in the quantum random oracle (QRO) model. Compared with the plain OAEP and its variants whose structure does not serve the quantum world very well, our OAEP† is designed with a new structure, admitting more...

2026/1941 (PDF) Last updated: 2026-09-09
DualMS 2.0: Practical Lattice-Based Two-Round Fiat-Shamir Multi-Signature with Better Efficiency
Qiqi Lai, Chongshen Chen, Feng-Hao Liu, Tianyu Zhao, Qi Wang, Zhedong Wang

We present a more practical lattice-based two-round Fiat–Shamir multi-signature scheme that achieves a substantial reduction in signature size compared with DualMS, the state-of-the-art two-round lattice-based Fiat-Shamir multi-signature. Our main technical contribution is a new simulation technique that enables individual signatures to be sampled from distributions with smaller parameters, yielding significant concrete efficiency gains. In addition, through applying the specific...

2026/1925 (PDF) Last updated: 2026-09-08
Reproducible Design-Space Study of Lightweight Lattice-Based Authentication and Signatures for Blockchain Transactions
Zhiqian Lin

Quantum computers threaten the classical public-key primitives (RSA, ECDSA) used by most blockchains today; NIST has therefore standardized lattice-based signatures (ML-DSA, FIPS 204; and FN-DSA, a FALCON-based scheme being finalized as FIPS 206) and mandated a transition of the underlying cryptosystems. This report describes a reproducible, teaching-level study of the design space of lightweight lattice-based authentication and signatures for blockchain-style transactions. We study...

2026/1924 (PDF) Last updated: 2026-09-08
Decryption-Failure Rate with Multidimensional Lattice Decoders: Unified Framework, Theory Refinement, and More Accurate Evaluation
Boyue Fang, Songlin Li, Yunlei Zhao
Public-key cryptography

Using a multidimensional lattice block code complicates decryption-failure analysis in two distinct ways. A norm or BDD certificate need not equal the implemented message-failure event, and structured polynomial products can make the residual coordinates dependent. We record every estimate by its decoder event, residual law, tail engine, and ciphertext/key aggregation. This event-aligned framework yields finite directional bounds for arbitrary residual laws and a finite Gaussian reference...

2026/1920 (PDF) Last updated: 2026-09-23
Compact Lattice Anonymous Credentials from Tighter Approximate Range Proofs
Corentin Jeudy, Olivier Sanders
Cryptographic protocols

Accommodating cryptographic authenticity with strong user privacy assurances has been the primary motivation for anonymous credentials systems. Their features have recently come into the spotlight with the European Digital Identity (EUDI) wallet initiative, insisting on the need for efficient and private solutions based on well-understood security foundations for high assurances. This coincides with the post-quantum transition, but current quantum-safe solutions based on standard assumptions...

2026/1904 (PDF) Last updated: 2026-09-11
When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA Implementation
Yuhan Zhao, Dalin He, Wei Cheng, Yuejun Liu, Jingdian Ming, Yongbin Zhou
Attacks and cryptanalysis

The standardization of ML-DSA has shifted the cryptographic community's focus toward its practical security. While profiled attacks against its implementations are well studied with a few traces, non-profiling attacks are widely assumed to require large trace complexity. We challenge this by introducing horizontal fusion attacks, demonstrating that non-profiling, few-trace key recovery is highly practical against ML-DSA, even against masked implementations. We expose a structural...

2026/1876 (PDF) Last updated: 2026-09-03
AH-BKZ: A Lattice Reduction Algorithm with Asynchronous Hybrid Processing
Renya Hashimoto, Junji Shikata, Atsushi Takayasu, Yuntao Wang
Attacks and cryptanalysis

Evaluating the hardness of the Shortest Vector Problem (SVP) is essential for selecting secure parameters in lattice-based cryptography. The fastest current SVP solvers are based on variants of G6K, but their large memory consumption remains a major bottleneck, making high-dimensional executions difficult. A common strategy for alleviating this memory bottleneck is strong basis reduction preprocessing before a sieve-based algorithm. This strategy can solve SVP instances in higher dimensions...

2026/1861 (PDF) Last updated: 2026-09-16
Anonymous Attribute-Based Signcryption: Definitions, Constructions, and Applications
Yongkang Lang, Fangguo Zhang, Zhiyuan An, Xinyi Huang, Xiaofeng Chen
Cryptographic protocols

We put forward a generalization of attribute-based signcryption, called anonymous attribute-based signcryption (A$^2$BSC). Beyond message confidentiality and ciphertext unforgeability, A$^2$BSC further requires \textit{ciphertext anonymity}: no information about the signcryptor's attributes or ciphertext-related attributes/policies is leaked, regardless of the decryption outcome. Specifically, we begin by establishing the syntax and security notions for A$^2$BSC within a \textit{unified}...

2026/1857 (PDF) Last updated: 2026-09-01
LatticeBlindFold: A Lattice-Based Analogue of NovaBlindFold
Luca Dall'Ava
Cryptographic protocols

Folding schemes compress many instances of a relation into a single accumulated one and, via composition with the Fiat-Shamir heuristic, yield SNARKs for arbitrarily large computations. However, essentially every folding scheme beyond Nova itself (including the lattice-based SuperNeo [NS26], LatticeFold(+) [BC24,BC25], and Cyclo [GLLO26]) is only randomizing, not blinding (i.e. honest-verifier zero-knowledge): its folding transcript leaks information about the witnesses being folded. We...

2026/1828 (PDF) Last updated: 2026-08-28
WeaveTLS: High-Throughput Cross-Connection ML-DSA Authentication in Mutual TLS
Ganqin Liu, Hao Cheng, Jipeng Zhang
Implementation

Mutual TLS (mTLS) authenticates both peers and therefore incurs post-quantum signature costs on every connection. Concurrent handshakes expose independent ML-DSA operations, but executing them jointly is difficult: signing is rejection-divergent, verification uses heterogeneous keys, and synchronous TLS APIs expose authentication work one connection at a time. We present WeaveTLS, a wire-transparent architecture that executes ML-DSA authentication across concurrent TLS connections....

2026/1822 (PDF) Last updated: 2026-09-08
Non-Malleable Reductions of Knowledge
Antonio Faonio, Lili Tong
Foundations

Non-malleability for non-interactive zero-knowledge proofs requires that, given a proof for a statement, it is infeasible to derive a valid proof for a related statement without knowing a corresponding witness. We introduce a modular framework for analyzing non-malleable reductions of knowledge (RoKs). A reduction of knowledge transforms the task of proving knowledge for a source relation into proving knowledge for a target relation, often simpler or more structured. RoKs are an extremely...

2026/1790 (PDF) Last updated: 2026-08-24
Lithium: Making Iterative Rejection Sampling Practical for Compact Lattice Signatures
Jipeng Zhang, Pengfei Chen, Long Chen, Cong Zhang, Jiaheng Zhang
Implementation

Post-quantum deployments need signatures that are both fast and small. ML-DSA gives a practical Fiat-Shamir lattice-signature baseline, but its signatures remain large enough to make bandwidth, certificate size, and signed-log storage first-order costs. Gaertner's iterative rejection sampling construction (CRYPTO'25) shows that this design family can be made much more compact. The open question is whether this theoretical design can be turned into a concrete, implementation-oriented...

2026/1761 (PDF) Last updated: 2026-08-21
Lightweight Lattice-based Single-Party Public-Key Authenticated Key Exchange
Alex Aïdan, Sébastien Canard, Emmanuel Fouotsa, Nyiang Melchisedech Mbeng
Public-key cryptography

Authenticated Key Exchange (AKE) is a cornerstone of secure communication, especially in resource-constrained IoT environments where lightweight and post-quantum security are paramount. While lattice-based cryptography offers promising solutions, existing post-quantum AKE protocols often prioritize strong security notions, such as the use of an IND-CCA encryption scheme, incurring overheads incompatible with IoT devices. This raises a critical question: Can one-way security (OW), a weaker...

2026/1750 (PDF) Last updated: 2026-08-20
Threshold Lattice-Based Zero-Knowledge Proofs
Scott Griffy, Victor Youdom Kemmoe, Ngoc Khanh Nguyen, Tjerand Silde
Cryptographic protocols

Lattice-based zero-knowledge proofs are now efficient enough for practical use, but in all known constructions a single prover holds the entire witness and is therefore a single point of failure. Thresholdizing them is understood only for three-round $\Sigma$-protocols, which certify shortness only $\textit{approximately}$. The $\textit{exact}$ statements needed by applications such as anonymous credentials require more rounds and rely on rejection sampling, and neither property survives...

2026/1743 (PDF) Last updated: 2026-08-19
Notes on Short-Limb Modular Multiplication Techniques: Barrett, Montgomery, Plantard, and the Explicit CRT
Bo-Yin Yang
Implementation

This note collects, in compressed form, some techniques for modular multiplication with word-size (“short-limb”), or at most a-handful-of-words sized moduli as they are used in implementations of lattice-based cryptography: Barrett reduction and multiplication (in signed and unsigned flavors, with exact error, range, and canonicality analyses), Montgomery reduction and multiplication (including the folded-constant form, the precise equivalence with Barrett multiplication, even moduli,...

2026/1738 (PDF) Last updated: 2026-08-19
Noisy Subset Product
Trey Li
Foundations

In 1978, Yao studied the subset product problem and proved its NP-completeness. Later, Galbraith, Zobernig, and Li considered a prime-based modular variant and studied its average-case hardness. More recently, Li introduced the general problem of unknown-coefficient multivariate exponential system solving and studied its hardness systematically in an abstract setting. Li's framework implies a noisy modular variant of subset product as a special case. In this paper, we study this noisy subset...

2026/1712 (PDF) Last updated: 2026-08-17
Statistical Inference from Noisy Randomness Leakage for ML-DSA Attacks
Niklas Paskarbeit, Carsten Schubert, Marian Margraf, Jean-Pierre Seifert
Attacks and cryptanalysis

ML-DSA is a NIST post-quantum signature standard whose security argument rests on rejection sampling making released signatures independent of the secret key. Liu et al. and Damm et al. showed that a single leaked bit of the masking randomness per signature breaks this guarantee, making ML-DSA subkeys recoverable from a number of so-called informative relations, and the resulting attacks were sharpened by Schubert et al. and Bashiri et al.. All of them treat every leaked bit as equally...

2026/1701 (PDF) Last updated: 2026-08-16
DTRU: A Versatile, Compact, Simple, and Robust NTRU KEM with Double $E_8$ Encoding
Hengchuan Zou, Songlin Li, Jieyu Zheng, Xiaowen Hu, Hanyu Wei, Weizhi Ao, Yifan Dong, Wenbo Guo, Yunlei Zhao
Public-key cryptography

Responding to China's 2025 call for commercial cryptographic standards mandating 128-bit, 256-bit, and 512-bit security (optional 384-bit), we propose DTRU, a versatile, compact, simple, and robust NTRU-based key encapsulation mechanism (KEM). Our principal design contribution is double $E_8$ encoding, which constructs 16-dimensional lattice codes from $E_8$ with low decoding complexity. We further provide a detailed analysis of decryption-failure probability under this encoding mechanism....

2026/1690 (PDF) Last updated: 2026-08-14
Concurrently Secure Compact Blind Signatures from Module-SIS
Olivier Blazy, Lola-Baie Mallordy, Weiqiang Wen
Cryptographic protocols

A blind signature scheme allows a user to interact with a signer to obtain a valid signature on a message, while ensuring that the signer cannot learn any information on the message being signed, nor link a given couple message-signature to the specific interaction that produced it (blindness). In round-optimal (i.e., two-move) blind signature schemes, a user sends a request (typically a commitment) for a message, and the signer responds with a signature. To achieve blindness, the resulting...

2026/1682 (PDF) Last updated: 2026-08-13
Incomplete Ciphertext Comparison in ML-KEM: From an IND-CCA2 Break to Key Recovery
Bhabani Sankar Das
Attacks and cryptanalysis

ML-KEM is IND-CCA2 secure only because of one check inside decapsulation: the receiver re-encrypts the message it recovered and returns the true shared secret only if the result matches the received ciphertext exactly. This is the Fujisaki–Okamoto (FO) check. wolfSSL implemented it in hand-written SIMD assembly, and on two backends it compared fewer than all of the ciphertext bytes. The x86-64 AVX2 path compared 1536 of 1568 bytes; the ARM64 NEON path compared roughly half. These bugs...

2026/1658 (PDF) Last updated: 2026-08-11
Upper bounds for failure probabilities of reductions from low density subset sum problems to lattice problems on linearly independent vectors
Shoichi Kamada
Foundations

As a new lattice problem, we introduce $l$-Shortest Independent Vectors Problem ($l$-SIVP for short), where $l$ is a positive integer no greater than the rank of a lattice. In the case where $l=1$, $l$-SIVP means SVP, and in the case where $l$ is the rank of a lattice, $l$-SIVP means SIVP. We estimate upper bounds on the failure probabilities of the reductions from the subset sum problems to the $l$-SIVPs in terms of Ehrhart theory. Especially, in the case of $l=1$, our upper bound is...

2026/1642 (PDF) Last updated: 2026-08-14
A Torus-Structured Generalisation of NTRU: the NTC Assumption, its Cryptanalysis, and a Compact KEM
Sidoine Djimnaibeye, Djiby Sow, Mahamat Borgou Hassan
Foundations

We introduce Noisy Torus Conjugation (NTC), a lattice assumption in which a short secret is confined to a non-split maximal torus of $GL_k(R_q)$ and acts by conjugation on a uniform matrix, the result being masked by a short additive error. NTRU is the $k=1$ member of the family. Passing to $k \ge 2$ changes the geometry of the underlying lattice in two specific ways. The planted module occupies a fraction $1/(2k)$ of the published lattice's dimension, against NTRU's $1/2$; and the norm-map...

2026/1639 (PDF) Last updated: 2026-08-08
LUNA+: More Succinct Post-Quantum ZK-SNARKs from Computational Privacy
Yuki Kume, Ron Steinfeld, Amin Sakzad, Mert Yassi
Public-key cryptography

We present LUNA+, a refinement of the LUNA designated-verifier lattice-based ZK-SNARG that achieves significantly improved concrete succinctness. While the original LUNA scheme achieves quasi-optimal asymptotic proof length ($O(\lambda)$), its practical parameters are constrained by its statistical privacy analysis. This analysis, founded on a Leftover Hash Lemma with Leakage (LHLL), necessitates the use of polynomially large, but still significant "smudging" noise to guarantee statistical...

2026/1628 (PDF) Last updated: 2026-08-06
Lattice-based Signature Schemes for Bitcoin
Dmytro Zakharov, Mikhail Kudinov, Viktoria Balatska, Yaroslava Chopa
Applications

Lattice-based cryptography offers a promising direction for transitioning Bitcoin toward post-quantum security, serving as a secure replacement for currently deployed discrete logarithm signatures. The primary advantages of lattice-based signature schemes include the compact combined size of signatures and public keys (e.g., in some cases below 1.6 KB), the robustness of underlying security assumptions, and an algebraic structure that, while not yet yielding practical constructions, holds...

2026/1624 (PDF) Last updated: 2026-08-27
Code Generation of Faster Formally Verified NTT with Plantard Reduction
Donnie Y. Xu, Rajeev Gore, Amin Sakzad, Ron Steinfeld, Raymond K. Zhao
Implementation

We present a formally verified implementation of the ML-KEM Number-Theoretic Transform (NTT) based on Plantard arithmetic, produced via a code generator that targets ML-KEM, ML-DSA, and FN-DSA from a single parameter triple. The generator embeds a static bound analyzer that places modular reductions at code-generation time without runtime branching, eliminating per-scheme manual tuning while preserving constant-time guarantees. Each generation produces structurally identical implementations...

2026/1585 (PDF) Last updated: 2026-08-05
Proving Threshold Regev PKE from Adaptive Hint-MLWE: Efficient, Non-interactive, and CCA Secure
Yisol Hwang, Shuichi Katsumata, Seonhong Min, Guilhem Niot, Yongsoo Song
Public-key cryptography

Threshold public-key encryption (tPKE) has recently attracted renewed interest, largely due to NIST's call for Multi-Party Threshold Cryptography. While classical tPKE has approached a high state of maturity, its post-quantum counterpart has not. Indeed, thresholdizing the celebrated lattice-based Regev PKE, which forms the basis of ML-KEM, remains unsatisfactory. Interestingly, how to thresholdize Regev PKE has not fundamentally changed in over a decade --- the only thing that has...

2026/1576 (PDF) Last updated: 2026-08-05
A Systematic Literature Review on Optimising CRYSTALS-Dilithium (ML-DSA) Performance for IoT Devices via Lightweight Hashing
Ceasar Njuguna Ngunu, Edward Ombui
Implementation

Background: The migration to post-quantum cryptography confronts resource-constrained Internet of Things (IoT) devices with a material performance cost. CRYSTALS-Dilithium, standardised as the Module-Lattice-Based Digital Signature Algorithm (ML-DSA) in FIPS 204, fixes the Keccak-based SHAKE functions as its only symmetric primitives, and profiling on embedded platforms identifies hashing as the largest single contributor to the scheme’s software cost. This review synthesises the performance...

2026/1559 (PDF) Last updated: 2026-07-30
Revisiting Shamir Secret Sharing for Threshold Fully Homomorphic Encryption
Jiseung Kim, Seunghu Kim, Hyung Tae Lee
Cryptographic protocols

Recent advances in lattice-based threshold cryptography, including threshold fully homomorphic encryption (ThFHE) and threshold public key encryption (ThPKE), commonly employ Shamir secret sharing over rings. While conceptually simple, these schemes suffer from rapidly growing denominator-clearing factors required for secret reconstruction as the number of parties $N$ increases, which in turn necessitates larger ciphertext moduli and complex reconstruction procedures. In this work, we...

2026/1550 (PDF) Last updated: 2026-07-29
Algorithms for Sparse LWE and LPN with Small Secrets
Shashwat Agrawal, Amitabha Bagchi, Rajendra Kumar
Attacks and cryptanalysis

We present new sample-runtime tradeoffs for the decisional sparse Learning With Errors (LWE) and sparse Learning Parity with Noise (LPN) problems over $\mathbb{Z}_q$, specifically in regimes where the secret vector is constrained by a small $l_{\infty}$ norm. While small-secret constraints are useful for the practical efficiency of lattice-based cryptography—such as homomorphic encryption and zero-knowledge proofs—the extent to which an adversary can exploit these bounds when the coefficient...

2026/1547 (PDF) Last updated: 2026-09-30
Silent Distributed Cryptography for DNFs and Threshold Policies from Lattices
Abtin Afshar, Rishab Goyal, Saikumar Yadugiri
Foundations

We study two central problems in threshold cryptography from lattices: (1) threshold encryption with silent setup for general thresholds $t \geq 2$, where no post-quantum constructions were previously known, and (2) threshold fully homomorphic encryption (TFHE) with sublinear parameters, an open problem since the work of [Boneh et al.; CRYPTO'18]. We introduce $\textit{$(\alpha,\beta)$-Scaled Linear Secret Sharing Schemes}$ (LSSS), a relaxation of standard LSSS in which each authorized...

2026/1540 (PDF) Last updated: 2026-07-28
Lattice-Based Shuffle Arguments using Subset Checking
Behzad Abdolmaleki, Prastudy Fauzi, Jiaqi Gu, Toomas Krips, Nahid Roustaeifar
Public-key cryptography

Shuffle arguments are a fundamental building block in mix-nets and related privacy-preserving systems, where they are used to prove that a set of ciphertexts or commitments is a permutation and rerandomization of another set without changing the underlying messages. Existing communication-efficient shuffle arguments rely on classical assumptions, whereas known lattice-based constructions are still significantly less efficient. In this paper, we present a lattice-based shuffle argument with...

2026/1526 (PDF) Last updated: 2026-08-06
On the Suitability of Syndrome Decoding for Proof-of-Work under Quantum Adversaries: Design and Analysis
Aleck Nash, Kim-Kwang Raymond Choo, Henry Chimal-Dzul
Cryptographic protocols

Proof-of-work (PoW) remains a fundamental mechanism for achieving decentralized consensus, most commonly instantiated using cryptographic hash functions. In such constructions, mining takes the form of an unstructured search problem over a large input space, where miners repeatedly evaluate candidate solutions until a valid one is found. While this design has proven effective in practice, it admits a quadratic quantum speedup via Grover’s algorithm, raising concerns about...

2026/1494 (PDF) Last updated: 2026-08-06
On $k$-way split multiplication algorithms
Mehmet Özgün Cihangir, Oğuz Yayla
Implementation

Efficient polynomial multiplication and matrix-vector operations are fundamental to computational algebra and modern cryptography. In lattice-based post-quantum cryptography (PQC), schemes utilizing Number Theoretic Transform (NTT)-unfriendly rings require highly optimized subquadratic multiplication algorithms. In this paper, we establish a rigorous mathematical framework for generalized $k$-way split polynomial multiplication and Toeplitz Matrix-Vector Product (TMVP) algorithms over...

2026/1483 (PDF) Last updated: 2026-07-20
MQ on my Hardware: Performance Analysis of MQOM on FPGA
Stelios Manasidis, Quinten Norga, Suparna Kundu, Ingrid Verbauwhede
Implementation

Recent algorithmic advancements in the Multi-Party Computation-in-the-Head (MPCitH) paradigm have resulted in more efficient post-quantum digital signature schemes. MQOM is a MPCitH-based digital signature scheme and candidate in the ongoing NIST Post-Quantum Cryptography (PQC) standardization effort, offering performance competitive with lattice- and multivariate-based schemes in software. In this work, we develop a dedicated hardware accelerator for MQOM and analyze the impact of recent...

2026/1464 (PDF) Last updated: 2026-07-17
Optimal Distributed Monotone-Policy Encryption for DNFs and More from Lattices
Jeffrey Champion, David J. Wu
Public-key cryptography

Distributed cryptography is a new cryptographic paradigm that enables fine-grained decryption capabilities in a trustless setting. In a distributed monotone-policy encryption scheme, users generate their own public and private keys. Thereafter, one can encrypt a message with respect to an arbitrary set of public keys together with an access policy. Any group of users that satisfies the access policy can recover the message; conversely, the message is computationally hidden from any group of...

2026/1459 (PDF) Last updated: 2026-07-24
Hybrid hash function based on the DLP and SIS problems
Dimitri Koshelev, Francesc Sebé
Implementation

This short note discusses in detail a folklore but little-known hybrid hash function grounded on both the discrete logarithm and short integer solution problems. In particular, specific satisfactory parameters are provided to ensure the standard $128$-bit security level for the lattice problem with $256$-bit module, which may be useful in its own right. The hash function is a natural generalization of the classical Pedersen and Ajtai ones. Nevertheless, to the authors' knowledge, no one has...

2026/1449 (PDF) Last updated: 2026-08-03
`ANSA-IBKEM`: Practical Quantum-Safe Identity-Based Key Encapsulation via Annular NTRU Trapdoors and Standardized PQC Arithmetic Reuse
Zhaohui Cheng, Kaixin Xiong
Public-key cryptography

Identity-based key encapsulation remains attractive for managed systems, but practical post-quantum instantiations must balance compact ciphertexts, low decryption-failure rate (DFR), high-throughput and protection-friendly private-key extraction, and meaningful concrete security reductions. Existing NTRU-based IBE schemes satisfy these requirements only partially: compact DLP-style constructions lack a satisfactory reduction and have high failure rates, while LATTE's higher-rank structure...

2026/1448 (PDF) Last updated: 2026-07-16
Improving Skipping Fault Correction Attacks on Randomized Dilithium via MILP
Haobo Ouyang, Chaoran Wang, Guowei Liu, Lixuan Wu, Meiqin Wang, Yanhong Fan
Attacks and cryptanalysis

Dilithium, as a quantum-secure digital signature standard in FIPS 204, has received widespread attention for its physical implementation security. NIST selected Dilithium's randomized signing mode as the default, which can mitigate the severe physical attacks that exploit the deterministic signing mode. However, the physical attack resilience of randomized signing mode is currently an open question. In 2024, Krahmer et al. demonstrated a key-recovery attack against randomized Dilithium by...

2026/1414 (PDF) Last updated: 2026-07-11
Evaluating Hybrid KEM/DSA for KpqC and NIST PQC on ARM Cortex-M4
Minjoo Sim, Minwoo Lee, Subeen Cho, Yulim Hyoung, Hwajeong Seo
Implementation

Primitive-only PQC benchmarks are insufficient for attributing composed hybrid costs on Cortex-M4 because shared hash backends, randomized-signature behavior, and fixed classical/wrapper work affect measured performance. We implement a common bare-metal Cortex-M4 harness for representative KpqC/NIST families, measuring uniform Hash-CT hybrid KEM benchmark rows with X25519 and Bindel et al. hybrid-signature AND-combiner rows. The goal is composed-cost attribution under a uniform benchmark...

2026/1410 (PDF) Last updated: 2026-07-11
A Memory-Efficient and Assembly-Optimized Implementation of NTRU+
SuBeen Cho, Jiwon Bang, Minjoo Sim, Hwajeong Seo
Implementation

This paper presents a memory-efficient and high-speed implementation of NTRU+, one of the key encapsulation mechanisms (KEMs) selected by Korea’s post-quantum cryptography project (KpqC), on the ARM Cortex-M4. NTRU+ is small enough to run on its own on a Cortex-M4 class microcontroller, yet in real embedded environments, the peak stack occupied by polynomial buffers and the running time dominated by the NTT become key constraints. To address this, in the proposed technique, we reduce memory...

2026/1400 (PDF) Last updated: 2026-07-09
What Happens When integrating Modulus Switching and Lossy Source Coding: A New Dual Attack Variant on LWE
Yechen Li, Qunxiong Zheng
Attacks and cryptanalysis

The threat of large-scale quantum computers to classical public-key cryptography has motivated the development of post-quantum cryptographic schemes. Among these, lattice-based constructions have become the mainstream choice in the ongoing NIST standardization process. The security of these schemes typically relies on the hardness of the LWE problem, and the dual-sieve-FFT attack is widely recognized as one of the most effective approaches against it. Recent improvements by MATZOV and...

2026/1364 (PDF) Last updated: 2026-07-02
Time vs Success Probability Tradeoff for SVP and BDD with Implications to LWE and SIS
Divesh Aggarwal, Haoxiang Jin
Foundations

Worst-case to average-case reductions from lattice problems such as GapSVP and Bounded Distance Decoding (BDD) to the Learning with Errors (LWE) problem form the backbone of the security guarantees for lattice-based cryptography. However, these classic reductions are notoriously lossy: even assuming exponential hardness for worst-case lattice problems, they yield only subexponential lower bounds on the hardness of LWE. Recent work by Aggarwal, Leong, and Veliche (AMV, TCC'24) proposed a new...

2026/1363 (PDF) Last updated: 2026-07-02
Slicing Bits and Cutting Costs in CDT Sampling: High-Order Masking of FrodoKEM's Gaussian Sampler, Revisited
Calvin Abou Haidar, Thomas Espitau, Clément Hoffmann, Mehdi Tibouchi
Implementation

FrodoKEM, a key encapsulation mechanism based on the standard (unstructured) LWE assumption, is recommended as a conservative choice for post-quantum key exchange by agencies like BSI and ANSSI. As such, it has garnered substantial attention from an implementation security standpoint. In particular, several papers have looked into masking FrodoKEM, and, like for various other lattice-based cryptosystems, identified the Gaussian sampling operation as a major bottleneck. In FrodoKEM, it is...

2026/1350 (PDF) Last updated: 2026-06-30
Refined Evaluation Methods of Decryption Failure Rate in Lattice-Based Public-Key Encryption with Message Encoding
Guoqing Zhou, Lin Wang, Yue Cao, Baosheng Huang, Sen Hou, Dawu Gu
Attacks and cryptanalysis

Lattice-based cryptography is one of the most promising candidates for post-quantum cryptography. Decryption Failure Rate (DFR) is a critical metric for the correctness and security of lattice-based public-key encryption (PKE) schemes. At present, most DFR evaluation methods for lattice-based PKE with message encoding rely on oversimplified assumptions, rough approximations, and fail to fully exploit the geometric structure of special encoding lattices, resulting in loose or inaccurate...

2026/1345 (PDF) Last updated: 2026-06-30
Double-Structured Genetic Algorithm for Solving the SVP Based on Double Optimization: Using Two Types of Chromosomes
Masaharu Fukase
Public-key cryptography

The shortest vector problem (SVP) is central in lattice-based cryptography. In this paper, we focus on one of recent classes of algorithms for solving SVP: genetic algorithms (GAs) for lattice. In this paper, we propose the fastest GA to date for solving the SVP. From a search strategy perspective, our algorithm can be seen as an improved version of Fukase's algorithm. On the other hand, from a structure perspective, our algorithm is more than just an improved version of Fukase's algorithm....

2026/1318 (PDF) Last updated: 2026-07-05
Cryptanalysis of HAWK: a Guessing Game
Ben Nelson, Joshua Limbrey, Cong Ling, Andrew Mendelsohn
Attacks and cryptanalysis

HAWK is a signature scheme that was introduced in 2022, and uses the lattice isomorphism problem (LIP) as a basis for post-quantum cryptography. In this work, we describe a classical algorithm that recovers the HAWK secret key in probabilistic polynomial time, assuming four number-theoretic heuristics. The reduction from the rank-2 module-LIP instances underlying HAWK to nrdPIP (Eurocrypt '25) is central to our algorithm. At a high level, we first conjugate the HAWK public Gram matrix $G$ by...

2026/1317 (PDF) Last updated: 2026-09-18
ProtogaLattice: Lattice-based Algebraic Folding
David Balbás, Anca Nitulescu, Maxime Plançon
Cryptographic protocols

Folding schemes are gaining traction recently as they are suited to prove streaming computations with low memory footprint. In particular, there has been a growing interest in post-quantum folding schemes for more expressive relations, and with improved proof sizes. While the landscape is vast, every lattice-based construction, such as Latticefold+, (Super)Neo, and Cyclo, heavily rely on the sumcheck protocol. Sumcheck gives efficient proving times, but the verifier circuits become very...

2026/1301 (PDF) Last updated: 2026-06-22
STRUCTURED LATTICES AND THEIR APPLICATIONS TO SECURITY
LENNY FUKSHANSKY, CAMILLA HOLLANTI, RAHINATOU Y. NJAH NCHIWO
Foundations

Euclidean lattices are an interesting object of study in many regards and can have a rich structure arising from various constructions, e.g., from number field extensions. A particularly interesting class is the one of well-rounded lattices, as they relate to the well-known densest sphere packing problem in geometry, theta function minimization, and the famous Minkowski and Woods conjectures. In addition to being an important mathematical object in their own right, lattices also play a...

2026/1293 (PDF) Last updated: 2026-06-20
Post-quantum Secure Non-Committing Registered Functional Encryption
Ramprasad Sarkar
Public-key cryptography

Non-committing encryption (NCE) is a key primitive for proving security against adaptive corruptions, enabling simulators to generate ciphertexts before the encrypted message is known. Existing non-committing constructions for attribute-based encryption primitives [Hiroka et al., ASIACRYPT 2021; Goyal et al., PKC 2025] typically rely on centralized trust that generate users' secret keys. However, modern cryptographic systems increasingly aim to eliminate such trust assumptions through...

2026/1289 (PDF) Last updated: 2026-06-19
A Toolkit for Succinct Lattice-Based Zero Knowledge Proofs
Beatrice Biasioli, Madalina Bolboceanu, Vadim Lyubashevsky, Antonio Merino-Gallardo, Michał Osadnik, Gregor Seiler, Patrick Steuer
Cryptographic protocols

The development of proof systems whose security relies on the hardness of lattice problems has been a fruitful research area in recent years. By leveraging the techniques introduced in LaBRADOR (Beullens, Seiler, Crypto 2023), the state-of-the-art lattice-based schemes have very fast provers and have output sizes under 100KB for arbitrarily large statements. These proofs are in fact the smallest, and often have the fastest provers, out of all post-quantum schemes. In addition to...

2026/1272 (PDF) Last updated: 2026-06-17
Parameter-Aware and Instruction-Driven Dilithium Optimization on AVX2 and NEON
Shi Ya, Liu Bingqian, Lu Xianhui, Qian Wenfei, Liu Ying, Wang Kunpeng
Applications

We improve the performance of the lattice-based cryptosystem Dilithium on AVX2 and NEON by deeply exploiting its algorithmic properties, such as small coefficient bounds and high sparsity, with the distinct instruction-level profiles of the underlying architectures. On AVX2, we deploy a single-modulus 16-bit NTT for $c \cdot \mathbf{s}_i$ and a multi-moduli 16-bit NTT coupled with a vectorized CRT reconstruction for $c \cdot \mathbf{t}_0$. These instruction-level optimizations accelerate the...

2026/1262 (PDF) Last updated: 2026-06-16
PQ-SMS: A Post-Quantum Sanitizable Multi-Signature Scheme for Satellite PKI
Long Wang, Zhaoman Liu, Jing Fan, Yanhong Fan
Applications

Satellite communication systems, as critical long-lifecycle infrastructure, face a dual security challenge in the coming decades: the threat of quantum computers and the operational rigidity of traditional Public Key Infrastructure (PKI). While migrating to Post-Quantum Cryptography (PQC) addresses the former, it fails to solve the inefficiency of certificate management, where in-orbit policy updates require a prohibitively slow and complex multi-party re-issuance process. To address...

2026/1248 (PDF) Last updated: 2026-06-12
Atlantis: Lattice-based Anonymous Tokens with Private Metadata Bit
Foteini Baldimtsi, Aayush Yadav
Cryptographic protocols

Anonymous tokens with private metadata bit (ATPM) allow an issuer to embed a hidden trust flag, as a single bit, within issued tokens. The bit remains hidden from the clients, but verifiers can read the bit and rate-limit or discard tokens marked suspect. A series of ATPM constructions exist in the literature, however all current constructions rely on classical hardness assumptions such as RSA groups, pairings, or elliptic-curve VRFs and do not provide any post-quantum security guarantees....

2026/1196 (PDF) Last updated: 2026-08-21
Grand Danois: Succinct Multilinear Polynomial Commitments over Lattices
Anders Kallesoe, Hamidreza Khoshakhlagh
Cryptographic protocols

We present Grand Danois, a new post-quantum multilinear polynomial commitment scheme from lattices for polynomials over $\mathbb{F}_q$ that achieves polylogarithmic $O(\lambda \ell)$ verification complexity and proof sizes. We build on the general approach introduced in Hachi (ePrint 2026/156) with three key changes. First, we switch to the vanishing Short Integer Solution (vSIS) assumption to obtain structured public parameters for our commitment scheme and utilize this structure to design...

2026/1188 (PDF) Last updated: 2026-09-04
Rank Ceiling for Twiddle-Perturbation Faults on the Forward NTT
Chakshu Gupta
Implementation

NIST standardised the lattice-based key-encapsulation mechanism ML-KEM and the lattice-based digital signature scheme ML-DSA in 2024. Both compute a forward number-theoretic transform (NTT) over secret-bearing polynomials; the NTT's twiddle constants are a documented fault-attack surface. Published attacks zero every twiddle at once on ML-KEM key generation, or individual twiddles on ML-DSA signing. Countermeasures detect or mask such faults but none quantifies how much a single-twiddle...

2026/1139 (PDF) Last updated: 2026-06-02
Exploiting the complexity of Lattice Isomorphism Problem via Irreducible Decomposition
Kaijie Jiang, Yinchen Liu
Foundations

The Lattice Isomorphism Problem (LIP) is a computational problem that has recently been introduced into cryptography and is believed to be hard. Its search version, Search Lattice Isomorphism Problem (SLIP), is considered even harder than the Shortest Vector Problem (SVP), yet its complexity is still not well understood. Haviv and Regev (SODA 2014) showed that the decisional version (DLIP) lies in a statistical zero-knowledge class and is therefore unlikely to be NP-hard. This result does...

2026/1113 (PDF) Last updated: 2026-06-20
Single-Hop HRA-Secure Owner-Encrypted Lattice-Based Proxy Re-Encryption without Statistical Noise Flooding
Haotian Yin, Jie Zhang, Yuji Dong, Dominik Wojtczak, Eng Gee Lim
Public-key cryptography

Existing lattice-based proxy re-encryption (PRE) schemes that achieve security against honest re-encryption attacks (HRA) typically rely on statistical noise flooding to hide dependencies between the source ciphertext, the re-encryption key, and the re-encrypted ciphertext. While effective, this technique causes large noise growth and significant parameter expansion. We present an owner-encrypted proxy re-encryption (OE-PRE) construction that achieves single-hop HRA security without...

2026/1103 (PDF) Last updated: 2026-06-01
Jevil: A Catastrophic-Failure-by-Design Signature Scheme
Nadim Kobeissi
Public-key cryptography

Few-time signatures cap how many signatures a signer can safely issue. Jevil is, to our knowledge, the first post-quantum and transparent (setup-free) few-time signature scheme with a sharp key-recovery cliff: its cap is enforced by a single sharp threshold rather than a slow slope. Signatures one through $n^{\star}$ are existentially unforgeable at approximately $124$-bit classical security; at the $(n^{\star}{+}1)$-th the entire secret polynomial becomes publicly recoverable, achieving...

2026/1098 (PDF) Last updated: 2026-09-16
A gentle introduction to lattice-based cryptography
Alfred Menezes
Public-key cryptography

We present four quantum-safe schemes: the Kyber (ML-KEM) and FrodoKEM key encapsulation mechanisms, and the Dilithium (ML-DSA) and Falcon (FN-DSA) signature schemes. We also develop the mathematical background on lattices needed to understand why Kyber, FrodoKEM, Dilithium and Falcon are regarded as lattice-based cryptosystems, and we provide insight into the computational hardness of the underlying lattice problems. The exposition is intended to be accessible to senior undergraduate...

2026/1081 (PDF) Last updated: 2026-05-28
From Perfect to Approximate Hints: Efficient LWE Secret Recovery Leveraging Low Hamming Weight
Minki Hhan, Ga Hee Hong, Jiseung Kim, Changmin Lee, JeongHwan Lee
Attacks and cryptanalysis

The Learning With Errors (LWE) problem is a cornerstone of lattice-based cryptography and underpins the security of numerous cryptographic schemes. To enhance efficiency, practitioners often employ sparse secrets in LWE, where the secret vector $\mathbf{s}$ has a significantly lower Hamming weight than its dimension $n$. While this approach improves performance, it raises security concerns, particularly against side-channel attacks that can leak partial information, or “hints,” about the...

2026/1078 (PDF) Last updated: 2026-05-28
Post-Quantum HAWK Signature Acceleration with RISC-V-Based Hardware-Software Co-Design
Rishabh Shrivastava, Utsav Banerjee
Implementation

Advances in quantum computing technology have motivated the development of post-quantum cryptography (PQC) algorithms. HAWK is a new post-quantum digital signature scheme and the only lattice-based candidate selected for Round 3 of the "Additional Digital Signatures" phase of the NIST PQC Standardization process. HAWK offers compact key and signature sizes compared to NIST standard ML-DSA (Dilithium), and its simple design avoids the use of floating-point arithmetic unlike NIST standard...

Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.