• [digest] 2026 Week 34

    From IACR ePrint Archive@noreply@example.invalid to sci.crypt on Mon Aug 24 02:32:00 2026
    From Newsgroup: sci.crypt

    ## In this issue
    1. [2025/1807] Traceability for Free: Traceable Ring Signatures ...
    2. [2026/223] Nested MuSig2
    3. [2026/247] Pairing-Based BARG for NP with Constant-Size Proofs ...
    4. [2026/293] Quantum Oracle Distribution Switching and ...
    5. [2026/1196] Grand Danois: Succinct Multilinear Polynomial ...
    6. [2026/1633] Rotational-Quasidifferential Framework - A ...
    7. [2026/1635] Limber: Low Overhead SNARKs for Integers from Any PCS
    8. [2026/1711] A Descent to Hades: Attacks on PKP and PEP over ...
    9. [2026/1715] How Compact Can NTRU Encryption Be? Heuristic ...
    10. [2026/1724] Data-Dependent Memory-Hard Functions: Sustained ...
    11. [2026/1725] Proof-of-Uniqueness: Sybil-Resistant Privacy- ...
    12. [2026/1726] Jacobi Signatures, Revisited
    13. [2026/1727] Enhancing Capital Efficiency in DeFi Lending and ...
    14. [2026/1728] A Controlled Case Study of Design Trade-offs in ...
    15. [2026/1729] A Unified Framework for Contract-Validated ...
    16. [2026/1730] New Techniques for Fast and Shallow FHE ...
    17. [2026/1731] Generic Ring-Signature Transforms for Fiat-Shamir ...
    18. [2026/1732] Indifferentiability of Public-Key Encryption: ...
    19. [2026/1733] TEE Server-Assisted Aggregated Offline Deployment ...
    20. [2026/1734] Key Recovery from Residue-Confined Errors in the ...
    21. [2026/1735] Adapting AES-Oriented Optimizations to ...
    22. [2026/1736] Copy-Protection with Correlated Challenges: Point ...
    23. [2026/1737] From Mechanical Lock-Picking to Autonomous Driving ...
    24. [2026/1738] Noisy Subset Product
    25. [2026/1739] Prop RFQ: Proprietary Request for Quote as ...
    26. [2026/1740] Non-Local Search-to-Decision Reduction over ...
    27. [2026/1741] One Proof to Rule Them All: Practical, Sublinear ...
    28. [2026/1742] Unclonable encryption from BB84 states: a ...
    29. [2026/1743] Notes on Short-Limb Modular Multiplication ...
    30. [2026/1744] Improved Collision Attack on RIPEMD-160
    31. [2026/1745] Round-Preserving Compilers for Super-Rushing Secure MPC
    32. [2026/1746] Chasing QuOCCAs in a Quantum World: Type-2 Oracles ...
    33. [2026/1747] Extending Distinguishing to Key Recovery for ...
    34. [2026/1748] SafeHub: End-to-end encrypted Git hosting system
    35. [2026/1749] CAKE-HI - Compact Authenticated Key Exchange Hiding ...
    36. [2026/1750] Threshold Lattice-Based Zero-Knowledge Proofs
    37. [2026/1751] Efficient Dynamic Group Signatures with Forward ...
    38. [2026/1752] L-BAS: A Lattice-Based Blind Adaptor Signature Scheme
    39. [2026/1753] Linear Distance for Fixed-Row-Weight Expand-- ...
    40. [2026/1754] SoK: Why Optimal Cryptographic Combiners Do Not Get ...
    41. [2026/1755] QuaILLL: Quaternion Ideal LLL and BKZ
    42. [2026/1756] Fully Homomorphic Encryption with Chosen-Ciphertext ...
    43. [2026/1757] Enabling Threshold Custody for the Lightning ...
    44. [2026/1758] $\textsf{Sluice}$: Prove-Phase Bounded-Memory ...
    45. [2026/1759] Revisiting the Transferability of Chosen- to Known- ...
    46. [2026/1760] Midpoint Reset: A Full-Round Poseidon Collision ...
    47. [2026/1761] Lightweight Lattice-based Single-Party Public-Key ...
    48. [2026/1762] Pilaf: Fully Tight Two-Round Threshold Signatures ...
    49. [2026/1763] Multidimensional Hill Cipher SubstitutionrCo ...
    50. [2026/1764] Two Novel Multidimensional Affine Variations of the ...
    51. [2026/1765] Exact linear correlations and the cost of Walsh- ...
    52. [2026/1766] Eavesdropper-Blind Remote State Preparation and ...
    53. [2026/1767] Circle-Linear Cryptanalysis: Bibrace Characters and ...
    54. [2026/1768] Constant-round MPC protocols with Fall-back Security
    55. [2026/1769] Rank Measures and Exponential Lower Bounds for ...
    56. [2026/1770] How Many Traces Suffice? PAC Guarantees for ...
    57. [2026/1771] New Lower Bounds for Rows of $d$-Disjunct Matrices ...
    58. [2026/1772] Multi-PGBF: Efficient Oblivious Key-Value Store and ...
    59. [2026/1773] Enforcing Winner-Only Disclosure: Verifiable Tally ...
    ## 2025/1807
    * Title: Traceability for Free: Traceable Ring Signatures Revisited
    * Authors: Xiangyu Liu
    * [Permalink](https://eprint.iacr.org/2025/1807)
    * [Download](https://eprint.iacr.org/2025/1807.pdf)
    ### Abstract
    Linkable Ring Signatures (LRS) allow anonymous signing on behalf of an ad hoc ring, while making any two signatures by the same signer publicly linkable. Traceable Ring Signatures (TRS), introduced by Fujisaki and Suzuki [PKC'07], strengthen linking to tracing: two signatures on different messages additionally reveal the signer's public key. Since cheating almost always means signing two distinct messages, for example two conflicting transactions, traceability turns detection into accountability and makes misbehavior costly. However, TRS remain far less studied and deployed than LRS. We identify two gaps and address both.
    First, the security notions inherited from [PKC'07], anonymity, linkability, and exculpability, do not capture attacks specific to tracing. For example, they together do not imply unforgeability, a fundamental requirement for all signature-like primitives. We close this gap by introducing extended linkability and extended exculpability, which reflect the security requirements of TRS more faithfully than their standard counterparts.

    Second, all existing TRS schemes trace in $O(n)$ time for a ring of size $n$, whereas LRS link in $O(1)$. Over a pool of $\ell$ signatures, pairwise tracing therefore costs $O(\ell^2 n)$ against $O(\ell^2)$ for linking. We design a new TRS framework with $O(1)$ tracing for valid signatures. Instantiated from DDH with Bulletproofs [S&P'18], it yields signatures of $(64\log n+544)$ bytes on Curve25519. To our knowledge this is the shortest TRS for $n \ge 12$, and it is on par with state-of-the-art DLog-based LRS schemes. TRS thus gains traceability at essentially no cost over LRS.
    ## 2026/223
    * Title: Nested MuSig2
    * Authors: Nadav Kohen
    * [Permalink](https://eprint.iacr.org/2026/223)
    * [Download](https://eprint.iacr.org/2026/223.pdf)
    ### Abstract
    Bitcoin Improvement Proposal 327 specifies a variant of the MuSig2 multi-signature protocol that is becoming widely adopted in Bitcoin applications. This protocol enables multiple participants to collaboratively compute (BIP 340) Schnorr signatures for a single aggregate public key efficiently, while preventing external parties from distinguishing whether multiple signers were involved. It has been widely proposed that it should be secure to allow MuSig2 participant keys to themselves be "nested" MuSig2-aggregated keys. No security argument has previously been presented for this practice, though various applications have been proposed that assume the security of such an operation.
    In this work, we propose NestedMuSig2, a recursive variant of MuSig2 that enables a tree of nested cosigners to privately generate aggregate Schnorr signatures while maintaining all of the efficiency and security benefits of MuSig2, including non-interactive public key aggregation. Nested signers in this scheme cannot distinguish between cosigners that are using further nesting and those that are not. In particular, this means that NestedMuSig2 is compatible with all existing protocols that use MuSig2. We reduce the security of NestedMuSig2 to the AOMDL assumption in the random oracle model. Similarly, we reduce the security of a more efficient and compact variant to the AOMDL assumption in the random oracle model used in conjunction with the algebraic group model.
    ## 2026/247
    * Title: Pairing-Based BARG for NP with Constant-Size Proofs and Applications
    * Authors: Zhe Jiang, Kai Zhang, Junqing Gong, Haifeng Qian
    * [Permalink](https://eprint.iacr.org/2026/247)
    * [Download](https://eprint.iacr.org/2026/247.pdf)
    ### Abstract
    This paper presents a pairing-based non-interactive batch argument (BARG) for NP in the common reference string (CRS) model with constant-size proofs and constant-cost verification. Our construction is fully black-box in its use of the underlying group and achieves a weak form of somewhere extractability under a new $q$-type assumption in composite-order pairing groups. We further show that this extractability guarantee implies somewhere soundness. Prior pairing-based BARGs in this setting suffer from proof size and verification cost proportional to the size of the Boolean circuit computing the NP relation, and our work removes this dependence.
    Technically, our starting point is the Waters--Wu framework [Asiacrypt'25] and the main idea is to replace the univariate polynomial commitment with a bivariate polynomial commitment together with univariate sumcheck arguments. This allows us to compress both wire and gate checks into a constant number of algebraic identities, leading to constant-size proofs and constant-cost verification.
    As a demonstration of the resulting somewhere-sound BARG, we show that it simplifies and improves existing generic constructions of NIZKs and rate-1 BARGs. In particular, we obtain:
    -a generic construction of NIZKs for NP from our somewhere-sound BARG, together with a one-time dual-mode commitment scheme with extraction and a leakage-resilient weak pseudorandom function. The resulting proof size is independent of the circuit size, whereas prior work incurs circuit-size-dependent proof overhead and either requires a local PRG or commits to all internal wires;
    -a generic construction of rate-1 BARGs from pairing-based assumptions by combining the somewhere sound BARG obtained from our construction with existing rate-1 fully local somewhere-extractable hashing. The resulting proof size is $h+\mathsf{poly}(\lambda,\log\ell)$, whereas prior work either requires proof size $h+o(h)\mathsf{poly}(\lambda,\log\ell)$ or relies on a RAM SNARG with partial-input soundness.
    Both generic constructions rely on weaker or fewer cryptographic primitives than prior work and the construction of NIZK also avoids the complicated parameter selection in prior work.
    ## 2026/293
    * Title: Quantum Oracle Distribution Switching and Applications to Falcon and Ring Signatures
    * Authors: Marvin Beckmann, Christian Majenz
    * [Permalink](https://eprint.iacr.org/2026/293)
    * [Download](https://eprint.iacr.org/2026/293.pdf)
    ### Abstract
    Motivated by digital signature algorithms ranging from Falcon to fully-anonymous ring signatures used in Signal-style key exchange, such as Gandalf, we revisit a fundamental problem in post-quantum security proofs: distinguishing oracle functions whose outputs are sampled independently from distributions $P$ and $Q$ that are close. In the context of signatures, closeness is often measured via R|-nyi divergences, which yield multiplicative bounds in the classical setting. A counterexample shows that such multiplicative-error bounds for distinguishers with classical oracle access have no analogue for quantum access, and we provide two alternative approaches based on small-range distributions and reprogramming techniques. We also give a concrete, optimal bound for the case where $P$ and $Q$ are close in statistical distance. We apply these techniques to the motivating constructions. (i) We give the first QROM security proof for Falcon that avoids oracle indistinguishability arguments based on statistical distance. This is crucial, as Falcon's ROM proof relies on R|-nyi divergence, while the statistical distance induced by its parameters is too large to yield meaningful bounds. (ii) We formalize and abstract the ring signature construction used in Gandalf as a modular framework by defining ring trapdoor preimage-sampleable functions (RPSFs), for which we obtain two QROM proofs.
    We also provide two QROM security proofs for AOS ring signatures, adapting existing QROM techniques. Together with our results on RPSF-based ring signatures, this yields QROM security proofs for a broad class of fully-anonymous linear ring signature constructions, including Gandalf and the AOS-based constructions Erebor and MayoRS.
    ## 2026/1196
    * Title: Grand Danois: Succinct Multilinear Polynomial Commitments over Lattices
    * Authors: Anders Kallesoe, Hamidreza Khoshakhlagh
    * [Permalink](https://eprint.iacr.org/2026/1196)
    * [Download](https://eprint.iacr.org/2026/1196.pdf)
    ### Abstract
    We present Grand Danois, a new post-quantum multilinear polynomial commitment scheme from lattices for polynomials over $\mathbb{F}_q$ that achieves polylogarithmic $O(\lambda \ell)$ verification complexity and proof sizes. We build on the general approach introduced in Hachi (ePrint 2026/156) with three key changes. First, we switch to the vanishing Short Integer Solution (vSIS) assumption to obtain structured public parameters for our commitment scheme and utilize this structure to design a sumcheck protocol amenable to succinct verification. Second, rather than casting ring relations into
    $\mathbb{F}_{q^k}[X]$, via the residual technique of Hachi, we express multiplication by fixed $\mathcal{R}_q$ elements through its rotation matrix, which lets the verifier fold each row of the constraint matrix in time linear rather than quadratic in the ring degree $d$. Third, we modify the quadratic relation used in Hachi and Greyhound (CRYPTO 2024) so that it becomes compatible with proving norm bounds using Johnson-Lindenstrauss projections. This is achieved through an adaptation of the structured projection strategy introduced in RoK and Roll (ASIACRYPT 2025). This has the benefit for communication complexity in that proving norm bounds and correct polynomial evaluation are integrated into a single protocol, reducing the number of commitments sent by the prover. Furthermore, we impose additional structure on our random projections to reduce the witness size even more aggressively during each round of recursion without sacrificing verification complexity. Under the vSIS assumption, our construction yields an estimated proof size of roughly $80$ KB for $2^{32}$-size polynomial evaluations.
    ## 2026/1633
    * Title: Rotational-Quasidifferential Framework - A Geometric Approach to Rotational-XOR Cryptanalysis
    * Authors: Myungkyu Lee, Byoungjin Seok, Dongjae Lee, Deukjo Hong, Jaechul Sung, Seokhie Hong
    * [Permalink](https://eprint.iacr.org/2026/1633)
    * [Download](https://eprint.iacr.org/2026/1633.pdf)
    ### Abstract
    Rotational-XOR (RX) cryptanalysis extends rotational cryptanalysis by combining rotational relations with XOR translations, enabling the analysis of symmetric-key primitives even in the presence of symmetry-breaking constants. Existing analyses of RX characteristics, however, typically rely on independence assumptions when estimating characteristic probabilities, which may lead to inaccurate probability evaluations and even incompatible characteristics.
    In this paper, we introduce the first application of the geometric approach to RX cryptanalysis. Inspired by the quasidifferential framework of Beyne and Rijmen, we develop an algebraic representation of RX characteristics and establish exact formulas expressing fixed-key RX characteristic probabilities in terms of rotational-quasidifferential trails. As a result, RX characteristics can be analyzed without relying on round-independence assumptions. By incorporating the key schedule into the state space, we further derive an exact expression for the Expected Rotational-XOR Probability (ERXP), the RX analogue of the Expected Differential Probability (EDP).
    We apply the framework to the AND-RX ciphers SIMON and SIMECK. In particular, we experimentally validate the theoretical predictions of the framework through the fixed-key analysis of a previously known RX characteristic for SIMECK32/64. We also revisit incompatible RX characteristics of SIMECK48/96 and SIMECK64/128, identifying additional constraints that lead to incompatibility. Finally, we reanalyze rotational-XOR differential rectangle attacks on SIMECK48/96 and obtain corrected estimates of the corresponding weak-key classes. These results demonstrate that the proposed framework provides an effective tool for the exact analysis of RX cryptanalysis and establishes a foundation for the study of rotational cryptanalytic techniques within the geometric approach.
    We further derive an explicit rotational-quasidifferential transition matrix for modular addition for arbitrary nonzero rotation offsets, extending the framework to the main nonlinear operation of ARX designs.
    ## 2026/1635
    * Title: Limber: Low Overhead SNARKs for Integers from Any PCS
    * Authors: Jessica Chen, Lucas Xia, Wilson Nguyen, Benedikt B|+nz
    * [Permalink](https://eprint.iacr.org/2026/1635)
    * [Download](https://eprint.iacr.org/2026/1635.pdf)
    ### Abstract
    In real-world applications of SNARKs, non-native arithmetic is a key bottleneck. It introduces large overheads, and proof system designers often resort to non-standard SNARK-friendly hash-functions or other means like elliptic curve cycles to mitigate its costs. Besides performance concerns, non-native circuit arithmetization is also a major cause of implementation errors. In a collection of 27 critical bugs in real world ZK systems (0xPARC/zkbugtracker), 9 were related to non-native arithmetization.
    We tackle these challenges by constructing a minimal overhead SNARK for integer computation that generically handles non-native arithmetic. We follow the recipe of Zaratan (PKC 26), which proves an integer relation such as $a\cdot b = c + u\cdot m$ by fingerprinting---reducing it to the same relation but over a randomly sampled prime field. Realizing this recipe requires an integer mod-PCS that commits to integer polynomials and opens their evaluations modulo a random prime, which is crucially chosen after the underlying PCS's setup and commitment phases.
    Our central contribution is Limber, the first practical integer mod-PCS construction that asymptotically has $o(1)$ multiplicative commitment overhead and can be instantiated with any standard field polynomial commitment scheme, including ones over small fields. Combining Limber with a PIOP for integer R1CS over the random prime yields our SNARK. We demonstrate its practicality by implementing our scheme and showing that we can prove RSA arithmetic more than $67\times$ faster than prior circuit-based approaches.
    ## 2026/1711
    * Title: A Descent to Hades: Attacks on PKP and PEP over Extension Fields
    * Authors: Alessandro Budroni, Jes||s-Javier Chi-Dom|!nguez, Jorge Chavez-Saab, Andre Esser
    * [Permalink](https://eprint.iacr.org/2026/1711)
    * [Download](https://eprint.iacr.org/2026/1711.pdf)
    ### Abstract
    The Permutation Code Equivalence Problem (PEP) and Permuted Kernel Problem (PKP) are two notorious computational problems over linear codes used for building post-quantum digital signature schemes.
    Although traditionally analyzed over prime fields, recent proposals, such as the signature schemes PERK and SETH, have considered extension fields to improve efficiency and compactness.
    In this work, we analyze the hardness of solving PKP and PEP when instantiated over field extensions.
    For binary field extensions, by exploiting a reduction to a structured variant of the Regular Syndrome Decoding Problem (RSD), we uncover new polynomial-time parameter regimes for both PKP and PEP, including families of self-orthogonal PEP instances and all self-dual instances over extensions of degree $\nu>4$. We also adapt the permutation-based Regular-ISD algorithm of Esser and Santini for RSD (CRYPTO '24) to PKP-derived instances, and uncover regimes of parameters for which it improves upon the state-of-the-art. Moreover, we present a reduction from a broad family of PEP instances over extension fields with odd characteristic to the Graph Isomorphism Problem, yielding a polynomial-time algorithm to solve those instances. Overall, our results invalidate the use of PEP over extension fields for most of the scenarios, and provide novel insights into the security of PKP over extension fields.
    ## 2026/1715
    * Title: How Compact Can NTRU Encryption Be? Heuristic Frontiers and Practical Schemes
    * Authors: Yijian Liu, Yu Zhang, Xianhui Lu, Yao Cheng, Yongjian Yin
    * [Permalink](https://eprint.iacr.org/2026/1715)
    * [Download](https://eprint.iacr.org/2026/1715.pdf)
    ### Abstract
    NTRU is one of the longest-tested lattice-based public-key encryption families and is often viewed as a compact alternative to (R/M)-LWE. Yet, after three decades of research, its potential for compactness remains an open area for further exploration: recent designs such as NEV (Asiacrypt 2023) and DAWN (Asiacrypt 2025) suggest that there is still room for improvement. This raises a natural question: Has NTRU reached its compactness limit? If not, how compact can it be while still remaining secure and efficient?
    Motivated by this question, we aim to formalize a unified relationship between compactness and efficiency under the required security level. We present a common two-stage view of NTRU decryption. In the first stage, the decoder constructs a small set of candidate wrap-around errors. In the second stage, it verifies these candidates using either algebraic redundancy or trapdoor-derived distributional information. We introduce Free Candidate Localization (FCL), a generic first-stage method that ranks coordinates by their proximity to the centered boundary. FCL could be used in most lattice-based encryptions; we instantiate it in ML-KEM to achieve a $10\%$ smaller ciphertext at the cost of a $5\%$ slower overall runtime in the reference C implementation under NIST-I.
    We organize modern NTRU encryptions into two frameworks. NTRU with Encoding leverages algebraic structure via auxiliary quotient rings. NTRU with Trapdoor exploits geometric structure through the NTRU trapdoor, then verifies candidate corrections using distributional tests. These frameworks give a common language for existing NTRU designs and for the compactness searches in this paper. Within an explicit search model, we derive heuristic compactness frontiers for both frameworks. At NIST-I, the encoding frontier yields a total public-key plus ciphertext size of 812 bytes, and the trapdoor frontier yields a size of 754 bytes, $15\%$/$21\%$ smaller than the previous lowest size of 964 bytes in DAWN.
    Furthermore, we propose END, an instantiation of NTRU with Trapdoor plus FCL. At NIST-I, \textsf{END} has a 384-byte ciphertext, which is exactly half the size of the 768-byte ciphertext of ML-KEM-512, and is $12-19\%$ smaller than the shortest prior NTRU-style ciphertexts in BAT (TCHES 2022) and DAWN. In our reference C implementation, the combined encapsulation and decapsulation cost of END-512 is about $3\%$ higher than that of ML-KEM-512.
    ## 2026/1724
    * Title: Data-Dependent Memory-Hard Functions: Sustained Space and Cumulative Complexity Trade-offs in the Parallel Random Oracle Model
    * Authors: Jeremiah Blocki, Blake Holman
    * [Permalink](https://eprint.iacr.org/2026/1724)
    * [Download](https://eprint.iacr.org/2026/1724.pdf)
    ### Abstract
    Memory-Hard Functions (MHFs) are a cryptographic primitive designed to protect passwords and other low-entropy secrets against brute-force attacks. The strongest and most natural formalization of memory-hardness is sustained space complexity (SSC), which measures how long an attacker's memory remains above a given threshold. Ideally, one would like to ensure that any parallel attacker must sustain $\Theta(N)$ memory for $\Theta(N)$ steps, while the function can also be computed in sequential time $\Theta(N)$. Unfortunately, this goal is impossible to achieve. Thus, the appropriate objective is to establish strong tradeoffs between sustained space complexity and cumulative memory complexity (CMC), another strong notion of memory hardness. Blocki and Holman (CRYPTO 2022) achieved strong SSC/CMC tradeoffs in the dynamic pebbling model, but their construction relied on expensive combinatorial graphs, and the pebbling abstraction does not rule out more efficient attacks in the stronger Parallel Random Oracle Model (PROM).
    We address both limitations. We construct a new data-dependent MHF (dMHF), DEGSample, and prove the first SSC/CMC tradeoff for dMHFs directly in the PROM. In the dynamic pebbling model, DEGSample achieves the same ideal tradeoff as prior work: any dynamic pebbling strategy either sustains $\Omega(N)$ memory for $\Omega(N)$ steps or incurs a maximal CMC penalty $\Omega(N^{3-\epsilon})$. In the PROM, we prove that any attacker either sustains $\Omega(N)$ memory for $\Omega(N)$ steps or incurs a steep CMC penalty of at least $\Omega(N^{2.5-\epsilon})$. To prove this, we introduce a new graph property called ancestral robustness and show that, together with another property called fractional depth-robustness, it suffices to obtain strong PROM tradeoffs via a natural dynamization procedure to turn the graph into a dMHF. The PROM lower bound combines a time-space trade-off argument with an extraction procedure that converts any PROM execution into a cost-equivalent pebbling of the realized graph.
    ## 2026/1725
    * Title: Proof-of-Uniqueness: Sybil-Resistant Privacy-Preserving Decentralized Identity through Threshold-OPRF and zk-SNARK Registry
    * Authors: Adam Vozda, Martin Peresini, Juraj Mariani, Ivan Homoliak
    * [Permalink](https://eprint.iacr.org/2026/1725)
    * [Download](https://eprint.iacr.org/2026/1725.pdf)
    ### Abstract
    Several decentralized applications and blockchains, such as blockchain-based voting systems or Proof-of-Social-Capital, require a strict one-account-per-person policy, yet public identity records often expose sensitive attributes or enable offline attribution. This work presents a Proof-of-Uniqueness blockchain-based registry that composes an issuer-signed verifiable credential, two zero-knowledge proofs, a threshold verifiable oblivious pseudorandom function (vOPRF), and a smart contract. The first proof authorizes a blinded evaluation of an issuer's certified canonical identifier, and the second validates the OPRF transcript and binds the resulting global nullifier to a wallet. The design further binds issuer authorization, credential status, validity bounds, canonical encoding, and replay state. Its person-level guarantee is conditional on a stable injective identifier within a coordinated issuance namespace and a stable, valid OPRF key. Confidentiality holds against public observers and against fewer than the OPRF threshold of nodes, but not against an issuer that actively probes its own identifiers. Our prototype couples Noir and UltraPlonk circuits, three local threshold OPRF nodes, and a Solidity contract. For one fixed-schema credential input, it derives a single wallet-bound deterministic nullifier, verifies a real 2,144-byte proof on-chain, and rejects a repeated nullifier with $O(1)$ lookups. One real enrollment consumes 615k gas, and proof construction takes about 65 seconds on one desktop software thread.
    ## 2026/1726
    * Title: Jacobi Signatures, Revisited
    * Authors: Yansong Feng
    * [Permalink](https://eprint.iacr.org/2026/1726)
    * [Download](https://eprint.iacr.org/2026/1726.pdf)
    ### Abstract
    We remove the Boneh--Lipton conjecture from the proof of Corrigan-Gibbs and Wu (CRYPTO~2024) that Jacobi signatures modulo $N=p^2q$ are one-way. This relates the one-wayness of the pseudorandom generator proposed by Damg{\aa}rd in 1988 to a standard number-theoretic problem alone.
    ## 2026/1727
    * Title: Enhancing Capital Efficiency in DeFi Lending and Liquidity Provision
    * Authors: Adam Smehyl, Ivan Homoliak
    * [Permalink](https://eprint.iacr.org/2026/1727)
    * [Download](https://eprint.iacr.org/2026/1727.pdf)
    ### Abstract
    Decentralized Finance (DeFi) continues to experience rapid growth, yet a significant portion of capital remains inefficiently utilized in overprovisioned lending reserves or inactive liquidity positions. This paper presents two extension-based improvement proposals aimed at increasing capital efficiency in DeFi protocols. The first addresses idle capital in pool-based lending by adding an allocation layer that can deploy otherwise unused liquidity into external yield-generating strategies. The second targets inactive concentrated-liquidity positions through a position-management layer that automates range migration. Both proposals are examined in terms of motivation, mechanism design, expected effects, implementation approach, and practical limitations. Evaluation results are proposal-specific: the lending analysis indicates meaningful supplier-yield uplift under selected external-yield assumptions, while the range-migration analysis focuses on active-time sensitivity and execution cost. Prototype benchmarks suggest that both mechanisms can be implemented as modular extensions, but also expose additional gas overhead and proposal-specific risks, including external-strategy dependence, recall and loss-allocation concerns, and range-policy misconfiguration.
    ## 2026/1728
    * Title: A Controlled Case Study of Design Trade-offs in DeFi Lending Protocols * Authors: Jan Findra, Zdenek Lapes, Ivan Homoliak
    * [Permalink](https://eprint.iacr.org/2026/1728)
    * [Download](https://eprint.iacr.org/2026/1728.pdf)
    ### Abstract
    Decentralized lending protocols encode credit markets as smart contracts whose design choices affect gas cost, capital efficiency, liquidation behavior, and risk allocation. We compare Aave V3, SparkLend, Compound III, and Morpho Blue in matched Ethereum fork tests with wstETH collateral, USDC debt, and one fixed chain state. The tests measure call-path gas, annualized rates, thirty-day debt growth, maximum borrow capacity, and liquidation outcomes. It is important to note that the observed orderings for gas costs and rates are specific to this test artifact and could change under different collateral assets or utilization regimes. Within this setting, Morpho Blue has the lowest measured interaction call-path gas and highest borrow capacity, while shifting risk selection to isolated permissionless markets. Furthermore, Morpho Blue's evaluation uses a deployed market for rate measurements but a constructed market for liquidation testing. Aave V3 and SparkLend provide broader pooled-market abstractions with higher measured call-path gas. Compound III simplifies borrowing around one base asset per market; its low-gas absorb step is offset by a separate buy collateral liquidation path. We provide a Foundry-based Ethereum-fork test suite for reproducing these measurements and comparing lending-design trade-offs.
    ## 2026/1729
    * Title: A Unified Framework for Contract-Validated Benchmarking of Zero-Knowledge Proving Systems
    * Authors: Matej Hulek, Martin Peresini, Ivan Homoliak
    * [Permalink](https://eprint.iacr.org/2026/1729)
    * [Download](https://eprint.iacr.org/2026/1729.pdf)
    ### Abstract
    Zero-knowledge proofs are an operational infrastructure for rollups, private payments, verifiable execution, and zkVM applications. We treat them as succinct proofs of validity whose privacy properties depend on the system and the mode of use. Published benchmarks often compare different workloads, proof modes, and hardware paths, which makes their results hard to interpret. This work presents a unified host-agent framework for benchmarking heterogeneous proving systems under a common execution and reporting method. Each prover runs in an isolated containerized agent and is selected through a scheme-adapter layer. The agent reports canonical JSON artifacts linked to a hashed run manifest and workload-specific semantic contracts. The host checks the public semantic fields and the agent's verification flag to ensure backends are compared on the same declared public claim, even when their circuits, traces, or guest pipelines differ. We evaluate circuit-based, transparent, GPU-accelerated, folding, and zkVM systems: Groth16, ICICLE, Halo2, Plonky3, Winterfell, Nova, RISC Zero with CUDA and Groth16 wrapping, and SP1 with and without AVX. The suite uses six primary workloads with comparable semantics, together with secondary hash workloads that expose specialization. No prover family dominates all deployment criteria. At 8 CPU cores, Plonky3 and Winterfell have the smallest across-case proving-time and RAM figures. Groth16 and ICICLE produce sub-kilobyte proofs. Winterfell has the lowest host verification time. zkVM systems trade larger proofs and higher memory for programmability. On the Merkle-path micro-benchmark, pairing artifacts remain sub-kilobyte, whereas wrapping a zkVM receipt yields a Groth16-sized artifact at a high proving cost. GPU acceleration helps most after fixed setup costs are amortized. The main contribution is methodological: validate the statement being proved, disclose the security profile, and report resource limits in addition to proving time.
    ## 2026/1730
    * Title: New Techniques for Fast and Shallow FHE Bootstrapping and Beyond
    * Authors: Aayush Jain, Huijia Lin, Zeyu Liu, Sagnik Saha
    * [Permalink](https://eprint.iacr.org/2026/1730)
    * [Download](https://eprint.iacr.org/2026/1730.pdf)
    ### Abstract
    The main barrier to practical fully homomorphic encryption remains the latency and cost of bootstrapping, the ciphertext refresh step that enables unbounded computation.
    We design new methods that reduce both the latency and the circuit depth of bootstrapping in the FHEW/TFHE framework, which represents the state-of-the-art for lightweight bootstrapping and for computing deep and unstructured Boolean functions over encrypted data.
    Our first contribution leverages LWE with a sparse small-norm secret, an assumption known to be equivalent to standard LWE and already widely used in FHE constructions.
    For an LWE secret of dimension $n$ and Hamming weight $h$, we obtain bootstrapping procedures whose arithmetic complexity decreases from $\tilde O(n^2)$ to $\tilde O(n h)$ $\mathbb{Z}_q$ multiplications while preserving the same asymptotic number of additions. Concretely, this yields a $4.5$--$7.5\times$ practical speedup for gate and functional bootstrapping over the state-of-the-art OpenFHE implementation.
    Our second contribution introduces a new RLWE variant with structured secrets, called \emph{\mainrlwevarianttext}, and uses it to significantly reduce the circuit depth of FHEW/TFHE bootstrapping via a new relinearization-free BV multiplication technique.
    In concrete parameter settings, this reduces the number of sequential NTT/INTT layers required for bootstrapping to just 3, compared to more than 500 in standard FHEW/TFHE, while keeping the overall number of unit 32 or 64-bit word operations comparable to standard FHEW/TFHE bootstrapping.
    This substantial depth reduction suggests the potential for significantly lower bootstrapping latency on parallel, high-throughput architectures such as GPUs.
    Finally, we analyze the security of the new RLWE assumption underlying our depth reduction, including worst-case-to-average-case and search-to-decision reductions, as well as evaluations against concrete attacks.
    ## 2026/1731
    * Title: Generic Ring-Signature Transforms for Fiat-Shamir with Aborts and Hash-and-Sign with Retry
    * Authors: Haruhisa Kosuge, Koutarou Suzuki
    * [Permalink](https://eprint.iacr.org/2026/1731)
    * [Download](https://eprint.iacr.org/2026/1731.pdf)
    ### Abstract
    Ring signatures provide signer anonymity for ad hoc sets of public keys. Generic Abe-Ohkubo-Suzuki (AOS) transforms are well understood for plain Fiat--Shamir and hash-and-sign signatures, but not for their rejection-sampling variants: Fiat--Shamir with aborts (FSwA) and hash-and-sign with retry (HSwR). We formalize AOS ring transforms for FSwA and HSwR and analyze their security in the quantum random-oracle model. For unforgeability, we reduce security under adaptive ring-signing queries to security without signing queries using essentially the same assumptions as in security proofs for the corresponding ordinary signatures; handling adaptive corruption additionally requires the simulation property to remain valid after key exposure. Strong unforgeability additionally requires response uniqueness and special soundness for FSwA, or second-preimage resistance and non-invertibility for HSwR. The residual no-signing-query requirement admits generic reductions, but with loss exponential in the number of honest keys. Finally, an ML-DSA case study shows that augmented public keys achieve the required key-exposure simulation while identifying its limitations; we also identify conditions for candidate HSwR instantiations.
    ## 2026/1732
    * Title: Indifferentiability of Public-Key Encryption: Theory Meets Practice
    * Authors: Taiyu Wang, Cong Zhang, Hong-Sheng Zhou, Jiayi Ai, Zhihong Jia, Wenli Wang, Jian Liu, Xin Wang, Li Lin, Kui Ren, Chun Chen
    * [Permalink](https://eprint.iacr.org/2026/1732)
    * [Download](https://eprint.iacr.org/2026/1732.pdf)
    ### Abstract
    Public-key encryption (PKE) is a fundamental primitive in modern cryptography, and many PKE schemes have been standardized and widely deployed. To reason about security in complex and highly compositional environments, Zhandry and Zhang (CRYPTO 2020) initiated the study of indifferentiability for public-key cryptosystems. However, their construction for PKE departs substantially from the design paradigms used in practice, and to date no practical public-key encryption schemes are known to achieve indifferentiability.
    In this work, we further investigate indifferentiability for public-key encryption, asking whether it can be achieved for practical, standardized schemes. We provide evidence that the answer is yes: slightly augmented standardized group-based encryption schemes can indeed achieve provable indifferentiability. Our contributions are threefold:
    -- Identifying a barrier in the existing ideal PKE model: We revisit the ideal PKE definition of Zhandry and Zhang and identify an artificial requirement---namely, pseudorandom public keys and ciphertexts---that constitutes an inherent barrier to achieving indifferentiability from groups.
    -- Redefining the idealized model for PKE: We propose a revised ideal PKE model that removes this pseudorandomness requirement, thereby opening the possibility of achieving indifferentiable public-key encryption from practical group-based schemes.

    --Making standardized PKE indifferentiable: We consider two public-key encryption schemes standardized in ISO/IEC 18033-2---Elliptic Curve Integrated Encryption Scheme (ECIES) and Public-Key Secure Encryption (PSEC)---and show that, under slight augmentation, both are indifferentiable from our revised ideal PKE.
    In conclusion, our work advances the development of indifferentiable yet practical public-key encryption schemes, enabling future research and protocol design to build on standard PKE schemes while enjoying strong composability guarantees.
    ## 2026/1733
    * Title: TEE Server-Assisted Aggregated Offline Deployment Scheme for Multiplication Triples
    * Authors: Puyu Wang, Ruidan, Zhenshen Liu, Ruiqi Yang, Hui Li
    * [Permalink](https://eprint.iacr.org/2026/1733)
    * [Download](https://eprint.iacr.org/2026/1733.pdf)
    ### Abstract
    With the growing deployment of secure multi-party computation (MPC) in data-intensive applications, the offline generation and distribution of authenticated multiplication triples has become a key scalability bottleneck. Existing software-only preprocessing protocols, such as MASCOT and LowGear, typically incur substantial interaction and computation costs when the number of participants or the triple demand is large. This paper proposes a trusted execution environment (TEE) serverrCoassisted aggregated offline deployment scheme that moves expensive interactive preprocessing into a remotely attested enclave and distributes participant-specific authenticated triple shares over authenticated-encrypted channels. Conceptually, the enclave serves as a TEE-backed pseudorandom correlation generator (PCG) that outputs authenticated correlated randomness for MPC with one-way delivery. We design an end-to-end workflow covering remote attestation, per-participant session establishment, and encrypted distribution. The proposed protocol applies to both semi-honest and malicious adversaries; we provide a security analysis against malicious adversaries with abort. Experimental results show clear efficiency improvements over MP-SPDZ implementations of MASCOT and LowGear. Specifically, the proposed scheme achieves a generation rate three times that of MASCOT, while exhibiting linear scalability up to 100k participants. Furthermore, by employing a streaming processing strategy, it efficiently supports the generation of up to 10M triples with an amortized time significantly lower than that of purely software-based protocols, enabling practical and highly scalable preprocessing for large-scale heterogeneous MPC deployments.
    ## 2026/1734
    * Title: Key Recovery from Residue-Confined Errors in the Pradhan CRT-RLWE Construction
    * Authors: Lukasz Olejnik, Bartosz Naskrecki
    * [Permalink](https://eprint.iacr.org/2026/1734)
    * [Download](https://eprint.iacr.org/2026/1734.pdf)
    ### Abstract
    We show that the CRT-FHE scheme of Pradhan et al. is insecure for laws within its assumed error distribution range. The secret key follows from the public key by a single ring inversion whenever the public multiplier is a unit. The plaintext is recovered from any ciphertext under such a law without the secret key, for every multiplier, giving chosen-plaintext advantage $1/2$. We further show that the transformation from ordinary Ring-LWE to CRT-RLWE does not preserve the error distribution, so it does not establish that CRT-RLWE is at least as hard as Ring-LWE.
    One mechanism underlies both. The Chinese remainder theorem (CRT) function is reduced modulo $p_1p_2$ while its output is used modulo a coprime modulus $q$, so under every zero-preserving section an error in $p_2\mathcal{R}$ encodes to zero. The law $p_2B_1$ is so confined, meets the stated conditions, and decrypts correctly. Confinement is not a weakness of scale: scaling any baseline law by $p_2$ leaves its ordinary Ring-LWE problem exactly equivalent, while the reduced encoder destroys every error it produces. The reduction discrepancy is a multiple of $p_1p_2$ and not of $q$, so the small-error premise of the proof cannot remove it, and at the reported parameters a single error coefficient refutes the identity while satisfying that premise. The centered binomial $B_2$ separates the coefficient laws at total variation distance $3/8$, and at the reported dimension that distance between the induced polynomial laws is exponentially close to one.
    ## 2026/1735
    * Title: Adapting AES-Oriented Optimizations to Rijndael-256: Cortex-M4, ARMv8-A, and CUDA
    * Authors: Siwoo Eum, Minho Song, Minjoo Sim, Anupam Chattopadhyay, Hwajeong Seo
    * [Permalink](https://eprint.iacr.org/2026/1735)
    * [Download](https://eprint.iacr.org/2026/1735.pdf)
    ### Abstract
    Rijndael-256 (R256), the 256-bit block variant of the Rijndael family, is practically relevant in ongoing NIST draft discussions on wider-block standardization and in several NIST post-quantum signature candidates. Relative to AES, R256 combines a wider $4\times8$ state with non-standard ShiftRows offsets $(0,1,3,4)$, invalidating key assumptions behind many AES-oriented optimizations. We study how these mismatches manifest on three targets and develop three corresponding adaptation strategies: wider classical bitslicing on Cortex-M4, Reuse with Reshuffling on AArch64, and Amortize the Mismatch on CUDA. This yields a bitsliced Cortex-M4 implementation with secret-independent control flow and memory access patterns (4,962 cycles/block), an AArch64 pre-shuffle design that reuses the AESE instruction with AddRoundKey folded in (up to 6,520 MB/s), and a CUDA shared-memory T-table implementation reaching 81.16 GiB/s; we report throughput on AArch64 and CUDA because per-block cycle measurement is not directly available on those platforms. Replacing the R256 cryptographic core in four NIST PQC reference codebases on Apple M2, with minimal integration changes where needed, yields signing speedups of $1.18\times$--$114.3\times$ and verification speedups up to $155.6\times$, with the end-to-end gain governed by each scheme's R256 fraction.
    ## 2026/1736
    * Title: Copy-Protection with Correlated Challenges: Point Functions and More via Decisional Coset Monogamy
    * Authors: Amit Behera, Alper |cakan, Vipul Goyal
    * [Permalink](https://eprint.iacr.org/2026/1736)
    * [Download](https://eprint.iacr.org/2026/1736.pdf)
    ### Abstract
    Copy-protection is one of the main applications of quantum information in cryptography. In copy-protection, we encode a functionality in a reusable quantum state so that it cannot be split into two states (called freeloader adversaries) that remain simultaneously useful. Despite a long line of research, previous works have only been able to show security with respect to independently sampled challenges in the plain-model. However, arguably a more natural security notion considers the two freeloader adversaries receiving the same challenge. This so-called identical-challenge security notion is also connected to other fundamental quantum cryptographic primitives such as unclonable bits (i.e. unclonable encryption) and copy-protection of point functions.
    In this work, first we make progress on the definitional foundations of these primitives, and then prove security in the plain model for our new stronger definitions, in particular also resolving the question of copy-protection with identical challenges and copy-protection of point functions. In more detail, we obtain the following results.
    -- Copy-protecting decryption keys (Single-decryptor encryption).}
    We define a new natural security notion for single-decryptor encryption (SDE) called {correlated challenge security}, and show that implies all previous security definitions for SDE, including identical-challenge security. Then, we prove that, assuming indistinguishability obfuscation (iO) and one-way functions, the SDE construction of Kitagawa and Yamakawa (TCC'25) satisfies correlated challenge security. We also provide an almost complete characterization of the relationship among previous SDE security notions.
    --Copy-Protecting General Functionalities with Correlated Challenges.
    We define correlated challenge unclonable puncturable obfuscation (UPO), allowing
    arbitrary correlations among challenge points and puncturing bits, plus auxiliary information before and after splitting. Security requires only
    conditionally uniform bits and $\lambda^c$ average conditional min-entropy in each point separately, for any constant $c>0$; thus, in particular the challenge points may be
    identical. Assuming polynomially secure post-quantum iO and quantum-hard LWE, we construct correlated UPO for arbitrary polynomial-size keyed circuits with input length at least $\lambda^c$, answering the open question of Ananth, Behera, Huang, Kitagawa, Yamakawa (EUROCRYPT'26) and |cakan-Goyal (EUROCRYPT'26).
    --Applications
    Our results yield the first plain-model copy protection for point functions, $k$-point functions, and compute-and-compare programs under natural security definitions, and identical-challenge copy protection for general puncturable functionalities.
    The technical core of our results is a new decisional monogamy theorem for coset states, which both simplifies the proofs and generalizes the results of existing copy-protection constructions, which may be of independent interest.
    ## 2026/1737
    * Title: From Mechanical Lock-Picking to Autonomous Driving Deception: A Comprehensive Review of Vehicle Attacks, Cyberattacks, and Defenses
    * Authors: Karim Lounis
    * [Permalink](https://eprint.iacr.org/2026/1737)
    * [Download](https://eprint.iacr.org/2026/1737.pdf)
    ### Abstract
    Modern vehicles have evolved into highly interconnected
    Software-Defined Cyber-Physical Systems (CPS), integrating
    embedded electronics, wireless communications, artificial
    intelligence, and Advanced Driver Assistance Systems
    (ADAS). While these technological advances have significantly
    improved vehicle safety, efficiency, and driving automation, they
    have also introduced a rapidly expanding cyber-physical attack
    surface. Consequently, automotive cybersecurity has become an
    active research area encompassing attacks on physical vehicle
    components, access and authentication mechanisms, electronic
    and software systems, and autonomous driving technologies.
    Although numerous studies and surveys have investigated these
    security threats, the existing literature remains fragmented, often
    focusing on specific vehicle subsystems or individual technologies.
    This paper presents a comprehensive survey of attacks and
    defense mechanisms targeting modern vehicles through a unified
    and orthogonal taxonomy that classifies the literature into four
    research directions: attacks on vehicle body and physical systems,
    vehicle access and engine start systems, electronic and software
    systems, and ADAS and autonomous driving systems. For each
    direction, the associated security issues, representative attacks,
    and existing countermeasures are systematically reviewed and
    analyzed. Furthermore, the survey identifies current research
    trends, highlights existing research gaps, and discusses future
    challenges toward the development of comprehensive and resilient
    automotive security solutions.
    ## 2026/1738
    * Title: Noisy Subset Product
    * Authors: Trey Li
    * [Permalink](https://eprint.iacr.org/2026/1738)
    * [Download](https://eprint.iacr.org/2026/1738.pdf)
    ### Abstract
    In 1978, Yao studied the subset product problem and proved its NP-completeness. Later, Galbraith, Zobernig, and Li considered a prime-based modular variant and studied its average-case hardness. More recently, Li introduced the general problem of unknown-coefficient multivariate exponential system solving and studied its hardness systematically in an abstract setting. Li's framework implies a noisy modular variant of subset product as a special case. In this paper, we study this noisy subset product problem in a concrete setting, prove equivalence relations among several related variants, and use these results to construct a post-quantum non-alternating key exchange scheme, with a natural one-sided interpretation as a key encapsulation mechanism. Unlike other noise-based schemes, such as lattice-based schemes, our construction does not rely on an additional reconciliation plaintext. Instead, the receiver is able to recover the sender's ephemeral secret key itself. Moreover, we reduce indistinguishability security directly to the search version of the noisy subset product problem, without relying on a separate decisional assumption.
    ## 2026/1739
    * Title: Prop RFQ: Proprietary Request for Quote as Pressure-Aware Exit Pricing for Redeemable Real-World Asset Tokens
    * Authors: Daniel Rolnik, Theodore Georgas, Ivan Homoliak
    * [Permalink](https://eprint.iacr.org/2026/1739)
    * [Download](https://eprint.iacr.org/2026/1739.pdf)
    ### Abstract
    Redeemable real-world asset tokens can trade onchain faster than their backing assets can be sold or settled. An immediate-exit facility cannot treat reported net asset value (NAV) as fully liquid. Within our scope, the mechanisms we compare do not jointly provide permissionless access, order-splitting resistance, and favorable small exits.
    In this paper, we propose a Proprietary Request for Quote (Prop RFQ), an onchain facility that prices exits against available reserves and mitigates, but does not eliminate, split-order incentives. Its quote combines NAV, an order-size curve, a funded-liquidity wall, decaying sell pressure, and a cadence response to repeated sells. The design seeks to keep isolated small exits useful while limiting reserve depletion and gains from splitting a concentrated exit. We evaluate the implemented Solana pricing path with fixed workloads and ablations, then sweep 15,120 parameter configurations. At the reference parameters, cadence reduces aggregate split advantage by 9.67% against matched pressure-only pricing, improves 34 of 40 split workloads, and raises worst-case reserve remaining from 10.49% to 17.66%. No simple policy or Prop RFQ ablation in our comparison dominates the reference configuration on common metrics. After correcting epoch rollover, implementation quotes match the explicitly rolled model at every tested recovery point. However, low-value sells enable cheap cadence griefing.
    ## 2026/1740
    * Title: Non-Local Search-to-Decision Reduction over $\mathbb{F}_2$
    * Authors: Prabhanjan Ananth
    * [Permalink](https://eprint.iacr.org/2026/1740)
    * [Download](https://eprint.iacr.org/2026/1740.pdf)
    ### Abstract
    Non-local search-to-decision asks whether two noncommunicating parties, given the two shares of a bipartite encoding of a uniformly random string $x\in \mathbb{F}_2^n$, can both predict the same random parity $\langle r,x\rangle$ without there also being local measurements with which both parties recover $x$. We prove that if their optimal probability of both recovering $x$ by local measurements is $p$, then their probability of both answering a common parity challenge correctly is at most $\min\{1,\frac12+5p^{1/22}\}$. The result is motivated by applications to unclonable cryptography, including unclonable encryption and quantum copy-protection. The proof is information-theoretic and does not provide an efficient extractor. The proof and the exposition were developed with assistance from ChatGPT using GPT-5.6 Sol Pro and Codex in the Ultra reasoning mode.
    ## 2026/1741
    * Title: One Proof to Rule Them All: Practical, Sublinear Verification for Actively Secure MPC on $\mathbb{Z}_{2^k}$ with Dishonest Majority and a Dealer (Full Version)
    * Authors: Andreas Br|+ggemann, Ariel Nof, Thomas Schneider
    * [Permalink](https://eprint.iacr.org/2026/1741)
    * [Download](https://eprint.iacr.org/2026/1741.pdf)
    ### Abstract
    Towards bridging the gap between passively and actively secure multiparty computation (MPC), the use of sublinear distributed zero-knowledge (DZK) proofs gained popularity. Such proofs enable extending a passively secure protocol by adding a verification step whose communication is sublinear in the circuit size. For arbitrarily many parties and a dishonest majority, adding a trusted dealer enables efficient computation, as recently shown by Asterisk (IEEE S&P'24) without requiring DZK. This setting is also compatible with DZK, as shown by Boyle et al. (CRYPTO'21). Unfortunately, their approach is not tailored to computation over a ring $\mathbb{Z}_{2^k}$, often favored for concrete efficiency and practicality, resulting in high computational overhead. In the honest majority setting with few parties, Li et al. (CCS'24) optimized DZK to rings, achieving significant performance improvements.
    In this work, we propose the first sublinear verification protocol that is both, designed for the $n$-party dishonest majority setting with a dealer, and tailored to computation over a ring $\mathbb{Z}_{2^k}$, combining and improving upon both approaches above. Previous approaches used $n$ DZK proofs to check correct behavior for each individual party. Instead, we show how to verify in a single, novel DZK proof that all parties together behave correctly. This decreases the communication complexity for verification from $\mathcal{O}(n \cdot \log m)$ to $\mathcal{O}(n + \log m)$ ring elements per party for $m$ multiplications. Hence, for the first time, active security using DZK scales well with the number of parties $n$. We provide the first public implementation for DZK with arbitrary $n$ and a dealer and show its practical efficiency. For $m=10^6$ multiplications across 30 layers, communication increases by only 0.7% over the passively secure base protocol with only moderate computation overhead. This becomes especially useful in a WAN setting, where we achieve active security at only 34% run time overhead over the passive variant. Compared to Asterisk (IEEE S&P'24), our protocol has 1.8x better communication and improves run time by 2.5x in WAN and 11.9x in LAN.
    ## 2026/1742
    * Title: Unclonable encryption from BB84 states: a simultaneous Goldreich-Levin reduction
    * Authors: Andrea Coladangelo, Qipeng Liu, Ziyi Xie
    * [Permalink](https://eprint.iacr.org/2026/1742)
    * [Download](https://eprint.iacr.org/2026/1742.pdf)
    ### Abstract
    Goldreich-Levin reductions are ubiquitous in cryptography: they convert an algorithm capable of guessing $\langle r, m \rangle$ (mod $2$) for a hidden string $m$ and a random challenge $r$, to one that is capable of extracting the entirety of $m$. Here, we describe a "simultaneous" Goldreich-Levin reduction for two entangled parties who are capable of guessing $\langle r, m \rangle$ given uniformly random identical challenges $r$. This allows to upgrade any unclonable encryption scheme satisfying "search" security to one satisfying the gold standard of unclonable "indistinguishability". As a corollary, we show that the simplest candidate unclonable encryption scheme from BB84 states satisfies unclonable indistinguishability.
    This result was discovered by GPT-5.6 Ultra after a few interactions. Our prompts included recent results on unclonable encryption by Ananth and Sahai, and Ragavan.
    ## 2026/1743
    * Title: Notes on Short-Limb Modular Multiplication Techniques: Barrett, Montgomery, Plantard, and the Explicit CRT
    * Authors: Bo-Yin Yang
    * [Permalink](https://eprint.iacr.org/2026/1743)
    * [Download](https://eprint.iacr.org/2026/1743.pdf)
    ### Abstract
    This note collects, in compressed form, some techniques for modular multiplication with
    word-size (rCLshort-limbrCY), or at most a-handful-of-words sized moduli as they are used in
    implementations of lattice-based cryptography: Barrett reduction and multiplication (in
    signed and unsigned flavors, with exact error, range, and canonicality analyses), Montgomery
    reduction and multiplication (including the folded-constant form, the precise equivalence with
    Barrett multiplication, even moduli, the multi-limb case, and the k-reduction), Plantard
    multiplication (the original unsigned algorithm, the signed variant, and a variant taking
    signed inputs to the canonical unsigned representative in [0,q)), and modular multiplication
    via the explicit Chinese remainder theorem. These are compressed out of my lecture slides in the class Post-Quantum Cryptography at National Taiwan University 2020--2025 (EE 5176/921 U2540). All numerical examples, ranges, and windows
    stated here have been verified by exhaustive or randomized machine search; several constants
    and ranges correct typos and miscalculations that circulated after lectures.
    ## 2026/1744
    * Title: Improved Collision Attack on RIPEMD-160
    * Authors: Zhengrong Lu, Hongbo Yu, Yingxin Li, Xindi Zhang, Xiaoen Lin
    * [Permalink](https://eprint.iacr.org/2026/1744)
    * [Download](https://eprint.iacr.org/2026/1744.pdf)
    ### Abstract
    RIPEMD-160 is an ISO/IEC hash function standard based on the Merkle-Damg|Nrd structure with a double-branch compression function. There have been many attempts at modular differential attacks on reduced RIPEMD-160, with the best previous result being a 40-step practical collision attack achieved in 2023. That attack constructs a simple local collision in round 2 of the left branch to minimize uncontrolled conditions. To achieve this, differences must be introduced into many message words, which constrains the maximum number of steps that can be attacked. To overcome this limitation and target more steps, we propose a new differential characteristic structure that abandons the sparse local collision in round 2 and instead uses a single continuous differential characteristic spanning rounds 1 to 2 for each branch. This structure allows us to inject a difference into only one message word. Using an automatic search tool based on the high-performance parallel SAT-solver PRS, we identify suitable differential characteristics by imposing more control over conditions, differences, and the probability of proper propagation. Based on the differential characteristics, we identify three colliding message pairs for 42-step RIPEMD-160 with theoretical time complexity of approximately $2^{47.4}$, thereby improving the best practical collision attack by 2 steps on this hash function.
    ## 2026/1745
    * Title: Round-Preserving Compilers for Super-Rushing Secure MPC
    * Authors: Michele Ciampi, Divya Ravi, Mingrui Zou
    * [Permalink](https://eprint.iacr.org/2026/1745)
    * [Download](https://eprint.iacr.org/2026/1745.pdf)
    ### Abstract
    Practical implementations of synchronous MPC protocols typically require each party to advance to the next round as soon as they have received all expected messages. This deviates from the theoretical synchronous round-based model, where instead each party advances in the next round after a timeout. To capture this gap between theory and practice, Asharov, Chandramouli, Cohen and Ishai in Eurocrypt 2025 proposed a new model where the adversary is super-rushing. In this, the adversary can see future messages of some honest parties before delivering current-round messages to slower ones. In this work, we study super-rushing security in both the computational and statistical settings, and design round-preserving compilers that transform standard synchronous MPC protocols into ones secure against super-rushing adversaries. Ours is the first work to investigate the security of computational MPC protocols against a super-rushing adversary.
    ## 2026/1746
    * Title: Chasing QuOCCAs in a Quantum World: Type-2 Oracles for CCA-Secure PKE * Authors: Barbara Jiabao Benedikt, Tommaso Gagliardoni, Patrick Struck
    * [Permalink](https://eprint.iacr.org/2026/1746)
    * [Download](https://eprint.iacr.org/2026/1746.pdf)
    ### Abstract
    In the context of PKE schemes, Gagliardoni et al. proposed at PQCrypto 2021 a qIND-qCPA security notion (a superposition-based analogue of the classical IND-CPA security notion), by using the theory of so-called type-2 unitary operators. On one hand, this notion is very natural, closely mirrors the classical intuition, and can be handled without relying on complex techniques such as ZhandryrCOs compressed oracles. On the other hand, it is restricted to a certain class of PKE schemes (so-called isometric). Moreover, it is not immediately clear how to extend the definition to chosen-ciphertext attack (CCA) scenarios, mainly due to the possibility of decryption failures rCo something that is entailed by most quantum-resistant PKE schemes.
    In this work, we use the theory of type-2 operators to extend superposition-based security notions to any PKE schemes, in the CPA and CCA setting, without ZhandryrCOs compressed oracle technique. We start first by showing that a trivial extension of Gagliardoni et al.rCOs techniques to the general case is not possible, even for the CCA1 case, by identifying barriers preventing the realization of a rCynaturalrCO type-2 decryption operator. Then we define a subclass of PKE schemes (which we call rCystrongly decryptablerCO ), for which it is easy to circumvent the aforementioned barriers and to define superposition-based CCA1 and CCA2 notions.
    Further, we introduce a novel transformation (that we call rCypurificationrCO) which applies to any PKE scheme, producing a rCyquasi-PKErCO scheme, for which it is possible to define properties that mimic the security notions defined for strongly decryptable schemes; we can thus rCyunloadrCO the security definitions for an arbitrary PKE scheme on its purification. Finally, we show implications and separations between our security notions, as well as constructions.
    ## 2026/1747
    * Title: Extending Distinguishing to Key Recovery for Subfield Subcodes of GRS codes
    * Authors: Kirill Vedenev
    * [Permalink](https://eprint.iacr.org/2026/1747)
    * [Download](https://eprint.iacr.org/2026/1747.pdf)
    ### Abstract
    Ghoshal, Ishai, Jain, and Sun recently introduced a novel quasipolynomial-time distinguisher for GRS subcodes (including Goppa codes), leaving key recovery as an open problem. This note presents an approach for turning the distinguisher into a full key-recovery attack. The overall complexity is dominated by a few executions of the distinguisher, and the approach is experimentally validated on Goppa codes over $\mathbb{F}_4$. We conjecture that this recovery route applies to binary Goppa codes as well.
    ## 2026/1748
    * Title: SafeHub: End-to-end encrypted Git hosting system
    * Authors: Easwar Vivek Mangipudi
    * [Permalink](https://eprint.iacr.org/2026/1748)
    * [Download](https://eprint.iacr.org/2026/1748.pdf)
    ### Abstract
    Private repositories remain readable to Git hosts despite transport and at-rest encryption. We present SafeHub, an end-to-end encrypted Git hosting system. It encrypts repository contents and semantic metadata - file names, commit messages,
    authors, branches, issues, pull requests, and refs - so the host sees only ciphertext, opaque identifiers, lengths, and order.
    Each repository is a Messaging Layer Security (MLS) group, providing admin-mediated membership, post-compromise healing, and per-invite history windows. Ordinary Git behavior is preserved within each member's window: branches, merges, and blame still work. Forward-only members start from a join shallow snapshot rather than the full past.
    Confidentiality alone is not enough: Git's hash-linked objects do not protect mutable refs. SafeHub records refs in an encrypted, device-signed, hash-chained manifest that detects rollback against a member's own anchor and host forks when
    members compare checkpoints; force-pushes require administrator co-signatures. We specify a single ideal functionality F_safehub for the system and prove that SafeHub universally composably realizes it against a malicious server and adaptive member corruptions, in a hybrid model over group key agreement and certification, assuming secure erasure in the quantum random oracle model.
    Our NIST PQ Category-5 Rust prototype measures full-stack push, pull, fetch, clone, merge, rebase, and force-push on a client-server pair of AWS Graviton4 hosts, together with the epoch rotation and consolidation that Git has no counterpart for. Against Git on its lowest-overhead native transport, wall-clock
    push runs 1.45x plain Git at a 0.05 MB delta and 0.98x at a 5 MB one, its marginal cost 46.7 ms/MB against Git's 49.3. We compare SafeHub with five other systems - plain Git, git-crypt, git-remote-gcrypt, and a reimplementation of the
    closest peer - over a single transport, with clients and remotes on separate hosts. The comparison separates designs whose cost follows the edit from designs
    whose cost follows the whole file. For a fixed 1 KiB edit, with the edited file growing from 10 KiB to 8 MiB, SafeHub's cost per update remains constant at
    6.7 kB, because it seals the packfile Git has already built, whereas the systems
    that encrypt each file individually grow with the file and reach 8.39 and
    13.4 MB. On that shared transport SafeHub is the fastest of the six at push, pull, fetch, merge, rebase, and force-push, each constant in history depth, and its stored size matches plain Git to within 0.2%, whereas the per-file encryption used by the other systems costs 13 to 21 times as much. The cost that
    does not amortize is clone, which grows with sealed history: a host that cannot read a repository cannot repack it.
    ## 2026/1749
    * Title: CAKE-HI - Compact Authenticated Key Exchange Hiding Identities
    * Authors: Uri Blumenthal, Gene Itkis, Roger Khazan, Brandon Luo, Sean O'Melia, Brian Proulx, David Stott, Gabriel Torres, David A. Wilson
    * [Permalink](https://eprint.iacr.org/2026/1749)
    * [Download](https://eprint.iacr.org/2026/1749.pdf)
    ### Abstract
    Modern public-key cryptography is threatened by advances in quantum computing. As a result, there has been a shift towards cryptographic algorithms that can resist attacks by a quantum computer. However, these algorithms use significantly longer keys, and produce larger ciphertexts and digital signatures than their classical counterparts. These bigger sizes pose problems for devices that are bandwidth- and/or power-limited, and wish to establish a secure, quantum resistant communication channel with another device.
    In order to reduce the overhead of using these algorithms in challenging environments while maintaining security posture, we present Compact Authenticated Key Exchange rCo Hiding Identities (CAKE-HI). To evaluate our protocol, we compare the key exchange handshake size and computational efficiency of mutual authenticated TLS and CAKE-HI. Measurements show that CAKE-HI significantly reduces the handshake size and the computational overhead of establishing a quantum-secure link.
    In addition, we formalize and prove security properties about CAKE-HI in the symbolic and computational model using the protocol analysis frameworks Verifpal and CryptoVerif.
    ## 2026/1750
    * Title: Threshold Lattice-Based Zero-Knowledge Proofs
    * Authors: Scott Griffy, Victor Youdom Kemmoe, Ngoc Khanh Nguyen, Tjerand Silde * [Permalink](https://eprint.iacr.org/2026/1750)
    * [Download](https://eprint.iacr.org/2026/1750.pdf)
    ### Abstract
    Lattice-based zero-knowledge proofs are now efficient enough for practical use, but in all known constructions a single prover holds the entire witness and is therefore a single point of failure. Thresholdizing them is understood only for three-round $\Sigma$-protocols, which certify shortness only $\textit{approximately}$. The $\textit{exact}$ statements needed by applications such as anonymous credentials require more rounds and rely on rejection sampling, and neither property survives thresholdization.
    We construct the first lattice-based threshold zero-knowledge proof systems for exact relations. The witness is Shamir-shared among $\mathtt{n}$ parties, any $\mathtt{t}$ of them can jointly produce a proof, and the proof has the same form as a single-prover proof, only a factor $\sqrt{\mathtt{t}}$ larger, with verification unchanged. We thresholdize the product proof of Attema, Lyubashevsky, and Seiler (CRYPTO 2020) and the exact proof of Esgin, Nguyen, and Seiler (ASIACRYPT 2020), making both rejection-free using Hint-MLWE and evaluating them over threshold homomorphic encryption. We define threshold commit-and-prove protocols with the corresponding zero-knowledge and simulation-extractability notions, and prove our constructions secure against passive adversaries that statically corrupt at most $\mathtt{t}-1$ parties.
    Of independent interest, we show that the Fiat--Shamir transforms of both proof systems are simulation-extractable in the random oracle model, and that MLWE remains hard when secrets are drawn from the subring fixed by a ring automorphism.
    ## 2026/1751
    * Title: Efficient Dynamic Group Signatures with Forward Security
    * Authors: Amin Mohammadali, Riham AlTawy
    * [Permalink](https://eprint.iacr.org/2026/1751)
    * [Download](https://eprint.iacr.org/2026/1751.pdf)
    ### Abstract
    In dynamic group signature schemes (GSS), forward security ensures that newly joined members cannot generate valid signatures for past time periods. Additionally, non-frameability prevents even privileged entities, such as the group manager or key issuer, from falsely attributing signatures to honest users. Most GSS either lack non-frameability or face significant efficiency challenges when updating signing keys to ensure forward security. In this paper, we introduce a forward-secure dynamic group signature scheme that guarantees non-frameability. We also present an alternative scheme that, while lacking non-frameability, offers higher efficiency compared to existing schemes with comparable security. For both protocols, we propose efficient revocation mechanisms that allow an authority to revoke users without requiring re-registering existing users. Additionally, we propose a technique that enables the verification process of both protocols to be performed in batches. We prove the security of our schemes, ensuring the standard dynamic GSS security notions; anonymity, traceability and non-frameability (second scheme). Experimental results demonstrate that our schemes are competitive in both computational and communication efficiency when compared to existing literature.
    ## 2026/1752
    * Title: L-BAS: A Lattice-Based Blind Adaptor Signature Scheme
    * Authors: Amin Mohammadali, Riham AlTawy
    * [Permalink](https://eprint.iacr.org/2026/1752)
    * [Download](https://eprint.iacr.org/2026/1752.pdf)
    ### Abstract
    Lattice-based blind signatures have attracted significant attention in recent years due to the rapid growth of digital currencies, the increasing demand for privacy-preserving digital interactions, and the ongoing transition toward quantum-resistant cryptographic primitives. While blind signatures provide anonymity guarantees, achieving fairness without compromising privacy to a third party remains a challenging problem. Blind adaptor signatures (BAS) address this limitation by enriching blind signatures with conditional-execution functionality, enabling fair exchange while preserving user anonymity. In particular, a BAS scheme allows a user to engage in an atomic swap with a verifier using an adapted blind signature obtained from a signer, thereby maintaining privacy against the signer while ensuring fairness between the user and the verifier.
    In this work, we observe that the ABDLOP commit-and-prove framework (CRYPTO 2022) exhibits a dichotomic structure that can be leveraged to realize adaptor functionality. Building on this, we propose a lattice-based blind adaptor signature (L-BAS) scheme that simultaneously achieves fairness along with the privacy guarantees of blind signing. Compared with the underlying lattice-based blind signature scheme, our construction incurs only a modest overhead, increasing the signature size by approximately 5.2 KB while largely preserving the efficiency of the original system. We formally analyze the security of the proposed construction and prove that it satisfies extractability, unique extractability, computational pre-verification soundness, one-more unforgeability, and blindness under standard lattice-based assumptions. Our results demonstrate that fairness can be incorporated into lattice-based blind signatures with minimal performance degradation, making the proposed scheme a practical candidate for privacy-preserving and quantum-resistant fair exchange applications.
    ## 2026/1753
    * Title: Linear Distance for Fixed-Row-Weight Expand--Accumulate Codes over Arbitrary Fields
    * Authors: Majid Khabbazian
    * [Permalink](https://eprint.iacr.org/2026/1753)
    * [Download](https://eprint.iacr.org/2026/1753.pdf)
    ### Abstract
    ExpandrCoaccumulate (EA) codes are sparse linear codes underlying constructions of correlated pseudorandomness and field-agnostic succinct arguments. In rCLField-Agnostic SNARKs from ExpandrCoAccumulate CodesrCY (CRYPTO 2024), Block et al. conjectured that a single fixed-row-weight EA component already achieves constant relative distance with inverse-polynomial failure probability.
    We prove this conjecture in a stronger, field-uniform form. For every rate $R\in(0,1)$, there exists $\delta_R>0$ such that, for every target exponent $C>0$, one can choose $\gamma=\gamma(R,C)>0$ for which the fixed-row ensemble with $t=\lceil\gamma\log N\rceil$ satisfies
    \[
    \mathbb{P}\!\left[
    \min_{x\in\mathbb{F}_q^{\lfloor RN\rfloor}\setminus\{0\}}
    \operatorname{wt}(xEA)
    \le \delta_R N
    \right]
    \le N^{-C}
    \]
    for all sufficiently large $N$. The same constants work for every prime power $q$; in particular, the field may vary arbitrarily with the block length. Thus, a single fixed-row-weight EA component is asymptotically good over all finite fields, and its polynomial reliability exponent can be made arbitrarily large by increasing the row-weight constant.
    The proof separates sparse and high-weight messages. Sparse messages are handled through expansion and a compact analysis of accumulator cancellations, while high-weight messages are controlled by a surplus of linear constraints over large fields and a stochastic accumulator analysis over bounded fields. A terminal-boundary obstruction shows that, for $t=\Theta(\log N)$, inverse-polynomial failure is qualitatively optimal.
    ## 2026/1754
    * Title: SoK: Why Optimal Cryptographic Combiners Do Not Get Deployed: Security, Complexity, and Adoption of Hybrid KEMs
    * Authors: Merland Chrislain Chadrel BAFOUETILA, Anis BKAKRIA
    * [Permalink](https://eprint.iacr.org/2026/1754)
    * [Download](https://eprint.iacr.org/2026/1754.pdf)
    ### Abstract
    XtM (XOR-then-MAC) is provably optimal against quantum adversaries. As of March 2025, no production cryptographic library implements it. HKDF, with weaker security guarantees, is deployed in 91% of the 44 libraries we examined. This gap is not accidental.This Systematization of Knowledge (SoK) introduces the (A, P, -a) framework to explain it: A measures authentication strength, P measures IETF standardization maturity, and -a measures implementation complexity. To our knowledge, this is the first falsifiable, quantitative model predicting cryptographic adoption grounded in observable software engineering indicators. We apply this framework to seven combiner families and 44 cryptographic libraries, validate -a against measured integration LOC across 9 real-world repositories, and derive predictions verifiable by 2028.Our evidence suggests that implementation complexity is a first-order explanatory factor in cryptographic adoption. The most deployable construction is not the most secure one in isolation: it is the most secure one engineers can integrate, audit, and maintain at scale.
    ## 2026/1755
    * Title: QuaILLL: Quaternion Ideal LLL and BKZ
    * Authors: Joshua Limbrey, Cong Ling, Christian Porter
    * [Permalink](https://eprint.iacr.org/2026/1755)
    * [Download](https://eprint.iacr.org/2026/1755.pdf)
    ### Abstract
    The current state of the art for cryptanalysis generic rank-2 module LIP schemes invokes an SVP oracle on the canonical real embedding, discarding the quaternionic structure made available by the reduction of rank-2 module LIP to the reduced-norm Principal Ideal Problem (nrd-PIP) over quaternion algebras (we note, that since writing, this is no longer the case for certain instances, such as Hawk). We address this gap by giving, to our knowledge, the first lattice reduction algorithms over quaternion rings applied in a cryptographic setting, and the first description of quaternion BKZ. We extend the celebrated LLL algorithm to leverage algebraic properties of quaternion orders and novel post-processing steps to design an LLL algorithm for lattices in not-necessarily-maximal orders. The strategy is to reduce over the Euclidean overlattice and then post-process, giving two routines: one returning a basis of a sublattice with the best bounds, the other a true basis of the original lattice at the cost of output quality. We further consider blocksize two BKZ as a generalisation of the LLL algorithm, and then extend this to arbitrary blocksize; utilising results on the shortness of Gauss and HKZ reduced bases and the relationship of successive minima for our specific sublattice. We then apply these algorithms to ideal lattices arising from nrd-PIP, including those instances given by rank-2 MLIP over cyclotomic fields such as Hawk, via a modification of the canonical embedding that preserves both dimension and quaternionic structure. This allows us to reduce a lattice basis of rank a constant factor of four smaller than the standard real embedding, improving basis bounds and asymptotic complexity in the generic setting.
    ## 2026/1756
    * Title: Fully Homomorphic Encryption with Chosen-Ciphertext Security from LWE * Authors: Rupeng Yang, Zuoxia Yu, Willy Susilo
    * [Permalink](https://eprint.iacr.org/2026/1756)
    * [Download](https://eprint.iacr.org/2026/1756.pdf)
    ### Abstract
    We construct (1-hop) fully homomorphic encryption (FHE) schemes with chosen-ciphertext (CCA) security from the learning with errors (LWE) assumption in the standard model. Security of our construction only relies on the circular-secure LWE, which matches the assumptions needed for FHE with the basic chosen-plaintext security. Besides, the scheme achieves a security notion that is strictly stronger than the CCA1 security. Prior FHE schemes with even just CCA1 security require either the random oracle model or non-falsifiable assumptions.
    The construction follows the well-known Naor-Yung double encryption paradigm. However, unlike previous works [Boneh et al., ITCS 2012; Canetti et al., PKC 2017; Manulis and Nguyen, Eurocrypt 2024], which employ general zero-knowledge succinct non-interactive arguments of knowledge (ZK-SNARKs), we design a special succinct argument to prove the validity of FHE ciphertexts. The succinct argument is constructed from batch arguments for NP and a new primitive called predicate extractable commitment, which may be of independent interest.
    ## 2026/1757
    * Title: Enabling Threshold Custody for the Lightning Network with Nested Threshold Multi-Signatures
    * Authors: Paul Gerhart, Nadav Kohen, Jesse Posner, Matias Furszyfer
    * [Permalink](https://eprint.iacr.org/2026/1757)
    * [Download](https://eprint.iacr.org/2026/1757.pdf)
    ### Abstract
    The Bitcoin Lightning Network secures hundreds of millions of dollars, yet channel endpoints rely on vulnerable single online keys.
    Although threshold signatures are routinely used to protect on-chain Bitcoin, no practical deployment has been possible for Lightning channels.
    This is because thresholdizing a Lightning party requires nesting a threshold signature scheme inside of an established two-party MuSig2 protocol without altering its nonce exchange or message flow.
    In this work, we resolve this limitation by formalizing nested threshold multi-signatures, a new cryptographic primitive for thresholdizing one participant inside a multi-signature protocol.
    As an instance of this primitive, we present Iceberg, the first construction for nested threshold MuSig2 signatures.
    Iceberg enables one side of a Lightning channel to operate as a $t$-of-$n$ threshold group while appearing to the counterparty as a standard MuSig2 participant.
    As a result, threshold custody can be deployed unilaterally on today's Lightning Network without requiring any modifications to Bitcoin, the Lightning protocol, or channel counterparties.
    We prove the security of Iceberg, integrate a prototype into a production Lightning node, and benchmark its performance.
    Our measurements show that thresholdizing a Lightning channel incurs only modest overhead, since a threshold group tolerating one corrupted member sustains over $93\%$ of the payment throughput of an unmodified endpoint.
    ## 2026/1758
    * Title: $\textsf{Sluice}$: Prove-Phase Bounded-Memory Groth16 via Read-Write Streaming
    * Authors: Kyeongtae Lee, Jihye Kim, Hyunok Oh
    * [Permalink](https://eprint.iacr.org/2026/1758)
    * [Download](https://eprint.iacr.org/2026/1758.pdf)
    ### Abstract
    We present $\textsf{Sluice}$, a read-write streaming Groth16 prover that reduces $\textit{prove-phase}$ random-access working memory from $\mathcal{O}(N)$ to $\mathcal{O}(\log N)$ once the CRS, QAP, and witness are materialized as private streams. It preserves the standard Groth16 interface: a proof of 3 group elements, 3-pairing verification, and unchanged verifier contracts.
    Our key technical contribution is $\textit{Split-Butterfly-Merge}$ ($\mathsf{SBM}$), an NTT algorithm in the read-write streaming model with $\mathcal{O}(\log N)$ memory, $\mathcal{O}(N \log N)$ total I/O, and $\mathcal{O}(\log N)$ sequential passes over external storage.
    Combining SBM with streaming sparse R1CS evaluation and chunked
    Pippenger MSM yields a verifier-compatible Groth16 proving path that
    exchanges RAM for sequential storage I/O and wall-clock time. Our
    prototype uses a fixed-window MSM engineering point; the measurements validate memory reduction and proof compatibility, while the theorem states the asymptotically tuned MSM schedule.
    We implement $\textsf{Sluice}$ over BN-254. Direct prove-only runs produce valid 128-byte proofs through $N=2^{25}$. The same-size bounded-memory comparison is at $N=2^{23}$: $\textsf{Sluice}$ succeeds under an 8GB Linux cgroup cap, whereas the standard prover is killed under 8GB and 12GB caps and succeeds only at 16GB. These results position $\textsf{Sluice}$ as a storage-rich, RAM-limited proving option rather than a replacement for optimized in-memory provers.
    ## 2026/1759
    * Title: Revisiting the Transferability of Chosen- to Known-plaintext Attacks and Applications to Round-reduced AES
    * Authors: Xiaomeng Sun, Eik List, Wenying Zhang
    * [Permalink](https://eprint.iacr.org/2026/1759)
    * [Download](https://eprint.iacr.org/2026/1759.pdf)
    ### Abstract
    Differential-based attacks represent the best known results for many block ciphers. Such attacks usually demand that the adversary an choose plaintexts (CP) or ciphertexts (CC) in subspaces to satisfy differential trails. However, many widespread modes of operation or applications prohibit the adversary from directly choosing inputs for the majority of primitive calls. While Biham and Shamir already suggested a straightforward trade-off for standard differential attacks in their work on the DES, studies on advanced differential-based types, such as impossible-differential, rectangle, or mixture attacks, have surprisingly received little attention so far.
    In this work, we study applications of differential-based attacks in the random known-plaintext model (RKP) of the above. For the AES as the probably most widespread block cipher, we derive the best existing distinguishers and attacks in the RKP model on all versions, improving earlier results by at least one round. Interestingly, we show that Demirci-Selcuk meet-in-the-middle attacks with differential enumeration, which require much related data, can also be effective in that setting without approaching the full codebook too closely. For several of our attacks, we showcase differences between the models as trails that lead to the best known attack complexities under chosen data are suboptimal in the RKP model, and can be replaced by better trails. While our results do not threaten the security of the full AES, and their complexities are too high to represent any threats, we hope to inspire cryptographers to also consider attacks in the RKP for future attacks.
    ## 2026/1760
    * Title: Midpoint Reset: A Full-Round Poseidon Collision from an Adaptively Chosen MDS Matrix
    * Authors: Sunghyeon Jo
    * [Permalink](https://eprint.iacr.org/2026/1760)
    * [Download](https://eprint.iacr.org/2026/1760.pdf)
    ### Abstract
    We give an explicit compression collision for all 28 rounds of the KoalaBear Poseidon instance with parameters $(t,\alpha,R_F,R_P)=(16,3,8,20)$, in the setting where the round constants are fixed before the MDS linear layer is chosen. The main problem is to construct a single linear layer that simultaneously controls two executions through both the full and partial rounds. We do this by tracking their midpoint and half-difference. In each two-round block, one prescribed image of the linear layer cancels the midpoint against the next round constant, so the following odd cubic S-box receives opposite states and resets the midpoint to zero. Two additional images are reused throughout the permutation to return the half-difference to the same one-dimensional subspace. The resulting trajectory constraints determine a linear layer, while a scalar recurrence closes the final difference under feed-forward. For the KoalaBear instance we obtain a collision in all sixteen output coordinates with an MDS matrix satisfying the prescribed linear-layer checks. The scalar construction reduces to low-degree equations and admits a family of parameter choices, so the collision is not an isolated instance. The result exposes an adaptive correlation between fixed round constants and a subsequently chosen linear layer that matrix-only checks do not capture.
    ## 2026/1761
    * Title: Lightweight Lattice-based Single-Party Public-Key Authenticated Key Exchange
    * Authors: Alex A|>dan, S|-bastien Canard, Emmanuel Fouotsa, Nyiang Melchisedech Mbeng
    * [Permalink](https://eprint.iacr.org/2026/1761)
    * [Download](https://eprint.iacr.org/2026/1761.pdf)
    ### Abstract
    Authenticated Key Exchange (AKE) is a cornerstone of secure communication, especially in resource-constrained IoT environments where lightweight and post-quantum security are paramount. While lattice-based cryptography offers promising solutions, existing post-quantum AKE protocols often prioritize strong security notions, such as the use of an IND-CCA encryption scheme, incurring overheads incompatible with IoT devices. This raises a critical question: Can one-way security (OW), a weaker but potentially more efficient notion, suffice for secure AKE in the post-quantum era? We address this challenge by revisiting the ALIKE framework (ISO/IEC 29192-4), which achieves OW-CCA-based AKE using deterministic RSA. However, RSArCOs quantum vulnerability and the lack of lattice-based OW-CCA schemes hinder its applicability today. Our work bridges this gap through three key contributions. First, we prove that the Hash-Before-Encrypt (HBE) paradigm generically transforms deterministic OW-CPA schemes into OW-CCA-secure ones. We additionally present the FujisakirCoOkamoto transform and its security proof construction, providing a reference for understanding the efficiency advantages of the proposed HBE-based approach. Second, we modify Bai et al.rCOs efficient lattice-based OW-CPA scheme to a deterministic variant and rigorously prove its security. Third, we generalize the SPAKE framework to support our OW-CCA construction, enabling post-quantum AKE with minimal assumptions, implement and benchmark the resulting protocol, demonstrating state-of-the-art efficiency for lightweight, quantum-resistant AKE. By relaxing security requirements from IND-CCA to OW-CCA while preserving adaptive security we achieve a practical balance between robustness and performance, paving the way for deployable solutions in constrained environments like IoT and connected vehicles.
    ## 2026/1762
    * Title: Pilaf: Fully Tight Two-Round Threshold Signatures with Adaptive Corruptions
    * Authors: Chen Qian, Xingyu Zhao, Hao Cheng, Zengpeng Li, Puwen Wei, Quan Yuan * [Permalink](https://eprint.iacr.org/2026/1762)
    * [Download](https://eprint.iacr.org/2026/1762.pdf)
    ### Abstract
    Threshold signatures are deployed in settings where an adversary may run many
    concurrent signing sessions and corrupt signers adaptively. Two-round schemes
    make this especially delicate. Their first-round messages are independent of
    the signed message and can be preprocessed offline, so a later corruption must
    reveal randomness that is consistent with commitments already published in
    prior transcripts. Existing adaptive constructions address this tension by
    adding rounds, relying on algebraic or knowledge assumptions, or paying
    non-tight losses from guessing the corruption pattern, the decisive session, or
    the final transcript.
    We construct $\mathsf{TPilaf}$, the first two-round threshold signature scheme that
    combines partially non-interactive signing with a fully tight proof against
    adaptive corruptions. The scheme is pairing-free and is built in prime-order
    groups from the $\mathsf{MDDH}$ assumption in the random-oracle model. Its first-round
    messages can be generated offline, and any threshold set of signers can
    aggregate their second-round shares into a single publicly verifiable
    signature.
    The proof combines two ingredients. First, we introduce a linearly homomorphic
    dual-mode commitment with targetable opening. This lets the simulator open an
    already fixed commitment to the aggregate target imposed by a later
    Fiat-Shamir challenge. Second, we use profile-wise zero-sum masking with
    posterior completion. Corruption openings and signing responses are therefore
    sampled from the exact conditional law while values already visible to the
    adversary remain cached. Together, these tools enable a delayed
    branch-decision argument. The reduction waits until the adversary's own
    queries determine the last touched coordinate, completes only latent state, and
    then binds the forged hidden branch. The final bound has no combinatorial loss
    in the number of users, threshold, sessions, or corruption patterns, and
    contains only the explicit bad-event and assumption terms appearing in the
    theorem.
    ## 2026/1763
    * Title: Multidimensional Hill Cipher SubstitutionrCo Permutation Network
    * Authors: Porter E. Coggins, III
    * [Permalink](https://eprint.iacr.org/2026/1763)
    * [Download](https://eprint.iacr.org/2026/1763.pdf)
    ### Abstract
    MD-Hill-SPN is the first Hill-based construction to combine a multi-tier diffusion mix
    layer, a memory-hard KDF, and a simultaneous multi-metric empirical evaluation. Two
    independent runs of the full metric suite yield: (a) full plaintext avalanche from round 1
    (mean 63.97rCo64.67 of 128 bits, ideal 64); (b) the differential-probability sampling floor of 2
    |u 10reA5 reached at round 4 (50,000 of 50,000 output differences distinct, both sessions); (c)
    algebraic-degree lower-bound saturation at the maximum observable value from round
    1; (d) linear-bias indistinguishable from random (combined exceedance 4.40%, below the
    4.55% noise floor); and (e) branch numbers at the Singleton (MDS) bound for every tier (B
    = 5 for 4 |u 4, B = 9 for 8 |u 8, B = 17 for 16 |u 16), computed exhaustively over weight-1 inputs.
    MD-Hill-SPN therefore moves beyond theoretical construction to a construction that
    passes a defined empirical evaluation suite: avalanche, differential sampling, linear-bias
    probing, algebraic-degree lower bounds, and MDS branch numbers under single-key,
    known-plaintext conditions with fixed parameters, an evaluation no prior Hill cipher variant
    has reported in full.
    ## 2026/1764
    * Title: Two Novel Multidimensional Affine Variations of the Hill Cipher
    * Authors: Porter Eldridge Coggins
    * [Permalink](https://eprint.iacr.org/2026/1764)
    * [Download](https://eprint.iacr.org/2026/1764.pdf)
    ### Abstract
    Two novel symmetric multidimensional affine nested variations of the Hill Cipher are presented. The Hill Cipher is a block
    polygraphic substitution encryption scheme based on a linear transformation of plaintext characters into ciphertext characters. In
    the time since Hill first published his encryption scheme, variations, modifications, and improvements of theoretical and
    practical importance have been published every year indicating that the Hill Cipher is an active area of cryptography research.
    The first variation presented in this paper incorporated invertible key matrices of orders 2, 4, and 8 such that the matrix values of
    the 2|u2 matrix rotate positions with each block of characters in a similar manner to the rotating letter wheels of a German
    Enigma Encoder, then results of the 2|u2 key matrices output are passed to 4|u4 key matrices, and 8x8 key matrix, 4|u4 key
    matrices, and rotative-value 2|u2 key matrices. The second variation is configured with invertible key matrices of orders 4, 8, and
    16 without rotation of matrix values in a similar manner to the first variation. In both variations, plaintext characters of each block
    are operated on by exclusive-or (XOR) vectors prior to multiplication with the matrices to create the affine ciphers. Strengths,
    weaknesses, and other considerations are provided in the discussion. Two proposals are also argued with rationale for a more
    robust character set for encryption and the increase in modulus that the character set allows, and the possible advantages and
    disadvantages of affine XOR vectors.
    ## 2026/1765
    * Title: Exact linear correlations and the cost of Walsh-transform key recovery, with application to SPEEDY
    * Authors: Guoqiang Liu, Bing Sun
    * [Permalink](https://eprint.iacr.org/2026/1765)
    * [Download](https://eprint.iacr.org/2026/1765.pdf)
    ### Abstract
    When two S-box layers of a round are separated by no key addition, the round correlation is a signed sum over all compatible intermediate masks, not a product
    of layer correlations, so the product rule can fail in either direction. Our central finding is that evaluating this intra-round sum exactly changes the assessment of the published linear cryptanalysis of SPEEDY, whose two S-box layers are separated only by ShiftColumns. We first develop the linear cryptanalysis of this setting: an exact one-round algorithm with a decidable exactness condition for the product rule, a dependency-graph decomposition, a covering-number bound strengthening linear-trail weight bounds, and a Walsh-support criterion in which the affine dimension of that support, limited by
    the endpoint key masks, fixes the key-recovery transform cost. Potentials use the
    independent-round-key model; complexities are in equivalent encryptions. Applied
    to SPEEDY, these tools revise published results: a reported five-round mask sequence has exact correlation $2^{-90.0962}$, not $2^{-93.0147}$; the new bound
    raises the unrestricted five-round weight bound from $53.7714$ to $62.2616$ bits;
    and the full-round attack on SPEEDY-7-192 reported at time $2^{158.06}$ needs at
    least $2^{199.97}$ encryptions in the pruning class considered. For SPEEDY-6-192
    we give a six-round known-plaintext attack (data $2^{169.84}$, time $2^{170.20}$,
    memory $2^{156}$) and show that the attack class defined here contains no attack
    with data and time both at most $2^{128}$, its time being at least $2^{136.302}$.
    The same exact evaluation also revises a four-round differential-linear correlation.
    ## 2026/1766
    * Title: Eavesdropper-Blind Remote State Preparation and Applications to Quantum Public-Key Encryption
    * Authors: Kaniuar Bacho, Alexandru Cojocaru
    * [Permalink](https://eprint.iacr.org/2026/1766)
    * [Download](https://eprint.iacr.org/2026/1766.pdf)
    ### Abstract
    Remote state preparation (RSP) is a central primitive in quantum cryptography, enabling classical parties to remotely construct quantum states using only classical communication. As a result, RSP serves as a key building block in numerous protocols involving classical clients and quantum servers, allowing classical parties to leverage the advantages offered by powerful quantum computers. All known constructions of RSP rely on strong cryptographic assumptions, typically variants of trapdoor claw-free functions (TCFs).
    In this work, we initiate the study of a weaker form of remote state preparation, which we call eavesdropper-blind remote state preparation (EB-RSP). Informally, EB-RSP requires blindness only against external observers who see the transcript of the honest protocol, rather than against the quantum server itself. Despite this relaxed adversarial model, the resulting notion remains sufficient for useful cryptographic applications. In particular, we show that two-message EB-RSP already suffices to construct quantum public-key encryption with classical public keys and quantum ciphertexts. We then construct two-message EB-RSP protocols from specific one-way group actions, yielding a first step toward RSP-type primitives based on assumptions that do not rely on trapdoors. Finally, we observe that existing RSP constructions are likely naturally adaptable to the two-message EB-RSP notion; we demonstrate this explicitly for a concrete TCF-based RSP construction.
    ## 2026/1767
    * Title: Circle-Linear Cryptanalysis: Bibrace Characters and Weak-Key Linear Distinguishers for CRAFT
    * Authors: Roberto Civino
    * [Permalink](https://eprint.iacr.org/2026/1767)
    * [Download](https://eprint.iacr.org/2026/1767.pdf)
    ### Abstract
    Linear cryptanalysis measures the correlation of a cipher with the characters of the group used to define differences. If that group is replaced by a second elementary abelian group structure on the same set, here the one coming from a binary bibrace, then the admissible masks are no longer the ordinary scalar products: exactly half of them survive, and the other half are forced to be quadratic. BeynerCOs geometric approach develops linear cryptanalysis over an arbitrary finite abelian group, providing a natural framework for this setting. We instantiate it on the group of a particular bibrace and apply it to Craft.
    Over this group the Midori/Craft S-box has four probability-one relations, forming a small subgroup of the dual which the S-box preserves in both directions. Inside that subgroup a mask propagates deterministically and linearly, so the search for the best trail is a minimum weight codeword problem, which we solve exactly by complete enumeration rather than heuristically.
    A trail costs correlation, and it restricts the key to a weak-key class. The two are usually derived from the same data. We show that the correct reading, obtained by analysing the diffusion layer and the key addition together rather than separately, gives a class several bits larger than the one obtained cell by cell. One concrete consequence is that CraftrCOs round constants, whatever their values, impose no restriction at all.
    On Craft we obtain weak-key distinguishers up to eighteen rounds. At fourteen rounds the squared correlation is 2reA44 over a class of 2^108 keys, against 2reA62.12 for the designersrCO linear hull, which is the best known linear result on the cipher and holds for all keys. On that class we therefore improve the best linear correlation by eighteen bits at equal round count, and we reach four rounds further than the best known linear hull. Both the distinguishers and the weak-key criterion are verified experimentally, with a negative control on random keys.
    ## 2026/1768
    * Title: Constant-round MPC protocols with Fall-back Security
    * Authors: Anasuya Acharya, Aditya Patankar, Arpita Patra, Divya Ravi, Raghavendra Vernekar
    * [Permalink](https://eprint.iacr.org/2026/1768)
    * [Download](https://eprint.iacr.org/2026/1768.pdf)
    ### Abstract
    The notion of Best-of-Both-Worlds introduced in the work of Ishai et al. (CRYPTO 2006) investigated whether an MPC protocol can simultaneously provide two incomparable security guarantees depending on the number of corrupted parties. As a special case of this, Chaum et al. initiated the study of protocols that tolerate unbounded corruption within a certain adversary structure and PPT corruption of any number of parties beyond that. More recently, Acharya et al. (CRYPTO 2023) formalized this notion as MPC with fall-back security. Although the feasibility of such protocols has now been thoroughly studied in prior works, most of the existing protocols require round complexity linear in the number of parties and the computation size.
    In this work, we study the round complexity of MPC with fall-back security in the threshold corruption setting, presenting constant-round protocols for optimal thresholds. We present a semi-honest fall-back secure protocol for $t < \frac{n}{2}$ with 3 rounds, in the plain model, whereas the best known protocol in the same setting takes at least 11 rounds. In the CRS model, we present a maliciously fall-back secure protocol for the same threshold with 4 rounds, satisfying unanimous abort (UA). Finally, we extend this to a 5-round protocol that satisfies fairness in the presence of unbounded adversaries for $t < \frac{n}{2}$ corruptions and UA tolerating PPT adversaries for arbitrary corruption beyond that. In the malicious setting, we construct the first constant-round fall-back secure protocols.
    ## 2026/1769
    * Title: Rank Measures and Exponential Lower Bounds for Multilinear Secret Sharing
    * Authors: Shahram Khazaei
    * [Permalink](https://eprint.iacr.org/2026/1769)
    * [Download](https://eprint.iacr.org/2026/1769.pdf)
    ### Abstract
    A multilinear secret-sharing scheme shares a vector secret and can therefore amortize share size over the secret dimension. This amortization can invalidate lower bounds proved for one-dimensional linear schemes, and the best previous explicit lower bound for multilinear schemes was quasipolynomial, $n^{\Omega(\log n)}$. We prove that the Razborov--G\'al rank measure survives amortization: the normalized size of a multi-target monotone span program is at least the rank measure of the function it computes. Combined with the rank witnesses of Pitassi and Robere, this gives an explicit family of access structures for which every perfect multilinear scheme over every finite field has average and maximum information ratio $2^{\Omega(n)}$. The worst-case multilinear
    information ratio is therefore $2^{\Theta(n)}$, answering a question of Beimel. We further extend the bound to schemes whose sharing algorithm is arbitrary and whose reconstruction is affine-linear, under pairwise statistical privacy below one; combined with the degree-reduction theorem of Beimel, Othman, and Peter, this yields exponential normalized lower bounds for every fixed reconstruction degree whenever the secret dimension is $2^{o(n)}$.
    ## 2026/1770
    * Title: How Many Traces Suffice? PAC Guarantees for Profiled and Non-profiled Side-Channel Analysis
    * Authors: Seyedmohammad Nouraniboosjin, Fatemeh Ganji
    * [Permalink](https://eprint.iacr.org/2026/1770)
    * [Download](https://eprint.iacr.org/2026/1770.pdf)
    ### Abstract
    Side-channel analysis (SCA) is commonly evaluated by reporting the number of traces required to reduce the rank of the correct key. Still, such evaluations remain empirical and do not explain how many traces suffice for reliable recovery, how profiling and attack data contribute separately, or when additional traces cannot overcome weak key distinguishability. We address these questions through a Probably Approximately Correct (PAC) formulation of profiled and non-profiled SCA. Our framework treats candidate-key scores as the common cryptanalytic object and separates finite-sample estimation from the intrinsic separation between the correct key and competing hypotheses. This distinction enables confidence guarantees for key rank and helps determine whether an attack failure is due to insufficient data or an inherently weak attack score. We instantiate the framework with representative profiled and non-profiled attacks chosen for their analytical tractability. Experiments on ASCAD-f and ASCAD-r show that this analytical tractability does not come at the cost of impractical attack performance. The profiled attack achieves exact recovery with tens of attack traces, whereas the non-profiled single-attack rank certificate guarantees exact recovery with about 1,000 traces. These results are competitive with recent ASCAD attacks and, in the non-profiled setting, substantially below the smallest trace counts identified in prior studies, while additionally providing finite-sample guarantees on key rank. More generally, the same finite-sample rank analysis can be adapted to other learners and distinguishers by deriving the corresponding score-gap guarantees. Overall, the framework turns trace complexity from an empirical attack observation into a reusable finite-sample criterion for key recovery.
    ## 2026/1771
    * Title: New Lower Bounds for Rows of $d$-Disjunct Matrices via Recursive Potentials
    * Authors: Xiaopeng Zhao
    * [Permalink](https://eprint.iacr.org/2026/1771)
    * [Download](https://eprint.iacr.org/2026/1771.pdf)
    ### Abstract
    In nonadaptive combinatorial group testing, given $n$ items with at most $d$ positives, the goal is to identify them using as few pooled tests as possible. A $t\times n$ binary matrix represents the design, where rows are tests and columns are items. The matrix is $d$-disjunct if no column is contained in the Boolean union of any $d$ others. Let $T(d)$ be the minimum $t$ for which such a matrix exists with $n>t$. Shangguan and Ge proved $T(d)\ge \frac{15+\sqrt{33}}{24}d^2$ by counting private pairs (IEEE Trans. Inf. Theory, 62(12):7518-7521, 2016). In this paper, we strengthen their argument by introducing a column-deletion recurrence in which the light-heavy threshold varies with the recursive state $z=(n-t)/d^2$, rather than remaining fixed. This yields the improved bound $T(d)\ge 0.9283d^2-O(d)$. The analytic core reduces to a first-order ODE, and a self-contained interval-arithmetic certificate verifies that the solution reaches the required contact point.
    ## 2026/1772
    * Title: Multi-PGBF: Efficient Oblivious Key-Value Store and Application to Private Set Intersection
    * Authors: Mingli Wu, Tsz Hon Yuen, Man Ho Au, Siu-Ming Yiu
    * [Permalink](https://eprint.iacr.org/2026/1772)
    * [Download](https://eprint.iacr.org/2026/1772.pdf)
    ### Abstract
    An oblivious key-value store is a data structure that can encode and decode $n$ key-value pairs in a table of size $m$ obliviously. After encoding, one cannot distinguish the encoded key-value pairs from other key-value pairs in the input domain. In this paper, we first propose a data structure called Peelable Garbled Bloom Filter (PGBF), which encodes the key-value pairs in a similar way to peeling and unpeeling an \emph{onion}. Specifically, it can divide the key-value pair set (i.e., onion) as multiple subsets (i.e., peels) and order them from the outermost peel to the innermost peel by using a counting Bloom filter. However, using a small expansion rate (i.e., $\eta=m/n$) in PGBF will result in a non-empty core issue with non-negligible probability. To handle this issue, we propose Multi-PGBF by combining multiple PGBFs to do the peelings and unpeelings recursively. In addition, we propose a variant C-Multi-PGBF by clustering a large set into small sets to achieve faster encoding efficiency.
    Our experiments show that Multi-PGBF and C-Multi-PGBF obtain the best encoding and decoding efficiency. Multi-PGBF improves the encoding time of RR (CCSrCO22) by $65.1\%\sim 77.6\%$, while C-Multi-PGBF improves the encoding time of the clustered RR variant by $60.2\%\sim 64.7\%$. For decoding, Multi-PGBF is $28.6\%\sim 62.4\%$ faster than RR (CCS'22) and $89.7\%\sim 96.3\%$ faster than RB-OKVS (Usenix'23). When integrated into the state-of-the-art two-party and multi-party private set intersection protocols (Eurocrypt'21, Usenix'24), Multi-PGBF and C-Multi-PGBF lead to faster protocols than those using existing OKVS constructions in most settings.
    ## 2026/1773
    * Title: Enforcing Winner-Only Disclosure: Verifiable Tally Hiding for Weighted DAO Governance
    * Authors: Jiayu Li, Gongli Li
    * [Permalink](https://eprint.iacr.org/2026/1773)
    * [Download](https://eprint.iacr.org/2026/1773.pdf)
    ### Abstract
    Token-weighted voting is widely used in DAO governance, but public voting weights together with weighted tallies can reveal identifiable voters' choices. Publishing only the final outcome reduces this disclosure, yet an output policy alone does not prevent a privileged participant from reconstructing the exact weighted tally during computation.
    We present a verifiable winner-only tally-hiding construction for weighted binary voting. Registered weights are bound to credentials in zero-knowledge ballots, while weighted contributions remain encrypted through aggregation and comparison against a public threshold. The blockchain adjudicates ballots, an off-chain backend performs the encrypted computation, and exact ciphertext and transcript bindings allow any public verifier to check that the published outcome corresponds to the accepted ballots. The only tally-derived plaintext output is the outcome bit.
    The construction is parameterized by electorate size and contribution width; our prototype and formal transcript-privacy result deliberately study a bounded eight-voter, eight-bit instance with 134 encrypted gates and an actual three-of-five final release. For honest execution by all five trustees, we prove passive-public-observer backend transcript privacy from the accepted ciphertexts and outcome alone. Privacy against malicious sub-threshold trustees remains open.
    --- Synchronet 3.22a-Linux NewsLink 1.2