D-James: Ultra Short Multivariate Signatures
Multivariate signature schemes are among the few post-quantum candidates capable of providing very short signatures, but designing secure constructions has proven challenging. HFE-based schemes such as...
View ArticleQuasipolynomial Cryptanalysis of the McEliece Cryptosystem (or: PIR Meets...
The McEliece code-based cryptosystem, utilizing binary Goppa codes, is the earliest public-key encryption scheme that is still considered post-quantum secure. We present a simple, classical...
View ArticleALFOMs and the Moirai: Quantifying the Performance/Security Tradeoff for...
Zero-Knowledge (ZK) protocols rely internally on hash functions for their security arguments. However, the hash functions that are the most efficient in this context differ substantially from e.g....
View ArticleCorrecting the modulus switch error in TFHE bootstrapping for real-valued...
Torus Fully Homomorphic Encryption (TFHE) enables the homomorphic evaluation of arbitrary functions via Programmable Bootstrapping (PBS). However, the modulus switching step inherent to bootstrapping...
View ArticleSecure Auctions in the Presence of Rational Adversaries
Sealed bid auctions are used to allocate a resource among a set of interested parties. Traditionally, auctions need the presence of a trusted auctioneer to whom the bidders provide their private bid...
View ArticleCode Generation of Faster Formally Verified NTT with Plantard Reduction
We present a formally verified implementation of the ML-KEM Number-Theoretic Transform (NTT) based on Plantard arithmetic, produced via a code generator that targets ML-KEM, ML-DSA, and FN-DSA from a...
View ArticleOn the BUFF Security of ECDSA with Key Recovery
In the usual syntax of digital signatures, the verification algorithm takes a verification key in addition to a signature and a message, whereas in ECDSA with key recovery, which is used in Ethereum,...
View ArticleSecure Cloud Storage: Modularization, Network Adversaries and Adaptive...
End-to-end cloud storage solutions are deployed at large scale, yet recent works have demonstrated severe attacks against their confidentiality and integrity. Motivated by this, a first formal...
View ArticleIcefish: Practical zk-SNARKs for Verifiable Genomics
Individual genomic data is a uniquely sensitive type of user data. While many papers have considered using Multi-Party Computation (MPC) or Fully Homomorphic Encryption (FHE) to allow collaborators to...
View ArticleGeneralized Greedy Algorithms for Synthesizing Low-depth CNOT Circuits
A CNOT circuit is a quantum circuit where the only type of gate appeared in the circuit is the CNOT gate. Given an n × n binary matrix which specifies the relationship between input and output,...
View ArticleHigh-Precision Lewis Weights via Fourth-Moment Control and Local Bregman...
We study the high-precision computation of $\ell_p$-Lewis weights for $p\ge4$ in the black-box exact-real full-vector leverage-score oracle model, measuring complexity by the number of adaptive oracle...
View ArticleUdMAC: Efficiently Updatable Message Authentication Codes
Message authentication codes (MAC) are ubiquitous and are considered to be the most important tool employed to ensure authenticity of messages in the symmetric key setting. In this work, we aim to...
View ArticleOn Removing Interaction from Quantum Proofs
An important open question in quantum cryptography is the construction of publicly-verifiable NIZKs for QMA. Classically, one can construct NIZKs for NP in the random oracle model (and sometimes in the...
View ArticleIdeal Secret Sharing Schemes over Small Domains
In any secret sharing scheme, the size of each share must be at least as large as the size of the secret. Schemes that attain this lower bound are called $k$-ideal, where $k$ is the size of the domain...
View ArticleExact CVP Is NP-Complete for Principal Cyclotomic Ideals
We prove that exact Euclidean decision-CVP is $\mathsf{NP}$-complete on the coefficient lattices of nonzero principal ideals in the power-of-two cyclotomic rings $R_d=\mathbb{Z}[y]/(y^d+1)$. A...
View ArticleSigning-Key Recovery from Unsalted Root Expansion and Salt-Binding Repair for...
We give the first passive classical EUF-CMA attack on MQOM v2 in which an optimal three-record parity-indexed XOR triangle detects every usable collision, recovers the complete signing key, and...
View ArticleOn the CCA security properties (and more) of a new variant of Paillier-ElGamal
We solve the long-standing open question of designing a "truly" linearly homomorphic scheme -- meaning it supports homomorphic additions on arbitrary plaintexts, with no restriction, in contrast to...
View ArticleSoK: Secure Computation over Secret Shares
Secure multiparty computation (MPC) enables mutually distrustful parties to jointly compute functions over private data without revealing their inputs. A central paradigm in MPC is the...
View ArticlePrivacy Coins Under Viewing Key Compromise
Anonymity guarantees of privacy-oriented cryptocurrencies are garnering negative attention from lawmakers who view them as antinomic to accountability. Having recognized their potential for innovation,...
View ArticleTrace-Moment Canonicalization for Average-Case Matrix Code Conjugacy
Matrix Code Conjugacy asks whether two matrix subspaces are related by one simultaneous change of basis. A recent average-case algorithm reaches a $\Theta(1/q)$ fraction when the code dimension equals...
View Article