Next Issue
Volume 10, August
Previous Issue
Volume 10, April
 
 

Cryptography, Volume 10, Issue 3 (June 2026) – 15 articles

Cover Story (view full-size image): This paper presents a space-efficient secret sharing scheme that leverages matrix normal forms to reduce share sizes while providing computational security. Embedded within an online architecture comprising authenticated public data and secure private shares, the scheme first improves upon an existing probabilistic matrix-based method by proving that its cyclic vector algorithm runs in polynomial time. A novel deterministic method based on the Frobenius canonical form is then introduced and analyzed, eliminating the need for cyclic vectors. The scheme is secure under a well-defined adversary model and has been implemented in Maple as an open-source project. Performance evaluation demonstrates that matrix normal forms can provide a practical framework for space-efficient secret sharing. View this paper
  • Issues are regarded as officially published after their release is announced to the table of contents alert mailing list.
  • You may sign up for e-mail alerts to receive table of contents of newly released issues.
  • PDF is the official format for papers published in both, html and pdf forms. To view the papers in pdf format, click on the "PDF Full-text" link, and use the free Adobe Reader to open them.
Order results
Result details
Section
Select all
Export citation of selected articles as:
17 pages, 1217 KB  
Article
ParaSM2: Enhancing SM2 Cryptographic Performance via Parallel Restructuring of KDF and HASH
by Hongjuan Kang, Bing Guo, Yufang Sun, Mingjie Zhao, Xin Chen and Kui Ye
Cryptography 2026, 10(3), 42; https://doi.org/10.3390/cryptography10030042 - 22 Jun 2026
Viewed by 285
Abstract
In the past decade, the high computational overhead of asymmetric cryptography has remained a central challenge in end-to-end secure communication systems. To mitigate the performance bottlenecks inherent in the full SM2 encryption and decryption workflow, this paper introduces ParaSM2, a parallel restructuring optimization [...] Read more.
In the past decade, the high computational overhead of asymmetric cryptography has remained a central challenge in end-to-end secure communication systems. To mitigate the performance bottlenecks inherent in the full SM2 encryption and decryption workflow, this paper introduces ParaSM2, a parallel restructuring optimization framework tailored for SM2-based cryptographic operations. ParaSM2 exploits the observed 2:1 processing ratio between KDF and HASH to perform cross-component parallel restructuring and applies fixed-prefix reuse together with dynamic task parallelism to eliminate 39.7% of redundant KDF computations. Furthermore, a vectorized reconstruction of the HASH message extension is incorporated to leverage SIMD parallel acceleration, thereby substantially enhancing throughput. Experimental evaluations against SM4-GCM and SM4-CBC on data blocks larger than 64 KB demonstrate that ParaSM2 achieves up to a 5.1× performance improvement on both x86 and ARM architectures, effectively reducing end-to-end latency and providing a scalable pathway for algorithmic optimization in cryptography across heterogeneous platforms. Full article
Show Figures

Figure 1

34 pages, 2143 KB  
Hypothesis
Mythos-Class Frontier Models and the Compression of Post-Quantum Cryptography Migration Timelines
by Robert Campbell
Cryptography 2026, 10(3), 41; https://doi.org/10.3390/cryptography10030041 - 18 Jun 2026
Viewed by 832
Abstract
Post-Quantum Cryptography (PQC) migration to National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) 203, 204, and 205 under the National Security Agency (NSA) Commercial National Security Algorithm Suite (CNSA) 2.0 is a multi-year, multi-domain transformation across cloud, enterprise, embedded, [...] Read more.
Post-Quantum Cryptography (PQC) migration to National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) 203, 204, and 205 under the National Security Agency (NSA) Commercial National Security Algorithm Suite (CNSA) 2.0 is a multi-year, multi-domain transformation across cloud, enterprise, embedded, operational technology (OT), tactical, and national-security systems. Anthropic’s Claude Mythos Preview (April 2026) introduces artificial intelligence (AI)-accelerated cybersecurity capabilities that intersect this migration directly, performing autonomous reasoning against previously unknown vulnerabilities in production software—a qualitative departure from signature-based and static and dynamic application security testing (SAST/DAST) tooling. Drawing on federal guidance from NIST, NSA, the Office of Management and Budget (OMB), and the Cybersecurity and Infrastructure Security Agency (CISA), and on independent analyses from the Centre for Emerging Technology and Security (CETaS) and the UK AI Security Institute, we present a lifecycle and architecture analysis of how Mythos-class models alter PQC migration timelines, risk surfaces, lifecycle dependencies, and architectural constraints. Modeling Mythos as both accelerator and destabilizer, we derive an analytic projection of a compressed two-to-four-year migration window for highest-exposure systems, against traditional baselines of five-to-ten years for small organizations and twelve-to-fifteen-plus years for large enterprises. The compression collapses human-labor bottlenecks in discovery, planning, and code modification, not cryptography itself. We propose a lifecycle-aligned migration model, an updated cost model, and governance requirements for frontier-model access. The binding constraint shifts domain-conditionally: defender capacity at adversary tempo governs software-analytical phases, while non-compressible external cadence governs embedded and regulated domains. Full article
Show Figures

Figure 1

20 pages, 370 KB  
Article
A Hybrid Attack on Small Private Exponent RSA via Continued Fractions and Lattices
by Mengce Zheng, Yansong Feng, Abderrahmane Nitaj and Yanbin Pan
Cryptography 2026, 10(3), 40; https://doi.org/10.3390/cryptography10030040 - 18 Jun 2026
Viewed by 433
Abstract
In this study, we propose a hybrid cryptanalytic technique targeting the RSA cryptosystem when instantiated with small private exponents. By integrating the continued fraction approach with Coppersmith’s lattice-based technique, we formulate a novel vulnerability framework. Utilizing an innovative relationship extracted from continued fraction [...] Read more.
In this study, we propose a hybrid cryptanalytic technique targeting the RSA cryptosystem when instantiated with small private exponents. By integrating the continued fraction approach with Coppersmith’s lattice-based technique, we formulate a novel vulnerability framework. Utilizing an innovative relationship extracted from continued fraction convergents, we deduce an improved upper bound for the secret key: d<N1α/3γ/2. In this context, α:=logNe and γ:=logN|p+qS|, where S serves as a known approximation of the prime sum p+q. As an extension of our preliminary conference proceedings, this paper supplies comprehensive proofs for all theoretical propositions, performs a comprehensive parameter sensitivity evaluation, and provides bounds for partial prime exposure scenarios. Empirical evaluations confirm the theoretical mechanics of our framework, demonstrating that it offers improved bounds in specific partial leakage scenarios compared to traditional lattice-only baselines. Full article
(This article belongs to the Special Issue Information Security and Privacy—ACISP 2025)
41 pages, 18483 KB  
Article
An Energy-Aware Post-Quantum Ascon–ML-KEM Cryptographic Framework for Low-Latency UAV Remote Sensing Communications
by Nedal Y. Al-Tamimi, Mahmoud AlJamal, Mohammad Q. Al-Jamal, Ayoub Alsarhan, Sami Aziz Alshammari, Nayef H. Alshammari, Khalid Hamad Alnafisah and Mohammed Kamel Aleinzi
Cryptography 2026, 10(3), 39; https://doi.org/10.3390/cryptography10030039 - 16 Jun 2026
Viewed by 473
Abstract
UAV-based remote sensing systems are increasingly deployed in smart surveillance, disaster response, environmental monitoring, and critical infrastructure inspection. In these applications, aerial sensing platforms must transmit telemetry, control commands, and observation data securely and reliably under strict latency, energy, and computational constraints. However, [...] Read more.
UAV-based remote sensing systems are increasingly deployed in smart surveillance, disaster response, environmental monitoring, and critical infrastructure inspection. In these applications, aerial sensing platforms must transmit telemetry, control commands, and observation data securely and reliably under strict latency, energy, and computational constraints. However, existing security approaches often fail to jointly provide lightweight payload confidentiality, quantum-resilient key establishment, and adaptive communication protection suitable for dynamic and resource-constrained aerial sensing environments. To address this challenge, this paper proposes an energy-aware post-quantum hybrid cryptographic framework for secure and low-latency UAV remote sensing communications in UAV–IoT mission networks. The proposed framework integrates Ascon-based authenticated encryption for low-overhead protection of remote sensing payloads and mission telemetry, ML-KEM-based post-quantum session-key establishment for long-term resilience against quantum-era threats, and an AI-driven adaptive rekeying mechanism that dynamically adjusts key-refresh decisions according to threat level, residual energy, mobility state, channel stability, anomaly density, traffic sensitivity, link type, and mission progression. Accordingly, rekeying is treated not as a static maintenance process but as an intelligent and context-aware cryptographic control function that adapts communication security to evolving mission and sensing conditions. The framework is evaluated across twenty progressively demanding scenarios involving different UAV counts, sensor densities, payload sizes, communication modes, and adversarial settings relevant to real-time remote sensing operations. Experimental results demonstrate a secure delivery rate of 99.2%, attack detection and mitigation effectiveness of 98.9%, end-to-end encryption latency of 8.7 ms, throughput of 5.03 Mbps, energy overhead of 11.6 mJ/session, rekeying overhead of 2.9 mJ/event, session resilience of 96.4%, and integrity verification success of 99.1%. These findings show that the proposed framework provides a practical and scalable contribution to post-quantum secure UAV remote sensing by unifying lightweight authenticated encryption, ML-KEM-based quantum-resilient key establishment, and AI-driven adaptive rekeying within a resilient aerial–terrestrial communication architecture. Full article
Show Figures

Figure 1

31 pages, 1039 KB  
Article
Asymmetric Multi-Party Private Set Union for Large-Repository Updates Without Non-Collusion Assumptions
by Yuqi Jia and Leyou Zhang
Cryptography 2026, 10(3), 38; https://doi.org/10.3390/cryptography10030038 - 14 Jun 2026
Viewed by 310
Abstract
Multi-party private set union (MPSU) allows multiple parties to compute a union without disclosing private inputs, but most existing protocols focus on balanced settings with comparable input sizes. In large-repository update scenarios, a leader maintains a massive base set while contributors submit small [...] Read more.
Multi-party private set union (MPSU) allows multiple parties to compute a union without disclosing private inputs, but most existing protocols focus on balanced settings with comparable input sizes. In large-repository update scenarios, a leader maintains a massive base set while contributors submit small update sets; directly using balanced MPSU makes the online cost scale with the leader’s repository size. We propose AegisUnion, an asymmetric MPSU protocol tailored to large-repository updates. AegisUnion separates repository-dependent computation from online update processing through an offline oblivious key-value store (OKVS) encoding phase. In the online phase, contributors perform private membership determination, cross-contributor private deduplication, conditional payload sharing, and secret-shared shuffling, without revealing raw inputs, repository-overlap relations, inter-contributor duplicates, or the source of each output element. Under the semi-honest model, AegisUnion tolerates any coalition of corrupted parties as long as at least one party remains honest, without non-collusion assumptions. Experiments show that, as the repository grows from 214 to 218, the online time remains stable at 663–715 ms. At repository size 218 and contributor update bound 210, AegisUnion achieves about 455× and 454× lower online time than symmetric-key-based MPSU and public-key-based MPSU baselines, respectively, and about 271× and 575× lower online communication. Full article
Show Figures

Figure 1

15 pages, 582 KB  
Article
Dynamic Asymmetric Group Key Agreement Based on SM9 Signature
by Guanglu Wei, Tiecheng Bai, Zehua Fan, Gang Wu, Wenxu Chen, Peng Qin and Kai Fan
Cryptography 2026, 10(3), 37; https://doi.org/10.3390/cryptography10030037 - 12 Jun 2026
Viewed by 289
Abstract
In 2021, the SM9 identity-based cryptographic algorithm became an ISO/IEC international standard, marking a significant advancement in China’s commercial cryptography technology and international standardization capabilities. The SM9 key exchange protocol, a component of the SM9 algorithm suite, provides secure communication by establishing a [...] Read more.
In 2021, the SM9 identity-based cryptographic algorithm became an ISO/IEC international standard, marking a significant advancement in China’s commercial cryptography technology and international standardization capabilities. The SM9 key exchange protocol, a component of the SM9 algorithm suite, provides secure communication by establishing a shared symmetric key between two parties. However, in a group of n users, directly applying this key exchange protocol requires each user to perform O(n) encryption operations and transmit an O(n)-sized ciphertext to ensure confidentiality, which becomes highly inefficient for large groups. To enable efficient secure group communication, we first develop a batch multi-signature algorithm based on SM9, and then we propose a dynamic asymmetric group key agreement (SMDAGKA) protocol based on this method. Our protocol reduces the required encryption operations and ciphertext size to O(1), significantly improving efficiency. Security proofs demonstrate that our scheme achieves a high level of security, and performance analysis shows that it incurs relatively lower computational overhead than related protocols. Full article
(This article belongs to the Special Issue Information and Communications Security—ICICS 2025)
Show Figures

Figure 1

41 pages, 3933 KB  
Article
Hybrid Architecture for Protected Data Communication Inside the Private Cloud
by Biswaranjan Senapati, Lalit Narayan Mishra, Awad Bin Naeem and Amit J. Rangari
Cryptography 2026, 10(3), 36; https://doi.org/10.3390/cryptography10030036 - 2 Jun 2026
Viewed by 664
Abstract
Private cloud object stores provide infrastructure isolation but leave application-layer data exposed to insider threats and compromised credentials. This paper presents an engineering integration of an Add-Rotate-XOR (ARX) block cipher and multi-bit Least Significant Bit (LSB) steganography into an end-to-end pipeline for private [...] Read more.
Private cloud object stores provide infrastructure isolation but leave application-layer data exposed to insider threats and compromised credentials. This paper presents an engineering integration of an Add-Rotate-XOR (ARX) block cipher and multi-bit Least Significant Bit (LSB) steganography into an end-to-end pipeline for private MinIO object storage. The cipher, KREA v2, is a SPECK-64/128 derived ARX construction with three application-driven choices: CRC32 key whitening, byte-aligned rotations (α=7, β=2), and deterministic CTR-mode nonces. Mixed Integer Linear Programming (MILP) trail analysis matches SPECK-64/128’s minimum-trail weights through rounds 1–4. KREA v2 ciphertext meets standard keystream-quality preconditions (NIST SP 800-22 battery, 49.98% mean avalanche, Shannon entropy 7.9992–7.9998 bits/byte across realistic XML, JSON, video, and HTTP/2 payloads). Modified LSB (MLSB) embeds 3 bits per RGB channel with an XOR watermark at 37–38 dB Peak Signal-to-Noise Ratio (PSNR), providing 3× standard-LSB capacity. Steganalysis uses chi-square and RS detectors plus a Convolutional Neural Network (CNN) detector (Yedroudj-Net) trained on 8000 BOSSBase-1.01 cover/stego pairs; CNN area under the ROC curve is ≥0.999 against the watermarked variant. The MinIO pipeline runs at 355.1 ms (68.6% network I/O) with 100% message fidelity. The XOR watermark increases RS detectability above 75% capacity; a 200-image ablation cuts median RS detection (0.289 to 0.000) and mean (0.342 to 0.130) in a sparse-keystream variant, prioritised for follow-on full-scale evaluation. The architecture is offered as a documented engineering integration with explicit security caveats and threat-model boundaries, not as a production-hardened cryptographic primitive. Full article
(This article belongs to the Special Issue Emerging Topics in Hardware Security (2nd Edition))
Show Figures

Figure 1

26 pages, 501 KB  
Article
MPC-in-the-Head Zero-Knowledge Proof for Rank Syndrome Decoding via Mixed-Field Secret Sharing
by Xueyi Tang, Kexin Qiao, Qinghao Wu and Licheng Wang
Cryptography 2026, 10(3), 35; https://doi.org/10.3390/cryptography10030035 - 29 May 2026
Viewed by 505
Abstract
Quantum computing poses significant challenges to traditional zero-knowledge proof schemes based on number-theoretic assumptions. As a result, code-based cryptography has attracted increasing attention for its resistance against quantum computing. In this paper, we study the Rank Syndrome Decoding problem (RSD) and investigate its [...] Read more.
Quantum computing poses significant challenges to traditional zero-knowledge proof schemes based on number-theoretic assumptions. As a result, code-based cryptography has attracted increasing attention for its resistance against quantum computing. In this paper, we study the Rank Syndrome Decoding problem (RSD) and investigate its ZK proof formulation within the MPC-in-the-Head framework. To prove the possession of a secret witness, we reformulate the secret witness as a mixed-field matrix multiplication preserving the rank constraint, and then obtain a representation that aligns naturally with the local-view paradigm of MPC-in-the-Head. Utilizing this value-to-calculation technique, we introduce the RSD relation into a ZKBoo-style (2, 3)-secret-sharing MPC-in-the-Head framework and obtain an RSD-based zero-knowledge proof scheme via mixed-field secret sharing. The resulting scheme reduces the proof size relative to generic formulations while preserving completeness, soundness, and zero-knowledge for the interactive protocol. The Fiat–Shamir non-interactive extension is analyzed only in the classical random oracle model; we do not claim QROM security for this variant. Full article
Show Figures

Figure 1

35 pages, 1110 KB  
Article
A Parameterizable Research Framework for Electronic Voting Based on Cryptographic Protocols and Blockchain Audit
by Tolegen Aidynov, Dina Satybaldina, Gulsipat Abisheva and Eldor Egamberdiyev
Cryptography 2026, 10(3), 34; https://doi.org/10.3390/cryptography10030034 - 27 May 2026
Viewed by 458
Abstract
Electronic voting requires the simultaneous admission of only legitimate participants, ballot uniqueness, vote confidentiality, storage integrity, and result verifiability. Blockchain alone does not solve these problems, since ledger immutability does not guarantee anonymity, ballot correctness, or reduced trust concentration. The purpose of this [...] Read more.
Electronic voting requires the simultaneous admission of only legitimate participants, ballot uniqueness, vote confidentiality, storage integrity, and result verifiability. Blockchain alone does not solve these problems, since ledger immutability does not guarantee anonymity, ballot correctness, or reduced trust concentration. The purpose of this work is to develop a parameterizable research framework for electronic voting scenarios with enhanced cryptographic protection, allowing the security level to be varied according to the requirements of a voting scenario. The main contribution of the work is a parameterizable research architecture for composing and experimentally comparing electronic voting configurations with different security and computational profiles. The cryptographic and audit mechanisms integrated into this architecture include blind-signature-based anonymous authorization, encrypted ballot submission, blockchain-style audit, receipt verification, homomorphic tally publication, and threshold-supported tally artifacts. These mechanisms are not proposed as new cryptographic primitives; rather, they are integrated into a reproducible prototype to study how their combination affects verifiability, privacy support, auditability, and computational cost. Compared with basic blockchain-based voting prototypes, this architecture explicitly separates security, privacy, and verifiability profiles and makes their computational cost observable. The implemented prototype is used as an experimental platform for analyzing supported security properties, threat modeling, and computational cost estimation. The results show that authentication, anonymous token issuance, and receipt verification maintain an almost constant cost at the studied scale, while the main cryptographic burden is associated with encrypted ballot submission and threshold-supported tally publication. The scientific novelty of the work lies in constructing a parameterizable architecture that integrates several cryptographic mechanisms and a blockchain audit layer into one reproducible research prototype. At the same time, the proposed approach retains prototype-level limitations associated with the absence of a full zero-knowledge proof stack, independently deployed threshold authorities, and coercion-resistance mechanisms. Full article
Show Figures

Figure 1

23 pages, 1341 KB  
Article
DPS: A Post-Quantum Proxy Signature Scheme from Dilithium for IoT Applications
by Yuteng Wang, Ruoyu Ding, Tianrun Yu, Zhen Han, Jian Weng and Jiasi Weng
Cryptography 2026, 10(3), 33; https://doi.org/10.3390/cryptography10030033 - 15 May 2026
Viewed by 643
Abstract
Proxy signatures enable the secure delegation of signing authority, which is particularly useful in resource-constrained Internet of Things (IoT) environments. However, most existing schemes rely on classical hardness assumptions and therefore cannot resist quantum attacks. To address the challenge, we propose a post-quantum [...] Read more.
Proxy signatures enable the secure delegation of signing authority, which is particularly useful in resource-constrained Internet of Things (IoT) environments. However, most existing schemes rely on classical hardness assumptions and therefore cannot resist quantum attacks. To address the challenge, we propose a post-quantum proxy signature scheme based on Dilithium for IoT scenarios. We first propose an asynchronous remote key generation (ARKG) scheme based on CRYSTALS-Kyber, enabling the delegator and proxy signer to generate proxy keys of Dilithium without real-time interaction. We further integrate ARKG with the Dilithium signature scheme to construct a proxy signature scheme called DPS while ensuring the unlinkability of proxy signatures. Additionally, our proposed DPS achieves post-quantum security and provides unforgeability, distinguishability, verifiability, and undeniability with formal proofs. Experimental performance evaluation shows that our scheme yields significant efficiency gains over existing quantum-safe proxy signature solutions, with 10× speedup for both the delegation and proxy signing phases, as well as a 2.4× improvement in the verification phase. Full article
(This article belongs to the Special Issue Advances in Post-Quantum Cryptography)
Show Figures

Figure 1

13 pages, 351 KB  
Article
Relaxation of Strict Avalanche Criterion on All SHA-256 Sub-Function Combinations
by Riley Vaughn and Mike Borowczak
Cryptography 2026, 10(3), 32; https://doi.org/10.3390/cryptography10030032 - 13 May 2026
Viewed by 411
Abstract
A cryptographic hash function should dissipate patterns, such that highly related inputs are transformed into unrelated outputs. This property, known as diffusion, has been effectively measured on SHA-256 via the Strict Avalanche Criterion (SAC) throughout the 64 rounds of compression. Additionally, variants of [...] Read more.
A cryptographic hash function should dissipate patterns, such that highly related inputs are transformed into unrelated outputs. This property, known as diffusion, has been effectively measured on SHA-256 via the Strict Avalanche Criterion (SAC) throughout the 64 rounds of compression. Additionally, variants of SHA-256 with individual sub-functions removed have previously been tested. In this study, the previous work is expanded; all combinations of the seven SHA-256 sub-functions are tested for SAC, throughout the 64 rounds of compression. The threshold as to whether a variant passes the SAC is calculated with the Bonferroni Method, which results in a relaxed threshold as compared to previous measures. The SAC of each sub-function variant is compared with the SAC of variants with shared sub-functions. The sub-functions Σ1, Integer Addition, Choose, and Message Scheduler are found to consistently contribute to SAC at the earliest rounds, throughout all combinations. Full article
Show Figures

Figure 1

28 pages, 1515 KB  
Article
Q-DP-GAN: Improving EEG Data Privacy Through Quantum-Inspired Differential Privacy-Based GAN
by Shouvik Paul and Garima Bajwa
Cryptography 2026, 10(3), 31; https://doi.org/10.3390/cryptography10030031 - 11 May 2026
Viewed by 976
Abstract
Electroencephalography (EEG)-based brain–computer interface (BCI) systems pose significant privacy risks, as EEG data remain vulnerable to inference and reconstruction attacks. Conventional privacy-preserving techniques, including data anonymization, encryption, and perturbation, frequently compromise data utility or prove ineffective against advanced adversaries. To address these limitations [...] Read more.
Electroencephalography (EEG)-based brain–computer interface (BCI) systems pose significant privacy risks, as EEG data remain vulnerable to inference and reconstruction attacks. Conventional privacy-preserving techniques, including data anonymization, encryption, and perturbation, frequently compromise data utility or prove ineffective against advanced adversaries. To address these limitations and balance utility and privacy, we propose a quantum-inspired, differential privacy-based generative adversarial network (Q-DP-GAN). Unlike classical GANs, which lack adaptive privacy mechanisms during training, our method uses quantum-inspired stochasticity to dynamically calibrate noise and the privacy budget. The experimental results demonstrate that Q-DP-GAN is more robust to membership inference and reconstruction attacks than existing approaches. Evaluation on the widely used BCI Competition IV Datasets 2A and 2B indicates that our framework produces high-quality synthetic EEG data while maintaining utility and data confidentiality for BCI classification tasks. Full article
Show Figures

Figure 1

68 pages, 5976 KB  
Article
A Hybrid Module-LWE and Hash-Based Framework for Memory-Efficient Post-Quantum Key Encapsulation
by Elmin Marevac, Esad Kadušić, Nataša Živić, Sanela Nesimović and Christoph Ruland
Cryptography 2026, 10(3), 30; https://doi.org/10.3390/cryptography10030030 - 3 May 2026
Viewed by 937
Abstract
Deploying post-quantum cryptography on highly constrained devices remains challenging due to the large key sizes and substantial storage and memory-traffic demands of leading lattice-based schemes. Although constructions such as Kyber, Dilithium, and NTRU offer strong resistance against quantum adversaries, their multi-kilobyte public keys [...] Read more.
Deploying post-quantum cryptography on highly constrained devices remains challenging due to the large key sizes and substantial storage and memory-traffic demands of leading lattice-based schemes. Although constructions such as Kyber, Dilithium, and NTRU offer strong resistance against quantum adversaries, their multi-kilobyte public keys and intensive memory access patterns limit practical adoption in microcontrollers, smart cards, and low-power edge environments. This work proposes a hybrid key-encapsulation mechanism that integrates a compact, seed-generated Module-LWE structure with a quantum-secure hash-based authentication layer. The design employs a small public seed to instantiate lattice matrices on demand via a lightweight pseudorandom generator and incorporates a Merkle-tree commitment to represent compressed auxiliary error information. Additional design considerations—including sparsity-aware secret keys, SIMD-friendly polynomial operations, and cache-efficient decryption paths—are intended to reduce runtime memory usage and computational overhead. The security of the proposed construction is analysed under both Module-LWE and hash-based one-way assumptions, with further consideration of constant-time execution and cache-line alignment to mitigate side-channel risks. This hybrid approach outlines a design pathway toward post-quantum key-encapsulation mechanisms suitable for deployment on memory-limited and energy-constrained platforms. Full article
(This article belongs to the Special Issue Advances in Post-Quantum Cryptography)
Show Figures

Figure 1

18 pages, 373 KB  
Article
Space-Efficient Secret Sharing Based on Matrix Normal Forms
by Eckhard Pfluegel, Razi Arshad and Mark Jones
Cryptography 2026, 10(3), 29; https://doi.org/10.3390/cryptography10030029 - 30 Apr 2026
Viewed by 692
Abstract
Secret sharing schemes distribute a secret among participants so that only authorised subsets can reconstruct it. In this paper, we focus on space-efficient secret sharing and show that matrix normal forms can significantly reduce share sizes while achieving computational security properties. Our scheme [...] Read more.
Secret sharing schemes distribute a secret among participants so that only authorised subsets can reconstruct it. In this paper, we focus on space-efficient secret sharing and show that matrix normal forms can significantly reduce share sizes while achieving computational security properties. Our scheme is implemented within an online secret sharing architecture, where authenticated public data P is maintained and shares of private data Q are issued over a secure channel. We study an existing probabilistic matrix-based approach to share size reduction and prove that the expected number of iterations of the underlying cyclic vector algorithm is small, yielding an expected polynomial runtime. We then design a novel deterministic method based on the Frobenius canonical normal form, avoiding reliance on cyclic vector techniques, and derive its runtime complexity. This yields a space-efficient secret sharing scheme that is computationally secure under a suitably defined adversary model. We have implemented our algorithm in the computer algebra system Maple as an Open Source project and provide an evaluation of its performance. Our results demonstrate that matrix normal forms can provide a suitable mathematical framework for secure and practical secret sharing. Full article
Show Figures

Figure 1

21 pages, 439 KB  
Article
A Post-Quantum End-to-End Secure Protocol for Instant Messaging Applications
by Alfonso F. De Abiega-L’Eglisse, Kevin A. Delgado-Vargas, Humberto A. Ortega Alcocer, Gina Gallegos-García and Eliseo Sarmiento-Rosales
Cryptography 2026, 10(3), 28; https://doi.org/10.3390/cryptography10030028 - 23 Apr 2026
Viewed by 1041
Abstract
Modern instant messaging systems require end-to-end (E2E) security guarantees while operating over server-mediated infrastructures that cannot be fully trusted. At the same time, the impending transition to post-quantum cryptography raises nontrivial challenges for the design of secure messaging protocols that preserve these guarantees. [...] Read more.
Modern instant messaging systems require end-to-end (E2E) security guarantees while operating over server-mediated infrastructures that cannot be fully trusted. At the same time, the impending transition to post-quantum cryptography raises nontrivial challenges for the design of secure messaging protocols that preserve these guarantees. In this work, we present the design of a post-quantum end-to-end secure protocol for instant messaging applications under an untrusted relay model. The proposed construction relies on lattice-based primitives standardized by NIST, namely ML-KEM for key establishment and ML-DSA for authentication, and follows a Double-KEM pattern combined with explicit context binding to derive an E2E session key known only to the communicating clients. The server acts solely as an authenticated relay and never gains access to plaintext messages or session keys. In addition to the protocol design, we complement the protocol description with an automated symbolic verification using ProVerif, establishing injective mutual authentication and session-key secrecy under a Dolev–Yao adversary model. Finally, we characterize the computational cost of different authentication and verification policies and evaluate the performance of the handshake on heterogeneous cloud-based architectures. The results provide practical insight into the feasibility of deploying post-quantum end-to-end secure protocols within existing instant messaging infrastructures. Full article
Show Figures

Figure 1

Previous Issue
Next Issue
Back to TopTop