About
Crypto 2026 is the 46th Annual International Cryptology Conference. It will take place on August 17-20, 2026, with affiliated events on August 15-16. Crypto 2026 is organized by the International Association for Cryptologic Research (IACR).
For anyone unable to join the conference in person, there is a possibility to attend virtually.
IBM contributions include "CORAL: Faster Isogeny Group Action for Post-Quantum NIKE", winner of the "Best paper authored by early career researchers" award.
Agenda
- Description:
We explore the use of level structures to generalize the SQIsign signature scheme. We give a general framework, where the challenge is a pair of level structures on the public key and the commitment curve, and the response is required to map one onto the other. We then instantiate the framework using 1-dimensional and 2-dimensional isogenies. In doing that we provide a new explicit Deuring correspondence for supersingular elliptic curves with level structures, solve new constrained norm equations and study the distribution of odd norm vectors in lattices of isogenies.
Authors: - Description:
We propose a generic framework called GAPP for aggregation of polynomial protocols. This allows proving n instances of a polynomial protocol using a single aggregate proof that has O(log n) size, and can be verified using O(log2 n) operations. The satisfiability of several univariate polynomial identities over a domain is reduced to the satisfiability of a single bivariate polynomial identity over a related domain, where the bivariate polynomials interpolate a batch of univariate polynomials over the domain. We construct an information-theoretic protocol for proving the satisfiability of the bivariate polynomial identity, which is then compiled using any bivariate polynomial commitment scheme (PCS) to yield an argument of knowledge for the aggregation relation. GAPP can be applied to several popular SNARKs over bilinear groups that are modeled as polynomial protocols in a black-box way. We present a new bivariate polynomial commitment scheme, bPCLB, with succinct verification that yields an efficient instantiation of GAPP. Towards this, we show a new folding technique that we call Lagrangian folding. The bivariate PCS bPCLB and the Lagrangian folding scheme are of independent interest. We implement bPCLB and experimentally validate the practical efficiency of our GAPP instantiation. For the popular PLONK proof system, we achieve 25-30% faster proof generation than the na ̈ıve baseline of generating n separate PLONK proofs. Compared to all existing aggregation schemes that incur additional prover overheads on top of the baseline, we achieve significantly more efficient proving, while retaining succinct verification. We demonstrate the versatility of our proposed GAPP framework by out- lining applications of practical interest: tuple lookups that significantly outperform existing lookup arguments in terms of prover overheads; and proofs for non-uniform computation with “à la carte” prover cost.
Authors: - Description:
The past several years have seen a rapid rise in practical lattice-based proof systems with linear-sized zero-knowledge proofs forming the foundation of many of the most efficient quantum-safe privacy protocols, and succinct proofs rapidly catching up and surpassing other quantum-safe alternatives in many metrics. A recent comparison of lattice-based aggregate signatures (Ethereum Foundation, 2025) involving the hash-based aggregate signature scheme Plonky3 and the instantiation of aggregate signatures from Falcon from the LaZer lattice library (Lyubashevsky, Seiler, Steuer, CCS 2024) using LaBRADOR (Beullens, Seiler, Crypto 2023), showed that lattice-based constructions have an advantage in terms of proof size and prover time, but are around an order of magnitude slower with regards to verification time. In general, it appears that slower verification times are the main obstacle to the adoption of succinct lattice-based proof systems.
In this work, we introduce and implement Orthus, a proof system with sub-linear verification designed for relations that naturally arise in lattice-based constructions. Asymptotically, the verification time grows with the square root of the witness size, and for a concrete example of aggregating Falcon signatures our implementation reduces the verifier running time by a factor of when aggregating signatures.
Authors:MBMadalina BolboceanuIBMJBVLPrincipal Research Scientist, Manager of the Foundational Cryptography GroupAMAntonio Merino GallardoIBMGSGregor SeilerIBM - Description:
There are two kinds of cryptographic group actions: restricted and unrestricted. While unrestricted actions like (qt-)PEGASIS are needed for more advanced constructions, restricted ones like dCTIDH are sufficient for instantiating a NIKE and are usually much more efficient.
In this work, we propose CORAL, a significantly faster algorithm to evaluate the same action as (qt-)PEGASIS, but in a restricted fashion; CORAL only computes two-dimensional two-isogenies to evaluate the action and outperforms both recent unrestricted (KLaPoTi, (qt-)PEGASIS) and (restricted) CSIDH-based approaches (SQALE, dCTIDH). In essence, CORAL trades off unrestrictedness for efficiency.
Our unoptimised C implementation evaluates a group-action in 178 ms with a 2032-bit prime. When used to construct a non-interactive key exchange, CORAL yields an actively secure post-quantum NIKE with compact public keys (e.g. 256 bytes for 2032-bit primes).
Speakers:Authors:
- Description:
Distributed key generation (DKG) protocols enable a set of parties to distributively generate a threshold-shared key pair (pk, sk), such that at least t parties must participate to reconstruct the secret. We introduce the first DKG protocols for discrete-logarithm based keys that are both universally composable and adaptively secure in the random oracle model, without erasure, inconsistent players, interactive assumptions, or oracle-aided simulation.
Our contributions are as follows:
- an adaptively secure, universally composable DKG that achieves guaranteed output delivery in three rounds assuming an honest majority,
- an adaptively secure, universally composable committed DKG that realizes our novel committed DKG functionality in two rounds with identifiable abort for a full corruption threshold, and
- as an application, an incredibly simple threshold Schnorr protocol in the committed DKG-hybrid model, implying a three-round adaptively secure and universally composable threshold Schnorr protocol with identifiable abort for a dishonest majority.
Most importantly, our DKG constructions are secure in the random oracle model under the DDH assumption. Our output guarantees are proven under the assumption of synchrony. To date, all existing DKG protocols for discrete-logarithm based keys satisfy weaker security notions or require stronger assumptions.
Authors:HEHanna EkNON-IBMKMKelsey MelissarisNON-IBMLRLance RoyIBM
More events
- —
IBM at Open Source Summit Korea 2026
- Seoul, Korea
- —
IBM at Agentic AI Summit 2026
- Berkeley, CA, USA and virtual
- —
IBM at USENIX Security 2026
- Baltimore, MD, USA


