LIPIcs, Volume 385

7th Conference on Information-Theoretic Cryptography (ITC 2026)



Thumbnail PDF

Event

Editor

Yevgeniy Dodis
  • New York University, NY, USA

Publication Details

  • published at: 2026-08-12
  • Publisher: Schloss Dagstuhl – Leibniz-Zentrum für Informatik
  • ISBN: 978-3-95977-426-0

Access Numbers

Documents

No documents found matching your filter selection.
Document
Complete Volume
LIPIcs, Volume 385, ITC 2026, Complete Volume

Authors: Yevgeniy Dodis


Abstract
LIPIcs, Volume 385, ITC 2026, Complete Volume

Cite as

7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 1-278, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@Proceedings{dodis:LIPIcs.ITC.2026,
  title =	{{LIPIcs, Volume 385, ITC 2026, Complete Volume}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{1--278},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026},
  URN =		{urn:nbn:de:0030-drops-275396},
  doi =		{10.4230/LIPIcs.ITC.2026},
  annote =	{Keywords: LIPIcs, Volume 385, ITC 2026, Complete Volume}
}
Document
Front Matter
Front Matter, Table of Contents, Preface, Conference Organization

Authors: Yevgeniy Dodis


Abstract
Front Matter, Table of Contents, Preface, Conference Organization

Cite as

7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 0:i-0:xii, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{dodis:LIPIcs.ITC.2026.0,
  author =	{Dodis, Yevgeniy},
  title =	{{Front Matter, Table of Contents, Preface, Conference Organization}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{0:i--0:xii},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.0},
  URN =		{urn:nbn:de:0030-drops-275385},
  doi =		{10.4230/LIPIcs.ITC.2026.0},
  annote =	{Keywords: Front Matter, Table of Contents, Preface, Conference Organization}
}
Document
Tighter Bounds for the Oblivious Bit-Fixing Inner Product Extractor on Biased Seeds

Authors: Jack Doerner and Lawrence Roy


Abstract
The Inner Product Extractor (IPE) of Impagliazzo, Levin, and Luby (STOC'89) takes a seed h ∈ 𝔽^γ and a source x ∈ {0,1}^γ for some γ ∈ ℕ and produces ⟨h,x⟩ with error ε = SD((⟨ℋ,𝒳⟩,ℋ),(𝒴,ℋ)) such that ε ≤ 1/2√{|𝔽|^{γ}/2^{H_∞(ℋ)}} √{|𝔽|/2^{H_∞(𝒳)}} where 𝒴 is the uniform distribution over 𝔽, and ℋ and 𝒳 are the independent but possibly non-uniform distributions from which h and x are drawn, respectively. In other words, the IPE’s error grows with the square root of seed bias, at most. This square root arises because prior works bound the squared error using the 2-universality of the IPE. The analysis requires an even power of the error, and the IPE is not 4-universal. Motivated by applications to multiparty computation, we revisit the problem of the IPE with biased seeds and prove far tighter bounds on the influence of seed bias by bypassing universal hashing. We first prove an Elevated General Leftover Hash Lemma, which yields an n^th root bound for functions that are almost n-universal. Bounding number of inputs on which the IPE is not 4-universal yields ε = SD((⟨ℋ,𝒲⟩,ℋ),(𝒴,ℋ)) where ε ≲ 2.1/2 (|𝔽|^γ/2^{H_∞(ℋ)}) ^{1/4} √{|𝔽|/2^{H_∞(𝒲)}} for any oblivious bit-fixing source 𝒲 with 2^{0.585 H_∞(𝒲)} ≤ |𝔽| ≤ 2^{H_∞(𝒲)}. Next, we use matroid theory to directly analyze the n-way multicollision probability of the IPE, yielding an asymptotic bound for any even n. For n ≥ 4, 0 < ε ≤ 0.83/(n - 2), and |𝔽| ≤ 2^{(1 - ε)⋅ H_∞(𝒲)}, as |𝔽| → ∞, ε ≤ (n - 1)/2 (|𝔽|^γ/2^{H_∞(ℋ)})^(1/n) √{2^{-ε⋅ H_∞(𝒲)}} (1 + o(1)). Computing a concrete version of this bound requires time exponential in n. We compute concrete {4,6,8}^th-root bounds and demonstrate that no one choice of n is optimal. Finally, we introduce a new class of seed-adaptive oblivious bit-fixing sources, extend our results to such sources, and use this extension to fix a bug that we identify in the proof of the oblivious linear evaluation protocol of Doerner et al. (SP'24).

Cite as

Jack Doerner and Lawrence Roy. Tighter Bounds for the Oblivious Bit-Fixing Inner Product Extractor on Biased Seeds. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 1:1-1:23, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{doerner_et_al:LIPIcs.ITC.2026.1,
  author =	{Doerner, Jack and Roy, Lawrence},
  title =	{{Tighter Bounds for the Oblivious Bit-Fixing Inner Product Extractor on Biased Seeds}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{1:1--1:23},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.1},
  URN =		{urn:nbn:de:0030-drops-270946},
  doi =		{10.4230/LIPIcs.ITC.2026.1},
  annote =	{Keywords: Leftover hash lemma, Inner product extractor, Randomness extraction, Oblivious linear evaluation}
}
Document
Limits on the Power of Private Constrained PRFs

Authors: Mengda Bi, Yaohua Ma, and Chenxin Dai


Abstract
Private constrained PRFs are constrained PRFs where the constrained key hides information about the predicate circuit. Although there are many constructions and applications of PCPRF, its relationship to basic cryptographic primitives, such as one-way functions and public-key encryptions, has been unclear. For example, we don't know whether one-way functions imply PCPRFs for general predicates, nor do we know whether 1-key secure PCPRF for all polynomial-sized predicates imply public-key primitives such as public-key encryption and secret-key agreement. In this work, we prove the black-box separation between a 1-key secure PCPRF for any predicate and a secret-key agreement, which is the first black-box separation result about PCPRF. Specifically, we prove that there exists an oracle relative to which 1-key secure PCPRFs exist while secret-key agreement does not. Our proof is based on the simulation-based technique proposed by Impagliazzo and Rudich (STOC 89). The main technical challenge in generalizing the simulation-based technique to PCPRF is the issue of unfaithfulness of Eve’s simulation to the real world because our oracle is more complicated than a random oracle. We introduce a new technique which we call the "weighting" technique and show how to leverage it to circumvent the issue of unfaithfulness in the proof framework of Impagliazzo and Rudich.

Cite as

Mengda Bi, Yaohua Ma, and Chenxin Dai. Limits on the Power of Private Constrained PRFs. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 2:1-2:22, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{bi_et_al:LIPIcs.ITC.2026.2,
  author =	{Bi, Mengda and Ma, Yaohua and Dai, Chenxin},
  title =	{{Limits on the Power of Private Constrained PRFs}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{2:1--2:22},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.2},
  URN =		{urn:nbn:de:0030-drops-270952},
  doi =		{10.4230/LIPIcs.ITC.2026.2},
  annote =	{Keywords: Black-box Separations, Private Constrained PRFs, Key Agreement}
}
Document
Interactive Proofs for Batch Polynomial Evaluation

Authors: Gal Arnon, Alessandro Chiesa, Giacomo Fenzi, and Eylon Yogev


Abstract
Polynomials are a fundamental mathematical object underlying virtually all of theoretical computer science. In proof systems, a common task for the verifier is to evaluate a polynomial of degree d at m distinct points. The best known algorithm for this problem performs O((m + d) ⋅ log²(m + d)) field operations. We present a concretely efficient MA protocol for this problem in which the verifier runs in linear time: the prover sends a single message consisting of d - 1 field elements, and the verifier performs only O(m + d) field operations. We further extend our protocol to handle the more general setting of evaluating multiple polynomials at multiple points, and for this problem, we construct an AMA protocol. Our protocols improve the verifier time in several interactive proofs. Most notable are the sumcheck protocol over a large summation domain and protocols that rely on polynomial quotienting. In particular, by a straightforward application of our results, we reduce the verifier’s runtime in the STIR protocol (CRYPTO 2024) to match that of WHIR (EUROCRYPT 2025), despite WHIR being highly optimized for verification time. As an additional application, we show that any univariate polynomial commitment scheme (PCS) can be transformed, in a black-box manner, into a new scheme that efficiently supports batch openings at multiple points. In particular, opening m points incurs only a constant overhead compared to opening a single point.

Cite as

Gal Arnon, Alessandro Chiesa, Giacomo Fenzi, and Eylon Yogev. Interactive Proofs for Batch Polynomial Evaluation. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 3:1-3:19, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{arnon_et_al:LIPIcs.ITC.2026.3,
  author =	{Arnon, Gal and Chiesa, Alessandro and Fenzi, Giacomo and Yogev, Eylon},
  title =	{{Interactive Proofs for Batch Polynomial Evaluation}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{3:1--3:19},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.3},
  URN =		{urn:nbn:de:0030-drops-270964},
  doi =		{10.4230/LIPIcs.ITC.2026.3},
  annote =	{Keywords: interactive proofs, polynomial evaluation}
}
Document
Fiat-Shamir for Bounded-Depth Adversaries

Authors: Liyan Chen, Yilei Chen, Zikuan Huang, Nuozhou Sun, Tianqi Yang, and Yiding Zhang


Abstract
We study how to construct hash functions that can securely instantiate the Fiat-Shamir transformation against bounded-depth adversaries. The motivation is twofold. First, given the recent fruitful line of research of constructing cryptographic primitives against bounded-depth adversaries under worst-case complexity assumptions, and the rich applications of Fiat-Shamir, instantiating Fiat-Shamir hash functions against bounded-depth adversaries under worst-case complexity assumptions might lead to further applications (such as SNARG for P, showing the cryptographic hardness of PPAD, etc.) against bounded-depth adversaries. Second, we wonder whether it is possible to overcome the impossibility results of constructing Fiat-Shamir for arguments [Goldwasser, Kalai, FOCS '03] in the setting where the depth of the adversary is bounded, given that the known impossibility results (against p.p.t. adversaries) are contrived. Our main results give new insights for Fiat-Shamir against bounded-depth adversaries in both the positive and negative directions. On the positive side, for Fiat-Shamir for proofs with certain properties, we show that weak worst-case assumptions are enough for constructing explicit hash functions that give AC⁰[2]-soundness. In particular, we construct an AC⁰[2]-computable correlation-intractable hash family for constant-degree polynomials against AC⁰[2] adversaries, assuming ⊕L/poly ⊈ Sum̃_{n^{-c}}∘AC⁰[2] for some c > 0. This is incomparable to all currently-known constructions, which are typically useful for larger classes and against stronger adversaries, but based on arguably stronger assumptions. Our construction is inspired by the Fiat-Shamir hash function by Peikert and Shiehian [CRYPTO '19] and the fully-homomorphic encryption scheme against bounded-depth adversaries by Wang and Pan [EUROCRYPT '22]. On the negative side, we show Fiat-Shamir for arguments is still impossible to achieve against bounded-depth adversaries. In particular, - Assuming the existence of AC⁰[2]-computable CRHF against p.p.t. adversaries, for every poly-size hash function, there is a (p.p.t.-sound) interactive argument that is not AC⁰[2]-sound after applying Fiat-Shamir with this hash function. - Assuming the existence of AC⁰[2]-computable CRHF against AC⁰[2] adversaries, there is an AC⁰[2]-sound interactive argument such that for every hash function computable by AC⁰[2] circuits, the argument does not preserve AC⁰[2]-soundness when applying Fiat-Shamir with this hash function. This is a low-depth variant of Goldwasser and Kalai.

Cite as

Liyan Chen, Yilei Chen, Zikuan Huang, Nuozhou Sun, Tianqi Yang, and Yiding Zhang. Fiat-Shamir for Bounded-Depth Adversaries. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 4:1-4:22, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{chen_et_al:LIPIcs.ITC.2026.4,
  author =	{Chen, Liyan and Chen, Yilei and Huang, Zikuan and Sun, Nuozhou and Yang, Tianqi and Zhang, Yiding},
  title =	{{Fiat-Shamir for Bounded-Depth Adversaries}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{4:1--4:22},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.4},
  URN =		{urn:nbn:de:0030-drops-270978},
  doi =		{10.4230/LIPIcs.ITC.2026.4},
  annote =	{Keywords: Fiat-Shamir, Correlation Intractability}
}
Document
Weak Zero-Knowledge and One-Way Functions

Authors: Rohit Chatterjee, Yunqi Li, and Prashant Nalini Vasudevan


Abstract
We study the implications of the existence of weak Zero-Knowledge (ZK) protocols for worst-case hard languages. These are protocols that have completeness, soundness, and zero-knowledge errors (denoted ε_c, ε_s, and ε_z, respectively) that might not be negligible. Under the assumption that there are worst-case hard languages in NP, we show the following: 1) If all languages in NP have NIZK proofs or arguments satisfying ε_c+ε_s+ε_z < 1, then One-Way Functions (OWFs) exist. This covers all possible non-trivial values for these error rates. It additionally implies that if all languages in NP have such NIZK proofs and ε_c is negligible, then they also have NIZK proofs where all errors are negligible. Previously, these results were known under the more restrictive condition ε_c+√{ε_s}+ε_z < 1 [Chakraborty et al., CRYPTO 2025]. 2) If all languages in NP have k-round public-coin ZK proofs or arguments satisfying ε_c+ε_s+(2k-1)⋅ε_z < 1, then OWFs exist. 3) If, for some constant k, all languages in NP have k-round public-coin ZK proofs or arguments satisfying ε_c+ε_s+k⋅ε_z < 1, then infinitely-often OWFs exist.

Cite as

Rohit Chatterjee, Yunqi Li, and Prashant Nalini Vasudevan. Weak Zero-Knowledge and One-Way Functions. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 5:1-5:21, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{chatterjee_et_al:LIPIcs.ITC.2026.5,
  author =	{Chatterjee, Rohit and Li, Yunqi and Vasudevan, Prashant Nalini},
  title =	{{Weak Zero-Knowledge and One-Way Functions}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{5:1--5:21},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.5},
  URN =		{urn:nbn:de:0030-drops-270987},
  doi =		{10.4230/LIPIcs.ITC.2026.5},
  annote =	{Keywords: One-way functions, zero-knowledge}
}
Document
Towards Characterizing Secure Samplability

Authors: Hari Krishnan P. Anilkumar, Keval Jain, Manoj Prabhakaran, and Vinod M. Prabhakaran


Abstract
This work deals with the fundamental problem of characterizing which multiparty distributions can be securely sampled with information-theoretic security against passive corruption, when there is no setup or honest-majority. We focus on the case of 4-party distributions with boolean outputs for each party. We show that such a distribution is securely samplable if and only if every 2-party distribution derived from it by partitioning the parties into two sets is securely samplable. This extends a similar characterization previously known for 3-party distributions.

Cite as

Hari Krishnan P. Anilkumar, Hari Krishnan P. Anilkumar, Keval Jain, Keval Jain, Manoj Prabhakaran, Manoj Prabhakaran, Vinod M. Prabhakaran, and Vinod M. Prabhakaran. Towards Characterizing Secure Samplability. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 6:1-6:21, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{anilkumar_et_al:LIPIcs.ITC.2026.6,
  author =	{Anilkumar, Hari Krishnan P. and Jain, Keval and Prabhakaran, Manoj and Prabhakaran, Vinod M.},
  title =	{{Towards Characterizing Secure Samplability}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{6:1--6:21},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.6},
  URN =		{urn:nbn:de:0030-drops-270991},
  doi =		{10.4230/LIPIcs.ITC.2026.6},
  annote =	{Keywords: secure sampling, information-theoretic MPC}
}
Document
Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography

Authors: Yuval Ishai, Hugo Krawczyk, and Tal Rabin


Abstract
We revisit the question of securely compressing multiparty correlations using only symmetric cryptography. A linear correlation C, defined by a linear subspace C ⊆ 𝔽ⁿ, samples a secret random 𝐜 ∈ C and assigns to each party a fixed subset of the entries of 𝐜. Gilboa and Ishai (Crypto 1999) and Cramer, Damgård and Ishai (TCC 2005) provide a general technique for securely compressing many independent samples from C by replicating independent keys of a pseudorandom function (PRF) among the parties. This implies a pseudorandom correlation function (PCF) for C from any PRF, where the PCF key size scales with the number of minimal-support codewords in C. We observe that the above generalizes to other types of useful target correlations C_T by using a secret replication pattern obtained via a random secret assignment of parties in C to parties in C_T. We present several corollaries of this general blueprint. These include a re-derivation of two-party PCF constructions for VOLE and subfield-VOLE over small domains (Roy, Crypto 2022) as well as new multiparty PCFs for small-domain VOLE-style correlations, including scalar-vector multiplication triples and their authenticated variants. Finally, we discuss applications to secure computation.

Cite as

Yuval Ishai, Hugo Krawczyk, and Tal Rabin. Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 7:1-7:22, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{ishai_et_al:LIPIcs.ITC.2026.7,
  author =	{Ishai, Yuval and Krawczyk, Hugo and Rabin, Tal},
  title =	{{Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{7:1--7:22},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7},
  URN =		{urn:nbn:de:0030-drops-271001},
  doi =		{10.4230/LIPIcs.ITC.2026.7},
  annote =	{Keywords: Pseudorandom correlation functions, correlated randomness, secure computation, symmetric cryptography}
}
Document
Fast Bounded-Independence Functions and Their Duals

Authors: Martijn Brehm, Yuval Ishai, and Nicolas Resch


Abstract
We continue the study of fast functions, computable by linear-size circuits, that share useful properties of random functions. Motivated by cryptographic applications, we generalize and improve on previous results in this area, obtaining the following results: - For any constant t, we construct a fast t-wise independent hash function with algebraic degree log₂ t (over F₂), simultaneously optimizing both asymptotic circuit size and degree. - We simplify and improve a recent construction (ITCS 2026) of a family of fast codes with fast duals, both meeting the Gilbert-Varshamov bound. Unlike the previous construction, our construction has negligible failure probability, can accommodate general fields and rates, supports a systematic encoding, and admits fast universal encoders. - We strengthen the above to support stronger random-like properties, such as optimal combinatorial list-decoding. This is achieved by constructing, for any constant t, a family of fast linear functions that map any t linearly independent inputs to uniform and statistically independent outputs. Prior to our work, this was only known for t = 1. We demonstrate the usefulness of the above results to cryptography. This includes the first nontrivial protocols for perfectly secure multiparty computation whose circuit complexity scales linearly with the number of parties, as well as protocols for computing encrypted matrix-vector products with optimal asymptotic circuit complexity.

Cite as

Martijn Brehm, Yuval Ishai, and Nicolas Resch. Fast Bounded-Independence Functions and Their Duals. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 8:1-8:23, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{brehm_et_al:LIPIcs.ITC.2026.8,
  author =	{Brehm, Martijn and Ishai, Yuval and Resch, Nicolas},
  title =	{{Fast Bounded-Independence Functions and Their Duals}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{8:1--8:23},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.8},
  URN =		{urn:nbn:de:0030-drops-271018},
  doi =		{10.4230/LIPIcs.ITC.2026.8},
  annote =	{Keywords: Linear codes, hash function families, efficient encoding, secure computation}
}
Document
Resilience of Inner-Product Masking Scheme Against Hamming Weight Leakage

Authors: Aniruddha Biswas, Jihun Hwang, Hemanta K. Maji, and Xiuyu Ye


Abstract
Additive masking is a widely used countermeasure against side-channel attacks in which a secret is additively split into multiple random shares. However, over binary fields, the number of 1’s in the binary representation (i.e., the Hamming weight) of the shares reveals information about the original secret. Inner-product masking scheme has been proposed as a promising alternative that is secure against such information leakage. In this work, we establish that inner-product masking over a binary extension field is provably secure against Hamming weight leakage, and it translates into security against arbitrary symmetric function leakage from the shares. In addition, we present an efficiently computable score function that quantifies its security against leakages, enabling users to test and certify its security. Finally, we derive a relationship between the leakage resilience of inner-product masking and additive masking over arbitrary fields; roughly speaking, they are at least as secure as additive masking. Our approach is Fourier-analytic and involves estimating spectral norms of the Hamming slice by studying Krawtchouk polynomials.

Cite as

Aniruddha Biswas, Jihun Hwang, Hemanta K. Maji, and Xiuyu Ye. Resilience of Inner-Product Masking Scheme Against Hamming Weight Leakage. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 9:1-9:23, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{biswas_et_al:LIPIcs.ITC.2026.9,
  author =	{Biswas, Aniruddha and Hwang, Jihun and Maji, Hemanta K. and Ye, Xiuyu},
  title =	{{Resilience of Inner-Product Masking Scheme Against Hamming Weight Leakage}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{9:1--9:23},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.9},
  URN =		{urn:nbn:de:0030-drops-271023},
  doi =		{10.4230/LIPIcs.ITC.2026.9},
  annote =	{Keywords: Local leakage resilience, additive masking, inner product masking, Hamming weight leakage, Fourier analysis, Krawtchouk polynomials}
}
Document
When Does Quantum Differential Privacy Compose?

Authors: Daniel Alabi and Theshani Nuradha


Abstract
Composition is a cornerstone of classical differential privacy, enabling strong end-to-end guarantees for complex algorithms through composition theorems (e.g., basic and advanced). In the quantum setting, however, privacy is defined operationally against arbitrary measurements, and classical composition arguments based on scalar privacy-loss random variables no longer apply. As a result, it has remained unclear when meaningful composition guarantees can be obtained for quantum differential privacy (QDP). In this work, we clarify both the limitations and possibilities of composition in the quantum setting. We first show that classical-style composition fails in full generality for POVM-based approximate QDP: even quantum channels that are individually perfectly private can completely lose privacy when combined through correlated joint implementations. We then identify a setting in which clean composition guarantees can be restored. For tensor-product channels acting on product neighboring inputs, we introduce a quantum moments accountant based on an operator-valued notion of privacy loss and a matrix moment-generating function. Although the resulting Rényi-type divergence does not satisfy a data-processing inequality, we prove that controlling its moments suffices to bound measured Rényi divergence, yielding operational privacy guarantees against arbitrary measurements. This leads to advanced-composition-style bounds with the same leading-order behavior as in the classical theory. Our results demonstrate that meaningful composition theorems for quantum differential privacy require carefully articulated structural assumptions on channels, inputs, and adversarial measurements, and provide a principled framework for understanding which classical ideas do and do not extend to the quantum setting.

Cite as

Daniel Alabi and Theshani Nuradha. When Does Quantum Differential Privacy Compose?. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 10:1-10:22, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{alabi_et_al:LIPIcs.ITC.2026.10,
  author =	{Alabi, Daniel and Nuradha, Theshani},
  title =	{{When Does Quantum Differential Privacy Compose?}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{10:1--10:22},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.10},
  URN =		{urn:nbn:de:0030-drops-271036},
  doi =		{10.4230/LIPIcs.ITC.2026.10},
  annote =	{Keywords: Quantum Information, Differential Privacy}
}
Document
Adaptive Garbled Circuits and Garbled RAM from Non-Programmable Random Oracles

Authors: Cruz Barnum, David Heath, Vladimir Kolesnikov, and Rafail Ostrovsky


Abstract
Garbled circuit techniques secure in the adaptive setting - where inputs are chosen after a garbled program is sent - are motivated by practice, but they are difficult to achieve. Prior adaptive garbling is either impractically expensive or encrypts the garbled program with the output of a programmable random oracle (PRO). This latter approach introduces a strong model and incurs computational overhead. We present a simple framework for proving adaptive security of garbling schemes in the non-programmable random oracle (NPRO) model. NPRO is a milder model than PRO, and it is close to the assumption required by the widely used Free XOR extension. Our framework is applicable to a number of existing GC techniques, which are proved adaptively secure without modification (and hence incurring no overhead). As our main application, we construct and prove adaptively secure a garbling scheme for tri-state circuits, a model that captures both Boolean circuits and RAM programs (Heath et al., Crypto 2023). For TSC C, our garbling of C is at most |C|⋅ λ bits long, for security parameter λ. This implies both an adaptively secure garbled Boolean circuit scheme, and an adaptively secure garbled RAM scheme where the garbling of a T-step RAM program has size O(T ⋅ log³ T ⋅ log log T ⋅ λ) bits. Our scheme is concretely efficient: its Boolean circuit handling matches the performance of half-gates, and it is adaptively secure from NPRO.

Cite as

Cruz Barnum, David Heath, Vladimir Kolesnikov, and Rafail Ostrovsky. Adaptive Garbled Circuits and Garbled RAM from Non-Programmable Random Oracles. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 11:1-11:21, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{barnum_et_al:LIPIcs.ITC.2026.11,
  author =	{Barnum, Cruz and Heath, David and Kolesnikov, Vladimir and Ostrovsky, Rafail},
  title =	{{Adaptive Garbled Circuits and Garbled RAM from Non-Programmable Random Oracles}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{11:1--11:21},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.11},
  URN =		{urn:nbn:de:0030-drops-271048},
  doi =		{10.4230/LIPIcs.ITC.2026.11},
  annote =	{Keywords: Adaptive Garbling, Garbled RAM, Random Oracle Model}
}
Document
Partial Derandomization for Leakage-Resilient Shamir’s Secret Sharing over Composite Order Fields

Authors: S. Venkitesh


Abstract
We make progress on the question of constructing explicit evaluation places for leakage-resilient Shamir’s secret sharing, over composite order fields. Previously, Maji et al. (EUROCRYPT 2024) showed that random evaluation places yield Shamir’s secret sharing over the composite order field 𝔽_{p^d} that is statistically secure against physical bit leakage. Later, Nguyen (EUROCRYPT 2025) established a dichotomy that linear code-based secret-sharing scheme over the field 𝔽_{p^d} is either statistically secure or completely insecure against such leakage. Building upon Nguyen’s dichotomy, we present a partial derandomization of evaluation places, improving upon the Maji et al. result for a restricted regime of parameters. We replace the random choice of n independent evaluation places by the iterates x_j = Φ^j(x₀) of a simple fixed rational function Φ, where the initial point x₀ ∈ 𝔽_{p^d}^* is randomly chosen. The randomness in the evaluation places thus drops from nd log p bits to dlog p bits. Our construction is valid for the regime n = O(d/log_p d), and any reconstruction threshold k ≥ 2; in fact, the scheme attains perfect security (statistical distance exactly zero) against single-block leakage. Building on Nguyen’s dichotomy, our technique is a partial-fraction non-degeneracy argument that exploits the distinct poles of the rational iterates.

Cite as

S. Venkitesh. Partial Derandomization for Leakage-Resilient Shamir’s Secret Sharing over Composite Order Fields. In 7th Conference on Information-Theoretic Cryptography (ITC 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 385, pp. 12:1-12:19, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{venkitesh:LIPIcs.ITC.2026.12,
  author =	{Venkitesh, S.},
  title =	{{Partial Derandomization for Leakage-Resilient Shamir’s Secret Sharing over Composite Order Fields}},
  booktitle =	{7th Conference on Information-Theoretic Cryptography (ITC 2026)},
  pages =	{12:1--12:19},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-426-0},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{385},
  editor =	{Dodis, Yevgeniy},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.12},
  URN =		{urn:nbn:de:0030-drops-271059},
  doi =		{10.4230/LIPIcs.ITC.2026.12},
  annote =	{Keywords: Shamir’s secret sharing, leakage resilience, physical bit probing, physical bit leakage, secure evaluation places, rational functions}
}

Filters


Any Issues?
X

Feedback on the Current Page

CAPTCHA

Thanks for your feedback!

Feedback submitted to Dagstuhl Publishing

Could not send message

Please try again later or send an E-mail