Public-Key Cryptography
| Status | Statement | Tags |
|---|---|---|
|
CPA PKE, Quantumly Broken The first item in the source’s Open Problems section. It builds counterexamples for PRFs, CPA-secure symmetric-key encryption, MACs, signatures and CCA-2-secure public-key encryption, all classically secure under LWE via black-box reductions and all quantumly broken with two or three classical queries. CPA-secure public-key encryption is the case its technique cannot reach, and it says why. 4 open |
Black Box SeparationsLearning With ErrorsQuantum Cryptographyseparation | |
|
Four-party NIKE, quadratic, Maurer’s model Open. Achieved in Shoup’s generic group model by the source paper (Construction 9, Theorem 10); in Maurer’s model the paper’s own O(n^2) attack sets a ceiling that a construction would meet exactly, and nothing is known about reaching it. 5 open |
Generic Group ModelNon Interactive Key Exchangeggmseparation | |
|
Quadratic attack on 3-NIKE, Shoup’s model Open in Shoup’s model. Settled by the source paper in Maurer’s model for every K at least 3, including imperfect correctness; its own three-party Shoup construction achieves only an n^1.5 gap, so the truth for three parties lies somewhere between n^1.5 and n^2. 5 open |
Generic Group ModelNon Interactive Key Exchangeggmlower-bound | |
|
Two-scheme key cycle Open in both directions, and the source paper says why the existing separations miss it: the counterexamples fix both schemes, whereas here the second is chosen after the first. Two hypotheses left implicit in the printed statement have to be added before it is even non-vacuous. 7 open |
Circular SecurityFully Homomorphic Encryptionassumption | |
|
1+1 adaptively secure lattice threshold signature Resolved. Oriole (Jiang, Wee, Zhu, ePrint 2026/793, posted April 2026, a month after Tweed) gives a lattice-based threshold signature with exactly this shape – two rounds, only the second message-dependent, adaptive security against T-1 corruptions with no erasures, from MSIS and MLWE in the ROM – verified here directly against the paper’s PDF (Definition of adp-TS-sUF-4 in its Figure 4, and the Theorem 2 + Theorem 3 reduction chain to MSIS), not just its abstract. The proof is human-written and published, but not yet independently re-verified line-by-line by this site, nor formalized in Lean. |
Learning With ErrorsThreshold SignaturesTight Reductionsromseparationresearch-solved | |
|
Sublinear-Time CGKA Refresh The source achieves worst-case sublinear communication with forward secrecy, but its refresh algorithms still run in time polynomial in the group size, and it leaves open, without committing to a specific target rate, whether sublinear-time refresh is achievable at all. 4 open |
Broadcast EncryptionContinuous Group Key Agreementcharacterization | |
|
r-round DLOG tradeoff Open for every intermediate r: the r = 1 endpoint is the source’s own theorem and r = T is Corrigan-Gibbs–Kogan, with nothing proved in between. The source conjectures the interpolating formula and says a matching attack exists at every r, so the missing half is the lower bound. 6 open |
AdaptivityDiscrete LogarithmGeneric Group ModelTime Space Tradeoffsggmtight-bound | |
|
Composability implies circular security Open with no partial result in either direction. The converse – circular security plus limited homomorphism gives full composability – is the source paper’s Theorem 6; this direction, which would make the two properties essentially equivalent, is conjectured there and nothing has been published towards it. 7 open |
Circular SecurityFully Homomorphic Encryptionequivalence | |
|
RBE needs Ω(log n) updates Refuted. Mahmoody and Qi, Online Mergers and Applications to Registration-Based Encryption and Accumulators (ITC 2023), construct an RBE scheme with O(log n / log log n) decryption updates and poly(kappa, log n) public parameters – strictly below the Omega(log n) this statement conjectured – via a fully online merger structure, matching the known lower bound exactly. The paper states this explicitly resolves the open question. 4 open |
Registration Based Encryptionlower-boundresearch-solvedadaptation (ai) | |
|
No expanding weak quadratic PRGs Open: whether every family of quadratic Λ(n)-bounded polynomials at stretch m ≥ n^{1+ε} admits an efficient distinguisher from the same evaluations plus bounded independent noise; the paper proves only the i.i.d.-nice special case (Theorem 2) and reports, without proof, that no degree-two candidate survives its attacks experimentally. 3 open |
Average Case HardnessPseudorandom Generatorsimpossibility | |
|
No key agreement from GC-OWF Open for round complexity growing with the security parameter. Proved in full for two messages, which is public-key encryption; the constant-round extension is sketched in the paper’s appendix without a theorem, its security half deferred to the PKE proof. 5 open |
Black Box SeparationsGarbled CircuitsKey Agreementotherseparationadaptation (ai) | |
|
Threshold one-shot decryption without extractability Open: whether threshold one-shot decryption (for every corruption threshold f < 1/2) follows from one-shot signatures and an ordinary, non-extractable witness encryption scheme. The one known construction needs the witness-encryption extractor to run its security reduction, and the source paper leaves open whether extractability can be weakened or dropped altogether. 4 open |
One Shot SignaturesWitness EncryptionassumptionIOG | |
|
OWFs are black-box useless for key agreement Open in the general case, which the paper names as the central open problem left by its work. Settled for three restricted protocol classes: constant-query perfect, constant-round constant-query imperfect, and Merkle-type. 5 open |
Black Box SeparationsKey AgreementOne Way Functionsotherimpossibility | |
|
OWF minimality, non-black-box reductions Open when the classical security implication is not witnessed by a black-box reduction between the two games. Settled affirmatively whenever it is, for uniform and non-uniform quantum adversaries alike, with the implementation reduction left arbitrary. 5 open |
Black Box SeparationsOne Way FunctionsQuantum Cryptographyequivalence | |
|
PKE from constant-noise planted k-XOR Open: whether public-key encryption can be based on the hardness of planted k-XOR with a linear number of equations and a constant noise rate, as a single assumption. The survey poses it as one of two closing open questions and does not return to it; every combinatorial scheme it surveys needs sub-constant noise. |
Average Case HardnessPlanted Constraint Satisfactionseparationbarrier (ai) | |
|
Ring-LWE error parity Open: whether recovering the Ring-LWE error modulo two is as hard as recovering the error itself. The easy direction is trivial; the source states it has no formal reduction for this one and relies on two heuristics instead, one of which changes the error distribution. 6 open |
Learning With Errorsequivalence | |
|
No round-optimal pairing-free blind signature Open for a polynomial query budget. The impossibility is proved when User_2 and Verify together make O(log lambda) random-oracle queries, including when oracle outputs contain group elements; the superpolynomial message space hypothesis is retained. 5 open |
Black Box SeparationsBlind SignaturesGeneric Group ModelSignature Schemesggmimpossibilityadaptation (ai) | |
|
Certifying no small non-expanding set Open: whether the non-existence of a small non-expanding set in a random unbalanced bipartite graph admits a nondeterministic certificate that is sound and complete on average, at the parameters the ABW cryptosystem uses. The survey poses it as one of two closing open questions, takes no position, and does not return to it. |
Average Case HardnessExpander Graphsseparation | |
|
Hold-Out Soundness, Dirty Coordinates The source’s distinguishing attack is unconditional and proved. Its decryption attack is heuristic, and this is the unproved step: completeness on clean coordinates is its Claim 6.2, while soundness on dirty ones is supported only by a heuristic dimension count and small-parameter experiments. 5 open |
Code Based CryptographyPrivate Information Retrievalcharacterization | |
|
Non-adaptive DDH bound Open, and asserted rather than asked: the source proves 1/2 + O~(T^2/N + sqrt(ST/N)), states twice that it conjectures this is not tight for DDH, and names 1/2 + O~(T^2/N + ST/N) as the right answer. The same theorem’s square-DDH bound is sharp, with a matching attack, which is what makes the DDH case a question rather than a suspicion. 6 open |
AdaptivityDiscrete LogarithmGeneric Group ModelTime Space Tradeoffsggmtight-boundadaptation (ai) | |
|
Three moves from DL, ROM only Open: three moves, black-box in the group, ROM only, from DL alone. Three moves is achieved from DDH in the ROM and from DL in AGM+ROM; four moves is achieved from DL in the ROM. 5 open |
Blind SignaturesRandom Oracle ModelSignature SchemesTight Reductionsromassumption | |
|
Single-session lattice Chevallier-Mames tightness Open: whether the one-session lattice translation of the Chevallier-Mames signature has a tight SUF-CMA reduction to search Module-LWE, or whether the paper’s two-fold parallel repetition (which doubles signature size and signing time) is inherent to a tight proof of this shape. 4 open |
Learning With ErrorsSignature SchemesTight Reductionsromtight-bound | |
|
RBE update bound, key-dependent schedules Resolved. Wei Qi, Tight Lower Bound on Witness Update Frequency in Additive Positive Accumulators (IACR Communications in Cryptology, 2026), generalizes the Mahmoody-Qi-Rahimi lower-bound framework to schedules that may depend on the sampled public keys themselves, via a new combinatorial structure (the falling-step sequence), and proves the same asymptotic bound holds. The paper states this explicitly resolves the open problem left in the source paper. 5 open |
Registration Based Encryptionlower-boundresearch-solvedadaptation (ai) |
No matching items