Open research questions in Cryptographic Implementations and Security
119 unresolved questions extracted from the limitations and future-work sections of 262 Cryptographic Implementations and Security papers in our library. Each links back to the study that raised it.
What the literature leaves open
The bit-level grouping mode does not match the byte operation architecture of cryptographic chips. The byte-value grouping mode causes unequal sizes of traces contained in two groups, reducing the test efficiency. There is a lack of theoretical guidance for the selection of test positions.
IHOG: Interval-Optimized Hamming-Weight-Oriented Grouping for Enhanced Side-Channel Leakage Detection · 2026 · DOIKleptographic attacks on post-quantum cryptosystems (specifically CRYSTALS-Kyber) are demonstrated in principle, but no study examines the detectability, prevalence, or mitigation of such backdoors in cryptographic implementations procured or deployed by Pakistan's government, defense, or financial institutions.
The methodology developed allows for further study of the widespread impact of strategically designed attacks on traffic cybersecurity, inspiring the development of efficient attack detection techniques and advanced vehicle controls.
The separation of security and clustering leads to a compromise between two crucial concerns. Prior work has focused on either algorithmic cryptographic efficiency or network-level energy optimization, but not both.
TTEA: designing a quantum-ready and energy-conscious encryption model for secure IoT environments · 2026 · DOIThe modular design of TTEA allows flexibility in selecting PQC algorithms, but formal analysis of security implications and performance trade-offs when substituting Kyber with alternative algorithms in specific deployment scenarios is limited.
TTEA: designing a quantum-ready and energy-conscious encryption model for secure IoT environments · 2026 · DOITo evaluate the proposed methods in real-world scenarios. To improve the security of Ascon by identifying potential vulnerabilities. To propose new methods for statistical fault analysis of other lightweight cryptography standards.
Statistical fault analysis of Ascon: multiple distinguishers and impossible-state exploitation · 2026 · DOIExisting fault attacks on Ascon often require substantial fault injections. There is a need for new methods that can recover the key of Ascon with a high success rate and fewer fault injections.
Statistical fault analysis of Ascon: multiple distinguishers and impossible-state exploitation · 2026 · DOITo further analyze the security of the HM-AKA+ protocol. To explore the use of other Post-Quantum primitives in the HM-AKA+ protocol. To investigate the application of the HM-AKA+ protocol in other scenarios.
The HM-AKA scheme fails to provide security against impersonation attacks by a semi-trusted TTP. The need for a protocol that maintains the framework’s flexibility while ensuring security.
Resource constraints of IoT devices, which limit the use of computationally intensive security mechanisms. The need for real-time anomaly detection and prevention in IoT systems. The requirement for transparent and tamper-evident logging mechanisms in IoT systems.
Enhancement of IoT Security with Hybrid Cryptosystem of ECC and TinyML Integrated with Blockchain · 2026 · DOIFuture research should focus on evaluating the proposed framework in real-world scenarios and large-scale IoT deployments. Future research should investigate the use of other machine learning algorithms and cryptographic techniques in the proposed framework. Future research should explore the application of the proposed framework to other domains, such as industrial IoT and healthcare IoT.
Enhancement of IoT Security with Hybrid Cryptosystem of ECC and TinyML Integrated with Blockchain · 2026 · DOIFuture research can focus on improving the accuracy and efficiency of the proposed method. The application of deep learning in cryptanalysis can be extended to other areas, such as side-channel analysis. The security of other block ciphers can be evaluated using the proposed method.
Improved polytopic differential neural distinguishers for SIMON, SIMECK, and SPECK block ciphers · 2026 · DOIThe existing differential neural distinguishers have limitations in terms of accuracy and efficiency. There is a need for novel data generation techniques to improve the performance of neural network-based distinguishers. The security of lightweight block ciphers in IoT devices is a significant concern.
Improved polytopic differential neural distinguishers for SIMON, SIMECK, and SPECK block ciphers · 2026 · DOITraditional cryptographic algorithms are not suitable for WoT devices due to limited resources. Lightweight cryptography has emerged as a solution, but there is a need for more efficient and secure schemes.
The lack of a rigorous algebraic proof of the injectivity of the core map G. The lack of a proof of Ω(4 MB) unconditionally under the parallel ROM. The need for a standard-model reduction for high-assurance deployments.
Technical Note: The Four Core Laws of FractalShield — A Framework for Oracle-Free Verification and Geometric Cost Escalation · 2026 · DOIIrregular ShiftRows offsets in Rijndael-256. Limited performance of fixslicing beyond AES-128. Need for cipher-specific and architecture-dependent implementations.
Constant-Time Bitsliced Rijndael-256 on ARM Cortex-M4: On the Limitations of Fixslicing Beyond AES-128 · 2026 · DOIThe implementation is limited to ARM Cortex-M4 microcontrollers. The paper does not provide a comparison with other implementations of Rijndael-256.
Constant-Time Bitsliced Rijndael-256 on ARM Cortex-M4: On the Limitations of Fixslicing Beyond AES-128 · 2026 · DOIOnly sublinear polynomial fraction of edit errors are robustly handled - Requires assumptions beyond standard cryptographic ones for binary alphabet codes - Open problem remains to find a reduction with smaller distortion
High-Rate Public-Key Pseudorandom Codes for Edit Errors · 2026Find a different reduction from edit robustness to Hamming robustness with substantially smaller distortion - Direct constructions of public-key pseudorandom codes that are robust to edit errors under standard assumptions
High-Rate Public-Key Pseudorandom Codes for Edit Errors · 2026The implementation of Shor's algorithm is limited to small factoring instances (N = 15, 21). The study uses a simulator only, without hardware results.
Bridging the Quantum Threat and Post-Quantum Defense: An Empirical Study of Shor’s Algorithm and ML-KEM-768 Performance · 2026 · DOIThe gap between the current state of quantum computing and the requirements for factoring RSA-2048 is approximately four orders of magnitude in qubit count alone.
Bridging the Quantum Threat and Post-Quantum Defense: An Empirical Study of Shor’s Algorithm and ML-KEM-768 Performance · 2026 · DOITo apply the technique to other ciphers with similar structures. To evaluate the security of ciphers against differential MITM attacks. To improve the attack by introducing new techniques.
The previous best known attack on 24-round CRAFT has a limited number of rounds. The differential MITM attack is constrained by the key schedule.
Modern data validation systems face a persistent trade-off between execution speed and structural vulnerability. Merkle-Damgård constructions and sponge-based alternatives have limitations in terms of computational overhead and performance degradation.
The search method is limited to the neighbourhood of the PW functions formed by up to four-orbit combinations. The large search spaces limit the ability to perform an exhaustive search for higher number of orbit combinations.
Most-cited papers in Cryptographic Implementations and Security
- Random number generators: good ones are hard to find · Communications of the ACM · 1988 · 842 citations
- Lest we remember · Communications of the ACM · 2009 · 684 citations
- Special Feature Exhaustive Cryptanalysis of the NBS Data Encryption Standard · Computer · 1977 · 449 citations
- On the security of multiple encryption · Communications of the ACM · 1981 · 151 citations
- Secure frameproof codes, key distribution patterns, group testing algorithms and related structures · Journal of Statistical Planning and Inference · 2000 · 149 citations
- Why cryptosystems fail · Communications of the ACM · 1994 · 148 citations
- CryptDB · Communications of the ACM · 2012 · 143 citations
- FAB: An FPGA-based Accelerator for Bootstrappable Fully Homomorphic Encryption · 2023 · 128 citations
- Efficiency and Security Evaluation of Lightweight Cryptographic Algorithms for Resource-Constrained IoT Devices · Sensors · 2024 · 81 citations
- Pseudorandom bit generators in stream-cipher cryptography · Computer · 1991 · 81 citations
Most recent work
- Securing elliptic curve cryptocurrencies against quantum vulnerabilities: Resource estimates and mitigations · PRX Quantum · 2026
- Auto-Mult: A Self-Optimizing Integer Multiplier via Hybrid Decomposition and Automated Parameter Search · IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems · 2026
- Using Learning with Rounding to Instantiate Post-Quantum Cryptographic Algorithms · ACM Transactions on Embedded Computing Systems · 2026
- TTEA: designing a quantum-ready and energy-conscious encryption model for secure IoT environments · Scientific Reports · 2026
- Quantum cryptanalysis of SPN ciphers with known plaintext · npj Quantum Information · 2026
- Statistical fault analysis of Ascon: multiple distinguishers and impossible-state exploitation · Cybersecurity · 2026
- AES Using Linear Feedback Shift Register (LFSR) for Enhanced Cryptographic Performance · INTERNATIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT · 2026
- HM-AKA+: Protecting against a semi-trusted third party with Hybrid Crypto · Cryptography and Communications · 2026
- Enhancement of IoT Security with Hybrid Cryptosystem of ECC and TinyML Integrated with Blockchain · Journal of Applied Science and Technology Trends · 2026
- NeuroSnitch: Exploiting Inter-Spike Interval Statistics for Timing Side-Channel Attacks on Noisy Neuromorphic Systems · SPIRE - Sciences Po Institutional REpository · 2026
Find a gap in your own Cryptographic Implementations and Security sub-topic
This page shows what the Cryptographic Implementations and Security literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.
Open the Research Gap Finder →