International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

02 July 2013

Benny Applebaum, Yoni Moses
ePrint Report ePrint Report
We study the problem of constructing locally computable Universal One-Way Hash Functions (UOWHFs) $\\mathcal{H}:\\{0,1\\}^n \\rightarrow \\{0,1\\}^m$. A construction with constant \\emph{output locality}, where every bit of the output depends only on a constant number of bits of the input, was established by [Applebaum, Ishai, and Kushilevitz, SICOMP 2006]. However, this construction suffers from two limitations: (1) It can only achieve a sub-linear shrinkage of $n-m=n^{1\\epsilon}$; and (2) It has a super-constant \\emph{input locality}, i.e., some inputs influence a large super-constant number of outputs. This leaves open the question of realizing UOWHFs with constant output locality and linear shrinkage of $n-m= \\epsilon n$, or UOWHFs with constant input locality and minimal shrinkage of $n-m=1$.

We settle both questions simultaneously by providing the first construction of UOWHFs with linear shrinkage, constant input locality, and constant output locality. Our construction is based on the one-wayness of ``random\'\' local functions -- a variant of an assumption made by Goldreich (ECCC 2000). Using a transformation of [Ishai, Kushilevitz, Ostrovsky and Sahai, STOC 2008], our UOWHFs give rise to a digital signature scheme with a minimal \\emph{additive} complexity overhead: signing $n$-bit messages with security parameter $\\kappa$ takes only $O(n+\\kappa)$ time instead of $O(n\\kappa)$ as in typical constructions. Previously, such signatures were only known to exist under an \\emph{exponential} hardness assumption.

As an additional contribution, we obtain new locally-computable hardness amplification procedures for UOWHFs that preserve linear shrinkage.

Expand
Mihir Bellare, Viet Tung Hoang, Sriram Keelveedhi
ePrint Report ePrint Report
This paper provides a (standard-model) notion of security for (keyed) hash functions, called UCE, that we show enables instantiation of random oracles (ROs) in a fairly broad and systematic way. Goals and schemes we consider include deterministic PKE; message-locked encryption; hardcore functions; point-function obfuscation; OAEP; encryption secure for key-dependent messages; encryption secure under related-key attack; proofs of storage; and adaptively-secure garbled circuits with short tokens. We can take existing, natural and efficient ROM schemes and show that the instantiated scheme resulting from replacing the RO with a UCE function is secure in the standard model. In several cases this results in the first standard-model schemes for these goals. The definition of UCE-security itself is quite simple, asking that outputs of the function look random given some \'leakage\', even if the adversary knows the key, as long as the leakage does not permit the adversary to compute the inputs.

Expand
Rafik Chaabouni
ePrint Report ePrint Report
The Wired Equivalent Protocol is nowadays considered as unsafe. However the only academic research that tries to break WEP has been done by Fluhrer, Mantin and Shamir, who have published a report on a specific attack. Nevertheless, an unknown person under the pseudonym Korek has published 17 attacks, which are now used by both AirCrack and WepLab. For a network with average load traffic, the FMS attack would need roughfly 40 days in order to find the key (4 millions packets needed), whereas Korek\'s attacks in addition to stimulation of the network load, reduce this time under 15 minutes (325\'000 packets needed) for a 128 bits key (104 bits secret key). We analyzed these attacks, gave a mathematical description of them and explained a new attack, in order to identify new ones.

Expand
Mihir Bellare, Viet Tung Hoang, Sriram Keelveedhi, Phillip Rogaway
ePrint Report ePrint Report
We advocate schemes based on fixed-key AES as the best route to highly

efficient circuit-garbling. We provide such schemes making only one AES call per garbled-gate evaluation. On the theoretical side, we justify the security of these methods in the random-permutation model, where parties have access to a public random permutation. On the practical side, we provide the JustGarble system, which implements our schemes.

JustGarble evaluates moderate-sized garbled-circuits at an amortized

cost of 23.2 cycles per gate (7.25 nsec), far faster than any prior reported results.

Expand
University of Washington Tacoma, USA, Earth
Job Posting Job Posting
The Institute of Technology at the University of Washington Tacoma is seeking applications for five full-time, tenure-track Associate/Assistant Professor positions for the Computer Science and Systems program and the Information Technology and Systems program. A Ph.D. or foreign equivalent in Computer Science, Information Technology, Information Systems or related field is required. Applicants should have experience in teaching and in externally-funded research. Our priority areas for research are (1) information assurance and cybersecurity – 2 positions, (2) data analytics – AI/intelligent systems, (3) CS theory/algorithms, and (4) spatial data/GIS; other areas will also be considered, especially if they are related to needs of the other Institute of Technology programs. Successful candidates will have demonstrated experience or promise for strong potential in research (as evidenced by publications). Evidence of potential to build strong relationships with partners in the technology industry and in developing collaborative research programs is highly desirable.

Applications should be submitted electronically to https://secure.interfolio.com/apply/21679 and include (1) a cover letter describing academic qualifications and experience for this position, (2) a statement of the candidate’s research program, (3) a list of publications, (4) a description of teaching philosophy, including a list of courses the candidate is qualified to teach, (5) evidence of teaching effectiveness, (6) a curriculum vitae, and (7) at least three letters of reference. Screening of applications will begin on October 15, 2013, and will continue until the positions are filled. Salary is competitive and will be commensurate with experience and qualifications.

Expand

01 July 2013

PhD Database PhD Database
Name: Viet Tung Hoang
Topic: Foundations of garbled circuits
Category: foundations

Description:

\r\nGarbled circuits, a classical idea rooted in the work of Andrew Yao, have long been understood as a cryptographic technique, not a cryptographic goal. Here we cull out a primitive corresponding to this technique. We call it a garbling scheme. We provide a provable-security treatment for garbling schemes, endowing them with a versatile syntax and multiple security definitions. The most basic of these, privacy, suffices for two-party secure function evaluation (SFE) and private function evaluation (PFE). We next consider obliviousness and authenticity, properties needed for private and verifiable outsourcing of computation. Starting from a PRF, we give efficient schemes to achieve all security notions above, and analyze their concrete security. Our treatment of garbling schemes provides ground for more efficient garbling, more rigorous analyses, and more modularly designed higher-level protocols.\r\n

\r\nOn the practical side, we provide extremely efficient garbling schemes based on fixed-key AES. We justify the security of these methods in the random-permutation model, where parties have access to a public random permutation, and build the JustGarble system to implement them. JustGarble evaluates moderate-sized garbled circuits at an amortized cost of 23.2 cycles per gate (7.25 nsec), far faster than any prior reported results.\r\n

\r\nStandard constructions of garbling schemes, including ours, provide only static security, meaning the input x is not allowed to depend on the garbled circuit F. But some application—notably one-time programs (Goldwasser, Kalai, and Rothblum2008) and secure outsourcing (Gennaro, Gentry, Parno 2010)—need adaptive security, where x may depend on F. We identify gaps in proofs from these papers with regard to adaptive security, which signifies the absence of a good abstraction boundary. We then investigate adaptive security of garbling schemes, giving definitions encompassing privacy, authenticity, and obliviousness,[...]

Expand
PhD Database PhD Database
Name: Phillip Rogaway
Topic: The Round Complexity of Secure Protocols
Category: foundations

Expand
PhD Database PhD Database
Name: Jeroen Doumen
Topic: Some Applications of Coding Theory in Cryptography
Expand
PhD Database PhD Database
Name: Prof.dr.ir. H.C.A. van Tilborg
Expand
Rockley, Christ Church, Barbados, March 3 - March 7
Event Calendar Event Calendar
Submission: 25 October 2013
Notification: 15 December 2013
From March 3 to March 7
Location: Rockley, Christ Church, Barbados
More Information: http://ifca.ai/fc14/index.html
Expand

30 June 2013

Conference Report Conference Report

6th International Conference on Information Theoretic Security (ICITS 2012)

ICITS 2012 was held from August 15 to 17, 2012 in Montréal (Canada). The organizing committee included Adam D. Smith (Program Chair), Jürg Wullschleger (General Chair), Alain Tapp, Claude Crépeau and Olivier Coutu.

It is a conference about all aspects of information-theoretic security. Its aim is to bring together researchers from all over the world from the areas of cryptography, information theory and quantum information. The conference was created as a successor of the “IEEE Information Theory Workshop on Theory and Practice in Information-Theoretic Security” on Awaji Island, Japan, and takes place every 18 month, alternating between Asia, Europe and North America. Previous ICITS conferences were held in Madrid (Spain), Calgary (Canada), Shizuoka (Japan) and Amsterdam (The Netherlands).

As in previous ICITS conferences, the plenary talks were given by the leading researchers in the field. This year, these talks were given by Serge Fehr (CWI Amsterdam), Patrick Hayden (McGill University), Negar Kiyavash (University of Illinois at Urbana-Champaign), Xin Li (University of Washington), Krzysztof Pietrzak (IST Austria) and Salil Vadhan (Harvard University).

The usual process for conferences in Computer Science is that all submitted papers first undergo a careful reviewing process, and all papers that are accepted are not only presented at the conference, but they also appear in the conference’s proceedings. Previous ICITS conferences also used this format, but it turned out not to be optimal for information theorists and physicists. For this years ICITS, the organizers therefore decided to make a special “workshop track,” in addition to the more standard “conference track,” where the speakers needed to submit only a one-page abstract which will appear in the proceedings. This new format with both a conference and a workshop track was a big success, both in quality and quantity, and having as additional track also increased the number of participants.

The ICITS 2013 will take place in Singapore, from November 28 to 30, 2013.

Expand
PhD Database PhD Database
Name: Yossef Oren
Topic: Secure Hardware - Physical Attacks and Countermeasures
Category: implementation

Description: Any cryptographic functionality, such as encryption or authentication, must be implemented in the real world before it can be put to practical use. This implementation typically takes the form of either a software implementation for a general-purpose device such as a personal computer, or as a dedicated secure hardware device, whose main purpose is to embody the cryptographic functionality. Examples of such secure hardware devices include smart cards, car alarm key fobs and computerized ballots. To evaluate the security of a cryptographic system, researchers look for flaws which allow an attacker to break the security assumptions of the system (for example, allowing an unauthorized party to view or modify a message intended for someone else). Physical attacks (also called implementation attacks) compromise the system by taking advantage of the physical aspects of the algorithm\'s implementation. Some physical attacks (such as, for example, power analysis) recover the secret key used by the secure device by analyzing physical effects produced during its use; Others (such as, for example, relay attacks) disable or otherwise limit its secure behaviour by exploiting design or implementation flaws or by changing the underlying assumptions made by the designers of the system. \r\n
\r\nThis research focuses on physical attacks on secure hardware devices and on countermeasures which protect against these attacks. My goals were to investigate vulnerabilities in current secure hardware implementations and to evaluate the effectiveness of current and proposed countermeasures against these vulnerabilities. The two main tracks of my research are side-channel analysis (and explicitly power analysis) and secure RFID.\r\n
\r\nIn the side-channel analysis track, I investigated ways of reducing the data requirements of power analysis attacks. We showed how to mount key recovery attacks on a secure device using an extremely low amount of measurement data. The main novelty of our[...]
Expand
PhD Database PhD Database
Name: Avishai Wool
Topic: Quorum Systems for Distributed Control Protocols
Category: foundations

Expand

29 June 2013

Forum Post Forum Post
Actually, what I was proposing is largely orthogonal to current "two-stage" review systems. My point was to have a system where authors and fellow PC members review the reviewers. Furthermore, this review would cause bad reviewers to lose the right to publish their own work at future top conferences. This would create (I think) a powerful incentive for reviewers to spend the time to craft better reviews -- at the very least, to understand better technically what is going on in a paper that they are supposed to be reviewing. -- Finally, coming back to the points raised in this thread about multi-stage reviews: At TCC 2013 this year, we tried out a system which allowed for *freeform* interaction between PC members and authors (i.e. a "poly-stage" review process). In my opinion as the PC chair with a global view of what happened, this interaction was extremely helpful, especially with papers that were "on the edge", or were misunderstood during the review process. --Amit From: 2013-29-06 06:34:34 (UTC)
Expand

28 June 2013

Buenos Aires, Argentina, March 26 - March 28
PKC PKC
Submission: 4 October 2013
Notification: 16 December 2013
From March 26 to March 28
Location: Buenos Aires, Argentina
More Information: http://www.iacr.org/workshops/pkc2014/
Expand
London (Royal Holloway University of London, Egham), United Kingdom, September 12 - September 13
Event Calendar Event Calendar
Submission: 21 July 2013
Notification: 16 August 2013
From September 12 to September 13
Location: London (Royal Holloway University of London, Egham), United Kingdom
More Information: http://workshop13.tclouds-project.eu/
Expand
University of Twente, The Netherlands
Job Posting Job Posting

The Centre for Telematics and Information Technology (CTIT) at the University of Twente invites applications for a 4-year PhD position in cryptographically enforced privacy in electronic healthcare starting immediately. The position is funded by the THeCS project (Trusted HealthCare Services) as part of the Dutch national program COMMIT (www.commit-nl.nl).

The PhD candidate will be working with Prof. Pieter Hartel and Andreas Peter from the Distributed and Embedded Security Group (DIES, dies.ewi.utwente.nl) and with Prof. Willem Jonker from the Database Group (www.utwente.nl/ewi/db) of the University of Twente. The candidate will be expected to do active and internationally visible research on modern topics of applied cryptography and cryptographic protocols with a focus on privacy in electronic healthcare. The PhD candidate will be appointed for a period of four years, at the end of which he/she must have completed a PhD thesis. During this period, the PhD student has the opportunity to broaden his/her knowledge by joining international exchange programs, to participate in national and international conferences and workshops, and to visit other research institutes and universities worldwide.

Successful candidates must hold an outstanding M.Sc. degree (or equivalent) from the university study of Information Security/Cryptology, Mathematics, Computer Science, or similar. Applications from students that are about to finish their master thesis will be accepted as well. The candidate is expected to have excellent skills in the English language.

The position will be closed as soon as a suitable candidate is found. Applications must include:

  • CV and academic transcript (with grades)
  • motivation letter (including a description of prior activities with relevance to cryptography or information security)
  • <

Expand
TU Darmstadt, Germany, EEA
Job Posting Job Posting
The Engineering Cryptographic Protocols Group in the Fachbereich Informatik of the Technische Universität Darmstadt is currently offering a position for a

Research Assistant in Engineering Cryptographic Protocols for Cloud Computing

with the goal to further develop the group\\\'s expertise in the area of engineering of cryptographic protocols, in particular for cloud computing environments. The position is initially assigned for 6 months, in which existing techniques for secure computation should be compared with regard to usage in cloud computing. In case third party funds are required, we aim to extend the position for up to three years and support the researcher to enroll in the Ph.D. program at Technische Universität Darmstadt.

Applicants must have completed (or be close to completing) a Master or Diplom with excellent grades in IT Security, Computer Science, Mathematics, Electrical Engineering, or a closely related subject. Knowledge in applied cryptography, IT security and programming skills are required. Additional knowledge in parallel computing, compiler construction, programming languages, and/or software engineering is a plus. We expect applicants to be highly qualified, self-motivated, and to conduct excellent, independent research within the context of EC SPRIDE, and actively support them in publishing their work on leading international conferences and journals.

Review of applications will start on July 10th, 2013 and applications will be accepted until the position has been filled.

Expand

27 June 2013

Fuzhou, China, May 12 - May 14
Event Calendar Event Calendar
Submission: 2 December 2013
Notification: 3 February 2014
From May 12 to May 14
Location: Fuzhou, China
More Information: http://icsd.i2r.a-star.edu.sg/ispec2014/
Expand

25 June 2013

University College London, United Kingdom, European Union
Job Posting Job Posting
We are looking for outstanding candidates for a fully funded PhD studentship in cryptography. The PhD studentship is funded by an ERC Starting Grant on Efficient Cryptographic Arguments and Proofs. The studentship will provide a tax-free annual stipend of £21,000, however, ERC funding does not cover student fees (currently £4,400 for UK/EU students and £20,250 for Overseas students).

The goal of the PhD studentship under the supervision of Dr Jens Groth is to develop new and efficient zero-knowledge techniques. Zero-knowledge proofs enable a prover to convince a verifier that a statement is true without revealing any other information and are widely used in cryptographic protocols.

University College London has been recognized by the EPSRC and GCHQ as an Academic Centre of Excellence in Cyber Security Research and is one of the highest ranked universities in Europe. The Computer Science Department is one of the largest in the UK and is located at UCL\\\'s main campus in the centre of London.

Expand
◄ Previous Next ►