IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
22 July 2013
Karine Gandolfi-Villegas, Nabil Hamzi
used in RSA and in elliptic curves based algorithms. Due to classical
differential power analysis (DPA and CPA), a lot of countermeasures to
protect exponents have been proposed since 1999 Kocher [20] and by
Coron [13]. However, these blinding methods present some drawbacks
regarding execution time and memory cost. It also got some weaknesses.
Indeed they could also be targeted by some attacks such as The Carry
Leakage on the Randomized Exponent proposed by P.A. Fouque et al.
in [23] or inefficient against some others analysis such as Single Power
Analysis. In this article, we explain how the most used method could
be exploited when an attacker can access test samples. We target here
new dynamic blinding methods in order to prevent from any learning
phase and also to improve the resistance against the latest side channel
analyses published.
Yuval Yarom, Katrina Falkner
Zhengjun Cao
Yoni De Mulder, Peter Roelse, Bart Preneel
Sanjam Garg, Craig Gentry, Shai Halevi, Mariana Raykova, Amit Sahai, Brent Waters
Indistinguishability obfuscation requires that given any two equivalent circuits C_0 and C_1 of similar size, the obfuscations of C_0 and C_1 should be computationally indistinguishable.
In functional encryption, ciphertexts encrypt inputs x and keys are issued for circuits C. Using the key SK_C to decrypt a ciphertext CT_x = Enc(x), yields the value C(x) but does not reveal anything else about x. Furthermore, no collusion of secret key holders should be able to learn anything more than the union of what they can each learn individually.
We give constructions for indistinguishability obfuscation and functional encryption that supports all polynomial-size circuits. We accomplish this goal in three steps:
- We describe a candidate construction for indistinguishability obfuscation for NC1 circuits. The security of this construction is based on a new algebraic hardness assumption. The candidate and assumption use a simplified variant of multilinear maps, which we call Multilinear Jigsaw Puzzles.
- We show how to use indistinguishability obfuscation for NC1 together with Fully Homomorphic Encryption (with decryption in NC1) to achieve indistinguishability obfuscation for all circuits.
- Finally, we show how to use indistinguishability obfuscation for circuits, public-key encryption, and non-interactive zero knowledge to achieve functional encryption for all circuits. The functional encryption scheme we construct also enjoys succinct ciphertexts, which enables several other applications.
Behnam Mafakheri, Taraneh Eghlidos, Hossein Pilaram
Nasour Bagheri, Masoumeh Safkhani
design a secure yoking-proof protocol. In addition, conforming to those guidelines and
EPC C1 G2, they presented a yoking-proof for low-cost RFID tags, named Kazahaya. However,
in this letter, we scrutinize its security showing how an passive adversary can retrieve secret
parameters of patient\'s tag in cost of O(216) o-line PRNG evaluations. Given the tag\'s secret
parameters, any security claims are ruined. Nevertheless, to show other weaknesses of the
protocol and rule out any possible improvement by increasing the length of the used PRNG,
we presented a forgery attack that shows that a proof generated at time tn can be used to
forge a valid proof for any desired time tj . The success probability of this attack is `1\' and the
complexity is negligible.
Newcastle University, UK
The post is supported by a five-year ERC Starting Grant on \\\"Self-enforcing Electronic Voting: Trustworthy Elections in the Presence of Corrupt Authorities\\\". The candidate should have a PhD in Computer Science, engineering or a related discipline, with a solid background in security. Previous research experience on e-voting is desirable but not required.
An ideal candidate would be the one who 1) has good understanding of theory; 2) has good practical skills; 3) has a keen interest to tackle real-world problems.
London, United Kingdom, March 3 - March 5
Notification: 18 January 2014
From March 3 to March 5
Location: London, United Kingdom
More Information: http://fse2014.isg.rhul.ac.uk
18 July 2013
Shashank Agrawal, Manoj Prabhakaran
Our results include the following:
-Fair exchange cannot be securely reduced to the problem of fair coin-tossing by an r-round protocol, except with an error that is $\\Omega(1/r)$.
-Finite fair {\\em sampling} problems with rational probabilities can all be reduced to fair coin-tossing and unfair 2-party computation (or equivalently, under computational assumptions). Thus, for this class of functionalities, fair coin-tossing is complete.
-Only sampling problems which have fair protocols without any fair setup are the trivial ones in which the two parties can sample their outputs independently. Others all have an $\\Omega(1/r)$ error, roughly matching an upper bound for fair sampling from Moran et al.(TCC 2009).
-We study communication-less protocols for sampling, given another sampling problem as setup, since such protocols are inherently fair. We use spectral graph theoretic tools to show that it is impossible to reduce a sampling problem with {\\em common information} (like fair coin-tossing) to a sampling problem without (like \'noisy\' coin-tossing, which has a small probability of disagreement).
The last result above is a slightly sharper version of a classical result by Witsenhausen from 1975. Our proof reveals the connection between the tool used by Witsenhausen, namely \'maximal correlation\', and spectral graph theoretic tools like Cheeger inequality.
Jiangxiao Zhang. Hua Guo. Zhoujun Li. Chang Xu
and the commuting signatures, to obtain the user\'s unlinkability and optimal anonymity. A publisher is introduced to publish the conditions, and is firstly formalized. By dividing the deposit protocol into two parts, the anonymity of the user is obtained in the deposit protocol. Compared with the existing conditional e-cash schemes, this scheme has the constant size for the computation and communication. Finally, we give the security proof in the standard model.
Johann Heyszl, Andreas Ibing, Stefan Mangard, Fabrizio De Santis, Georg Sigl
Peter Pessl, Michael Hutter
Mitsugu Iwamoto, Junji Shikata
Yongge Wang
(e.g., SHA1, SHA2, and SHA3) and symmetric
key block ciphers (e.g., AES and TDES) have been commonly used
to design pseudorandom generators with counter modes
(e.g., in Java Crypto Library and in NIST SP800-90A standards).
It is assumed that if these primitives
are secure then the pseudorandom generators
based on these primitives are also secure. However,
no systematic research and analysis have been done
to support this assumption.
Based on complexity theoretic results for pseudorandom sequences,
this paper analyzes stochastic properties of long sequences
produced by hash function based pseudorandom generators DRBG from
NIST SP800-90A and SHA1PRNG from Java Crypto Library.
Our results show that none of these sequences satisfy the
law of the iterated logarithm (LIL) which holds
for polynomial time pseudorandom sequences. Our results also
show that if the seeds and counters for pseudorandom generators
are not appropriately chosen, then the generated sequences
have strongly biased values for LIL-tests
and could be distinguished from uniformly chosen sequences
with a high probability.
Based on these results, appropriate seeding and counter
methods are proposed for pseudorandom generator designs.
The results in this paper reveal some ``non-random\'\' behavior of
SHA1, SHA2, and of the recently announced SHA3.
17 July 2013
Charles Bouillaguet, Chen-Mou Cheng, Tung Chou, Ruben Niederhagen, Bo-Yin Yang
Salil Vadhan, Colin Jia Zheng
We describe several applications, including: a more modular and improved uniform version of Impagliazzo\'s Hardcore Theorem (FOCS \'95); regularity theorems that provide efficient simulation of distributions within any sufficiently nice convex set (extending a result of Trevisan, Tulsiani and Vadhan (CCC \'09)); an improved version of the Weak Regularity Lemma of Frieze and Kannan; a Dense Model Theorem for uniform algorithms; and showing impossibility of constructing Succinct Non-Interactive Arguments (SNARGs) via black-box reductions under uniform hardness assumptions (using techniques from Gentry and Wichs (STOC \'11) for the nonuniform setting).
16 July 2013
Washington, DC, United States, August 14 - August 16
Location: Washington, DC, United States
More Information: https://www.usenix.org/conference/usenixsecurity13
University of Luxembourg
Potential candidates should send their application by email to lacs.acrypt(at)gmail.com. The application material should contain a cover letter explaining the candidate\'s motivation and research interests, a detailed CV (including photo), a list of publications, copies of diploma certificates, and names and contact details of three references.
Positions are available from 1-September 2013.
15 July 2013
Large, prestigious Bank in Manchester, England
Head of Card Authentication Services to lead the development of cryptographic applications to further support risk operations.
You will be responsible for developing cryptographic applications utilising your SME knowledge of cryptography. You will utilise your in-depth knowledge of security models and technologies including Public-Key Infrastructure (PKI) and Hardware Security Modules (HSMs). In addition, you will have strong application development knowledge, in particular with Java and .NET technologies. You will draw upon your experience in a similar role where you have delivered change.
This role also requires experience and understanding in authentication.
To be considered for this business critical position, you will have:
* In-depth knowledge of Cryptography concepts and authentican services/practices
* Strong knowledge of PKI
* Extensive knowledge of HSMs
* Developed cryptographic applications
* Adept with Java and .NET technologies
* Delivered change focused projects
* Excellent communication and presentation skills
This is an excellent opportunity for an Information Security Specialist to further progress their knowledge and career within Information Security, for a global organisation who is renowned in the marketplace for their commitment to change.
You will be able to demonstrate your in-depth Information Security knowledge, in particular with cryptography, PKI, authentication, and HSMs. In return, you will be offered a permanent role, a package around £100,000.