IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
02 August 2013
Telecom ParisTech, Communication and Electrical Engineering Department, Sophia-Antipolis, France
We are looking for a postdoctoral researcher to contribute a project named LibreCloud on self hosted, distributed, redundant and secured cloud services. The main goal of the LibreCloud project is to help end users to better control their personal information and data, at a very low cost and with the quality of service of a commercial cloud solution.
The LibreCloud project aims at packaging a GNU/Linux distribution tailored for cheap and power efficient personal computers (Raspberry Pi, Parallella, Plug Computers). The distribution shall be easy to install and manage and shall embed the largest possible set of services (agenda, notes, address books, bookmarks, keyring, storage, e-mail,...) that are usually found on commercial cloud infrastructures. Its main characteristics shall be strong security (privacy, confidentiality, integrity) and safety (redundancy, backups, continuous availability across time and space).
Qingji Zheng, Shouhuai Xu, Giuseppe Ateniese
However, since the cloud is not fully trusted, the outsourced data should be encrypted, which brings a range of problems, such as: How can authorized data users search over a data owner\'s outsourced encrypted data?
How should a data owner grant search capabilities to data users?
How can data users be assured that the cloud faithfully executed the search operations? Towards ultimately addressing these problems, in this paper we propose a novel cryptographic scheme, called {\\em verifiable attribute-based keyword search} (\\vabks). This scheme
allows a data user, whose attributes or credentials satisfy a data owner\'s access control policy,
to (i) search over the data owner\'s outsourced encrypted data,
(ii) outsource the tedious search operations to the cloud, and
(iii) verify whether the cloud has faithfully executed the search operations.
We define \\vabks\'s security properties, and present concrete constructions that are proven to possess these properties. Performance evaluation shows that the proposed schemes are practical.
Reza Hooshmand, Masoumeh Koochak Shooshtari, Mohammad Reza Aref
Stephan Neumann, Christian Feier, Melanie Volkamer, Reto Koenig
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay
01 August 2013
Zongbin Liu, Neng Gao, Jiwu Jing, Peng Liu
result is so far the best outcome. It can be assumed that hardware implementations of ZUC following our architecture will fit in future LTE equipments better
29 July 2013
Paul Baecher, Christina Brzuska, Arno MIttelbach
We complement these latter works in several ways. First, we show that any simulator satisfying the reset indifferentiability notion must be stateless and pseudo-deterministic. Using this characterization we show that, with respect to reset indifferentiability, two ideal models are either equivalent or incomparable, that is, a model cannot be strictly stronger than the other model. In the case of the random oracle model and the ideal cipher model, this implies that the two are incomparable. Finally, we examine weaker notions of reset indifferentiability that, while not being able to allow composition in general, allow composition for a large class of multi-stage games. Here we show that the seemingly much weaker notion of 1-reset indifferentiability proposed by Luykx et al. is equivalent to reset indifferentiability. Hence, the impossibility of coming up with a reset indifferentiable construction transfers to the setting where only one reset is permitted, thereby re-opening the quest for an achievable and meaningful notion in between the two variants.
Rafik Chaabouni
27 July 2013
University of Bristol
- Analysis of “real world” protocols
- Formal Methods applied to security protocols
- Fully Homomorphic Encryption
- Lattice Based Cryptography
- Provable Security, i.e. Protocol and Mechanism design
- Multi-Party Computation
You will hold a PhD, or expect to be awarded soon, and have experience in one of the sub-areas of cryptography mentioned above.
You will have a good level of analytical skills and the ability to communicate complex information clearly, both orally and through the written word together with the ability to use personal initiative, and creativity, to solve problems encountered in the research context.
Ideally, you will also have a strong publication record in top relevant venues, such as the IACR conferences and journal, ACM-CCS, IEEE S&P, ESORICS, etc
Appointment may be made at the Research Assistant (grade I) or Research Associate (grade J) level depending on skills and experience and will be for 2 to 3 years in the first instance.
LIX, École polytechnique, France
We are looking for a postdoctoral researcher to participate in Project CATREL (theoretical and practical improvements for algorithms for breaking discrete logarithms over finite fields). This two-year position is with the GRACE team at the École polytechnique (in the southern suburbs of Paris), starting no later than January 1, 2014.
For more information, see
http://catrel.loria.fr/
http://catrel.loria.fr/positions.en.html
http://www.lix.polytechnique.fr/cryptologie/
Candidates should have a PhD in number theory or computer science.
Good programming skills and knowledge of number theory are essential; experience in C/C++ development, algorithmic number theory, and computer algebra systems (such as Magma, Sage, Pari-GP, etc) would be an advantage.
26 July 2013
Purushothama B R, B B Amberker
Florian Böhl, Véronique Cortier, Bogdan Warinschi
In this paper we provide techniques for bypassing the perceived limitations of deduction soundness and demonstrate that it enjoys vastly improved composition properties. More precisely, we show that a deduction sound implementation can be modularly extended with all of the basic cryptographic primitives (symmetric/asymmetric encryption, message authentication codes, digital signatures, and hash functions). We thus obtain the first soundness framework that allows for the joint use of multiple instances of all of the basic primitives.
In addition, we show how to overcome an important restriction of the bare deduction soundness framework which forbids sending encrypted secret keys. In turn, this prevents its use for the analysis of a large class of interesting protocols (e.g. key exchange protocols). We allow for more liberal uses of keys as long as they are hidden in a sense that we also define. All primitives typically used to send secret data (symmetric/asymmetric encryption) satisfy our requirement which we also show to be preserved under composition.
Joppe W. Bos, Craig Costello, Michael Naehrig
23 July 2013
Chalmers University of Technology, Gothenburg, Sweden
More concretely, part of the research will involve the analysis and development of authentication protocols in specific settings. This will include investigating resistance of both existing and novel protocols against different types of attacks, theoretically and experimentally. In addition to investigating established settings, such as RFID authentication, the research will also explore more general authentication problems, such as those that arise in the context of trust in social networks, smartphone applications and collaborative data processing. This will be done by grounding the work in a generalised decision-making framework. The project should result in the development of theory and authentication mechanisms for noisy, constrained settings that strike an optimal balance between reliable authentication, privacy-preservation and resource consumption. Some previous research related to this research project can be found here: http://lasecwww.epfl.ch/~katerina/Publications.html
Applicants for the position shall have a Master’s Degree or corresponding in Computer Science, Informatics, Telecommunications or in a related discipline. A master\\\'s degree in information security or cryptography is a bonus.
Amit Sahai, Brent Waters
to apply indistinguishability obfuscation towards cryptographic
problems. We use this technique to carry out a systematic study of
the applicability of indistinguishability obfuscation to a variety of
cryptographic goals. Along the way, we resolve the 16-year-old open
question of Deniable Encryption, posed by Canetti, Dwork, Naor,
and Ostrovsky in 1997: In deniable encryption, a sender who is forced
to reveal to an adversary both her message and the randomness she used
for encrypting it should be able to convincingly provide ``fake\'\'
randomness that can explain any alternative message that she would
like to pretend that she sent. We resolve this question by giving the
first construction of deniable encryption that does not require
any pre-planning by the party that must later issue a denial.
In addition, we show the generality of our punctured programs
technique by also constructing a variety of core cryptographic objects
from indistinguishability obfuscation and one-way functions (or close
variants). In particular we obtain: public key encryption, short
``hash-and-sign\'\' selectively secure signatures, chosen-ciphertext
secure public key encryption, non-interactive zero knowledge proofs
(NIZKs), injective trapdoor functions, and oblivious transfer. These
results suggest the possibility of indistinguishability
obfuscation becoming a ``central hub\'\' for cryptography.
Tancrède Lepoint, Matthieu Rivain
In this paper, we describe a new attack against the original implementation of Chow et al. (SAC 2002), which efficiently recovers the AES secret key as well as the private external encodings in complexity $2^{22}$. Compared to the previous attack due to Billet et al. (SAC 2004) of complexity $2^{30}$, our attack is not only more efficient but also simpler to implement. Then, we show that the \\emph{last} candidate white-box AES implementation due to Karroumi (ICISC 2010) can be broken by a direct application of either Billet et al. attack or ours. Specifically, we show that for any given secret key, the overall implementation has the \\emph{exact same} distribution as the implementation of Chow et al. making them both vulnerable to the same attacks.
By improving the state of the art of white-box cryptanalysis and putting forward new attack techniques, we believe our work brings new insights on the failure of existing white-box implementations, which could be useful for the design of future solutions.
22 July 2013
Bin Wang, Xiaojing Hong
Ryad Benadjila, Jian Guo, Victor Lomné, Thomas Peyrin
In this article, we explore general software implementations of lightweight ciphers on x86 architectures, with a special focus on LED, Piccolo and PRESENT. First, we analyze table-based implementations, and we provide a theoretical model to predict the behavior of various possible trade-offs depending on the processor cache latency profile. We obtain the fastest table-based implementations for our lightweight ciphers, which is of interest for legacy processors. Secondly, we apply to our portfolio of primitives the vperm implementation trick for 4-bit Sboxes, which gives good performance, extra side-channels protection, and is quite fit for many lightweight primitives. Finally, we investigate bitslice implementations, analyzing various costs which are usually neglected (bitsliced form (un)packing, key schedule, etc.), but that must be taken in account for many lightweight applications. We finally discuss which type of implementation seems to be the best suited depending on the applications profile.
Gora Adj, Alfred Menezes, Thomaz Oliveira, Francisco Rodr\\\'iguez-Henr\\\'iquez
presented new algorithms for computing discrete logarithms in finite
fields of small and medium characteristic. We show that these new
algorithms render the finite field $\\Fmain = \\FF_{3^{3054}}$ weak for
discrete logarithm cryptography in the sense that discrete logarithms
in this field can be computed significantly faster than with the
previous fastest algorithms. Our concrete analysis shows that the
supersingular elliptic curve over $\\FF_{3^{509}}$ with embedding degree
6 that had been considered for implementing pairing-based cryptosystems
at the 128-bit security level in fact provides only a significantly
lower level of security.