IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
04 September 2013
Gilad Asharov, Yehuda Lindell, Thomas Schneider, Michael Zohner
In this work we present optimizations and efficient implementations of OT and OT extensions in the semi-honest model. We propose a novel OT protocol with security in the standard model and improve OT extensions with respect to communication complexity, computation complexity, and scalability. We also provide specific optimizations of OT extensions that are tailored to the secure computation protocols of Yao and Goldreich-Micali-Wigderson and reduce the communication complexity even further. We experimentally verify the efficiency gains of our protocols and optimizations. By applying our implementation to current secure computation frameworks, we can securely compute a Levenshtein distance circuit with 1.29 billion AND gates at a rate of 1.2 million AND gates per second. Moreover, we demonstrate the importance of correctly implementing OT within secure computation protocols by presenting an attack on the FastGC framework.
Martin Hirt, Pavel Raykov
Pablo Rauzy, Sylvain Guilley, Zakaria Najm
This failure is due to the fact that formal methods work with models rather than implementations.
Of course, we can use formal methods to prove non-functional security properties such as the absence of side-channel leakages.
But a common obstacle is that those properties are very low-level and appear incompatible with formalization.
To avoid the discrepancy between the model and the implementation, we apply formal methods directly on the implementation.
Doing so, we can formally prove that an assembly code is leak-free, provided that the hardware it runs on satisfies a finite (and limited) set of properties that we show are realistic.
We apply this technique to prove that a PRESENT implementation in 8~bit AVR assembly code is leak-free.
Ueli Maurer, Björn Tackmann, Sandro Coretti
is an important primitive in practical security protocols; a prime example is
the widely deployed TLS protocol, which is usually run in this mode.
Unilateral key-exchange protocols are employed in a client-server setting
where only the server has a certified public key. The client is then
authenticated by sending credentials via a connection that is secured with the
key obtained from the protocol. Somewhat surprisingly and despite its
importance in practical scenarios, this type of key exchange has received
relatively little attention in the cryptographic literature compared to the
type with mutual authentication.
In this work, we follow the constructive cryptography paradigm of Maurer and
Renner (ICS 2011) to obtain a (composable) security definition for
key-exchange protocols with unilateral authentication: We describe a
\"unilateral key\" resource and require from a key-exchange protocol that it
constructs this resource in a scenario where only the server is authenticated.
One main advantage of this approach is that it comes with strong composition
guarantees: Any higher-level protocol proven secure with respect to the
unilateral key resource remains secure if the key is obtained using a secure
unilateral key-exchange protocol.
We then describe a simple protocol based on any CPA-secure KEM and prove that
it constructs a unilateral key (previous protocols in this setting relied on a
CCA-secure KEM). The protocol design and our security analysis are fully
modular and allow to replace a sub-protocol $\\pi$ by a different sub-protocol
$\\pi\'$ by only proving security of the sub-protocol $\\pi\'$; the composition
theorem immediately guarantees that the security of the modified full protocol
is maintained. In particular, one can replace the KEM by a sub-protocol based
on Diffie-Hellman, obtaining a protocol that is similar to the A-DHKE protocol
proposed by Shoup. Moreover, our analysis is simpler because the actual
key-exchange part of the protocol can be analyzed in a simple three-party
setting; we show that the extension to the multi-party setting follows
generically.
Compared to the TLS handshake protocol, the \"de facto\" standard for unilateral
key exchange on the Internet, our protocol is more efficient (only two
messages) and is based on weaker assumptions.
Oleksandr Kazymyrov, Valentyna Kazymyrova
In this paper we consider a number of algebraic aspects of the GOST R 34.11. We show how one can express the cipher in AES-like form over the finite field $\\F_{2^8}$, and consider some approaches that can be used for the fast software implementation.
Zvika Brakerski, Guy N. Rothblum
We prove that the construction is a secure obfuscation in a generic multilinear group model, under the black-box definition of Barak et al.\\ (CRYPTO 2001). Security is based on a new {\\em worst-case} hardness assumption about exponential hardness of the NP-complete problem 3-SAT, the {\\em Bounded Speedup Hypothesis}.
One of the new techniques we introduce is a method for enforcing input consistency, which we call {\\em randomizing sub-assignments}. We hope that this technique can find further application in constructing secure obfuscators.
The family of functions we obfuscate is considerably richer than previous works that consider black-box obfuscation. As one application, we show how to achieve {\\em obfuscated functional point testing}: namely, to construct a circuit that checks whether $f(x)=y$, where $f$ is an arbitrary ``public\'\' polynomial-time computable function, but $y$ is a ``secret\'\' point that is hidden in the obfuscation.
Kevin Henry, Maura B. Paterson, Douglas R. Stinson
In this paper we explore this issue, with specific reference to classes of key predistribution schemes based on transversal designs. We demonstrate through experiments that, for a wide range of parameters, randomly removing keyrings in fact has a negligible and largely predictable effect on the parameters of the scheme. In order to facilitate these computations, we provide a new, efficient, generally applicable approach to computing important properties of combinatorial key predistribution schemes.
We also show that the structure of a resolvable transversal design can be exploited to give a deterministic method of removing keyrings to adjust the network size, in such a way that the properties of the resulting scheme are easy to analyse. We show that these schemes have the same asymptotic properties as the transversal design schemes on which they are based, and that for most parameter choices their behaviour is very similar.
Christian Matt, Ueli Maurer
To remedy this situation, we propose a novel interpretation of functional encryption, based on the Constructive Cryptography framework, in which a protocol is seen as a construction of an ideal resource with desired properties from a real resource, which is assumed to be available. The resulting ideal resource can then be used as a real resource in other protocols to construct more advanced resources. The real resource we consider here corresponds to a public repository that allows everyone to read its contents. Such repositories are indeed widely available on the internet. Using functional encryption, we construct, as the ideal resource, a repository with fine-grained access control.
Based on this constructive viewpoint, we propose a new security definition, called FA-security, for functional encryption by adequately modifying an established definition, and prove the equivalence to our notion of construction. This gives evidence that FA-security is an appropriate definition. We further consider known impossibility results and examine a weaker security definition. We show that this weaker definition, for which secure schemes exist, is sufficient to construct a repository that restricts the number and order of interactions. This makes explicit how such schemes can be used.
Ben Morris, Phillip Rogaway
Pawel Morawiecki, Josef Pieprzyk, Marian Srebrny, Michal Straus
Santa Barbara, USA, August 17 - August 21
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/crypto2014/
03 September 2013
Ruhr-Universität Bochum, Germany
The future occupant of the position Mobile Security represents the department in this field in research and teaching. The appointment will be at the rank of an assistant professor.
His/her scientific work should focus on one or more of the following key research areas:
- Security of mobile systems at the hard- or software level
- Security aspects of new application domains (especially cyber-physical systems)
- Reverse engineering of hardware and software systems
- Security aspects of distributed systems
- Secure and dependable software systems
A doctoral degree of outstanding quality and evidence of special aptitude in teaching are just as much required as the willingness to participate in the self-governing bodies of the RUB. Furthermore, we expect the candidate to generally get involved in university processes according to RUB’s mission statement. Beside the specific skills the candidate should have a profound didactical qualification to develop new learning environments such as research oriented teaching.
We expect furthermore readiness to participate in interdisciplinary academic work, willingness and ability to attract external funding, ability to work in teams, and the will to participate in collaborative research.
The Ruhr-Universität Bochum is an equal opportunity employer.
Vienna, Austria, January 20
Notification: 29 November 2013
From January 20 to January 20
Location: Vienna, Austria
More Information: http://www.cs2.deib.polimi.it/
30 August 2013
United Technologies Research Centre, Cork - Ireland
The candidate should have a solid background in vulnerability assessment and thorough knowledge of best practices in countermeasures and design processes for secure systems, for example, encryption, authentication and anomaly detection. A successful candidate would also have a solid background in embedded systems and cyber-physical systems with past experience in applying cyber-physical security concepts to the particular constraints of embedded systems, including scalability of countermeasures. Practical experience in identifying and demonstrating both vulnerabilities and countermeasures is highly desirable for this position.
Candidates should have a proven track record of research (top journals and conferences) in cyber-security or cyber-physical security.
The ideal candidate is a self-starter who works well in an international teaming environment, is extremely well-organized and has excellent interpersonal, leadership and communication skills. Besides technical excellence, an entrepreneurial attitude towards innovation is essential.
The candidate should have a PhD in Computer Science, Electrical and Computer Engineering or related fields, with particular expertise in Cyber-Physical Systems and Wireless Sensor Networks. The candidate should also have a strong international publication record and demonstrated ability to do independent research. Fluency in written and spoken English is required.
Hochschule Furtwangen University, Germany, EEA
* The Chair for Security in Distributed Systems, computer science Hochschule Furtwangen, Germany, offers two full-time PhD positions
* The position involves research in the area of IT-security within the BMBF project
ProSeCCo \\\'Promotionsvorhaben zur Erarbeitung von Sicherheitserweiterungen für das
Cloud Computing\\\' in cooperation with the Albert-Ludwig University of Freiburg at the \\\'Institut für Informatik und Gesellschaft (IIG) - Telematik\\\' (Prof. Dr.
Günter Müller) and the university of Karlsruhe (KIT) at the \\\'Institut for Kryptographie und Sicherheit (IKS) (Prof. Dr. Jörn Müller-Quade).
The successful candidate is expected to contribute to research in IT-Security and applied cryptography for Cloud Security.
Besides other cloud security related aspects topics of interest for the two open positions are
- application of homomorphic cryptographic primitives for secure cloud storage,
- monitoring- and attestation mechanisms to control information flow between VMs.
* The position is available from November on and is fully funded. The salary scale for both positions is TV-L E13.
The gross income depends on the candidate\\\'s experience level. At the lowest level it corresponds to approx. 40,000 EUR per year.
* Contracts are initially offered for two years. An extension is possible.
* She or he is given the possiblity to carry out a Ph.D.
* The successful candidate should have a Master\\\'s degree in Computer Science, Mathematics, Information Security, or a related field.
Deep Knowledge in cryptography is not a must but an asset.
* The deadline for applications is September 20, 2013. However, late applications will be considered until the position is filled.
Please send your application with reference number 11
Santa Barbara, California, USA, August 22 - August 23
Notification: 13 June 2014
From August 22 to August 23
Location: Santa Barbara, California, USA
More Information: http://csrc.nist.gov/groups/ST/hash/sha-3/Aug2014/SHA3-aug2014-call-for-papers.pdf
Junghyun Nam, Kim-Kwang Raymond Choo, Juryon Paik, Dongho Won
Zvika Brakerski, Vinod Vaikuntanathan
Our approach consists of three main ideas: Noise-bounded sequential evaluation of
high fan-in operations; Circuit sequentialization using Barrington\'s Theorem; and finally,
successive dimension-modulus reduction.
Przemysław Dąbrowski, Grzegorz Łabuzek, Tomasz Rachwalik, Janusz Szmidt
Hoda A. Alkhzaimi, Martin M. Lauridsen