IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
27 September 2013
Marcin Nagy, Emiliano De Cristofaro, Alexandra Dmitrienko, N. Asokan, Ahmad-Reza Sadeghi
This paper introduces the Common Friends service, a framework for finding common friends which protects privacy of non-mutual friends and guarantees authenticity of friendships. First, we present a generic construction that reduces to secure computation of set intersection, while ensuring authenticity of announced friends via bearer capabilities. Then, we propose an efficient instantiation, based on Bloom filters, that only incurs a constant number of public-key operations and appreciably low communication overhead. Our software is designed so that developers can easily integrate Common Friends into their applications, e.g., to enforce access control based on users\' social proximity in a privacy-preserving manner. Finally, we showcase our techniques in the context of an existing application for sharing (tethered) Internet access, whereby users decide to share access depending on the existence of common friends. A comprehensive experimental evaluation attests to the practicality of proposed techniques.
Marika Mitrengová
25 September 2013
Douglas R. Stinson, Jalaj Upadhyay
In this paper, we propose a new type of scheme that we term a proof-of-data-observability scheme. Our definition tries to capture the stronger requirement that the server must have
an actual copy of M in its memory space while it executes the challenge-response protocol.
We give some examples of schemes that satisfy this new security definition. As well, we analyze the efficiency and security of the protocols we present, and we prove some necessary conditions for the existence of these kinds of protocols.
Hugo Jonker, Sjouke Mauw, Jun Pang
verifiability states that a voter can trace the effect of her vote on the result. This can be addressed using various privacy-enabling cryptographic primitives which also offer verifiability.
As more and more refined voting systems were proposed, understanding of first privacy and later verifiability in voting increased, and notions of privacy as well as notions of verifiability in voting became increasingly more refined. This has culminated in a variety of verifiable systems that use cryptographic primitives to ensure specific kinds of privacy. However, the corresponding privacy and verifiability claims are not often verified independently. When they are investigated, claims have been invalidated sufficiently often to warrant a cautious approach to them.
The multitude of notions, primitives and proposed solutions that claim to achieve both privacy and verifiability form an interesting but complex landscape. The purpose of this paper is to
survey this landscape by providing an overview of the methods, developments and current trends regarding privacy and verifiability in voting systems.
Xiaolin Cao, Ciara Moore, Maire O\'Neill, Elizabeth O\'Sullivan, Neil Hanle
To the author\'s knowledge, this paper presents the first hardware implemen-tations of encryption primitives for FHE over the integers using FPGA technol-ogy. First of all, a super-size hardware multiplier architecture utilising the Inte-ger-FFT multiplication algorithm is proposed, and a super-size hardware Barrett modular reduction module is designed incorporating the proposed multiplier. Next, two encryption primitives that are used in two schemes of FHE over the integers are designed employing the proposed super-size multiplier and modular reduction modules. Finally, the proposed designs are implemented and verified on the Xilinx Virtex-7 FPGA platform. Experimental results show that the speed improvement factors of up to 44.72 and 54.42 are available for the two FHE encryption schemes implemented in FPGA when compared to the corresponding software implementations. Meanwhile, the performance analysis shows that further improvement is speed of these FHE encryption primitives may still be possible.
24 September 2013
Security Innovation, Wilmington, MA, USA
Responsibilities will include:
· Work on NTRU crypto research, including efficient signature schemes
· Helping to better understand lattice reduction algorithms, potentially including:
o A complete or partial reimplementation of algorithms developed by Nguyen and Chen to properly understand their claims
o Research into use of the structure of NTRU / ideal lattices to obtain improvements over generic lattice reduction algorithms
o Exploring the relationship between expected-shortest and actual-shortest vector in a lattice and how it affects reduction times
· Support cryptographic queries that come in to NTRU as a result of the GPL move, including participating in discussions on forums such as crypto.stackexchange and others
· Support the codebase of the GPL implementation of NTRU, including:
o General optimizations for the C implementation on 32- and 64-bit processors such as including multiple coefficients in a single word
o Architecture-specific optimizations such as exploring what advantage can be taken of SIMD, etc
o Potentially writing and/or managing a Java implementation
· Support standardization activity
o In particular, manage the passing of one or more NTRU-related TLS ciphersuite drafts through IETF.
RMIT University, Melbourne, Australia
Full-time, Continuing (i.e., permanent) position
Annual Salary: $121,048 to $133,357 + 17% superannuation
Information Security forms one of the research strengths of the School. The Master of Applied Science in Information Security and Assurance is one of the programs in the school with more than 50 coursework students.
Please see the following link for further information about the research group
http://www.rmit.edu.au/browse;ID=3kk0nfsjwuuc
and the following for further information about Master\\\'s program in Information Security and Assurance
http://www.rmit.edu.au/programs/mc159
Situated within the College of Science, Engineering and Health, the School of Mathematical and Geospatial Sciences draws together disciplines involving the collection of data, the analysis of data, data security, and the understanding and optimisation of systems through modelling and visualisation. The School has more than 60 academic staff and over 70 postgraduate research students.
Reporting to the Head of School, the Associate Professor - Mathematical Science will be expected to be an active researcher. This will include supervising research students; undertaking and publishing high quality research, and applying for research grants.
Xiaofei Guo, Ramesh Karri
function Grøstl. We provide experimental results and formal proofs to show that REPO detects all single-bit and single-byte faults. Experimental results show that REPO achieves close to 100% fault coverage for multiple byte faults. The hardware and throughput overheads are compared with those of previously reported CED techinques on two Xilinx Virtex FPGAs. The hardware overhead is 12.4-27.3%, and the throughput is 1.2-23Gbps, depending on the AES architecture, FPGA family, and detection latency. The performance overhead ranges from 10% to 100% depending on the security
level. Moreover, the proposed technique can be integrated into various block cipher modes of operation. We also discuss the limitation of REPO and its potential vulnerabilities.
23 September 2013
Lausanne, Switzerland, June 10 - June 13
Notification: 14 March 2014
From June 10 to June 13
Location: Lausanne, Switzerland
More Information: http://acns2014.epfl.ch/
Jörg Schwenk
We propose the first such model, where time is modelled as a global counter T . We argue that this model closely matches several implementations of time in computer environments. The usefulness of the model is shown by giving complexity-theoretic security proofs for OTP protocols, HMQV-like one-round AKE protocols, and a variant of the basic Kerberos building block.
Masao KAS
Dominique Unruh
recipient can decrypt only after a specified amount of time T
(assuming that we have a moderately precise estimate of his computing
power). A revocable timed-release encryption is one where,
before the time T is over, the sender can \"give back\" the
timed-release encryption, provably loosing all access to the data. We
show that revocable timed-release encryption without trusted parties
is possible using quantum cryptography (while trivially impossible
classically).
Along the way, we develop two proof techniques in the quantum random
oracle model that we believe may have applications also for other
protocols.
Finally, we also develop another new primitive, unknown recipient
encryption, which allows us to send a message to an
unknown/unspecified recipient over an insecure network in such a way
that at most one recipient will get the message.
Franck Landelle, Thomas Peyrin
Guangjun Fan, Yongbin Zhou, Hailong Zhang, Dengguo Feng
normalization process should be integrated as a necessary part of profile attacks in order to better understand the practical threats of these attacks.
Ruan de Clercq, Leif Uhsadel, Anthony Van Herrewege, Ingrid Verbauwhede
Jeroen Delvaux, Ingrid Verbauwhede
Mitsugu Iwamoto, Thomas Peyrin, Yu Sasaki
Moreover, we show that almost all known collision attacks are in fact more than just a collision finding algorithm, since the difference mask for the message input is usually fixed. A direct and surprising corollary is that these collision attacks are interesting for cryptanalysis even when their complexity goes beyond the $2^{n/2}$ birthday bound and up to the $2^{n}$ preimage bound, and can be used to derive distinguishers using the limited-birthday problem. Interestingly, cryptanalysts can now search for collision attacks beyond the $2^{n/2}$ birthday bound.
Finally, we describe a generic algorithm that turns a semi-free-start collision attack on a compression function (even if its complexity is beyond the birthday bound) into a distinguisher on the whole hash function when its internal state is not too wide. To the best of our knowledge, this is the first result that exploits classical semi-free-start collisions on the compression function to exhibit a weakness on the whole hash function. As an application of our findings, we provide distinguishers on reduced or full version of several hash functions, such as RIPEMD-128, SHA-256, Whirlpool, etc.
Essam Ghadafi
Blind signatures, on the other hand, allow a user to obtain a signature on a message while maintaining the privacy of the message.
Blind ring signatures combine properties of both primitives and hence provide a strong notion of anonymity where the privacy of both the identity of the signer and the message is preserved.
Blind ring signatures find applications in various systems; including multi-authority e-voting and distributed e-cash systems.
In this paper we provide the first provably secure blind ring signature construction that does not rely on random oracles, which solves an open problem raised by Herranz and Laguillaumie at ISC 2006. We present different instantiations all of which are round-optimal (i.e.\\ have a two-move signing protocol), yield sub-linear size signatures, and meet strong security requirements.
In order to realize our constructions efficiently, we construct a sub-linear size set membership proof which works in the different bilinear group settings, which may be of independent interest.
As a secondary contribution, we show how to generically combine our set membership proof with any secure signature scheme meeting some conditions to obtain ring signatures whose security does not rely on random oracles. All our constructions work over the efficient prime-order bilinear group setting and yield signatures of sub-linear size. In addition, our constructions meet strong security requirements: namely, anonymity holds under full key exposure and unforgeability holds against insider-corruption.
Finally, we provide some example instantiations of the generic construction.
22 September 2013
Xiaofei Guo, Ramesh Karri
plement our scheme in many ways; designers can trade off performance, reliability, and security according to the available resources.