IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
05 October 2013
Deng Tang, Claude Carlet, Xiaohu Tang
04 October 2013
Oxford, England, June 21 - June 25
Notification: 7 May 2014
From June 21 to June 25
Location: Oxford, England
More Information: http://www.sigsac.org/wisec/WiSec2014/
Paris, France, April 13 - April 15
Notification: 10 February 2014
From April 13 to April 15
Location: Paris, France
More Information: http://
Technical University of Denmark, DTU
Candidates for the first postdoc position should have a strong cryptanalytic and mathematical background and be able to analyze the security of ciphers to be designed. Candidates for the second postdoc should have a solid background in hardware design and automation and be able to work on the physical constraints and optimization of the hardware implementations.
Centre for Secure Information Technologies (CSIT), Queen’s University Belfast, UK
Applicants must have at least a 2:1 Honours Degree (or equivalent) in Electrical and Electronics Engineering, Computer Science, Mathematics or closely related discipline and a PhD, or expect, within 6 months, to obtain a PhD, in a relevant subject. Evidence of high quality research in a relevant field commensurate with stage of academic career, or extensive industrial experience in a relevant area, is essential. Applicants with research expertise in one or more of the following areas are strongly encouraged to apply: applied cryptography, side channel analysis, security protocols, malware/botnet analysis, network forensics, cloud security, threat and attack mitigation, insider threat behaviour, software security.
01 October 2013
Boaz Barak, Sanjam Garg, Yael Tauman Kalai, Omer Paneth, Amit Sahai
This changed with the work of Garg, Gentry, Halevi, Raykova, Sahai, and Waters ({FOCS 2013}), which gave the first candidate construction of general-purpose obfuscation. The heart of their construction is an obfuscator for log-depth (\\textbf{NC$^1$}) circuits, building upon a simplified subset of the Approximate Multilinear Maps framework of Garg, Gentry, and Halevi ({Eurocrypt 2013}) that they call Multilinear Jigsaw Puzzles.
Given the importance of general-purpose obfuscation, it is imperative that we gain as much confidence as possible in candidates for general-purpose obfuscation. In this work, we focus on the following question: Do there exist \\emph{algebraic} attacks (a.k.a. generic multilinear attacks) against candidate constructions of general-purpose obfuscation? Indeed, Garg \\emph{et al.} posed
the problem of proving that there exist no generic multilinear attacks against their core \\textbf{NC$^1$} scheme as a major open problem in their work. Solving this problem will give us essential evidence that mathematical approaches to general purpose obfuscation introduced by Garg \\emph{et al.} are sound.
This problem was first addressed in the recent work of Brakerski and Rothblum (eprint 2013), who constructed a variant of the Garg \\emph{et al.} candidate obfuscator, and proved that it achieves the strongest definition of security for general-purpose obfuscation --- Virtual Black Box (VBB) security --- against
all generic multilinear attacks, albeit under an unproven assumption they introduce as the Bounded Speedup Hypothesis, which strengthens the Exponential Time Hypothesis.
In this work, we resolve the open problem of Garg \\emph{et al.} completely, by removing the need for this additional assumption. More specifically, we describe
a different (and arguably simpler) variant of the construction of Garg \\emph{et al.}, for which we can prove that it achieves Virtual Black Box security against
all generic multilinear attacks, \\emph{with no further assumptions}.
Ahmed Mahmoud, Ulrich Rührmair, Mehrdad Majzoobi, Farinaz Koushanfar
in the scientific literature, and are also gaining ground
in commercial applications. Recently, however, several attacks
on PUF core properties have been reported. They concern
their physical and digital unclonability, as well as their
assumed resilience against invasive or side channel attacks.
In this paper, we join some of these techniques in order
to further improve their effectiveness. The combination of
machine-learning based modeling techniques with side channel
information allows us to attack so-called XOR Arbiter
PUFs and Lightweight PUFs up to a size and complexity
that was previously out of reach. For Lightweight PUFs,
for example, we report successful attacks for bitlengths of
64, 128 and 256, and for up to nine single Arbiter PUFs
whose output is XORed. Previous work at CCS 2010 and
IEEE TIFS 2013, which provides the currently most efficient
modeling results, had only been able to attack this structure
for up to five XORs and bitlength 64.
Our attack employs the first power side channel (PSC) for
Strong PUFs in the literature. This PSC tells the attacker
the number of single Arbiter PUF within an XOR Arbiter
PUF or Lightweight PUF architecture that are zero or one.
This PSC is of little value if taken by itself, but strongly
improves an attacker\'s capacity if suitably combined with
modeling techniques. At the end of the paper, we discuss efficient
and simple countermeasures against this PSC, which
could be used to secure future PUF generations.
30 September 2013
Mingjie Liu, Jiazhe Chen
Jiawei Yuan, Shucheng Yu
Kazuhiko Minematsu
The proposed scheme has attractive features for fast and compact operation.
It requires rate-1 blockcipher call, and uses the encryption function of a blockcipher for both encryption and decryption.
Moreover, the scheme enables one-pass, parallel operation under two-block partition.
The proposed scheme thus attains similar characteristics as the seminal OCB mode, without using the inverse blockcipher.
The key idea of our proposal is a novel usage of two-round Feistel permutation, where the round functions are derived from the theory of tweakable blockcipher.
We also describe an instantiation of our idea using a non-invertible primitive, such as a keyed hash function.
Ivan Damgård, Thomas P. Jakobsen, Jesper Buus Nielsen, Jakob I. Pagter
securely store sensitive information such as cryptographic keys. Applications like this include many cases where secure multiparty computation is outsourced to the cloud, and in particular
a number of online auctions and benchmark computations with confidential inputs. We consider fully autonomous servers that switch between online and offline periods without communicating with anyone from outside the cloud, and semi-autonomous
servers that need a limited kind of assistance from outside the cloud when doing the transition. We study the levels of security one can - and cannot - obtain in this model, propose light-weight protocols achieving maximal security, and report on their practical performance.
Joop van de Pol, Nigel P. Smart
29 September 2013
Kevin D. Bowers, Catherine Hart, Ari Juels, Nikos Triandopoulos
facilities, such as intrusion-detection systems and syslog, that we generically call Security Analytics Sources (SASs).
Security analytics are only as good as the data being analyzed. Yet nearly all SASs today lack even basic protections on data collection. An attacker can undetectably suppress or tamper with SAS messages to conceal attack evidence. Moreover, by merely monitoring network traffic they can discover sensitive SAS instrumentation and message-generation behaviors.
We introduce PillarBox, a tool for securely relaying SAS messages in a security analytics system. PillarBox enforces integrity: It secures SAS messages against tampering, even against an attacker that controls the network and compromises a message-generating host. It also (optionally) offers stealth: It can conceal alert generation, hiding select SAS alerting rules and actions from an adversary.
We present an implementation of PillarBox and show experimentally that it can secure messages against attacker suppression or tampering even in the most challenging environments where SASs generate real-time security alerts. We also show, based on data from a large enterprise and on-host performance measurements, that PillarBox has minimal overhead and is practical for real-world big data security analytics systems.
28 September 2013
Christina Garman, Matthew Green, Ian Miers
In this work we propose a novel anonymous credential scheme that eliminates the need for a trusted credential issuer. Our approach builds on recent results in the area of electronic cash and uses techniques --- such as the calculation of a distributed transaction ledger --- that are currently in widespread deployment in the Bitcoin payment system. Using this decentralized ledger and standard cryptographic primitives, we propose and provide a proof of security for a basic anonymous credential system that allows users to make flexible identity assertions with strong privacy guarantees. Finally, we discuss a number of practical applications for our techniques, including resource management in ad hoc networks and prevention of Sybil attacks. We implement our scheme and measure its efficiency.
Yossi Gilad, Amir Herzberg, Haya Shulman
traffic is not cryptographically protected. Typical justification is that most
attackers are off-path and cannot intercept traffic; hence, intuitively,
challenge-response defenses should suffice to ensure authenticity. Often,
the challenges re-use existing header fields to protect widelydeployed
protocols such as TCP and DNS.
We argue that this practice may often give an illusion of security.
We review recent off-path TCP injection and DNS poisoning attacks,
enabling attackers to circumvent existing challenge-response defenses.
Both TCP and DNS attacks are non-trivial, yet practical. The attacks
foil widely deployed security mechanisms, and allow a wide range of
exploits, such as long-term caching of malicious objects and scripts.
We hope that this review article will help improve defenses against
off-path attackers. In particular, we hope to motivate, when feasible,
adoption of cryptographic mechanisms such as SSL/TLS, IPsec and
DNSSEC, providing security even against stronger Man-in-the-Middle
attackers.
Xiaolin Cao, Ciara Moore
27 September 2013
Brajesh Kumar Singh
Zhou et al. (Inform. Sci. 180(2) (2010) 256-265).
This article is concerned with some new bounds on global avalanche characteristics of two $q$-ary functions. Based on the above result we obtain a bound on $\\sigma_{f}$ of $f \\in \\cB_{n, q}$ in terms of $\\sigma_{f_{\\ell}}\'$s of the restricted functions on $\\BBZ_{n-1}^q$, and construct a class of $q$-ary bent functions from $1$-plateaued functions having dijoint Walsh spectra.
Pierre-Alain Fouque, Pierre Karpman
resistant to such attacks in this model. A side-result of this is a proper formalization for an unproven alternative
to DESX proposed by Kilian and Rogaway; this construction can now be shown to be sound in our model.
Meet-in-the-middle attacks exploit weaknesses in key schedule algorithms,
and building constructions resistant to such attacks is an important issue for improving the security of block ciphers.
Our construction is generic so that it can be used on top of any block cipher, and it does not require to increase the key-length.
We use an exposure resilient function (or ERF) as a building block and we propose a concrete and efficient instantiation strategy
based on compression functions.
Jeroen Delvaux, Ingrid Verbauwhede