IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
16 November 2013
Karthik Abinav, Saikrishna Badrinarayanan, C. Pandu Rangan, S. Sharmila Deva Selvi, S. Sree Vivek, Vivek
having the key-escrow problem and the lack of use of certificates. Online-Offline signature schemes are
extremely relevant today because of their great practical applications. In an online-offline signature
scheme all the heavy computation is done on powerful processors and stored securely in the offline
phase, and the online component requires only light computation. Hence, it is widely used in several
low-resource devices like mobile phones, etc. Revocation is another important problem of wide interest
as it helps to keep a check on misbehaving users. Currently, there are very few revocable certificateless
signature schemes in the literature. We have addressed some of the limitations of the previously existing
schemes and designed a new model for the same that involves periodic time generated keys. We present
a revocable online-offline certificateless signature scheme without pairing. Pairing, though a very useful
mathematical function, comes at the cost of heavy computation. Our scheme is proved secure in the
random oracle model using a tight security reduction to the computational Diffie-Hellman problem.
Dr. G.S.G.N.Anjaneyulu, A.Vijayabarathi
Gérald Gavin
is built over $\\mathbb{Z}_n$
($n$ being an RSA modulus). An encryption of $x\\in \\mathbb{Z}_n$
is a randomly chosen vector $e$ such that $\\Phi(e)=x$ where $\\Phi$ is a secret multivariate polynomial.
This private-key cryptosystem is not homomorphic in the sense that the vector sum is not a homomorphic operator. Non-linear homomorphic operators are then
developed. The security relies on the difficulty of solving systems of nonlinear equations (which is a $\\mathcal{NP}$-complete problem). While the security of our scheme has not been reduced to a provably hard instance of this problem,
its security is globally investigated.
15 November 2013
Bristol, United Kingdom, December 2 - December 5
From December 2 to December 5
Location: Bristol, United Kingdom
More Information: http://2013.cloudcom.org/
14 November 2013
Chris Litsas, Aris Pagourtzis, Giorgos Panagiotakos, Dimitris Sakavalas
which is particularly suitable for ad hoc networks. We address the issue of determining the maximum number of corrupted players $t^{\\mathrm{CPA}}_{\\max}$ that CPA can tolerate under the $t$-locally bounded adversary model, in which the adversary may corrupt at most
$t$ players in each player\'s neighborhood. For any graph $G$ and dealer-node $D$ we provide upper and lower bounds on $t^{\\mathrm{CPA}}_{\\max}$ that can be efficiently computed in terms of a graph theoretic parameter that we introduce in this work. Along the way we obtain an efficient 2-approximation algorithm for $t^{\\mathrm{CPA}}_{\\max}$. We further introduce two more graph parameters, one of which matches $t^{\\mathrm{CPA}}_{\\max}$exactly. Our approach allows to provide an affirmative answer to the open problem of CPA Uniqueness posed by Pelc and Peleg in 2005.
University of Connecticut, USA
The Computer Science and Engineering (CSE) Department at the University of Connecticut invites applications for a tenure-track faculty position at the assistant or associate professor level, with an expected start date of August 23, 2014. The research specialties of interest are:
- Machine Learning,
- Privacy, Cryptography or Computer Security, or
- Techniques for the analysis of Big Data with applications in diverse areas including biomedical informatics.
The successful candidate will:
- Develop and sustain an internationally-recognized, externally-funded research program in one of these areas of interest;
- Teach undergraduate and graduate courses that meet the curricular needs of our CSE department;
- Advise and mentor undergraduate and graduate students;
- Provide service and leadership to all units of the University of Connecticut, to external academic and scientific communities, and to the general public.
Minimum Qualifications:
- Completed all requirements for a Ph.D. in computing or a related discipline by the time of the appointment—equivalent foreign degrees are acceptable;
- Research credentials in Computer Science, with a specialty in one of the topics prescribed above.
Preferred Qualifications:
- A record of consistent, outstanding research contributions in one of the topics prescribed above;
- Significant relevant teaching experience.
This is a 9-month, tenure-track position with an expected start date of August 23, 2014. The successful candidate`s primary academic
appointment will be at the Storrs campus with the option to work at UConn`s regional campuses across the state. Salary and rank will be
commensurate with qualifications.
To apply, applications must be submitted using Acade
Hyun-A Park
the character-wise encryption preserves the degree of similarity between two plaintexts, and renders approximate string matching between the corresponding ciphertexts possible without decryption.
Maurizio Adriano Strangio
The author shows that the IDAK key agreement protocol is secure in the Bellare-Rogaway model with random oracles and also provides an ad-hoc security proof claiming that the IDAK protocol is not vulnerable to Key Compromise Impersonation attacks.
In this report, we claim that the IDAK protocol is vulnerable to key-compromise impersonation attacks. Indeed, Wang\'s results are valid only for a passive adversary that can corrupt parties or reveal certain session-specific data but is not allowed to manipulate protocol transcripts; a model considering this type of adversary is unable to afford KCI resilience.
Joppe W. Bos, J. Alex Halderman, Nadia Heninger, Jonathan Moore, Michael Naehrig, Eric Wustrow
Michael Tunstall, Carolyn Whitnall, Elisabeth Oswald
Jean-Marie Chauvet
Gora Adj, Alfred Menezes, Thomaz Oliveira, Francisco Rodriguez-Henriquez
In this paper, we study the effectiveness of the new algorithms combined with a carefully crafted descent strategy for the fields F_{3^{6*1429}} and F_{2^{4*3041}}. The intractability of the discrete logarithm problem in these fields is necessary for the security of pairings derived from supersingular curves with embedding degree 6 and 4 defined, respectively, over F_{3^{1429}} and F_{2^{3041}}; these curves were believed to enjoy a security level of 192 bits against attacks by Coppersmith\'s algorithm. Our analysis shows that these pairings offer security levels of at most 91 and 129 bits, respectively, leading us to conclude that they are dead for pairing-based cryptography.
13 November 2013
Shafi Goldwasser, Vipul Goyal, Abhishek Jain, Amit Sahai
We formulate both indistinguishability-based and simulation-based definitions of security for this notion, and show close connections with indistinguishability and virtual black-box definitions of obfuscation. Assuming indistinguishability obfuscation for circuits, we present constructions achieving indistinguishability security for a large class of settings. We show how to modify this construction to achieve simulation-based security as well, in those settings where simulation security is possible. Assuming differing-inputs obfuscation [Barak et al., FOCS\'01], we also provide a construction with similar security guarantees as above, but where the keys and ciphertexts are compact.
Robert Wicik, Tomasz Rachwalik
Vipul Goyal, Abhishek Jain, Venkata Koppula, Amit Sahai
{\\L}ukasz Krzywiecki, Przemys{\\l}aw Kubiak, Miros{\\l}aw Kuty{\\l}owski
The scheme is based on lazy construction of a tree of signatures.
Stamp\\&Extend returns a timestamp immediately after the request, unlike the schemes based on the concept of timestamping rounds.
Despite the fact that all timestamps are linearly linked, verification of a timestamp requires a logarithmic number of steps with respect to the chain length.
An extra feature of the scheme is that any attempt to forge a timestamp by the Time Stamping Authority (TSA) results in revealing its secret key, providing an undeniable cryptographic evidence of misbehavior of TSA.
Breaking Stamp\\&Extend requires not only breaking Schnorr signatures,
but to some extend also breaking Pedersen commitments.
Yongqiang Li, Mingsheng Wang, Yuyin Yu
nonlinearity is of cardinal significance in cryptography. In the
present paper, we show that numerous differentially 4-uniform
permutations over GF(2^{2k}) can be constructed by composing
the inverse function and cycles over GF(2^{2k}). Two sufficient
conditions are given, which ensure that the differential uniformity
of the corresponding compositions equals 4. A lower bound on
nonlinearity is also given for permutations constructed with the
method in the present paper. Moreover, up to CCZ-equivalence, a new
differentially 4-uniform permutation with the best known
nonlinearity over GF(2^{2k}) with $k$ odd is constructed. For
some special cycles, necessary and sufficient conditions are given
such that the corresponding compositions are differentially
4-uniform.
11 November 2013
Florian�polis, Brazil, September 17 - September 19
Notification: 23 August 2014
From September 17 to September 19
Location: Florian�polis, Brazil
More Information: https://sites.google.com/site/latincrypt2014/
08 November 2013
Okinawa, Japan, November 18 - November 20
Notification: 16 November 2013
From November 18 to November 20
Location: Okinawa, Japan
More Information: http://www.iwsec.org/2013/index.html
CloudFlare Inc., San Francisco, CA, USA, the Northern Hemisphere
CloudFlare is looking for a talented security engineer to join our team. We are working on a number of ambitious projects to secure the web and protect our customers from threats of all sorts. The role of security engineer at CloudFlare is more that of a builder than a breaker. You will have to approach problems with creativity and flexibility and be able to identify and use the best tools for the job or build better ones from scratch. At CloudFlare, we are serious about protecting our customers and advancing the state of the art in computer security.
Requirements:
Strong systems-level programming skills?
Deep understanding of networking protocols (TCP/IP, SSL/TLS, DNS)
Experience with cryptographic libraries and APIs
Expert in C/C++ and performance analysis
Proficiency in Go and/or Lua or willingness to learn
Strong understanding of security concepts (key management, access control, authentication)
Understanding of Linux internals
Interest in advancements in security and cryptography
Bonus Points:
Contributions to the open source community
Experience implementing production-grade cryptographic algorithms
Knowledge or expertise in White-box cryptography
Experience with DNSSEC
Familiarity with compilers or code generation tools
Experience with cryptographic hardware (TPM, HSM, etc.)
Healthy sense of paranoia