IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
30 November 2013
Improvement of Lin-Tzeng Solution to Yao\'s Millionaires Problem and Its Cheating Advantage Analysis
Zhengjun Cao, Lihua Liu
Shuai Han, Shengli Liu, Kefei Chen, Dawu Gu
Elena Andreeva, Andrey Bogdanov, Atul Luykx, Bart Mennink, Elmar Tischhauser, Kan Yasuda
Elena Andreeva, Beg\\\"ul Bilgin, Andrey Bogdanov, Atul Luykx, Bart Mennink, Nicky Mouha, Kan Yasuda
Kazuhiko Minematsu, Stefan Lucks, Tetsu Iwata
This paper provides an improvement over the previous security proof, by showing that EAX is unforgeable up to $O(2^{n/2})$ data with multiple verification queries. Our security proof is based on the techniques appeared in a paper of FSE 2013 by Minematsu et al. which studied the security of a variant of EAX called EAX-prime.
We also provide some ideas to reduce the complexity of EAX while keeping our new security bound. In particular, EAX needs three blockcipher calls and keep them in memory as a pre-processing, and our proposals can effectively reduce three calls to one call. This would be useful when computational power and memory are constrained.
Long Zhang, Qiuling Yue
The new improved scheme encrypts the message by applying the modular mathematical operation
and the Chinese remainder theorem, and the security of the scheme is based on the the difficulty of approximate greatest common divisor problem and the spare subset sum problem. The improved scheme we got has the advantages of encrypt fast, and the size of ciphertext is small. So compared with the original scheme, it is better for practical application.
29 November 2013
Yalin Chen, Jue-Sam Chou2
Marcin Andrychowicz, Stefan Dziembowski, Daniel Malinowski, Łukasz Mazurek
Firstly, we show that the BitCoin system provides an attractive way to construct a version of \"timed commitments\", where the committer has to reveal his secret within a certain time frame, or to pay a fine. This, in turn, can be used to obtain fairness in some multiparty protocols. Secondly, we introduce a concept of multiparty protocols that work \"directly on BitCoin\". Recall that the standard definition of the MPCs guarantees only that the protocol \"emulates the trusted third party\". Hence ensuring that the inputs are correct, and the outcome is respected is beyond the scope of the definition. Our observation is that the BitCoin system can be used to go beyond the standard \"emulation-based\" definition, by constructing protocols that link their inputs and the outputs with the real BitCoin transactions.
As an instantiation of this idea we construct protocols for secure multiparty lotteries using the BitCoin currency, without relying on a trusted authority (one of these protocols uses the BitCoin-based timed commitments mentioned above). Our protocols guarantee fairness for the honest parties no matter how the looser behaves. For example: if one party interrupts the protocol then her money is lost and transferred to the honest participants. Our protocols are practical (to demonstrate it we performed their transactions in the actual BitCoin system), and can be used in real life as a replacement for the online gambling sites. We think that this paradigm can have also other applications. We discuss some of them.
Fei Tang, Hongda Li, Qihua Niu, and Bei Liang
28 November 2013
Moscow, Russia, June 5 - June 6
Notification: 14 April 2014
From June 5 to June 6
Location: Moscow, Russia
More Information: http://www.tc26.ru/en/CTCryptEN/CTCrypt2014/
26 November 2013
Vienna, Austria, July 19 - July 22
Notification: 11 April 2014
From July 19 to July 22
Location: Vienna, Austria
More Information: http://csf2014.di.univr.it/index
University of Neuchatel, Switzerland
Further information soon available at http://www2.unine.ch/sciences/cms/op/edit/lang/fr/emploi
Royal Holloway, University of London, UK
The post-doc will join a team of post-docs and PhD students working under the leadership of Prof. Kenny Paterson. The aim of the project is to find weaknesses in cryptographic specifications and implementations, to understand how these weaknesses can be addressed in practical ways, and to develop extensions of current cryptographic theory that permit more realistic modelling of cryptographic primitives as they are used in fielded systems. The position will also involve activities designed to engage both the theory community and practitioners in the research.
Applicants should have already completed, or be close to completing, a PhD in a relevant discipline. Applicants should have an outstanding research track record in Cryptography, in either theoretical or applied aspects of the subject, and, ideally, in both aspects. Applicants should be able to demonstrate scientific creativity, research independence, and the ability to communicate their ideas effectively in written and verbal form.
Salary is in the range £32,862 to £34,724 per annum inclusive of London Allowance
Informal enquiries can be made to Kenny Paterson at kenny.paterson (at) rhul.ac.uk.
To view further details of this post and to apply please visit http://www.rhul.ac.uk/aboutus/jobvacancies/home.aspx . The RHUL Recruitment Team can be contacted with queries by email at: recruitment (at) rhul.ac.uk or via telephone on: +44 (0)1784 41 4241.
Please quote the reference: X1113/7450
Closing Date: Midnight, Sunday 22nd December 2013
Interview Date: To be confirmed
The Ethics Committee of the IACR is responsible for providing recommendations to editors, program chairs, program-committee members, and reviewers concerning fairness and ethical aspects of all matters under the influence of the IACR, such as its operations, its events, and its publications.
The mission of the Ethics Committee is described in the "IACR Policy for the Ethics Committee", available at http://www.iacr.org/docs/
The Ethics committee has discussed only a handful of cases in 2013. In the interest of raising awareness for ethical matters among the researchers in cryptology, the Ethics Committee may occasionally inform the IACR members about its work. An account of one case follows.
A team of authors submitted a paper to a non-IACR conference in the field of cryptology and information security. After submitting the work, the authors developed their method further and discovered other ways to attack the problem. Before receiving an acceptance or rejection notification from the conference, the authors had written another paper on the second method and submitted this to a second conference, this one sponsored by the IACR. The second paper did not cite or mention the first paper.
Some reviewers in the overlap of the two program committees spotted a similarity of the works, and, in line with the IACR Policy on Irregular Submissions, they shared this information with the program chairs of the two venues. The program chair of the first conference then rejected the first paper declaring that it was a "potential double submission" and informed the program chair of the IACR conference about this. The authors then reached out to the IACR Ethics Committee and explained their case. They wanted to obtain a clarification that there was no double submission.
The Ethics Committee reviewed the situation and examined the submitted papers superficially. The committee then concluded that there was no obvious case of "parallel submissions" as described in the IACR Policy and that the second paper should enter the regular reviewing process of the IACR conference. The committee also remarked that it cannot make any statement towards the first conference because it is not an IACR venue. To the committee, it seemed that there was a misunderstanding because the existence and nature of technical links between the contributions of the two papers were not mentioned by the authors.
Last but not least, the committee recommended to the authors that, in the interest of being transparent in scientific work, authors should always cite existing known related work, even when a new contribution would not directly build on it. Furthermore, considering the delicate issues around double submissions, this point was particularly important with related work from the same authors.
IACR Ethics Committee (2013)
- Josh Benaloh
- Thomas Berson
- Christian Cachin (chair)
Amalfi, Italy, September 3 - September 5
Notification: 9 June 2014
From September 3 to September 5
Location: Amalfi, Italy
More Information: http://scn.dia.unisa.it/
25 November 2013
Mridul Nandi, Nilanjan Datta
Bartosz Zoltak
Our new algorithm produced $2^{46.8}$ undistinguishable from random 3-bit outputs in the same test. We probed $2^{51}$ outputs of the algorithm in different statistical tests with different word sizes
and found no way of distinguishing the keystream from a random source. The size of the algorithm\'s internal state is $2^{3424}$ (for an 8-bit implementation). The algorithm is cryptographically secure to the extent we were able to analyse it. Its design is simple and easy to implement. We present the generator along with a key scheduling algorithm processing both keys and initialization vectors.
Martin Hirt, Ueli Maurer, Pavel Raykov
sender to send a value from a domain of size $d$ to a set of parties.
A broadcast protocol emulates the $d$-broadcast primitive using only
point-to-point channels, even if some of the parties cheat, in
the sense that all correct recipients agree on the same value $v$
(consistency), and if the sender is correct, then $v$ is the value
sent by the sender (validity). A celebrated result by Pease, Shostak
and Lamport states that such a broadcast protocol exists if and only if $t 3$ no broadcast amplification
is possible, i.e., $\\phi_n(d)=d$ for any $d$.
However, if other parties than the sender can also broadcast some
short messages, then broadcast amplification is possible for
\\emph{any}~$n$. Let $\\phi^*_n(d)$ denote the minimal $d\'$ such that
$d$-broadcast can be constructed from primitives $d\'_1$-broadcast,
\\ldots, $d\'_k$-broadcast, where $d\'=\\prod_i d\'_i$ (i.e., $\\log
d\'=\\sum_i \\log d\'_i$). Note that $\\phi^*_n(d)\\leq\\phi_n(d)$.
We show that broadcasting $8n\\log n$ bits in
total suffices, independently of $d$, and that at least $n-2$ parties,
including the sender, must broadcast at least one bit. Hence
$\\min(\\log d,n-2) \\leq \\log \\phi^*_n(d) \\leq 8n\\log n$.
Omar Choudary, Markus G. Kuhn
eavesdrop on tamper-resistant hardware. They model the probability
distribution of leaking signals and noise to guide a
search for secret data values. In practice, several numerical
obstacles can arise when implementing such attacks
with multivariate normal distributions.
We propose
efficient methods to avoid these. We also demonstrate how to achieve
significant performance improvements, both in terms of information
extracted and computational cost, by pooling covariance estimates
across all data values. We provide a detailed and systematic
overview of many different options for implementing such
attacks. Our experimental evaluation of all these methods based on
measuring the supply current of a byte-load instruction executed in
an unprotected 8-bit microcontroller leads to practical guidance for
choosing an attack algorithm.
Wuqiang Shen, Shaohua Tang