IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
18 December 2013
New York University Polytechnic School of Engineering, USA, North America
17 December 2013
Alex Biryukov, Vesselin Velichkov
Amir Moradi, Sylvain Guilley, Annelie Heuser
Jian Ye, Chenglian Liu
Dennis Hofheinz, Christoph Striecks
(a) We propose threshold extractable hash proof instantiations from the \"Extended Decisional Diffie-Hellman\" (EDDH) assumption due to Hemenway and Ostrovsky (PKC 2012). This in particular yields EDDH-based variants of threshold public key encryption, threshold signatures, and revocation schemes. In detail, this yields a DCR-based revocation scheme.
(b) We show that our EDDH-based revocation scheme allows for a mild form of traitor tracing (and, thus, yields a new trace-and-revoke scheme). In particular, compared to Wee\'s factoring-based scheme, our DCR-based scheme has the advantage that it allows to trace traitors.
Aggelos Kiayias, Qiang Tang
functions? This question appears to be fundamentally hard to address
since in this setting the owner of the key {\\em is} the adversary:
she wishes to share a program or device that (potentially only
partly) implements her main cryptographic functionality. Given that
she possesses the cryptographic key, it is impossible for her to be
{\\em prevented} from writing code or building a device that uses
that key. She may though be {\\em deterred} from doing so.
We introduce {\\em leakage-deterring} public-key cryptographic
primitives to address this problem. Such primitives have the feature
of enabling the embedding of owner-specific private data into the
owner\'s public-key so that given access to {\\em any} (even
partially functional) implementation of the primitive, the recovery
of the data can be facilitated. We formalize the notion of
leakage-deterring in the context of encryption, signature, and
identification and we provide efficient generic constructions that
facilitate the recoverability of the hidden data while retaining
privacy as long as no sharing takes place.
Abderrahmane Nitaj, Mohamed Ould Douh
Umar Mujahid, M.Najam-ul-islam, Jameel Ahmed
In this paper, a brief survey of eminent ultralightweight authentication protocols has been presented & then a four-layer security model, which comprises of various passive and active attacks, has been proposed. Cryptanalysis of these protocols has also been performed under the implications of the proposed security model
Xi-Jun Lin, Lin Sun
After the analysis, we found that these protocols do not possess the desirable security attributes.
Suvadeep Hajra, Debdeep Mukhopadhyay
greatly increases the success rate of DPA attacks in the presence of high noise. The experimental results on both simulated power traces and real power traces are also provided as an evidence.
Liina Kamm, Jan Willemson
Ulrich Rührmair, Xiaolin Xu, Jan Sölter, Ahmed Mahmoud, Farinaz Koushanfar, Wayne Burleson
channel attacks on Strong Physical Unclonable Functions (Strong
PUFs). We illustrate our method by the example of the two
currently most secure (CCS 2010, IEEE T-IFS 2013) electrical
Strong PUFs, so-called XOR Arbiter PUFs and Lightweight
PUFs, and successfully attack them at sizes and complexities
far beyond the reach of pure modeling techniques (CCS 2010,
IEEE T-IFS 2013).
Our approach makes use of the first power and timing
side channels on PUFs reported in the literature. Both provide
information on the single outputs of the many parallel Arbiter
PUFs inside an XOR Arbiter PUF or Lightweight PUF, and
indicate how many of these single outputs (in sum) were equal
to one (and how many were equal to zero) before they entered
the final XOR gate. Taken for itself, this side channel information
is of little value. But if combined with suitably adapted machine
learning techniques, it substantially changes attack performance:
It reduces the empirically estimated complexities for modeling the
above two PUFs from exponential (CCS 2010, IEEE T-IFS) to
low degree polynomial.
The practical viability of our attacks is firstly demonstrated
by SPICE simulations, and by subsequent ML experiments on
numerically simulated CRPs. We thereby confirm attacks on the
two above PUFs for up to 16 XORs and challenge bitlengths
of up to 512. Secondly, we execute a full experimental proof-ofconcept
for our timing side channel, successfully attacking FPGA implementations of the two above PUF types for 8, 12, and 16
XORs, and bitlengths 64, 128, 256 and 512. We implement these
sizes for the first time in the literature in silicon, and subsequently attack them successfully by our new methods. We remark that in recent works (CCS 2010, IEEE T-IFS 2013), 8 XOR architectures
with bitlength 512 had been explicitly suggested as secure and
beyond the reach of current attacks.
Finally, we discuss efficient countermeasures against our power
and timing side channels. They could and should be used to secure
future Arbiter PUF generations against the latter.
Dongxia Bai, Hongbo Yu, Gaoli Wang, Xiaoyun Wang
16 December 2013
Hao Wang, Lei Wu Zhihua Zheng
Marcin Andrychowicz, Stefan Dziembowski, Daniel Malinowski, Łukasz Mazurek
Shi Bai, Steven D. Galbraith
Our ideas seem to be particularly suitable for signature schemes whose security, in the random oracle model, is based on standard worst-case computational assumptions. Our signatures are shorter than any previous proposal for provably-secure signatures based on standard lattice problems: at the 128-bit level we improve signature size from (more than) 16500 bits to around 9000 to 12000 bits.
Shi Bai, Steven D. Galbraith
Seung Geol Choi, Jonathan Katz, Dominique Schröder, Arkady Yerukhimovich, Hong Sheng Z
Motivated by this result, we investigate the minimal number of stateless tokens needed for universally composable OT/secure computation. We prove that our protocol is optimal in this regard for constructions making black-box use of the tokens (in a sense we define). We also show that nonblack-box techniques can be used to obtain a construction using only a single stateless token.
Johannes Braun, Florian Volk, Johannes Buchmann, Max Mühlhäuser
assigned to the Web Public Key Infrastructure (Web PKI) and trusted
by current browsers imposes severe security issues. Apart from being
impossible for relying entities to assess whom they actually trust, the
current binary trust model implemented with the Web PKI makes each
CA a single point of failure. In this paper, we present the concept of
trust views to manage variable trust levels for exactly those CAs actually
required by a relying entity. This reduces the set of trusted CAs
and minimizes the risk to rely on malicious certicates issued due to CA
failures or compromises.
Arthur Gervais, Ghassan Karame, Srdjan Capkun, Vedran Capkun
the services, decision making, mining, and the incident resolution processes in Bitcoin. We also show that third-party entities can unilaterally decide to \"devalue\" any specific set of Bitcoin addresses pertaining to any entity participating in the system. Finally, we explore possible avenues to enhance the decentralization in the Bitcoin system.