IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
14 February 2014
Masayuki Abe, Jens Groth, Miyako Ohkubo, Mehdi Tibouchi
State of the art structure-preserving signatures in the asymmetric setting consist of 3 group elements, which is known to be optimal. Our construction preserves the signature size of 3 group elements and also at the same time minimizes the verification key size to 1 group element.
Depending on the application, it is sometimes desirable to have strong unforgeability and in other situations desirable to have randomizable signatures. To get the best of both worlds, we introduce the notion of selective randomizability where the signer may for specific signatures provide randomization tokens that enable randomization.
Our structure-preserving signature scheme unifies the different pairing-based settings since it can be instantiated in both symmetric and asymmetric groups. Since previously optimal structure-preserving signatures had only been constructed in asymmetric bilinear groups this closes an important gap in our knowledge. Having a unified signature scheme that works in all types of bilinear groups is not just conceptually nice but also gives a hedge against future cryptanalytic attacks. An instantiation of our signature scheme in an asymmetric bilinear group may remain secure even if cryptanalysts later discover an efficiently computable homomorphism between the source groups.
Yuanxi Dai, John Steinberger
times with itself under independent keys---has received considerable
attention of late from the standpoint of provable security. Despite
these efforts proving definitive security bounds (i.e., with matching
attacks) has remained elusive even for the special case of triple
encryption. In this paper we close the gap by improving both the best
known attacks and best known provable security, so that both bounds
match. Our results apply for arbitrary number of rounds and show that
the security of $\\ell$-round multiple encryption is precisely
$\\exp(\\kappa + \\min\\{\\kappa (\\ell\'-2)/2), n (\\ell\'-2)/\\ell\'\\})$ where
$\\exp(t) = 2^t$ and where $\\ell\' = 2\\lceil \\ell/2\\rceil$ is the even
integer closest to $\\ell$ and greater than or equal to $\\ell$, for all
$\\ell \\geq 1$. Our technique is based on Patarin\'s H-coefficient
method and reuses a combinatorial result of Chen and Steinberger
originally required in the context of key-alternating ciphers.
Koji Nuida
Christina Brzuska, Pooya Farshim, Arno Mittelbach
We show that the existence of indistinguishability obfuscation (iO) implies (non-black-box) attacks on all the definitions that BHK proposed within their UCE framework in the original version of their paper, in the sense that no concrete hash function can satisfy them. We also show that this limitation can be overcome, to some extent, by restraining the class of admissible adversaries via a statistical notion of unpredictability. Following our attack, BHK (ePrint 2013/424, September 2013), independently adopted this approach in their work.
In the updated version of their paper, BHK (ePrint 2013/424, September 2013) also introduce two other novel source classes, called bounded parallel sources and split sources, which aim at recovering the computational applications of UCEs that fall outside the statistical fix. These notions keep to a computational notion of unpredictability, but impose structural restrictions on the adversary so that our original iO attack no longer applies. We extend our attack to show that indistinguishability obfuscation is sufficient to also break the UCE security of any hash function against bounded parallel sources. Towards this goal, we use the randomized encodings paradigm of Applebaum, Ishai, and Kushilevitz (STOC 2004) to parallelize the obfuscated circuit used in our attack, so that it can be computed by a bounded parallel source whose second stage consists of constant-depth circuits. We conclude by discussing the composability and feasibility of hash functions secure against split sources.
13 February 2014
Topic: On the Design of signcryption Schemes
Category: public-key cryptography
10 February 2014
Himanshu Tyagi, Shun Watanabe
The closeness of the two distributions is measured in terms of the exponent of the probability of error of type II for a binary hypothesis testing problem, thus bringing out a structural connection between secret key agreement and binary hypothesis testing. When the underlying data consists of an independent and identically distributed sequence, an application of our bound recovers several known upper bounds for the asymptotic rate of a secret key that can be generated, without requiring the agreement error probability or the security index to vanish to 0 asymptotically.
Also, we consider the following problem of secure function computation with trusted parties: Multiple parties observing correlated data seek to compute a function of their collective data. To this end, they communicate interactively over an insecure communication channel. It is required that the value of the function be concealed from an eavesdropper with access to the communication. When is such a secure computation of a given function feasible? Using the aforementioned upper bound, we derive a necessary condition for the existence of a communication protocol that allows the parties to reliably recover the value of a given function, while keeping this value concealed from an eavesdropper with access to (only) the communication.
Anne Canteaut, Thomas Fuhr, Henri Gilbert, Maria Naya-Plasencia, Jean-René Reinhard
cryptanalysts. Several results on reduced versions have been published
to date; the best one is an attack on 8 rounds out of the total number
of 12. In this paper we improve this result by two rounds: we provide
an attack on 10 rounds of the cipher with a data complexity of $2^{57.94}$ and a time complexity of $2^{60.62}$, corresponding to 118.56 security bits, instead of 126 for the generic attacks. Our attack uses multiple differentials and exploits some properties of PRINCE for recovering the whole key. PRINCE is defined as a member of a family of ciphers, differing by the choice of an Sbox among a distinguished set. We also show that the security offered by all the members of the family is not equivalent, by identifying an Sbox for which our attack can be extended up to 11 rounds with a data complexity of $2^{59.81}$ and a time complexity of $2^{62.43}$.
Virginie Lallemand, María Naya-Plasencia
S. M. Dehnavi, A. Mahmoodi Rishakani, M. R. Mirzaee Shamsabad
sigma-LFSR\'s.
Masao KASAHARA
K(I)SOPKC is constructed on the basis of K(XIV)SE(1)PKC, a modified version of K(XII)SE(1)PKC, K(XIII)SE(1)PKC and ${\\rm K_p(XIII)SE(1)PKC}$.
Manuel Barbosa, Pooya Farshim
Additionally we formalize Luck\'s transform and show that it does not always work if related keys are derived in an oracle-dependent way, and then prove it sound under appropriate restrictions.
Jacob Alperin-Sheriff, Chris Peikert
2009), for ``refreshing\'\' ciphertexts of a somewhat homomorphic
encryption scheme so that they can support further homomorphic
operations. To date, bootstrapping remains the only known way of
obtaining fully homomorphic encryption for arbitrary unbounded
computations.
Over the past few years, several works have dramatically improved the
efficiency of bootstrapping and the hardness assumptions needed to
implement it. Recently, Brakerski and Vaikuntanathan~(ITCS~2014)
reached the major milestone of a bootstrapping algorithm based on
Learning With Errors for \\emph{polynomial} approximation factors.
Their method uses the Gentry-Sahai-Waters~(GSW)
cryptosystem~(CRYPTO~2013) in conjunction with Barrington\'s ``circuit
sequentialization\'\' theorem~(STOC~1986). This approach, however,
results in \\emph{very large} polynomial runtimes and approximation
factors. (The approximation factors can be improved, but at even
greater costs in runtime and space.)
In this work we give a new bootstrapping algorithm whose runtime and
associated approximation factor are both \\emph{small} polynomials.
Unlike most previous methods, ours implements an elementary and
efficient \\emph{arithmetic} procedure, thereby avoiding the
inefficiencies inherent to the use of boolean circuits and
Barrington\'s Theorem. For $2^{\\lambda}$ security under conventional
lattice assumptions, our method requires only a \\emph{quasi-linear}
$\\Otil(\\lambda)$ number of homomorphic operations on GSW ciphertexts,
which is optimal (up to polylogarithmic factors) for schemes that
encrypt just one bit per ciphertext. As a contribution of independent
interest, we also give a technically simpler variant of the GSW system
and a tighter error analysis for its homomorphic operations.
07 February 2014
Wentao Zhang, Zhenzhen Bao, Dongdai Lin, Vincent Rijmen, Bohan Yang, Ingrid Verbauwhede
ANGLE. The main idea of the design of RECTANGLE is to allow lightweight
and fast implementations using bit-slice techniques. RECTANGLE uses an SP-
network. The substitution layer consists of 16 4×4 S-boxes in parallel. The per-
mutation layer is composed of 3 rotations. As shown in this paper, RECTAN-
GLE offers great performance in both hardware and software environment, which
proves enough flexibility for different application scenario. The following are 3
main advantages of RECTANGLE. First, RECTANGLE is extremely hardware-
friendly. For the 80-bit key version, a one-cycle-per-round parallel implementa-
tion only needs 1467 gates for a throughput of 246 Kbits/sec at 100KHz clock
and an energy efficiency of 1.11 pJ/bit. Second, RECTANGLE achieves a very
competitive software speed among the existing lightweight block ciphers due to
its bit-slice style. Using 128-bit SSE instructions, a bit-slice implementation of
RECTANGLE reaches an average encryption speed of about 5.38 cycles/byte for
messages around 1000 bytes. Last but not least. We propose new design criteria
for 4×4 S-boxes. RECTANGLE uses such a new type of S-box. Due to our care-
ful selection of the S-box and the asymmetric design of the permutation layer,
RECTANGLE achieves a very good security-performance tradeoff. Our exten-
sive and deep security analysis finds distinguishers for up to 14 rounds only, and
the highest number of rounds that we can attack, is 18 (out of 25).
Aleksandra Mileva
Wei Jiang, Dan Lin, Feng Li, Elisa Bertino
the efficiency of our protocol. Another advantage of the proposed protocol is lightweight computation and storage requirement, particularly suitable for any mobile devices with limited computation power and storage space.
Michael Backes, Aniket Kate, Praveen Manoharan, Sebastian Meiser, Esfandiar Mohammadi
In this work we present AnoA: a generic framework for defining, analyzing, and quantifying anonymity properties for AC protocols. AnoA relies on a novel relaxation of the notion of (computational) differential privacy, and thereby enables a unified quantitative analysis of well- established anonymity properties, such as sender anonymity, sender unlinkability, and relationship anonymity. While an anonymity analysis in AnoA can be conducted in a purely information theoretical manner, we show that the protocol\'s anonymity properties established in AnoA carry over to secure cryptographic instantiations of the protocol. We exemplify the applicability of AnoA for analyzing real-life systems by conducting a thorough analysis of the anonymity properties provided by the Tor network against passive adversarys. Our analysis significantly improves on known anonymity results from the literature.
06 February 2014
Victoria, Canada, September 15 - September 18
Notification: 6 June 2014
From September 15 to September 18
Location: Victoria, Canada
More Information: http://www.nspw.org/2014/cfp
Aarhus, Denmark, May 5 - May 9
Location: Aarhus, Denmark
More Information: http://ctic.au.dk/workshops-conferences/mpc-2014/
Fribourg, Switzerland, September 8 - September 12
Notification: 23 May 2014
From September 8 to September 12
Location: Fribourg, Switzerland
More Information: http://www.ectcm.net
05 February 2014
Daniel Kraschewski, Hemanta K. Maji, Manoj Prabhakaran, Amit Sahai
We provide a polynomial time algorithm to test whether a 2-party finite secure function evaluation (SFE) functionality (possibly randomized) is complete or not. The main tools in our solution include:
-- A formal linear algebraic notion of {\\em redundancy} in a general 2-party randomized function.
-- A notion of {\\em statistically testable games}. A kind of interactive proof in the information-theoretic setting where {\\em both} parties are computationally unbounded but differ in their knowledge of a secret.
-- An extension of the (weak) {\\em converse of Shannon\'s channel coding theorem}, where an adversary can adaptively choose the channel based on it view.
We show that any function $f$, if complete, can implement any (randomized) circuit $C$ using only $O(|C| + k)$ calls to $f$, where $k$ is the statistical security parameter. In particular, for any two-party functionality $g$, this establishes a universal notion of its quantitative ``cryptographic complexity\'\' independent of the setup and has close connections to circuit complexity.