International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

16 March 2014

Announcement Announcement
Scott Vanstone (1947-2014)
Expand

15 March 2014

Paris, France, November 5 - November 7
Event Calendar Event Calendar
Submission: 27 June 2014
From November 5 to November 7
Location: Paris, France
More Information: http://www.cardis.org/
Expand
Announcement Announcement

It is a great honor for me to have been elected as the President of the IACR and a challenge at the same time. Today cryptography is a vibrant research field that offers important and exciting questions to work on. It has not lost any of its fascination to me over the last 20 years since I entered the field as a graduate student -- quite to the contrary. In the age of cloud computing, cryptology continues to be a key technology for securing the digital world. Starting with the Snowden revelations in 2013, cryptography has also regained a level of political visibility that reminds me of the debates that were taking place in the 1990's. This gives us, as cryptologists and members of the IACR, an exposure that is hard to match.

In 2013 cryptology demonstrated (again) the power of its contributions to society, science, and technology by Shafi Goldwasser and Silvio Micali winning the ACM Turing Award, the highest distinction in computer science. As the ACM Turing Award page shows very visibly (http://amturing.acm.org/bysubject.cfm), cryptology is one of the most promising research topics for winning the Turing Award. Congratulations, Shafi and Silvio!

The IACR's events were well-attended and well-organized in 2013. The first two of our 2014 events, TCC in San Diego and FSE in London, are already over with about 120 and about 160 attendees, respectively. For the upcoming Eurocrypt in Copenhagen, everyone is advised to book early. Due to Eurovision Song Contest 2014 in the week just before Eurocrypt, hotels may be difficult to find or expensive.

The composition of the Board of Directors has changed for 2014. New members of the Board are: Ivan Damgaard, as new JoC Editor-in-Chief; Steven Galbraith, Asiacrypt 2015 General Chair; Svetla Petkova-Nikova, Eurocrypt 2015 General Chair; and Thomas Ristenpart, Crypto 2015 General Chair. Matt Franklin will stay on the Board in 2014 for easing the transition of the Journal to Ivan Damgaard.

IACR exists only through the work of volunteers, who bring our conferences, events, online systems, and publications to life. I'd like to thank everyone for contributing their time to IACR. It is hard work but important for our organization. At the same time, I am looking forward to hearing about your future plans and ideas for how you would like to help and to improve IACR.

Very concretely, the European members of the Board of Directors are currently looking for a proposal to host Eurocrypt 2016. If you are inclined and would like to know more about exposing your skills as a conference organizer, please step forward and contact Michel Abdalla or any other member of the Board.

For 2014 and beyond, the IACR will have to address the challenges to scientific publishing posed by two factors, by the Internet and by the growing field. The IACR has a long tradition of operating with a liberal, author-friendly attitude to copyright. This has made it possible, among other things, that all IACR publications starting from 1982 are now openly available over the Internet via the IACR website; only the last two years are restricted to IACR members. Second, the growth in our field has boosted the number of paper submissions and conference attendees, but also led to record low acceptance rates and excessive reviewing load. We will resume the open discussion on the future of IACR's publications, in order to address these challenges.

With my new role as President, I have to cut back on other ends. I am glad that Nigel Smart has taken over my job as co-editor of the Cryptology ePrint Archive, or "eprint" as called by most. He shares this workload with Tal Rabin. Almost 15 years ago, when I had created the online system that still runs today, it had not occurred to me that the eprint archive would ever play such a useful role for research in cryptology.

Shortly before writing this, the sad news reached us that Scott Vanstone has passed away on March 2nd. He was a giant in the field, and the IACR will honor his contributions separately. Let me only mention that he was a past Director of the IACR and had helped to grow the organization, and he became an IACR Fellow in 2011.

I look forward to interacting with you in 2014.

Christian Cachin
IACR President

This letter had stated erroneously that Scott Vanstone was past President of the IACR; in fact, he was a member of the Board of Directors.

Expand

14 March 2014

Benlcouiri Younes, Azizi Abdelmalek, Moulay Chrif Ismaili
ePrint Report ePrint Report
This paper is structured on securing of storage, transmission and the traceability of digital images. It consists in the design of the cryptographic algorithms appropriate to the case of fixed and moving images.

In this sense, we have introduced two approaches that is different in the synthesis of confusion and diffusion on using the principles of substitu-tion and/or transposition to secure JPEG and MPEG format.

Expand
Jian Guo, Jérémy Jean, Thomas Peyrin, Wang Lei
ePrint Report ePrint Report
In this short article, we describe a very practical and simple attack on the authentication part of POET authenticated encryption mode proposed at FSE 2014. POET is a provably secure scheme that was designed to resist various attacks where the adversary is allowed to repeat the nonce, or even when the message is output before verifying the validity of the tag when querying the decryption oracle. However, we demonstrate that using only a single encryption query and a negligible amount of computations, even without any special misuse from the attacker, it is possible to generate many valid ciphertext/tag pairs for POET. Our work shows that one should not use POET for any application where authentication property is required. Furthermore, we propose a possible patch to overcome this particular issue, yet without backing up this patch with a security proof.

Expand

13 March 2014

Sai Raghu Talluri, Swapnoneel Roy
ePrint Report ePrint Report
In this work we consider two protocols for performing cryptanalysis and security enhancement. The first one by Jiang et al., is a password-based authentication scheme which does not use smart cards. We note that this scheme is an improvement over Chen et al.\'s scheme shown vulnerable to the off-line dictionary attack by Jiang et al. We perform a cryptanalysis on Jiang at al.\'s improved protocol and observe that it is prone to the clogging attack, a kind of denial of service (DoS) attack. We then suggest an improvement on the protocol to prevent the clogging attack.

The other protocol we consider for analysis is by Wang et al. This is a smart card based authentication protocol. We again perform the clogging (DoS) attack on this protocol via replay. We observe that all smart card based authentication protocols which precede the one by Wang et al., and require the server to compute the computationally

intensive modular exponentiation are prone to the clogging attack. We suggest (another) improvement on the protocol to prevent the clogging attack, which also applies to the protocol by Jiang et. al.

Expand
Dan Boneh, Brent Waters, Mark Zhandry
ePrint Report ePrint Report
We use multilinear maps to provide a solution to the long-standing problem of public-key broadcast encryption where all parameters in the system are small. In our constructions, ciphertext overhead, private key size, and public key size are all poly-logarithmic in the total number of users. The systems are fully secure against any number of colluders. All our systems are based on an O(logN)-way multilinear map to support a broadcast system for N users. We present three constructions based on different types of multilinear maps and providing different security guarantees. Our systems naturally give identity-based broadcast systems with short parameters.

Expand
Wroclaw, Poland, September 7 - September 11
Event Calendar Event Calendar
Submission: 2 April 2014
Notification: 10 June 2014
From September 7 to September 11
Location: Wroclaw, Poland
More Information: http://esorics2014.pwr.wroc.pl/index.html
Expand
Javad Alizadeh, Mohammad Reza Aref, Nasour Bagheri
ePrint Report ePrint Report
In this paper we present JHAE, an authenticated encryption (AE) mode based on the JH hash mode. JHAE is a dedicated AE mode based on permutation. We prove that this mode, based on ideal permutation, is provably secure.

Expand
TELECOM-ParisTech
Job Posting Job Posting
TELECOM-ParisTech crypto group seeks 4 PhD students

TELECOM-ParisTech crypto group develops prototype solutions to fight against cyber and physical penetration of embedded devices.

Our contributions in this field of research are:

  • Security building blocks:

    • with security / cost tradeoffs (quantifiable), e.g. \\\"Low Entropy Masking Schemes\\\" (LEMS), where security and cost are tunable by the amount of injected randomness,

    • resistance against invasive attacks (e.g., circuit editing, backside probing),

    • processor aware of malware usual attack strategies

  • Security policies:

    How to implement a responsive \\\"security driver\\\" that collects all the alarms and take adequate actions?

    Such piece of software is critical: it must be functionally validated and tamper resistant

  • Formal proofs:

    • Both security-oriented hardware and software codes must be proven, as compliant with their specification and implementing indeed the properties they are assumed to have

    • Mathematical analysis of proposed countermeasures (e.g. LEMS)

We seek four PhD candidates on those subjects:

  1. \\\"Calculer dans les codes comme contremesure aux attaques physiques\\\", https://edite-de-paris.fr/spip/spip.php?page=phdproposal&id=10213751

  2. \\\"Native Protection of Processors against Cyber-Attacks\\\", https://edite-de-paris.fr/spip/spip.php?page=phdproposal&id=10253861

  3. \\\"Insertion automatique de contre-mesures dans des circuits de sécurité\\\", https://edite-de-paris.fr/spip/spip.php?page=phdproposal&id=10213779

  4. \\\"Attaques FIRE : Rétroconception de cryptographie secrète\\\", https://edite-de-paris.fr/spip/spip.php?page=phdproposal&id=10166999

Working language is French or English.

Positions are open until Aug 2014.

To ap

Expand
Istanbul, Turkey, October 16 - October 17
Event Calendar Event Calendar
Submission: 1 August 2014
Notification: 15 September 2014
From October 16 to October 17
Location: Istanbul, Turkey
More Information: http://www.gstl.itu.edu.tr/BalkanCryptSec/
Expand

12 March 2014

Özgür Dagdelen, Daniele Venturi
ePrint Report ePrint Report
Fischlin\'s transformation is an alternative to the standard Fiat-Shamir transform to turn a certain class of public key identification schemes into digital signatures (in the random oracle model).

We show that signatures obtained via Fischlin\'s transformation are existentially unforgeable even in case the adversary is allowed to get arbitrary (yet bounded) information on the entire state of the signer (including the signing key and the random coins used to generate signatures). A similar fact was already known for the Fiat-Shamir transform, however, Fischlin\'s transformation allows for a significantly higher leakage parameter than Fiat-Shamir.

Moreover, in contrast to signatures obtained via Fiat-Shamir, signatures obtained via Fischlin enjoy a tight reduction to the underlying hard problem. We use this observation to show (via simulations) that Fischlin\'s transformation, usually considered less efficient, outperforms the Fiat-Shamir transform in verification time for a reasonable choice of parameters. In terms of signing Fiat-Shamir is faster for equal signature sizes. Nonetheless, our experiments show that the signing time of Fischlin\'s transformation becomes, e.g., 22% of the one via Fiat-Shamir if one allows the signature size to be doubled.

Expand
Jaydeep Howlader, Sanjit Kumar Roy, Ashis Kumar Mal
ePrint Report ePrint Report
Sealed-Bid auction is an efficient and rational method to

establish the price in open market. However sealed-bid auctions are sub-

ject to bid-rigging attack. Receipt-free mechanisms were proposed to

prevent bid-rigging. The prior receipt-free mechanisms are based on two

assumptions; firstly, existence of untappable channel between bidders

and auction authorities. Secondly, mechanisms assume the authorities

to be honest (not colluding). Moreover the bandwidth required to com-

municate the receipt-free bids is huge. This paper presents a sealed-bid

auction mechanism to resist bid-rigging. The proposed method does not

assume untappable channel nor consider the authorities to be necessarily

honest. The proposed mechanism also manages the bandwidth efficiently,

and improves the performance of the system.

Expand
Michael Hutter, Jörn-Marc Schmidt
ePrint Report ePrint Report
In this paper, we present practical results of data leakages of CMOS devices via the temperature side channel---a side channel that has been widely cited in literature but not well characterized yet. We investigate the leakage of processed data by passively measuring the dissipated heat of the devices. The temperature leakage is thereby linearly correlated with the power leakage model but is limited by the physical properties of thermal conductivity and capacitance. We further present heating faults by operating the devices beyond their specified temperature ratings. The efficiency of this kind of attack is shown by a practical attack on an RSA implementation. Finally, we introduce data remanence attacks on AVR microcontrollers that exploit the Negative Bias Temperature Instability (NBTI) property of internal SRAM cells. We show how to recover parts of the internal memory and present first results on an ATmega162. The work encourages the awareness of temperature-based attacks that are known for years now but not well described in literature. It also serves as a starting point for further research investigations.

Expand
Benoit Feix, Mylène Roussellet, Alexandre Venelli
ePrint Report ePrint Report
We present a new side-channel attack path threatening state-of-the-art protected implementations of elliptic curves embedded scalar multiplications. Regular algorithms such as the double-and-add-always and the Montgomery ladder are commonly used to protect the scalar multiplication from simple side-channel analysis. Combining such algorithms with scalar and/or point blinding countermeasures lead to scalar multiplications protected from all known attacks. Scalar randomization, which consists in adding a random multiple of the group order to the scalar value, is a popular countermeasure due to its efficiency. Amongst the several curves defined for usage in elliptic curves products, the most used are those standardized by the NIST. The modulus, hence the orders, of these curves are sparse, primarily for efficiency reasons. In this paper, we take advantage of this specificity to present new attack paths and recover the secret scalar of state-of-the-art protected elliptic curve implementations.

Expand
Abdoul Aziz Ciss
ePrint Report ePrint Report
This paper studies the task of two-sources randomness extractors for elliptic curves defined over finite fields $K$, where $K$ can be a prime or a binary field. In fact, we introduce new constructions of functions over elliptic curves which take in input two random points from two differents subgroups. In other words, for a ginven elliptic curve $E$ defined over a finite field $\\mathbb{F}_q$ and two random points $P \\in \\mathcal{P}$ and $Q\\in \\mathcal{Q}$, where $\\mathcal{P}$ and $\\mathcal{Q}$ are two subgroups of $E(\\mathbb{F}_q)$, our function extracts the least significant bits of the abscissa of the point $P\\oplus Q$ when $q$ is a large prime, and the $k$-first $\\mathbb{F}_p$ coefficients of the asbcissa of the point $P\\oplus Q$ when $q = p^n$, where $p$ is a prime greater than $5$. We show that the extracted bits are close to uniform.

Our construction extends some interesting randomness extractors for elliptic curves, namely those defined in \\cite{op} and \\cite{ciss1,ciss2}, when $\\mathcal{P} = \\mathcal{Q}$. The proposed constructions can be used in any cryptographic schemes which require extraction of random bits from two sources over elliptic curves, namely in key exchange protole, design of strong pseudo-random number generators, etc.

Expand

11 March 2014

Yosuke Todo
ePrint Report ePrint Report
The integral attack is one of the most powerful attack against block ciphers. In this paper, we propose two new techniques for the integral attack, the FFT technique and the key concealment technique. The FFT technique is useful for the integral attack with enormous chosen plaintexts. As the previous result using FFT, Collard et al. showed a new technique which reduces the complexity for the linear attack. In this paper, we review the result of Collard et al. to estimate the complexity in detail, and we show the complexity can be estimated from the number of times using the addition of integers. Moreover, we show that attacks using FFT can be applied to the integral attack. As applications, we show integral attacks against AES and CLEFIA. For AES, we show that 6-round AES can be attacked with about $2^{51.7} additions. For CLEFIA, we show that 12-round CLEFIA can be attacked with about $2^{86.9}$ additions.

Expand

10 March 2014

Andrey Bogdanov, Martin M. Lauridsen, Elmar Tischhauser
ePrint Report ePrint Report
Authenticated encryption (AE) has recently gained renewed interest due to the ongoing CAESAR competition. This paper deals with the performance of block cipher modes of operation for AE in parallel software. We consider the example of the AES on Intel\'s new Haswell microarchitecture that has improved intructions for AES rounds and finite field multiplication.

As opposed to most previous high-performance software implementations of operation modes -- that have considered the encryption of single messages -- we propose to process multiple messages in parallel. We demonstrate that this message scheduling is of significant advantage for most modes. As a baseline for longer messages, the performance of AES-CBC encryption on a single core increases by factor 6.8 when adopting this approach.

For the first time, we report optimized AES-NI implementations of the novel AE modes OTR, McOE-G, COBRA, and POET -- both with single and multiple messages. For almost all AE modes considered, we obtain a consistent speed-up when processing multiple messages in parallel. Notably, among the nonce-based modes, AES-CCM gets by factor 3.5 faster and its performance is about 1.2 cpb which is close to that of AES-GCM (the latter, however, possessing classes of weak keys), with AES-OCB3 still performing at only 0.69 cpb. Among the nonce-misuse resistant modes, AES-McOE-G receives a speed-up by factor 4 and its performance is about 1.44 cpb, which is faster than AES-COBRA with its 1.55 cpb but slower than AES-COPA with 1.29 cpb.

Expand
University of and CWI Amsterdam, the Netherlands, Europe
Job Posting Job Posting
The Institute for Logic, Language & Computation (ILLC) at the University of Amsterdam, and the Centrum Wiskunde & Informatica (CWI) are looking for a PhD candidate in the area of quantum cryptography under the supervision of Dr. Christian Schaffner.

The aim of the PhD project is to develop new quantum-cryptographic protocols (beyond the task of key distribution) and explore their possibilities and limitations. An example of an active research topic is position-based quantum cryptography. Another aspect is to investigate the security of classical cryptographic schemes against quantum adversaries (post-quantum cryptography).

Full-time appointment is on a temporary basis for a period of four years. For the first two years the PhD candidate will be appointed at the ILLC, University of Amsterdam, initially for a period of 18 months and then, on positive evaluation, for a further six months. During the final two years, the PhD candidate will be employed by the Centrum Wiskunde and Informatica (CWI). On the basis of a full-time appointment (38 hours per week), the gross monthly salary amounts to €2,083 during the first year, rising to €2,664 during the fourth year.

Requirements:

  • A Master\\\'s degree with excellent grades in computer science, mathematics or physics with outstanding results or a comparable degree;

  • candidates with a strong background in cryptography or quantum information processing are preferred;

  • good academic writing and presentation skills;

  • good social and organisational skills.

Preferred starting date is 1 September 2014 (or earlier if possible).

Expand

09 March 2014

Karthikeyan Bhargavan, Cédric Fournet, Markulf Kohlweiss, Alfredo Pironti, Pierre-Yves Strub, Santiago Zanella-Béguelin
ePrint Report ePrint Report
The TLS protocol features a mixed bag of cryptographic algorithms and constructions, letting clients and servers negotiate their use for each run of the handshake. Although many ciphersuites are now well-understood in isolation, their composition remains problematic, and yet it is critical to obtain practical security guarantees for TLS. We experimentally confirm that all mainstream implementations of TLS share key materials between many different algorithms, some of them of dubious strength. We outline new attacks we found in their handling of session resumption and renegotiation, stressing the need to model multiple related instances of the handshake.

We systematically study the provable security of the TLS handshake, as

it is implemented and deployed. To capture the details of the standard and its main extensions, we rely on miTLS, a verified reference implementation of the protocol. miTLS inter-operates with mainstream browsers and servers for many protocol versions, configurations, and ciphersuites; and it provides application-level, provable security for some.

We propose new agile security definitions and assumptions for the signatures, key encapsulation mechanisms, and key derivation algorithms used by the TLS handshake. By necessity, our definitions are stronger than those expected with simple modern protocols.

To validate our model of key encapsulation, we prove that RSA

ciphersuites satisfy the security assumption needed for our proof of

the handshake. Specifically, we formalize the use of PKCS#1v1.5 encryption in TLS, including recommended countermeasures against Bleichenbacher attacks, and build a 3,000-line EasyCrypt proof of its security against replayable chosen-ciphertext attacks under the assumption that ciphertexts are hard to re-randomize.

Based on our new agile definitions, we construct a modular proof of security for the miTLS reference implementation of the handshake, including ciphersuite negotiation, key exchange, renegotiation, and resumption, treated as a detailed 3,600-line executable model.

We present our main definitions, constructions, and proofs for an abstract model of the protocol, featuring series of related runs of the handshake with different ciphersuites. We also describe its refinement to account for the whole reference implementation, based on automated verification tools.

Expand
◄ Previous Next ►