International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

22 March 2014

Subhabrata Samajder, Palash Sarkar
ePrint Report ePrint Report
This paper develops two methods for exploring the structure of the stream cipher TRIVIUM.

We consider whether it is possible to compute the algebraic normal form (ANF) of such functions.

Since the key and the IV together make up 160 variables, doing this directly is not possible.

Instead, one can choose a subset of the key and IV variables of size $n$ and fix the other variables to constants.

As an application of this tool, we run some randomness experiments on the first output bit of TRIVIUM.

Three types of tests were conducted on full (and reduced) round TRIVIUM.

For the tests done, we fix a subset of $n$ key variables and vary the remaining $160 - n$ key and IV bit positions.

The first test tried to find polynomials which are non-random in some sense.

This is along the line of work done by Aumasson et. al. on their work on cube testers.

However, here we do not use any cube.

We try to find polynomials corresponding to the first output bit of TRIVIUM which are non-random.

Our experiments did reveal a number of polynomials which showed deviation from randomness.

The second test conducted checks the balancedness amongst the first $l$ output bits of TRIVIUM.

A proper statistical model for conducting such a test is proposed.

Tests results shows that the first $8$ output bits are unbalanced.

For the third test we consider $N$ random choices of the constant values keeping the $n$ key variables fixed.

A simple test of hypothesis is applied to detect possible non-randomness in the distributions.

Mostly, the results are negative.

In a few cases, the results seem to indicate the presence of possible non-randomness, though, nothing conclusive can be inferred from this test.

The symbolic computation tool developed here can conceivably be used for exploring other features of TRIVIUM.

Further, the idea behind the development of the tool can be used to build similar tools for other ciphers.

Expand

21 March 2014

Graz University of Technology, Austria, Europe
Job Posting Job Posting

The Institute of Applied Information Processing, Faculty of Computer Science and Biomedical Engineering at Graz University of Technology is inviting applications for a tenured professor position in Cryptography.

We are looking for an excellent researcher and teacher who advances the design and analysis of modern cryptographic methods for security and privacy in relevant application areas. The applicant should reinforce or complement existing research strengths at Graz University of Technology.

The Institute for Applied Information Processing and Communications researches information security in a broad context. More than 50 researchers work in fields such as cryptography, e-identity, trusted computing, secure system architectures, RFID security, secure implementation of cryptographic algorithms, side-channel analysis, network security, privacy and formal methods for design and verification.

Graz University of Technology is committed to increasing the percentage of female scientists in teaching and research. Given applicants with equal qualifications, we give priority to women.

Expand
CWI Amsterdam, NL, Europe
Job Posting Job Posting
CWI Amsterdam is looking for an excellent researcher in the area of cyber security, particularly the interface between mathematical cryptology and applied information security.

You have an excellent international research track record in cryptanalysis, with expertise in areas such as cryptographic hash functions, symmetric-key cryptography and side-channel attacks. Besides, you have broad scientific knowledge in cryptology, both in its theoretical, mathematical foundations as well as in its practical aspects, including design of algorithms, development of software, high-performance computing, industry standards and/or commercial products. You have a proven interest in applications of cryptology to practical information security (such as internet security) and you are willing to initiate or participate in research projects that relate to the Dutch cyber security policy.

As a researcher at CWI Amsterdam you are expected to perform fundamental and application-oriented research, to supervise Ph.D. students, to participate in or lead research projects together with other academic institutes or industry, and to acquire external funding. You are able to work as an independent researcher who can set his/her own research agenda, as demonstrated by previous post-doctoral work experience. You can connect to current research at CWI while at the same time bringing in substantial new expertise.

The Cryptology group operates on the interface between mathematics and computer science and

is currently focused on public-key cryptology, secure multi-party computation, quantum information theory and -cryptography, cryptanalysis and mathematical cryptology at large.

The group is affiliated with the Dutch mathematics research cluster “Discrete, Interactive and Algorithmic Mathematics, Algebra and Number Theory” (DIAMANT).

For more information about CWI, requirements, terms and conditions and how to apply, please vi

Expand
Katsuyuki Takashima
ePrint Report ePrint Report
We propose a key-policy attribute-based encryption (KP-ABE) scheme with constant-size ciphertexts, whose (selective) security is proven under the decisional linear (DLIN) assumption in the standard model. The access structure is expressive, that is given by non-monotone span programs. It also has fast decryption, i.e., a decryption includes only a constant number of pairing operations. As an application of our KP-ABE construction, we also propose a fully secure attribute-based signatures with constant-size secret (signing) key from the DLIN assumption. For achieving the above results, we employ a hierarchical reduction technique on dual pairing vector spaces (DPVS), where a high-level problem given on DPVS is used for proving the scheme security and then the security of the problem is reduced to that of the DLIN problem.

Expand

20 March 2014

Busan, Korea, September 23
Event Calendar Event Calendar
Submission: 23 May 2014
Notification: 27 June 2014
From September 23 to September 23
Location: Busan, Korea
More Information: http://conferenze.dei.polimi.it/FDTC14/index.html
Expand
Colin O\'Flynn, Zhizhang (David) Chen
ePrint Report ePrint Report
This paper introduces a complete side channel analysis toolbox, inclusive of the analog capture hardware, target device, capture software, and analysis software. The highly modular design allows use of the hardware and software with a variety of existing systems. The hardware uses a synchronous capture method which greatly reduces the required sample rate, while also reducing the data storage requirement, and improving synchronization of traces. The synchronous nature of the hardware lends itself to fault injection, and a module to generate glitches of programmable width is also provided. The entire design (hardware and software) is open-source, and maintained in a publicly available repository. Several long example capture traces are provided for researchers looking to evaluate standard cryptographic implementations.

Expand
Ling Ren, Christopher Fletcher, Xiangyao Yu, Albert Kwon, Marten van Dijk, Srinivas Devadas
ePrint Report ePrint Report
Oblivious RAM (ORAM) is a cryptographic primitive that hides memory access patterns to untrusted storage. ORAM may be used in secure processors for encrypted computation and/or software protection. While recursive Path ORAM is currently the most practical ORAM for secure processors, it still incurs large performance and energy overhead and is the performance bottleneck of recently proposed secure processors.

In this paper, we propose two optimizations to recursive Path ORAM.

First, we identify a type of program locality in its operations to improve performance. Second, we use pseudorandom function to compress the position map. But applying these two techniques in recursive Path ORAM breaks ORAM security. To securely take advantage of the two ideas, we propose unified ORAM. Unified ORAM improves performance both asymptotically and empirically. Empirically, our experiments show that unified ORAM reduces data movement from ORAM by half and improves benchmark performance by 61% as compared to recursive Path ORAM.

Expand

19 March 2014

Santa Barbara, USA, August 14 - August 18
CRYPTO CRYPTO
From August 14 to August 18
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/
Expand
Santa Barbara, USA, August 20 - August 24
CRYPTO CRYPTO
From August 20 to August 24
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/
Expand
Santa Barbara, USA, August 19 - August 23
CRYPTO CRYPTO
From August 19 to August 23
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/
Expand

18 March 2014

PhD Database PhD Database
Name: Diego F. Aranha
Topic: Efficient software implementation of elliptic curves and bilinear pairings
Category: implementation

Description:

The development of asymmetric or public key cryptography made possible new applications of cryptography such as digital signatures and electronic commerce. Cryptography is now a vital component for providing confidentiality and authentication in communication infra-structures. Elliptic Curve Cryptography is among the most efficient public-key methods because of its low storage and computational requirements. The relatively recent advent of Pairing-Based Cryptography allowed the further construction of flexible and innovative cryptographic solutions like Identity-Based Cryptography and variants. However, the computational cost of pairing-based cryptosystems remains significantly higher than traditional public key cryptosystems and thus an important obstacle for adoption, specially in resource-constrained devices.\r\n

\r\nThe main contributions of this work aim to improve the performance of curve-based cryptosystems, consisting of:
(i) efficient implementation of binary fields in 8-bit microcontrollers embedded in sensor network nodes;
(ii) efficient formulation of binary field arithmetic in terms of vector instructions present in 64-bit architectures, and on the recently-introduced native support for binary field multiplication in the latest Intel microarchitecture families;
(iii) techniques for serial and parallel implementation of binary elliptic curves and symmetric and asymmetric pairings defined over prime and binary fields. \r\n
\r\nThese contributions produced important performance improvements and, consequently, several speed records for computing relevant cryptographic algorithms in modern computer architectures ranging from embedded 8-bit microcontrollers to 8-core processors.

[...]
Expand
Pune, India, October 18 - October 22
Event Calendar Event Calendar
Submission: 1 June 2014
Notification: 11 July 2014
From October 18 to October 22
Location: Pune, India
More Information: http://cse.iitkgp.ac.in/conf/SPACE2014/#
Expand

17 March 2014

Dan Bogdanov, Peeter Laud, Sven Laur, Pille Pullonen
ePrint Report ePrint Report
Secure multiparty computation systems are commonly built form a small set of primitive components. Composability of security notions has a central role in the analysis of such systems, since it allows us to deduce security properties of complex protocols from the properties of its components. We show that the standard notions of universally composable security are overly restrictive in this context and can lead to protocols with sub-optimal performance. As a remedy, we introduce a weaker notion of privacy that is satisfied by simpler protocols and is preserved by composition. After that we fix a passive security model and show how to convert a private protocol into a universally composable protocol. As a result, we obtain modular security proofs without performance penalties.

Expand
Rosario Gennaro, Valerio Pastro
ePrint Report ePrint Report
We consider the problem of a client who outsources the computation of a function $f$ over an input $x$ to a server, who returns $y=f(x)$. The client wants to be assured of the correctness of the computation and wants to preserve confidentiality of the input $x$ and possibly of the function $f$ as well. Moreover, the client wants to invest substantially less effort in verifying the correctness of the result than it would require to compute $f$ from scratch.

This is the problem of secure outsourced computation over encrypted data. Most of the work on outsourced computation in the literature focuses on either privacy of the data, using {\\em Fully Homomorphic Encryption (FHE)}, or the integrity of the computation. No general security definition for protocols achieving both privacy and integrity appears in the literature. Previous definitions only deal with a very limited security model where the server is not allowed to

issue {\\em verification queries} to the client: i.e. it is not allowed to ``see\'\' if the client accepts or rejects the value $y$.

In this paper we present:

-- A formal definition of {\\em private and secure} outsourced computation {\\em in the presence of verification queries};

-- A protocol based on FHE that achieves the above definition for arbitrary poly-time computations;

-- Some additional protocols for the computation of {\\em ad-hoc} functions (such as the computation of polynomials and linear

combinations) over encrypted data. These protocols do not use the power of FHE, and therefore are much more efficient than the generic approach. We point out that some existing protocols in the literature for these tasks become insecure in the presence of verification queries, while our protocols can be proven in the stronger security model where verification queries are allowed.

Expand
LIASD, University Paris 8, France
Job Posting Job Posting
The ANR \\\"SIMPATIC: SIM and PAiring Theory for Information and Communications security\\\" will recruit one post-doc position for the academic year 2014-2015.

The successful applicant will be a member of the Computer Science (LIASD) laboratory at Paris 8 University, France.

The position is open for one year, and may exceptionnally be renewed for a second year. If necessary, the starting date can be arranged as convenient.

The partners involved in the SIMPATIC project are the crypto teams of the Laboratoire d\\\'Informatique de l\\\'ENS Paris, of IMB (Bordeaux), of University Paris 8 (LAGA and LIASD), of University of Caen, Oberthur, INVIA, ST (Le Mans) and Orange Labs (Caen). Further information about the SIMPATIC project can be found on its webpage http://simpatic.orange-labs.fr/ .

Preference will be given to condidates whose profile is adapted to one of the following priorities of the project:

(i) The study of suitable pairing-friendly curves, both theoretical and algorithmic aspects. Candidates should therefore have a good background in relevant number theory and algebraic geometry. Some experience in software implementation (for example in Pari, Magma, Sage, ...) would be useful.

(ii) The secure implementation of efficient arithmetic suitable for SIMs and other small supports. Candidates are expected to have a good potential in theoretical cryptography.

(iii) The study of side channel attack in pairing based cryptography, both theoretical and practical. Candidates are expected to have a good potential in theoretical cryptography. He/she will be expected to interact with members of Oberthur.

Candidates must hold a PhD thesis or equivalent in mathematics or computer science, together with a strong research record.

Expand
Santa Barbara, USA, August 19 - August 23
CRYPTO CRYPTO
From August 19 to August 23
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/
Expand
Santa Barbara, USA, August 20 - August 24
CRYPTO CRYPTO
From August 20 to August 24
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/
Expand
Santa Barbara, USA, August 14 - August 18
CRYPTO CRYPTO
From August 14 to August 18
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/
Expand
Santa Barbara, USA, August 16 - August 20
CRYPTO CRYPTO
From August 16 to August 20
Location: Santa Barbara, USA
More Information: http://www.iacr.org/conferences/
Expand
Eric M. Mahé, Jean-Marie Chauvet
ePrint Report ePrint Report
This paper presents a fast implementation to compute the scalar multiplication of elliptic curve points based on a ``General-Purpose computing on Graphics Processing Units\'\' (GPGPU) approach. A GPU implementation using Dan Bernstein\'s Curve25519, an elliptic curve over a 255-bit prime field complying with the new 128-bit security level, computes the scalar multiplication in less than a microsecond on AMD\'s R9 290X GPU. The presented methods and implementation considerations can be applied to any parallel architecture.

Expand
◄ Previous Next ►