IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
03 April 2014
Technische Universität Darmstadt, Germany
Our group is involved in the two main research centers for IT security in Darmstadt, the Center for Advanced Security Research Darmstadt (CASED) and the European Center for Security and Privacy by Design (EC SPRIDE). We develop new methods and tools to optimize and automatically generate cryptographic protocols. See http://encrypto.de for details.
The candidate will work in the EU FP 7 research project PRACTICE (Privacy-Preserving Computation in the Cloud), http://www.practice-project.eu, with the goal of developing, optimizing, and automatically generating secure computation protocols for cloud computing.
The candidate is expected to have a completed Master (or equivalent) degree with excellent grades in IT security, computer science, electrical engineering, mathematics, or a closely related field. Solid knowledge in IT security, applied cryptography, and programming skills is required. Additional knowledge in cryptographic protocols, parallel computing, compiler construction, programming languages, and software engineering is a plus.
Review of applications starts immediately until the position is filled.
Please consult the webpage given below for more details and how to apply.
02 April 2014
Istanbul, Turkey, September 1 - September 2
Notification: 11 July 2014
From September 1 to September 2
Location: Istanbul, Turkey
More Information: www.light-sec.org/
Wroclaw, Poland, September 10 - September 11
Notification: 10 July 2014
From September 10 to September 11
Location: Wroclaw, Poland
More Information: http://wls.orange-labs.fr/smartcondevsp2014/
01 April 2014
Mohammad Rezaeirad, Muhammad Aamir Iqbal, Dmitri Perkins, Magdy Bayoumi
Sorina Ionica, Emmanuel Thomé
abelian varieties and whose edges are isogenies between these varieties. In
his thesis, Kohel described the structure of isogeny graphs for elliptic
curves and showed that one may compute the endomorphism ring of an elliptic
curve defined over a finite field by using a depth first search algorithm
in the graph. In dimension 2, the structure of isogeny graphs is less understood and existing algorithms for computing endomorphism rings are very expensive.
Our setting considers genus 2 jacobians with complex multiplication,
with the assumptions that the real multiplication subring is maximal and
has class number one. We fully describe the isogeny graphs in that
case.
Over finite fields, we derive a depth first search algorithm for computing endomorphism rings locally at prime numbers, if the real multiplication is maximal. To the best of our knowledge, this is the first DFS-based algorithm in genus 2.
Kwangsu Lee
In this paper, we propose an efficient SUE scheme and its extended schemes. First, we propose an SUE scheme with short public parameters in prime-order bilinear groups and prove its security under a $q$-type assumption. Next, we extend our SUE scheme to a time-interval SUE (TI-SUE) scheme that supports a time interval in ciphertexts. Our TI-SUE scheme has short public parameters and also secure under the $q$-type assumption. Finally, we propose the first large universe RS-ABE scheme with short public parameters in prime-order bilinear groups and prove its security in the selective revocation list model under a $q$-type assumption.
Yark{\\i}n Dor\\\"{o}z, Berk Sunar, Ghaith Hammouri
Yark{\\i}n Dor\\\"{o}z, Aria Shahverdi, Thomas Eisenbarth, and Berk Sunar
Xiangyao Yu, Ling Ren, Christopher Fletcher, Albert Kwon, Marten van Dijk, Srinivas Devadas
With ORAM, a curious adversary cannot tell what data address the user is accessing when observing the bits moving between the user and the storage system.
All existing ORAM schemes achieve obliviousness by adding redundancy to the storage system, i.e., each access is turned into multiple random accesses.
Such redundancy incurs a large performance overhead.
Though traditional data prefetching techniques successfully hide memory latency in DRAM based systems, it turns out that they do not work well for ORAM.
In this paper, we exploit ORAM locality by taking advantage of the ORAM internal structures.
Though it might seem apparent that obliviousness and locality are two contradictory concepts, we challenge this intuition by exploiting data locality in ORAM without sacrificing provable security.
In particular, we propose an ORAM prefetching technique called dynamic super block scheme and comprehensively explore its design space.
The dynamic super block scheme detects data locality in the program\'s working set at runtime, and exploits the locality in a data-independent way.
% based on the key observation that position map ORAMs have better locality than the data ORAM.
Our simulation results show that with dynamic super block scheme, ORAM performance without super blocks can be significantly improved. After adding timing protection to ORAM, the average performance gain is 25.5\\% (up to 49.4\\%) over the baseline ORAM and 16.6\\% (up to 30.1\\%) over the best ORAM prefetching technique proposed previously.
Alexandra Boldyreva, Nathan Chenette
Next we identify an optimal security notion for EFSE. We demonstrate that existing schemes do not meet our security definition and propose a new scheme that we prove secure under basic assumptions. Unfortunately, the scheme requires large ciphertext length, but we show that, in a sense, this space-inefficiency is unavoidable for a general, optimally-secure scheme.
Seeking the right balance between efficiency and security, we then show how to construct schemes that are more efficient and satisfy a weaker security notion that we propose. To illustrate, we present and analyze a more space-efficient scheme for supporting fuzzy search on biometric data that achieves the weaker notion.
Paris, France, September 1 - September 5
Notification: 16 June 2014
From September 1 to September 5
Location: Paris, France
More Information: http://2014.qcrypt.net/
Gaithersburg, USA, April 2 - April 3
Notification: 1 February 2015
From April 2 to April 3
Location: Gaithersburg, USA
More Information: http://www.nist.gov/itl/csd/ct/post-quantum-crypto-workshop-2015.cfm
29 March 2014
Achiya Bar-On, Itai Dinur, Orr Dunkelman, Virginie Lallemand, Mar\\\'{\\i}a Naya-Plasencia, Boaz Tsaban
In this paper, we analyze the security of Zorro-like ciphers with partial non-linear layers by devising differential and linear characteristic search algorithms and key recovery algorithms. These algorithms exploit in a generic way the small number of Sboxes in a Zorro-like round, and are independent of any specific property of its linear layer (such as the one exploited by Wang et al.), or its Sbox implementation. When applied to the Zorro block cipher itself, we were able to find \\emph{the highest} probability characteristics for the full cipher and devise significantly improved attacks. Our differential attack has a time complexity of about $2^{45}$, requiring about $2^{44}$ chosen plaintexts, and our linear attack has a time complexity of about $2^{45}$, requiring about $2^{45}$ known plaintexts.
Independently of our results, the recently published paper by Rasoolzadeh et al. found similar iterative characteristics for Zorro by exploiting in a different way the devastating property of its linear layer, described by Wang et al. However, our improved key recovery techniques result in differential and linear attacks which are at least $2^{11}$ times faster. More significantly, the surprisingly large number of Zorro-like rounds analyzed by some of our generic techniques raises questions over the general design strategy of Zorro, namely, the use of partial non-linear layers.
Mohammad Rezaeirad, Sahar Mazloom, Mahdi Orooji, Miao Jin, Magdy Bayoumi
Achiya Bar-Or, Itai Dinur, Orr Dunkelman, Virginie Lallemand, Mar\\\'{\\i}a Naya-Plasencia, Boaz Tsaban
In this paper, we analyze the security of Zorro-like ciphers with partial non-linear layers by devising differential and linear characteristic search algorithms and key recovery algorithms. These algorithms exploit in a generic way the small number of Sboxes in a Zorro-like round, and are independent of any specific property of its linear layer (such as the one exploited by Wang et al.), or its Sbox implementation. When applied to the Zorro block cipher itself, we were able to find \\emph{the highest} probability characteristics for the full cipher and devise significantly improved attacks. Our differential attack has a time complexity of about $2^{45}$, requiring about $2^{44}$ chosen plaintexts, and our linear attack has a time complexity of about $2^{45}$, requiring about $2^{45}$ known plaintexts.
Independently of our results, the recently published paper by Rasoolzadeh et al. found similar iterative characteristics for Zorro by exploiting in a different way the devastating property of its linear layer, described by Wang et al. However, our improved key recovery techniques result in differential and linear attacks which are at least $2^{11}$ times faster. More significantly, the surprisingly large number of Zorro-like rounds analyzed by some of our generic techniques raises questions over the general design strategy of Zorro, namely, the use of partial non-linear layers.
Mohamed Ahmed Abdelraheem, Andrey Bogdanov, Elmar Tischhauser
weak key testing strategy, and demonstrate how to leverage them to obtain universal forgeries.
28 March 2014
Tapas Pandit, Rana Barua
Léo Perrin, Dmitry Khovratovich
Secondly, we investigate the T-sponge construction and show how certain CPS and rate values lead to an improved preimage attack on long messages. As an example, we find collisions for the GLUON-64 internal function, approximate its CPS, and show an attack that violates the security claims. For instance, if a message ends with a sequence of 1~Mb (respectively 1~Gb) of zeros, then our preimage search takes time $2^{115.3}$ (respectively $2^{105.3}$) instead of $2^{128}$.
Henry Carter, Charles Lever, Patrick Traynor
27 March 2014
IBM Research – Almaden, 650 Harry Road, San Jose, CA 95120-6099, USA
An important aspect of this position entails porting [our] existing algorithms and code into ARM TrustZone and/or hardware so as to conform to design principles of conventional standardized APIs. 3+ years of coding experience in C/C++ is required. Proficiency in programming FPGAs is a definite plus, as is experience in JNI.
This is a 3-month position with flexible start/end dates during May - September 2014 time frame.