IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
20 May 2014
Yefim Leifman
Andrea Huszti
19 May 2014
Zoya Dyka, Thomas Basmer, Christian Wittke, Peter
Yao Lu, Rui Zhang, Dongdai Lin
\\begin{itemize}
\\item We improve May\'s results (PKC\'04) on small secret exponent attack on RSA variant with moduli $N = p^rq$ ($r\\geq 2$).
\\item We extend Nitaj\'s result (Africacrypt\'12) on weak encryption exponents of RSA and CRT-RSA.
\\end{itemize}
Erik-Oliver Blass, Travis Mayberry, Guevara Noubir, Kaan Onarlioglu
laptops, hard disk encryption is more important than ever. In
particular, being able to plausibly deny that a hard disk contains
certain information is a very useful and interesting research
goal. However, it has been known for some time that existing
``hidden volume\'\' solutions, like TrueCrypt, fail in the face of an
adversary who is able to observe the contents of a disk on multiple,
separate occasions. In this work, we explore more robust
constructions for hidden volumes and present HIVE, which is
resistant to more powerful adversaries with multiple-snapshot
capabilities. In pursuit of this, we propose the first security
definitions for hidden volumes, and prove HIVE secure under these
definitions. At the core of HIVE, we design a new write-only
Oblivious RAM. We show that, when only hiding writes, it is
possible to achieve ORAM with optimal O(1) communication complexity
and only poly-logarithmic user memory. This is a significant
improvement over existing work and an independently interesting
result. We go on to show that our write-only ORAM is specially
equipped to provide hidden volume functionality with low overhead
and significantly increased security. Finally, we implement HIVE as
a Linux kernel block device to show both its practicality and
usefulness on existing platforms.
Craig Gentry, Shai Halevi, Charanjit Jutla, Mariana Raykova
In this work we examine the feasibility of this approach, focusing specifically on secure-computation protocols based on somewhat-homomorphic encryption (SWHE). We devised and implemented secure two-party protocols in the semi-honest model for the path-ORAM protocol of Stefanov et al. This provides access by index or keyword, which we extend (via pre-processing) to limited conjunction queries and range queries. Some of our sub-protocols may be interesting in their own right, such as our new protocols for encrypted comparisons and blinded permutations.
We implemented our protocols on top of the HElib homomorphic encryption library. Our basic single-threaded implementation takes about 30 minutes to process a query on a database with $2^{22}$ records and 120-bit long keywords, providing a cause for optimism about the viability of this direction, and we expect a better optimized implementation to be much faster.
Kim Laine, Kristin Lauter
Our variant improves the computational complexity at the cost of a moderate increase in memory consumption, but we also improve the computational complexity even when we limit the memory usage to that of Diem\'s original algorithm. Finally, we examine how parallelization can help to reduce both the memory cost per computer and the running time for our algorithms.
Ilan Komargodski, Tal Moran, Moni Naor, Rafael Pass, Alon Rosen, Eylon Yogev
about its structure beyond what is apparent from executing it. There are several ways of formalizing this goal. Specifically, in
indistinguishability obfuscation, first defined by Barak et al. (CRYPTO 2001), the requirement is that the results of obfuscating any two
functionally equivalent programs (circuits) will be computationally indistinguishable. Recently, a fascinating candidate construction for
indistinguishability obfuscation was proposed by Garg et al. (FOCS 2013). This has led to a flurry of discovery of intriguing constructions of
primitives and protocols whose existence was not previously known (for instance, fully deniable encryption by Sahai and Waters, STOC 2014). Most
of them explicitly rely on additional hardness assumptions, such as one-way functions.
Our goal is to get rid of this extra assumption. We cannot argue that indistinguishability obfuscation of all polynomial-time circuits implies
the existence of one-way functions, since if $P = NP$, then program obfuscation (under the indistinguishability notion) is possible. Instead, the
ultimate goal is to argue that if $P \\neq NP$ and program obfuscation is possible, then one-way functions exist.
Our main result is that if $NP \\not\\subseteq ioBPP$ and there is an efficient (even imperfect) indistinguishability obfuscator, then there are
one-way functions. In addition, we show that the existence of an indistinguishability obfuscator implies (unconditionally) the existence of SZK-
arguments for NP. This, in turn, provides an alternative version of our main result, based on the assumption of hard-on-the average NP problems.
To get some of our results we need obfuscators for simple programs such as CNF formulas.
Helger Lipmaa
Eli Ben-Sasson, Alessandro Chiesa, Christina Garman, Matthew Green, Ian Miers, Eran Tromer, Madars Virza
In this paper, we construct a full-fledged ledger-based digital currency with strong privacy guarantees. Our results leverage recent advances in zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARKs).
First, we formulate and construct decentralized anonymous payment schemes (DAP schemes). A DAP scheme enables users to directly pay each other privately: the corresponding transaction hides the payment\'s origin, destination, and transferred amount. We provide formal definitions and proofs of the construction\'s security.
Second, we build Zerocash, a practical instantiation of our DAP scheme construction. In Zerocash, transactions are less than 1 kB and take under 6 ms to verify --- orders of magnitude more efficient than the less-anonymous Zerocoin and competitive with plain Bitcoin.
Franziskus Kiefer, Mark Manulis
In this work we propose the extended concept of distributed smooth projective hash functions where the computation of the hash value is distributed across $n$ parties and show how to instantiate the underlying approach for languages consisting of Cramer-Shoup ciphertexts.
As an application of distributed smooth projective hashing we build a new framework for the design of two-server password authenticated key exchange protocols, which we believe can help to \"explain\" the design of earlier two-server password authenticated key exchange protocols.
Cryptography, Security, and Privacy Research Group, Koç University, Istanbul, Turkey
For more information about our group and projects, visit
http://crypto.ku.edu.tr
For questions, contact Asst. Prof. Alptekin Küpçü
http://home.ku.edu.tr/~akupcu
For applying online, and questions about the application-process, visit
http://gsse.ku.edu.tr
For summer internship opportunities, visit
http://kusrp.ku.edu.tr
Ruhr-Universität Bochum, Germany
The future holder of the position will represent the subject in research and teaching.
We are seeking a candidate with an excellent research record in cryptography, in particular in theoretical cryptography, provable security, protocols, or secure multi-party computation.
The position is non-tenured with an initial appointment for 3 years, and renewable for another 3 years after a positive mid-term review.
Candidates for the professorship are expected to have strong leadership qualities, particularly
• excellent level of commitment in academic teaching
• willingness to participate in interdisciplinary research
• willingness and ability to attract externally funded research projects
• or to contribute to joint research projects of the department.
15 May 2014
Rachid El Bansarkhani, Johannes Buchmann
John Almeida
Joppe W. Bos, Kristin Lauter, Michael Naehrig
encryption methods used today provide only very restricted possibilities or none at all to operate on encrypted data without decrypting it first. Homomorphic encryption provides a tool for
handling such computations on encrypted data, without decrypting the data, and without even needing the decryption key.
In this paper, we discuss possible application scenarios for homomorphic encryption in order to ensure privacy of sensitive medical data. We describe how to privately conduct predictive analysis tasks on encrypted data using homomorphic encryption. As a proof of concept, we present a working implementation of a prediction service running in the cloud (hosted on Microsoft\'s Windows Azure), which takes as input private encrypted health data, and returns the probability of suffering cardiovascular disease in encrypted form. Since the cloud service uses homomorphic encryption, it makes this prediction while handling only encrypted data, learning nothing about
the submitted confidential medical data.
Kenneth G. Paterson, Jacob C.N. Schuldt, Dale L. Sibborn
Sebastian Faust, Pratyay Mukherjee, Jesper Buus Nielsen, Daniele Venturi
The compiled program tolerates arbitrary independent tampering of the disks. That is, the adversary can tamper with the intermediate values produced by the CPU, and the program code of the compiled primitive on the public disk. In addition, it tolerates bounded independent leakage from the disks and continuous leakage from the communication channels between the disks and the CPU.
Although it is required that the circuit of the CPU is tamper and leakage proof, its design is independent of the actual primitive being computed and its internal storage is non-persistent, i.e., all secret registers are reset between invocations. Hence, our result can be interpreted as reducing the problem of shielding arbitrary complex computations to protecting a single, simple and ``universal\'\' component. As a main ingredient of our construction we use continuous
non-malleable codes that satisfy certain additional properties.
Yi Deng
Mohammed Alfateh Hassouna, Mohsin Hashim
the proposed signature scheme is short and efficient, it is also has strength point that the KGC has no contribution in signature generation/verification process, therefore any compromise
of the KGC does not affect the non-repudiation service of the system. Furthermore, even the KGC cannot do signature forgery by (temporary) replacing the user\'s public key.