IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
11 June 2014
Jan Camenisch, Anja Lehmann, Anna Lysyanskaya, Gregory Neven
We propose the first t-out-of-n TPASS protocol for any n > t that does not suffer from this shortcoming. We prove our protocol secure in the UC framework, which for the particular case of password-based protocols offers important advantages over property-based definitions, e.g., by correctly modeling typos in password attempts.
Universitat Rovira i Virgili, Tarragona, Catalonia, Spain
We offer a post-doctoral research contract at Universitat Rovira i Virgili, for up to three years. The selected candidate will work in a new generously funded research project at the UNESCO Chair in Data Privacy/CRISES research group within the Department of Computer Engineering and Mathematics.
What we require:
Candidates should have provable research expertise in game theory (specifically mechanism design and/or implementation theory) and also be familiar with cryptographic protocols. Suitable backgrounds include but are not limited to computer science, mathematics, economics and engineering.
Where we are:
Universitat Rovira i Virgili (URV) is based in Tarragona (Catalonia), which is a coastal city 90 km south of Barcelona. URV has been ranked by Times Higher Education 2014 as the world´s 66th best university under 50 years of age. Also, according to the CWTS Leiden 2014 ranking, URV has the second highest research impact on ``Math., Comp. Sci. and Engineering´´ among European universities.
What candidates should send:
Send your CV and publication record, plus two recommendation letters to Prof. Josep Domingo-Ferrer ( josep.domingo (at) urv.cat ).
Bochum, Germany, July 3 - July 4
Location: Bochum, Germany
More Information: http://wiki.crypto.rub.de/CrossFyre/index.html
10 June 2014
Nuttapong Attrapadung
We propose a generic framework that abstracts the concept of dual system encryption techniques. We introduce a new primitive called \\emph{pair encoding} scheme for predicates and show that it implies fully secure functional encryption (for the same predicates) via a generic construction. Using the framework, we obtain the first fully secure schemes for functional encryption primitives of which only selectively secure schemes were known so far. Our three main instantiations include FE for regular languages, unbounded attribute-based encryption (ABE) for large universes, and ABE with constant-size ciphertexts.
Our main ingredient for overcoming the barrier of inapplicability for the dual system techniques to certain predicates is a computational security notion of the pair encoding scheme which we call \\emph{doubly selective security}. This is in contrast with most of the previous dual system based schemes, where information-theoretic security are implicitly utilized. The doubly selective security notion resembles that of selective security and its complementary notion, co-selective security, and hence its name. Our framework can be regarded as a method for boosting doubly selectively security (of encoding) to full security (of functional encryption).
Besides generality of our framework, we remark that improved security is also obtained, as our security proof enjoys tighter reduction than previous schemes, notably the reduction cost does not depend on the number of all queries, but only that of \\emph{pre-challenged} queries.
University of Cambridge, England, UK, European Union
This Studentship is funded through Government Communication Headquarters (GCHQ) under their Academic Centres of Excellence in Cyber Security Research (ACE-CSR) programme. As part of this programme, the doctoral student will be able to visit and work with GCHQ experts in Cheltenham. To enable such collaboration, this studentship is awarded under the condition that the applicant obtains an advanced UK government security clearance (“developed vetting”). To make this feasible, the applicant should have lived in the UK for the last 10 years and ideally be a British National.
Santa Barbara, USA, August 23 - August 24
Notification: 7 July 2014
From August 23 to August 24
Location: Santa Barbara, USA
More Information: http://2014.diac.cr.yp.to
Washington, D.C., USA, March 30 - April 1
Notification: 15 December 2014
From March 30 to April 1
Location: Washington, D.C., USA
More Information: http://www.iacr.org/workshops/pkc2015/
09 June 2014
Temasek Laboratories, National University of Singapore, Singapore
Applicants are expected to have a PhD degree in Mathematics/Computer Science/Engineering and experience in analysis/design of symmetric ciphers.
Preferred candidates are expected to be proficient in C/C++ language, a team worker and able to conduct independent research.
Review of applications will start immediately and continue until position is filled.
Interested candidates can contact Dr Tan Chik How tsltch (at) nus.edu.sg.
Closing Date for applications : 10 July 2014
University of Birmingham, UK
Research Project:
Modern automotive vehicles have several wireless interfaces, are interconnected with various devices and with the internet. This connectivity adds great functionality but it also introduces a number of security and privacy threats.
This PhD studentship will be focused on improving the security of the next generation electronic vehicle architecture. Develop optimized implementations of cryptographic primitives and protocols for time critical automotive applications.
Requirements:
Istanbul Technical University, Istanbul, Turkey
• wireless and network security,
• secure software,
• cyber supply chain security,
• cybersecurity policy,
• cryptography,
• multimedia forensics.
Applicants should have a well-established record of research. Duties of these positions include mainly research and teaching at graduate level. The salaries for these positions are internationally competitive and commensurate with candidates’ qualifications and academic ranks. “Information Security and Cryptography” department is a newly opening division at ITU and the prospective candidates for these positions are supposed to assume duties as early as September, 2015.
Istanbul Technical University, located at the heart of Istanbul, is one of the most prominent research universities of Turkey. Admission to ITU is highly competitive and the student body is from top scorers of the nationwide university entrance exam. With its well-qualified departments and institutions, ITU provides an excellent research environment for engineers and scientists. As a state university, ITU provides a free of charge health and dental insurance for its faculty members and their families.
About the application procedure:
To apply please send your application package including a cover letter, CV, research plan, and the names of 3 or 4 references to:
hiring (at) be.itu.edu.tr
Istanbul, Turkey, October 17 - October 18
From October 17 to October 18
Location: Istanbul, Turkey
More Information: http://www.iscturkey.org
Scottsdale, USA, November 3
Notification: 25 August 2014
From November 3 to November 3
Location: Scottsdale, USA
More Information: https://www.cylab.cmu.edu/news_events/events/wpes2014/
06 June 2014
Craig Costello, Alyson Deines-Schartz, Kristin Lauter, Tonghai Yang
CM-values of these functions are algebraic numbers, and when computed to high enough precision, LLL can recognize their minimal polynomials. Motivated by fast cryptography on Kummer surfaces, we investigate a variant of the CM method for computing cryptographically strong Rosenhain models of curves (as well as their associated Kummer surfaces) and use it to generate several example curves at different security levels that are suitable for use in cryptography.
Long Wen, Meiqin Wang, Andrey Bogdanov, Huaifeng Chen
Ivan Damg{\\aa}rd, Sunoo Park, Sarah Zakarias
A technical contribution of independent interest is a construction of a poly-logarithmic depth PRF from LPN that is secure if at most a predetermined number $\\ell$ of queries are asked; if more queries are asked, the same PRF is still secure, but now under a stronger assumption closely related to LPN. The basic idea of the construction also applies to other problems with a similar structure, such as subset-sum.
Thomaz Oliveira, Diego F. Aranha, Julio López, Francisco Rodríguez-Henríquez
Sashank Dara, Scott Fluhrer
FNR can cipher small domain data formats like IPv4, Port numbers, MAC Addresses, IPv6 address, any random short strings and numbers while preserving their input length.
In addition to the classic Feistel networks, Naor and Reingold propose usage of pair-wise independent permutation (PWIP) functions in first and last rounds of LR constructions to provide additional randomness and security. But their PWIP functions are based on Galois Fields. Representing GF(2n) for different input lengths would be
complicated for implementation. For this reason, the PWIP functions we propose are based on random N X N Invertible matrices.
In this paper we propose the specification of FNR mode of encryption. Its properties, limitations, features etc.
We provide possible example applications of this block cipher for preserving formats of input types like IPv4 addresses, Credit card numbers. We provide reference implementation\'s experimental results and performance numbers in different setups. FNR should be used only when deterministic encryption is needed. It does not provide semantic security.
FNR denotes Flexible Naor and Reingold
Gilles Barthe, Gustavo Betarte, Juan Diego Campo, Carlos Luna, David Pichardie
particularly effective in virtualized or cloud-based environments,
where they have been used to recover secret keys from cryptographic
implementations. One common approach to thwart cache-based attacks is
to use \\emph{constant-time} implementations, i.e.\\, which do not
branch on secrets and do not perform memory accesses that depend on
secrets. However, there is no rigorous proof that constant-time
implementations are protected against concurrent cache-attacks in
virtualization platforms with shared cache; moreover, many prominent
implementations are not constant-time. An alternative approach is to
rely on system-level mechanisms. One recent such mechanism is stealth
memory, which provisions a small amount of private cache for programs
to carry potentially leaking computations securely. Stealth memory
induces a weak form of constant-time, called \\emph{S-constant-time},
which encompasses some widely used cryptographic
implementations. However, there is no rigorous analysis of stealth
memory and S-constant-time, and no tool support for checking if
applications are S-constant-time.
We propose a new information-flow analysis that checks if an x86
application executes in constant-time, or in
S-constant-time. Moreover, we prove that constant-time
(resp. S-constant-time) programs do not leak confidential information
through the cache to other operating systems executing concurrently on
virtualization platforms (resp. platforms supporting stealth
memory). The soundness proofs are based on new theorems of independent
interest, including isolation theorems for virtualization platforms
(resp. platforms supporting stealth memory), and proofs that
constant-time implementations (resp. S-constant-time implementations)
are non-interfering with respect to a strict information flow policy
which disallows that control flow and memory accesses depend on
secrets. We formalize our results using the \\textsf{Coq} proof
assistant and we demonstrate the effectiveness of our analyses on
cryptographic implementations, including PolarSSL AES, DES and RC4,
SHA256 and Salsa20.
Shai Halevi, William E. Hall, Charanjit S. Jutla
upto 2^{64}-1 bits and hash outputs of length upto 512 bits. Notably, Fugue is not based on a compression function. Rather, it is directly a hash function that supports variable-length inputs.
The starting point for Fugue is the hash function Grindahl, but it extends that design to protect against the kind of attacks that were developed for Grindahl, as well as earlier hash functions like SHA-1.
A key enhancement is the design of a much stronger round function which replaces the AES round function of Grindahl, using better
codes (over longer words) than the AES 4 X 4 MDS matrix. Also,
Fugue makes judicious use of this new round function on a much larger
internal state.
The design of Fugue is proof-oriented: the various components are
designed in such a way as to allow proofs of security, and yet be efficient to implement. As a result, we can prove that current attack methods cannot find collisions in Fugue any faster than the trivial birthday attack. Although the proof is computer assisted, the assistance is limited to computing ranks of various matrices.
05 June 2014
Ulrich Rührmair
statements can be proven remotely over digital communication
channels, but without using classical secret keys, and without
assuming tamper-resistant and trusted measurement hardware in the location of the prover. Examples for the considered physical statements are: (i) \"the temperature of a certain object is X
°C\", (ii) \"two certain objects are positioned at distance X\", or (iii) \"a certain object has been irreversibly altered or destroyed\". In lack of an established name, we would like to call the corresponding security protocols \"virtual proofs of reality\" (VPs).
While a host of variants seems conceivable, this paper focuses
on VPs in which the verifier has handed over one or more
specific physical objects O_i to the prover at some point prior
to the VP. These \"witness objects\" assist the prover during the
proof, but shall not contain classical digital keys nor be assumed
tamper-resistant in the classical sense. The prover is allowed to
open, inspect and alter these objects in our adversarial model,
only being limited by current technology, while he shall still
be unable to prove false claims to the verifier.
In order to illustrate our concept, we give example
protocols built on temperature sensitive integrated circuits, disordered optical scattering media, and quantum systems. These
protocols prove the temperature, destruction/modification, or
relative position of witness objects in the prover\'s location. Full
experimental realizations of these schemes are beyond the scope
of this paper. But the protocols utilize established technologies
from the areas of physical unclonable functions and quantum
cryptography, and hence appear plausible also without such
proof. Finally, we also discuss potential advancements of our
method in theory, for example \"public virtual proofs\" that
function without exchanging witness objects Oi between the
verifier and the prover.
Our work touches upon and partly extends several established cryptographic and security concepts, including physical unclonable functions, quantum cryptography, and interactive proof systems.