International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

18 July 2014

Daniel Augot, Pierre-Alain Fouque, Pierre Karpman
ePrint Report ePrint Report
This paper investigates large linear mappings with very good diffusion and efficient software implementations, that can be used as part of a block cipher design.

The mappings are derived from linear codes over a small field (typically $F^{2^4}$) with a high dimension (typically 16) and a high minimum distance. This results in diffusion matrices with equally high dimension and a large branch number.

Because we aim for parameters for which no MDS code is known to exist, we propose to use more flexible algebraic-geometry codes.

We present two simple yet efficient algorithms for the software implementation of matrix-vector multiplication in this context, and derive conditions on the generator matrices of the codes to yield efficient encoders. We then specify an appropriate code and use its automorphisms as well as random sampling to find good such matrices.

We provide concrete examples of parameters and implementations, and the corresponding assembly code. We also give performance figures in an example of application which show the interest of our approach.

Expand

15 July 2014

The School of Informatics, University of Edinburgh, UK
Job Posting Job Posting
The University of Edinburgh is looking for a Lecturer (Assistant Professor) and Reader (Associate Professor, close to Professor) in areas related to Cyber Security and Privacy.

Areas of particular interest are applied cryptography, systems/network security, human factors for security and privacy, and information Assurance.

Both positions are full-time and permanent. The start date is 1st October 2014, or a later date by negotiation.

We also have PhD positions, which are recruited continually.

The School of Informatics at Edinburgh is the largest informatics School in the UK, enjoying a city centre location in a modern building in the beautiful capital city of Scotland.

Please visit the web page for full details.

Expand

14 July 2014

IBM Research - Zurich, Switzerland
Job Posting Job Posting
The cryptography and privacy group of the IBM Research - Zurich research laboratory in Switzerland is looking for highly motivated Ph.D. students and Post-Docs in the area of provably secure cryptography, in particular the design of privacy-enhancing cryptographic protocols.

Candidates will perform scientific research in the areas mentioned above under the direct guidance of the permanent researchers in our team. Their main task will consist of publishing at respected academic conferences and journals. They will also collaborate with international partners in EU research projects and occasionally implement prototypes of cryptographic protocols.

PhD student candidates must have a Master degree or equivalent in computer science, mathematics, electrical engineering, or related disciplines. Knowledge of basic cryptography is required, proven experience in the form of theses or published papers is a strong asset.

Post-Doc candidates must have a PhD degree in cryptography. All candidates must be fluent in spoken and written English; knowledge of German is not required.

IBM Research - Zurich offers a stimulating international research environment among experts in computer science, physics, and mathematics. The laboratory is located in Rüschlikon, Switzerland, at 10km from the city of Zurich and on the coast of Lake Zurich. A competitive salary will be offered, adjusted to the high local living standards.

The positions will remain open until suitable candidates have been hired.

Expand
October 31
Event Calendar Event Calendar
Submission: 31 October 2014
Notification: 3 April 2015
From October 31 to October 31
More Information: http://tinyurl.com/qykzlrp
Expand

11 July 2014

Scottsdale, Arizona, United States of America, November 3
Event Calendar Event Calendar
Submission: 25 July 2014
Notification: 25 August 2014
From November 3 to November 3
Location: Scottsdale, Arizona, United States of America
More Information: http://www.trusted-workshop.de
Expand

10 July 2014

University of Twente, The Netherlands
Job Posting Job Posting

The Centre for Telematics and Information Technology (CTIT) at the University of Twente invites applications for a 4-year PhD position in cryptographic protocol design.

In the course of the PhD project, the PhD student will deal with cryptographic concepts such as Homomorphic Encryption, Functional Encryption, and Secure Multiparty Computation. The research focus of the project is on the design and evaluation of new cryptographic protocols for specific application scenarios.

The PhD candidate will be expected to do active and internationally visible research which will be supervised by Dr. Andreas Peter from the Services, Cybersecurity and Safety Group of the University of Twente. The PhD candidate will be appointed for a period of four years, at the end of which he/she must have completed a PhD thesis. During this period, the PhD student has the opportunity to broaden his/her knowledge by joining international exchange programs, to participate in national and international conferences and workshops, and to visit other research institutes and universities worldwide.

Successful candidates must hold an outstanding M.Sc. degree (or equivalent) from the university study of Computer Science, Mathematics, or similar, obtained within the last two years. The topic of the master thesis should ideally have relevance to cryptography. Applications from students that are about to finish their master thesis will be accepted as well. Further requirements include excellent skills in the English language, firm knowledge in cryptography and basic programming skills. Early experiences with scientific publications are of advantage.

The position will be closed as soon as a suitable candidate is found. Applications must include:

  • CV and academic transcript (with grades)
  • motivation letter (including a description of prior
Expand
Bucharest, Romania, July 21 - July 24
Event Calendar Event Calendar
From July 21 to July 24
Location: Bucharest, Romania
More Information: http://www.cs.bris.ac.uk/cryptosummerschool/
Expand
Singapore, Singapore, April 14 - April 17
Event Calendar Event Calendar
Submission: 26 October 2014
Notification: 22 December 2014
From April 14 to April 17
Location: Singapore, Singapore
More Information: http://icsd.i2r.a-star.edu.sg/asiaccs15/
Expand
İstanbul, Turkey, March 8 - March 11
FSE FSE
Submission: 7 November 2014
Notification: 16 January 2015
From March 8 to March 11
Location: İstanbul, Turkey
More Information: http://light-sec.org/fse2015/
Expand

09 July 2014

Massimo Chenal, Qiang Tang
ePrint Report ePrint Report
In his seminal paper at STOC 2009, Gentry left it as a future work to investigate (somewhat) homomorphic encryption schemes with IND-CCA1 security. At SAC 2011, Loftus et al. showed an IND-CCA1 attack against the somewhat homomorphic encryption scheme presented by Gentry and Halevi at Eurocrypt 2011. At ISPEC 2012, Zhang, Plantard and Susilo showed an IND-CCA1 attack against the somewhat homomorphic encryption scheme developed by van Dijk et al. at Eurocrypt 2010. Both attacks recover the secret key of the encryption schemes.

In this paper, we continue this line of research and show that most existing somewhat homomorphic encryption schemes are not IND-CCA1 secure. In fact, we show that these schemes suffer from key recovery attacks (stronger than a typical IND-CCA1 attack), which allow an adversary to recover the private keys through a number of decryption oracle queries. The schemes, that we study in detail, include those by Brakerski and Vaikuntanathan at Crypto 2011 and FOCS 2011, and that by Gentry, Sahai and Waters at Crypto 2013. We also develop a key recovery attack that applies to the somewhat homomorphic encryption scheme by van Dijk et al., and our attack is more efficient and conceptually simpler than the one developed by Zhang et al.. Our key recovery attacks also apply to the scheme by Brakerski, Gentry and Vaikuntanathan at ITCS 2012, and we also describe a key recovery attack for the scheme developed by Brakerski at Crypto 2012.

Expand
Tian Tian, Wen-Feng Qi
ePrint Report ePrint Report
Nonlinear feedback shift registers (NFSRs) are an important type of sequence generators used for building stream ciphers. The shift register used in Grain, one of eSTREAM finalists, is a cascade connection of two NFSRs, which is also known as nonlinear product-feedback shift registers proposed in 1970. This paper provides a series of algorithms to decompose a given NFSR into a cascade connection of two smaller NFSRs. By decomposing an NFSR into a cascade connection of two smaller NFSRs, some properties regarding cycle structure of the original NFSR could be known.

Expand
Georg Fuchsbauer
ePrint Report ePrint Report
We extend the notion of verifiable random functions (VRF) to constrained VRFs, which generalize the concept of constrained pseudorandom functions, put forward by Boneh and Waters (Asiacrypt\'13), and independently by Kiayias et al. (CCS\'13) and Boyle et al. (PKC\'14), who call them delegatable PRFs and functional PRFs, respectively. In a standard VRF the secret key $\\sk$ allows one to evaluate a pseudorandom function at any point of its domain; in addition, it enables computation of a non-interactive proof that the function value was computed correctly. In a constrained VRF from the key $\\sk$ one can derive constrained keys $\\sk_S$ for subsets $S$ of the domain, which allow computation of function values and proofs only at points in $S$.

After formally defining constrained VRFs, we derive instantiations from the multilinear-maps-based constrained PRFs by Boneh and Waters, yielding a VRF with constrained keys for any set that can be decided by a polynomial-size circuit. Our VRFs have the same function values as the Boneh-Waters PRFs and are proved secure under the same hardness assumption, showing that verifiability comes at no cost. Constrained (functional) VRFs were stated as an open problem by Boyle et al.

Expand

08 July 2014

Jaiganesh Balasundaram
ePrint Report ePrint Report
The notion of indifferentiability, which is a stronger version of the classic notion of indistinguishability, was introduced by Maurer, Renner, and Holenstein in 2003. Indifferentiability, among other things, gives us a way of ``securely replacing\" a random oracle of one type by a random oracle of a different type. Most indifferentiability proofs in the literature are very complicated, which makes them difficult to verify and in some cases, has even resulted in them being erroneous. In this paper, we use a simple yet rigorous proof technique for proving indifferentiability theorems. This technique is a generalization of the indistinguishability proof technique used by Bernstein in to prove the security of the Cipher Block Chaining (CBC) construction. We use this technique to prove the indifferentiability result for a very simple construction which processes just two blocks of input. This construction can be viewed as bearing close resemblance to the so called Sponge construction, on which the winner of SHA-3 competition is based. Also as a warm up, we prove the indistinguishability result for this construction using the coupling argument from probability theory. We also prove the non-indifferentiability result for the CBC construction and some of its standard variants, and survey the indifferentiability and non-indifferentiability results for the Merkle-Damg{\\aa}rd (MD) construction, some of its standard variants, and the Feistel construction, from the literature.

Expand
Cong Chen, Thomas Eisenbarth, Ingo von Maurich, Rainer Steinwandt
ePrint Report ePrint Report
This work presents the first differential power analysis of an implementation of the McEliece cryptosystem. Target of this side-channel attack is a state-of-the-art FPGA implementation of the efficient QC-MDPC McEliece decryption operation as presented at DATE 2014. The presented cryptanalysis succeeds to recover the complete secret key after a few observed decryptions. It consists of a combination of a differential leakage analysis during the syndrome computation followed by an algebraic step that exploits the relation between the public and private key.

Expand
Xiaofeng Wang, Chen Xu, Guo Li, Hanling Lin
ePrint Report ePrint Report
A presentation of a group with two generators having unsolvable word problem and an explicit countable presentation of Mihailova subgroup of F_2×F_2 with finite number of generators are given. Where Mihailova subgroup of F_2×F_2 enjoys the unsolvable subgroup membership problem.One then can use the presentation to create entities\' private key in a public key cryptsystem.

Expand
Jesper Buus Nielsen, Daniele Venturi, Angela Zottarel
ePrint Report ePrint Report
We investigate new models and constructions which allow

leakage-resilient signatures secure against existential forgeries,

where the signature is much shorter than the leakage bound.

Current models of leakage-resilient signatures against existential

forgeries demand that the adversary cannot produce a new valid

message/signature pair $(m, \\sigma)$ even after receiving some

$\\lambda$ bits of leakage on the signing key. If $\\vert \\sigma \\vert

\\le \\lambda$, then the adversary can just choose to leak a valid

signature $\\sigma$, and hence signatures must be larger than the

allowed leakage, which is impractical as the goal often is to have

large signing keys to allow a lot of leakage.

We propose a new notion of leakage-resilient signatures against

existential forgeries where we demand that the adversary cannot

produce $n = \\lfloor \\lambda / \\vert \\sigma \\vert \\rfloor + 1$

distinct valid message/signature pairs

$(m_1, \\sigma_1), \\ldots, (m_n, \\sigma_n)$ after receiving

$\\lambda$ bits of leakage. If $\\lambda =

0$, this is the usual notion of existential unforgeability. If $1

Expand
Khoongming Khoo, Thomas Peyrin, Axel Y. Poschmann, Huihui Yap
ePrint Report ePrint Report
In this article, we propose a new comparison metric, the figure of adversarial merit (FOAM), which combines the inherent security provided by cryptographic structures and components with their implementation properties. To the best of our knowledge, this is the first such metric proposed to ensure a fairer comparison of cryptographic designs. We then apply this new metric to meaningful use cases by studying Substitution-Permutation Network permutations that are suited for hardware implementations, and we provide new results on hardware-friendly cryptographic building blocks. For practical reasons, we considered linear and differential attacks and we restricted ourselves to fully serial and round-based implementations. We explore several design strategies, from the geometry of the internal state to the size of the S-box, the field size of the diffusion layer or even the irreducible polynomial defining the finite field. We finally test all possible strategies to provide designers an exhaustive approach in building hardware-friendly cryptographic primitives (according to area or FOAM metrics), also introducing a model for predicting the hardware performance of round-based or serial-based implementations. In particular, we exhibit new diffusion matrices (circulant or serial) that are surprisingly more efficient than the current best known, such as the ones used in AES, LED and PHOTON.

Expand
Paolo Palmieri, Luca Calderoni, Dario Maio
ePrint Report ePrint Report
The wide availability of inexpensive positioning systems made it possible to embed them into smartphones and other personal devices. This marked the beginning of location-aware applications, where users request personalized services based on their geographic position. The location of a user is, however, highly sensitive information: the user\'s privacy can be preserved if only the minimum amount of information needed to provide the service is disclosed at any time. While some applications, such as navigation systems, are based on the users\' movements and therefore require constant tracking, others only require knowledge of the user\'s position in relation to a set of points or areas of interest. In this paper we focus on the latter kind of services, where the location information is essentially used to determine membership in one or more geographic sets. We address this problem using Bloom Filters (BF), a compact data structure for representing sets. In particular, we present an extension of the original bloom filter idea: the Spatial Bloom Filter (SBF). SBF\'s are designed to manage spatial and geographical information in a space efficient way, and are well-suited for enabling privacy in location-aware applications. We show this by providing two multi-party protocols for privacy-preserving computation of location information, based on the known homomorphic properties of public key encryption schemes. The protocols keep the user\'s exact position private, but allow the provider of the service to learn when the user is close to specific points of interest, or inside predefined areas. At the same time, the points and areas of interest remain oblivious to the user.

Expand
Georg T. Becker
ePrint Report ePrint Report
Physical Unclonable Functions (PUFs) have emerged as a promising solution for securing resource-constrained embedded devices such as RFID-tokens. PUFs use the inherent physical differences of every chip to either securely authenticate the chip or generate cryptographic keys without the need of non-volatile memory. Securing non-volatile memory and cryptographic algorithms against hardware attacks is very costly and hence PUFs are believed to be a good alternative to traditional cryptographic algorithms and key generation on constrained embedded devices.

However, PUFs have shown to be vulnerable to model building attacks if the attacker has access to challenge and response pairs. In these model building attacks, machine learning is used to determine the internal parameters of the PUF to build an accurate software model. Nevertheless, PUFs are still a promising building block and several protocols and designs have been proposed that are believed to be resistant against machine learning attacks. In this paper we take a closer look at a two such protocols, one based on reverse fuzzy extractors[15] and one based on pattern matching [15,17]. We show that it is possible to attack these protocols using machine learning despite the fact that an attacker does not have access to direct challenge and response pairs. The introduced attacks demonstrate that even highly obfuscated responses or helper data can be used to attack PUF protocols.

Hence, our work shows that even protocols in which it would be computationally infeasible to compute enough challenge and response pairs for a direct machine learning attack can be attacked using machine learning.

Expand

07 July 2014

Forum Post Forum Post
Hi, I think that this is not exactly obfuscation: To my understanding, obfuscation is a reversible permutation, because its actually 1-1 mapping. The process of logic synthesis proposed in the publication is inherently not reversible, because it involves a loss of information. The only way to reverse it is to go through all possible inputs and record the associated outputs, which is similar to brute force attack From: 2014-07-07 09:25:43 (UTC)
Expand
◄ Previous Next ►