International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

15 September 2014

Sofia, Bulgaria, April 26 - April 30
Eurocrypt Eurocrypt
Submission: 28 September 2014
Notification: 8 January 2015
From April 26 to April 30
Location: Sofia, Bulgaria
More Information: https://www.cosic.esat.kuleuven.be/eurocrypt_2015/index.shtml
Expand

14 September 2014

Southern Illinois University Carbondale, USA
Job Posting Job Posting

The Interdisciplinary Research (IR) Lab in the Department of Computer Science at Southern Illinois University Carbondale (SIUC) is looking for talented and highly motivated PhD students.

The IR Lab explores interesting and exciting research areas on the intersection of computer and social sciences ranging from computer security and privacy, applied cryptography, game theory, big data analysis and software development to economics, psychology and cognitive science. Our interdisciplinary setting provides attractive and flexible research environment for brilliant and creative PhD candidates.

Currently, there are many active projects in the IR lab among which are: computational models of trust and influence mimicking human reasoning, securely computable economic model, game theory and economic aspects of security and privacy, design and analysis of sealed-bid auction protocols, and computational models of collaboration by social networks analysis and mining.

The successful candidates perform research on the aforementioned projects based on their experience and research interests. They must have strong background in Computer Science and/or Mathematics. They are expected to publish articles in well-known conferences and journals. Although all applications will be carefully evaluated, candidates with prior publications as well as research experience in the following areas are specifically encouraged to apply: secret sharing, secure multiparty computation, rational cryptography, game theory and computational or mathematical modeling.

Financial support and tuition waiver are provided for these positions and they will remain open until filled.

Expand

12 September 2014

Mohammad Wazid
ePrint Report ePrint Report
Security is the biggest concern in Wireless Sensor Networks (WSNs) especially for the ones which are deployed for military applications and monitoring. They are prone to various attacks which degrades the network performance very rapidly. Sometimes multiple attacks are launched in the network using hybrid anomaly. In this situation it is very difficult to find out which kind of anomaly is activated. In this paper, we have proposed a hybrid anomaly detection technique with the application of k-means clustering. The analysis of the network data set consists of traffic data and end to end delay data is performed. The data set is clustered using weka 3.6.10. After clustering, we get the threshold values of various network performance parameters (traffic and delay). These threshold values are used by the hybrid anomaly detection technique to detect the anomaly. During the experimentation, it has been observed that two types of anomalies are activated in the network causing misdirection and blackhole attacks.

Expand
Yossi Azar, Seny Kamara, Ishai Menache, Mariana Raykova, Bruce Shepherd
ePrint Report ePrint Report
We consider the problem of designing multi-tenant public infrastructure clouds

resistant to cross-VM attacks without relying on single-tenancy or on

assumptions about the cloud\'s servers. In a cross-VM attack (which have

been demonstrated recently in Amazon EC2) an adversary launches malicious

virtual machines (VM) that perform side-channel attacks against co-located VMs

in order to recover their contents.

We propose a formal model in which to design and analyze \\emph{secure}

VM placement algorithms, which are online vector bin packing

algorithms that simultaneously satisfy certain optimization

constraints and notions of security. We introduce and formalize several notions

of security, establishing formal connections between them. We also introduce a

new notion of efficiency for online bin packing algorithms that better captures

their cost in the setting of cloud computing.

Finally, we propose a secure placement algorithm that achieves our strong

notions of security when used with a new cryptographic mechanism we refer to as

a shared deployment scheme.

Expand

11 September 2014

Yehuda Lindell
ePrint Report ePrint Report
In this short paper, we present a Fiat-Shamir type transform that takes any Sigma protocol for a relation $R$ and outputs a non-interactive zero-knowledge proof (not of knowledge) for the associated language $L_R$, in the common reference string model. As in the Fiat-Shamir transform, we use a hash function $H$. However, zero-knowledge is achieved under standard assumptions in the common reference string model (without any random oracle), and soundness is achieved in the \\emph{non-programmable} random oracle model. The concrete computational complexity of the transform is only slightly higher than the original Fiat-Shamir transform.

Expand
Masao KASAHARA
ePrint Report ePrint Report
Extensive studies have been made of the public key cryptosystems based on multivariate polynomials (Multi-variate PKC, MPKC) over $\\mathbb{F}_2$ and $\\mathbb{F}_2^m$.

However most of the proposed MPKC are proved not secure.

In this paper, we propose a new class of MPKC based on Reed-Solomon code, referred to as K(XI)RSE(2)PKC.

In Appendix, we present another class of MPKC referred to as K(X)RSE(2)PKC over $\\mathbb{F}_2$.

Both K(X)RSE(2)PKC and K(XI)RSE(2)PKC yield the coding rate of 1.0.

We show that the proposed schemes can be sufficiently secure against various attacks, including Gr\\\"obner basis attack.

Expand

10 September 2014

Singapore, Singapore, April 14
Event Calendar Event Calendar
Submission: 28 December 2014
Notification: 31 January 2015
From April 14 to April 14
Location: Singapore, Singapore
More Information: http://icsd.i2r.a-star.edu.sg/cpss15/
Expand
Announcement Announcement

Here is a brief update on IACR matters as of CRYPTO 2014.

\r\n\r\n\r\n

***Communications and website

\r\n\r\n

First of all, I would like to thank Christopher Wolf for his service\r\nand dedication to the IACR in his role as Newsletter Editor (later,\r\nCommunications Secretary). From 2009 until this summer, he has led\r\nthe communications and publicity activities of the IACR and made the\r\nwebsite an interesting and interactive experience.

\r\n\r\n

The Board of Directors has appointed Mike Rosulek (Oregon State\r\nUniversity, US) as the Communications Secretary; Yu Yu (Shanghai Jiao\r\nTong University, CN) also joins the communications team and serves as\r\none of the webmasters.

\r\n\r\n\r\n\r\n

***Cryptography Research Fund for Students

\r\n\r\n

Thanks to the generous donation of 1 Mio. USD from Cryptography\r\nResearch Inc. (a division of Rambus) the IACR has created the\r\n*Cryptography Research Fund for Students.*

\r\n\r\n

The fund aims at promoting cryptology to students and supporting\r\nscholarly work in the field. With its help, the IACR can greatly\r\nincrease its support for students in cryptology through:

\r\n\r\n

1) Waiving the registration fee for student speakers at EUROCRYPT,\r\n CRYPTO, ASIACRYPT and, now, also at CHES, FSE, TCC and PKC;

\r\n\r\n

2) Expanding its support for Cryptology Schools (see below);

\r\n\r\n

3) Further activities, as coordinated by an Endowment Committee that\r\n oversees the fund. (Please contact its chair, Greg Rose, with more\r\n ideas.)

\r\n\r\n

The IACR has created an investment fund with a conservative strategy\r\nso that this program can be funded in perpetuity. Combined with a\r\nsmaller commitment from the IACR, the sum in the fund can support the\r\nongoing activities detailed above as well as let the capital keep\r\nup with inflation.

\r\n\r\n\r\n\r\n

***Parallel sessions

\r\n\r\n

In response to the growth of the field over the last years, the Board\r\nin 2011 sent a message to Program Chairs and Program Committees of the\r\nthree main conferences asking them \"to accept substantially more\r\npapers than used to be the case and to work with their General Chair\r\nfor the logistics to make this possible.\" As one can see from the\r\npublication statistics over the recent years\r\n(http://www.iacr.org/publications/statistics.html) the message has\r\nbeen received partially, but not uniformly implemented. As of today,\r\nthe Board believes that this effort should go further. During the\r\nrecent meeting at CRYPTO, a majority of the Board expressed the opinion\r\nthat a program of, say, 60 or more talks should be arranged at least\r\npartially in parallel sessions.

\r\n\r\n

Hence, during its meeting at CRYPTO, the Board has decided to ask the\r\nProgram Chairs and Committees of the three IACR conferences in 2015\r\n\"to have parallel sessions for a significant part of the program.\" It\r\nis intended for 2015 only. At a discussion during the membership\r\nmeeting, a vote indicated a clear majority in favor of this change for\r\n2015, but there was also a significant minority against. After\r\nASIACRYPT 2015 a referendum among the IACR membership will be held for\r\ndeciding whether the format should be kept like this.

\r\n\r\n

Per IACR\'s policy, Program Chairs and Committees are responsible for\r\nthe scientific program; the General Chairs are responsible for the\r\nlogistics and the organization. The Board guides these processes and\r\nensures continuity across IACR\'s activities.

\r\n\r\n\r\n\r\n

***Cryptology Schools

\r\n\r\n

The Board has approved funding for the first three IACR Cryptology\r\nSchools, which take place later this year and next year.

\r\n\r\n

1) School on Cryptographic Attacks (http://attackschool.di.uminho.pt/)\r\n 13-17 October 2014, Porto, Portugal

\r\n\r\n

2) School on Design and Security of Cryptographic Algorithms and Devices,\r\n 5-10 July 2015 (tentative), location to be decided.

\r\n\r\n

3) Asian Workshop on Symmetric Key Cryptography - Cryptology School,\r\n 19-22 December 2014, Chennai, India (http://ask2014.iiitd.ac.in/)

\r\n\r\n

See the website http://www.iacr.org/schools/ for more information.

\r\n\r\n\r\n\r\n

***Elections

\r\n\r\n

There will be elections for three IACR Director positions later this\r\nyear; nominations are now open and due by October 10, 2014. Please\r\nconsider running and see the announcement on the website:\r\n http://www.iacr.org/elections/2014/

\r\n\r\n\r\n

Regards,


\r\n\r\n Christian Cachin\r\n IACR President\r\n
Expand
PhD Database PhD Database
Name: Elisabeth Oswald
Topic: On Side-Channel Attacks and the Application of Algorithmic Countermeasures
Category: implementation

Expand
PhD Database PhD Database
Name: Carolyn Whitnall
Topic: Statistical methods for non-profiled differential side-channel analysis: Theory and evaluation
Category: (no category)

Description:

\r\nDifferential side-channel analysis (DSCA) aims at recovering cryptographically-secured secret information by exploiting the relationship between the physically-observable characteristics of a device and the data manipulated inside it. Prior knowledge about this relationship (obtained, perhaps, by detailed examination of an equivalent device) is known to greatly enhance attack success. What may be achieved with little or no prior knowledge at all is less clear. Strategies designed on such a basis have been loosely termed `generic\', but the scenarios in which these are possible without some meaningful knowledge on the leakage appear rare.\r\n

\r\n\r\n

\r\nIn this thesis we formalise the notion of `generic DSCA\' in order to understand it better and to make concrete statements about when and in what sense it is possible. We confirm that the range of scenarios to which it may be applied truly is limited---requiring that the device at some stage implements a predictable function which is non-injective and sufficiently nonlinear (e.g. the DES S-Box transformations).\r\n

\r\n\r\n

\r\nWe explore popular proposals based on mutual information and other non-parametric statistics. To facilitate meaningful comparisons we first introduce a theoretic evaluation framework to enable like-for-like comparisons between different methods and avoid the pit-falls of (necessarily estimator-dependent) empirical comparisons. One of the lessons learned by employing this framework is that mutual information is indeed optimal in some information-theoretic sense (as was initially supposed) and that it is the added burden of estimation which makes it a poor choice in all but the most unusual of leakage scenarios.\r\n

\r\n\r\n

\r\nWe also analyse linear regression-based methods and their use as `generic\' strategies. Applied in this way, they are restricted to the same limited scope as any other such strategy. However, we identify a unique feature of the way they operate whi[...]

Expand

09 September 2014

Shenghui Su, Shuwang Lu
ePrint Report ePrint Report
Enlightened by the IDEA block cipher, the authors put forward the REESSE3+ block cipher (a symmetric key cryptosystem) based on three group arithmetics: addition modulo 2 (bit XOR), addition modulo 2 ^ 16, and multiplication modulo 2 ^ 16 + 1. Different from IDEA, REESSE3+ uses 128-bit block inputs, a 256-bit key, and a renovative round function. The authors describe the REESSE3+ cipher algorithm in the graph, and expound the encryption subkeys, encryption operation, decryption subkeys, and decryption operation. Further, demonstrate the correctness of the REESSE3+ cipher algorithm, and analyze the security of REESSE3+ from three aspects. The measures for assuring the security of REESSE3+ cover those for assuring the security of IDEA, and thus, the ability of REESSE3+ in resisting differential analysis is at least equivalent to that of IDEA.

Expand
Christian Hanser, Daniel Slamanig
ePrint Report ePrint Report
Structure-preserving signatures are a quite recent but important building block for many cryptographic protocols. In this paper, we introduce a new type of structure-preserving signatures, which allows to sign group element vectors and to consistently randomize signatures and messages without knowledge of any secret.

More precisely, we consider messages to be (representatives of) equivalence classes on vectors of group elements (coming from a single prime order group), which are determined by the mutual ratios of the discrete logarithms of the representative\'s vector components. By multiplying each component with the same scalar, a different representative of the same equivalence class is obtained.

We propose a definition of such a signature scheme, a security model and give an efficient construction, which we prove secure in the SXDH setting, where EUF-CMA security is proven against generic forgers in the generic group model and the so called class hiding property is proven under the DDH assumption.

As a second contribution, we use the proposed signature scheme to build an efficient multi-show attribute-based anonymous credential system (ABC) that allows to encode an arbitrary number of attributes. This is -- to the best of our knowledge -- the first ABC system that provides constant-size credentials and constant-size showings. To allow an efficient construction in combination with the proposed signature scheme, we also introduce a new, efficient, randomizable polynomial commitment scheme. Aside from these two building blocks, the credential system requires a very short and constant-size proof of knowledge to provide freshness in the showing protocol. We present our ABC system along with a suitable security model and rigorously prove its security.

Expand
Carmit Hazay, Hila Zarosim
ePrint Report ePrint Report
The problem of securely outsourcing computation to an untrusted server gained momentum with the recent penetration of cloud computing services. The ultimate goal in this setting is to design efficient protocols that minimize the computational overhead of the clients and instead rely on the extended resources of the server. In this paper, we focus on the outsourced database search problem which is highly motivated in the context of delegatable computing since it offers storage alternatives for massive databases, that may contain confidential data. This functionality is described in two phases: (1) setup phase and (2) query phase. The main goal is to minimize the parties workload in the query phase so that it is proportional to the query size and its corresponding response.

Our starting point is the semi-honest protocol from FaustHV13 (ICALP 2013) that offers a simulation based secure protocol for outsourced pattern matching in the random oracle setting with optimal workload. In this work we study whether the random oracle is necessary for protocols with minimal interaction that meet the optimal communication/computation bounds in the query phase. We answer this question negatively and demonstrate a lower bound on the communication or the computational overhead in this phase. We further abstract the security properties of the underlying cryptographic primitive that enables to obtain private outsourced database search with minimal interaction. For a large class of search functionalities the communication complexity of our protocol meets the above lower bound.

Expand
Sebastien Tiran, Guillaume Reymond, Jean-Baptiste Rigaud, Driss Aboulkassimi, Benedikt Gierlichs, Mathieu Carbone, Gilles Ducharme, Philipp
ePrint Report ePrint Report
This paper introduces Side-Channel Analysis results obtained on an unprotected circuit characterized by a surprisingly non-linear leakage. While in such a case, Correlation Power Analysis is not adapted, we show that a more generic attack, based on the Analysis Of Variance (AOV) outperfoms CPA. It has the advantage of detecting non-linear leakage, unlike Correlation Power Analysis, and of providing similar or much better results in all cases, with a similar computation time.

Expand
Jan Camenisch, Stephan Krenn, Anja Lehmann, Gert Læssøe Mikkelsen, Gregory Neven, Michael Østergaard Pedersen
ePrint Report ePrint Report
Privacy-enhancing attribute-based credentials (PABCs) are the core ingredient to privacy-friendly authentication systems, allowing users to obtain credentials on attributes and prove possession of these credentials in an unlinkable fashion while revealing only a subset of the attributes. To be useful in practice, however, PABCs typically need additional features such as i) revocation, ii) pooling prevention by binding credentials to users\' secret keys, iii) pseudonyms as privacy-friendly user public keys, iv) proving equality of attributes without revealing their values, v) or advanced issuance where attributes can be \"blindly\" carried over into new credentials. Provably secure solutions exist for most of these features in isolation, but it is unclear how they can be securely combined into a full-fledged PABC system, or even which properties such a system would aim to fulfill. We provide a formal treatment of PABC systems supporting the mentioned features by defining their syntax and security properties, resulting in the most comprehensive definitional framework for PABCs so far. Unlike previous efforts, our definitions are not targeted at one specific use-case; rather, we try to capture generic properties that can be useful in a variety of scenarios. We believe that our definitions can also be used as a starting point for diverse application-dependent extensions and variations of PABCs. We present and prove secure a generic and modular construction of a PABC system from simpler building blocks, allowing for a \"plug-and-play\" composition based on different instantiations of the building blocks. Finally, we give secure instantiations for each of the building blocks, including in particular instantiations based on CL- and Brands-signatures which are the core of the Idemix and U-Prove protocols.

Expand
Fang Song
ePrint Report ePrint Report
Shor\'s quantum factoring algorithm and a few other efficient quantum algorithms break many classical crypto-systems. In response, people proposed post-quantum cryptography based on computational problems that are believed hard even for quantum computers. However, security of these schemes against \\emph{quantum} attacks is elusive. This is because existing security analysis (almost) only deals with classical attackers and arguing security in the presence of quantum adversaries is challenging due to unique quantum features such as no-cloning.

This work proposes a general framework to study which classical security proofs can be restored in the quantum setting. Basically, we split a security proof into (a sequence of) classical security reductions, and investigate what security reductions are ``quantum-friendly\'\'. We characterize sufficient conditions such that a classical reduction can be ``lifted\'\' to the quantum setting.

We then apply our lifting theorems to post-quantum signature schemes. We are able to show that the classical generic construction of hash-tree based signatures from one-way functions and and a more efficient variant proposed in~\\cite{BDH11} carry over to the quantum setting. Namely, assuming existence of (classical) one-way functions that are resistant to efficient quantum inversion algorithms, there exists a quantum-secure signature scheme. We note that the scheme in~\\cite{BDH11} is a promising (post-quantum) candidate to be implemented in practice and our result further justifies it. Actually, to obtain these results, we formalize a simple criteria, which is motivated by many classical proofs in the literature and is straightforward to check. This makes our lifting theorem easier to apply, and it should be useful elsewhere to prove quantum security of proposed post-quantum cryptographic schemes. Finally we demonstrate the generality of our framework by showing that several existing works (Full-Domain hash in the quantum random-oracle model~\\cite{Zha12ibe} and the simple hybrid arguments framework in~\\cite{HSS11}) can be reformulated under our unified framework.

Expand

08 September 2014

CWI / University of Amsterdam
Job Posting Job Posting

The Institute for Logic, Language & Computation (ILLC) at the University of Amsterdam, and the Centrum Wiskunde & Informatica (CWI) are looking for a PhD candidate in the area of quantum cryptography.

The aim of the PhD project is to develop new quantum-cryptographic protocols (beyond the task of key distribution) and explore their limitations. An example of an active research is position-based quantum cryptography. Another aspect is to investigate the security of classical cryptographic schemes against quantum adversaries (post-quantum cryptography).

Full-time appointment is on a temporary basis for a period of four years. For the first two years the PhD candidate will be appointed at the ILLC, University of Amsterdam, initially for a period of 18 months and then, on positive evaluation, for a further six months. During the final two years, the PhD candidate will be employed by the Centrum Wiskunde and Informatica (CWI). On the basis of a full-time appointment (38 hours per week), the gross monthly salary amounts to €2,083 during the first year, rising to €2,664 during the fourth year.

Requirements:

  • a Master\'s degree with excellent grades in computer science, mathematics or physics with outstanding results or a comparable degree;
  • candidates with a strong background in cryptography or quantum information are preferred;
  • demonstrated research abilities by completion of an (undergraduate) research project;
  • good academic writing and presentation skills;
  • good social and organisational skills.
Expand

05 September 2014

Zhigang Chen, Jian Wang, ZengNian Zhang , Xinxia Song
ePrint Report ePrint Report
Fully homomorphic encryption is faced with two problems now. One is candidate fully homomorphic encryption schemes are few. Another is that the efficiency of fully homomorphic encryption is a big question. In this paper, we propose a fully homomorphic encryption scheme based on LWE, which has better key size. Our main contributions are: (1) According to the binary-LWE recently, we choose secret key from binary set and modify the basic encryption scheme proposed in Linder and Peikert in 2010. We propose a fully homomorphic encryption scheme based on the new basic encryption scheme. We analyze the correctness and give the proof of the security of our scheme. The public key, evaluation keys and tensored ciphertext have better size in our scheme. (2) Estimating parameters for fully homomorphic encryption scheme is an important work. We estimate the concert parameters for our scheme. We compare these parameters between our scheme and Bra12 scheme. Our scheme have public key and private key that smaller by a factor of about logq than in Bra12 scheme. Tensored ciphertext in our scheme is smaller by a factor of about log2q than in Bra12 scheme. Key switching matrix in our scheme is smaller by a factor of about log3q than in Bra12 scheme.

Expand
Oscar Garcia-Morchon, Ronald Rietman, Ludo Tolhuizen, Domingo Gomez-Perez, Jaime Gutierrez
ePrint Report ePrint Report
This paper describes HIMMO, an identity-based pairwise symmetric key establishment method. The acronym \"HIMMO\" is derived from two interpolation problems that are essential for the

security of the scheme: the HI problem, which is related to the

well-known noisy interpolation problem, and the apparently novel MMO problem, presented at ISSAC\'14.

HIMMO is non-interactive: nodes in a network can directly generate a common key without exchanging messages. Each node in the network has an identifier, and a trusted third pay (TTP) provides it with secret keying material---linked to the node identifier---in a secure way.

A node that wishes to communicate with another node uses its own secret keying material and the identity of the other node to generate a common pairwise key.

HIMMO allows for efficient operation with respect to both the amount of stored keying material and the key computation time, which is especially relevant for resource-constrained devices.

It has similar operational characteristics as previous ID-based symmetric key establishment methods, but has superior resistance against attacks in which multiple colluding or compromised nodes co-operate to obtain information on keys between other non-colluding or non-compromised nodes.

Expand
Christina Boura, Mar\\\'ia Naya-Plasencia, Valentin Suder
ePrint Report ePrint Report
Impossible differential cryptanalysis has shown to be a very powerful form of cryptanalysis against block ciphers. These attacks, even if extensively used, remain not fully understood because of their high technicality. Indeed, numerous are the applications where mistakes have been discovered or where the attacks lack optimality. This paper aims in a first step at formalizing and improving this type of attacks and in a second step at applying our work to block ciphers based on the Feistel construction. In this context, we derive generic complexity analysis formulas for mounting such attacks and develop new ideas for optimizing impossible differential cryptanalysis. These ideas include for example the testing of parts of the internal state for reducing the number of involved key bits. We also develop in a more general way the concept of using multiple differential paths, an idea introduced before in a more restrained context. These advances lead to the improvement of previous attacks against well known ciphers such as CLEFIA-128 and Camellia, while also to new attacks against 23-round LBlock and all members of the Simon family.

Expand
◄ Previous Next ►