IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
26 December 2017
Shuang Qiu, Rui Zhang, Yongbin Zhou, Wei Cheng
25 December 2017
Santa Barbara, USA, 1 April - 1 July 2018
Submission deadline: 31 March 2018
Notification: 30 June 2018
Halifax, Canada, 30 July - 3 August 2018
Submission deadline: 1 March 2018
Notification: 1 April 2018
24 December 2017
DTU, Technical University of Denmark
Through the position the University seeks to strengthen the research within cyber security. The cyber security section at DTU has experts in cryptology, in particular the design and analysis of ciphers, hash functions and in side-channel analysis, and in the security of distributed and pervasive computing systems, in particular support for secure collaboration across administrative domains and in other low trust environments. The section wishes to broaden its research within all areas of cyber security.
Topics of particular interest include:
access control (both policies and mechanisms);
authentication and identity management systems;
blockchains and distributed ledger technologies
malware analysis, digital forensics, and ethical hacking;
privacy and privacy enhancing technologies;
security in pervasive computing systems (incl. cyber physical systems, IoT, mobile healthcare systems and wireless computing systems); and
trust management systems.
Interest and skills in pedagogical work and dissemination of mathematical sciences will play an important role.
Closing date for applications: 1 February 2018
Contact: Professor Lars Ramkilde Knudsen, lrkn (at) dtu.dk
More information: http://www.dtu.dk/job/job?id=ad063634-bc8a-42e1-82f1-b6a93908941d
Singapore University of Technology and Design (SUTD)
I am looking for postdocs / research fellows with expertise on cyber-physical system security, especially on the legacy CPS protection. The candidates should have track record of strong R&D capability, be able to perform deep system-level investigations of security mechanisms, be a good team player, and also have good written/oral communication skills. The position will provide an excellent opportunity to perform both basic and translational research in close collaboration with industry. Successful candidates will be offered internationally competitive remuneration, and enjoy high-quality living and low tax rates in Singapore.
Interested candidates please send your CV with a research statement to Prof. Jianying Zhou.
Email: jianying_zhou (at) sutd.edu.sg
Home: http://jianying.space/
Closing date for applications: 28 February 2018
Contact: Prof. Jianying Zhou
More information: http://jianying.space/
23 December 2017
Li Hongda, Pan Dongxue, Ni Peifang
Taotao Li, Parhat Abla, Mingsheng Wang, Qianwen Wei
Koichiro Akiyama, Yasuhiro Goto, Shinya Okumura, Tsuyoshi Takagi, Koji Nuida, Goichiro Hanaoka, Hideo Shimizu, Yasuhiko Ikematsu
Mridula Singh, Patrick Leu, Srdjan Capkun
22 December 2017
Cloudflare Inc. (San Francisco, USA and London, UK)
At Cloudflare, we have our eyes set on an ambitious goal: to help build a better Internet. Today, Cloudflare runs one of the world’s largest distributed networks that powers more than 1.5 trillion page views each month across 5 million Internet properties. More than 10 percent of all global Internet requests flow through Cloudflare’s network. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code.
Responsibilities
The Cryptography team is focused on solving difficult problems in security, performance, and privacy at scale using cryptographic tools. This involves systems engineering, open source software development, protocol design, the implementation of cryptographic primitives, contributions to cutting-edge research in collaboration with academia, participation in Internet standards organizations like the IETF, and more.
We are looking for systems engineers, programmers and researchers with a broad background and a specialization in cryptography to work on our team. Experience in Go, C and/or Lua is required, experience with x86/amd64 assembly is preferred.
Requirements
Currently in a M.S. or Ph.D. Computer Science or related field, or equivalent experience.
Advance knowledge of networking protocols - TCP/IP, DNS, BGP, QUIC etc.
In-depth knowledge of authentication protocols, applied cryptography, PKI and SSL/TLS
Proficiency in the following languages - Go, C and/or Lua
Proven track record of independently driving projects in a fast-paced environment
Excellent communication skills on both technical and non-technical issues
Bonus Points:
Substantial contributions to cryptography software such as OpenSSL or Go\'s crypto/tls
Experience with high throughput/low latency real-time systems and/or content delivery networks
Closing date for applications: 31 December 2018
More information: https://boards.greenhouse.io/cloudflare/jobs/608495#.Wjw-yBNSwws
Shunli Ma, Yi Deng, Debiao He, Jiang Zhang, Xiang Xie
Thang Hoang, Ceyhun D. Ozkaptan, Gabriel Hackebeil, Attila A. Yavuz
We propose new oblivious data structures called Oblivious Matrix Structure (OMAT) and Oblivious Tree Structure (OTREE), which allow tree-based ORAM to be integrated into database systems in a more efficient manner with diverse query functionalities supported. OMAT provides special ORAM packaging strategies for table structures, which not only offers a significantly better performance but also enables a broad range of query types that may not be practical in existing frameworks. OTREE allows oblivious conditional queries to be deployed on tree-indexed databases more efficient than existing techniques. We fully implemented our proposed techniques and evaluated their performance on a real cloud database with various metrics, compared with state-of-the-art counterparts.
Thang Hoang, Attila A. Yavuz, Jorge Guajardo
In this article, we introduce a new Dynamic Searchable Symmetric Encryption (DSSE) framework called Incidence Matrix (IM)-DSSE, which achieves a high level of privacy, efficient search/update, and low client storage with actual deployments on real cloud settings. We harness an incidence matrix along with two hash tables to create an encrypted index, on which both search and update operations can be performed effectively with minimal information leakage. This simple set of data structures surprisingly offers a high level of DSSE security while at the same time achieving practical performance. Specifically, IM-DSSE achieves forward privacy, backward privacy and size-obliviousness properties simultaneously. We also create several DSSE variants, each offering different trade-offs (e.g., security, computation) that are suitable for different cloud applications and infrastructures. Our framework was fully-implemented and its performance was rigorously evaluated on a real cloud system (Amazon EC2). Our experimental results confirm that IM-DSSE is highly practical even when deployed on mobile phones with a large outsourced dataset. Finally, we have released our IM-DSSE framework as an open-source library for a wide development and adaptation.
Jean-Charles Faug\`{e}re, Kelsey Horan, Delaram Kahrobaei, Marc Kaplan, Elham Kashefi, Ludovic Perret
Rafaël del Pino, Vadim Lyubashevsky, Gregory Neven, Gregor Seiler
Christina Boura, Ilaria Chillotti, Nicolas Gama, Dimitar Jetchev, Stanislav Peceny, Alexander Petric
Gilles Barthe, Benjamin Grégoire, Vincent Laporte
We consider the problem of preserving side-channel countermeasures by compilation, and present a general method for proving that compilation preserves software-based side-channel countermeasures. The crux of our method is the notion of 2-simulation, which adapts to our setting the notion of simulation from compiler verification. Using the Coq proof assistant, we verify the correctness of our method and of several representative instantiations.
Motahhareh Gharahi, Shahram Khazaei
Houda Ferradi, David Naccache
Marcel Keller, Valerio Pastro, Dragos Rotaru
- We present a protocol that uses semi-homomorphic (addition-only) encryption. For two parties, our BGV-based implementation is 6 times faster than MASCOT on a LAN and 20 times faster in a WAN setting. The latter is roughly the reduction in communication.
- We show that using the proof of knowledge in the original work by Damgård et al. (Crypto '12) is more efficient in practice than the one used in the implementation mentioned above by about one order of magnitude.
- We present an improvement to the verification of the aforementioned proof of knowledge that increases the performance with a growing number of parties, doubling it for 16 parties.