IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
04 January 2018
Murali Godi, Roopa Vishwanathan
Christian Badertscher, Ueli Maurer, Björn Tackmann
As DSSs serve as a building block in numerous complex cryptographic protocols, a security definition that specifies the guarantees of a DSS under composition is needed. Canetti (FOCS 2001, CSFW 2004) as well as Backes, Pfitzmann, and Waidner (CCS 2003) have described ideal functionalities for signatures in their respective composable-security frameworks. While several variants of these functionalities exist, they all share that the verification key and signature values appear explicitly.
In this paper, we describe digital signature schemes from a different, more abstract perspective. Instead of modeling all aspects of a DSS in a monolithic ideal functionality, our approach characterizes a DSS as a construction of a functionality for authentically reading values written by a certain party from certain assumed functionalities, e.g., for transmitting verification key and signature values. This approach resolves several technical complications of previous simulation-based approaches, captures the security of signature schemes in an abstract way, and allows for modular proofs.
We show that our definition is equivalent to existential unforgeability. We then model two example applications: (1) the certification of values via a signature from a specific entity, which with public keys as values is the core functionality of public-key infrastructures, and (2) the authentication of a session between a client and a server with the help of a digitally signed assertion from an identity provider. Single-sign-on mechanisms such as SAML rely on the soundness of the latter approach.
Kaiyan Zheng, Peng Wang
03 January 2018
Benedikt Auerbach, Bertram Poettering
This paper proposes two new proof systems for a wide set of properties that RSA and related moduli might have. The protocols are particularly efficient: The necessary computations are simple, the communication is restricted to only one round, and the exchanged messages are short. While the first protocol is based on prior work (improving on it by reducing the number of message passes from four to two), the second protocol is novel. Both protocols require a random oracle.
Falk Schellenberg, Dennis R.E. Gnad, Amir Moradi, Mehdi B. Tahoori
Luxembourg Institute of Science and Technology, Luxembourg
Based on the profile of the applicant, the topic can be either lightweight authentication protocols for IoT devices or privacy-preserving IoT data analysis protocols. More details will be available through email inquiries.
Closing date for applications: 31 March 2018
Contact: Dr. Qiang Tang
qiang.tang (at) list.lu
Pooya Farshim, Julia Hesse, Dennis Hofheinz, Enrique Larraia
a) We can prove that the multilinear decisional Diffie--Hellman (MDDH) assumption holds in our setting, assuming the used ingredients are secure (in a well-defined and standard sense). In particular, and in contrast to previous constructions, our GES does not succumb to so-called ``zeroizing'' attacks. Indeed, our scheme is currently the only GES for which no known cryptanalysis applies. b) Encodings in our GES do not carry any noise. Thus, unlike previous GES constructions, there is no upper bound on the number of operations one can perform with our encodings. Hence, our GES essentially realizes what Garg et al.~(EUROCRYPT 2013) call the ``dream version'' of a GES.
Technically, our scheme extends a previous, non-graded approximate multilinear map scheme due to Albrecht et al.~(TCC 2016-A). To introduce a graded structure, we develop a new view of encodings at different levels as polynomials of different degrees.
Thomas Agrikola, Dennis Hofheinz
02 January 2018
University of Tartu, Estonia
Successful candidates will help to design and evaluate privacy-enhancing cryptographic techniques for blockchains and perform other research duties to help with the project, coordinate and advise partners on implementing research prototypes (the candidate may or may not participate in implementing) and ensure the smooth administration of the project including the timely delivery of research output. (Some of these duties apply only to the postdoctoral researcher.) We expect candidates to be able to develop and devote significant time to their own research agenda around the theme of the project.
The EU H2020 project PRIViLEDGE requires travel to and collaboration with colleagues throughout the European Union. Full travel and equipment budget is available to support the activities of the project.
For any inquiries or to apply for the positions, submit a full research curriculum-vitae (cv), names of two references, and a research statement (obligatory for the postdoctoral researcher) to Prof Helger Lipmaa (firstname.lastname (at) ut.ee) clearly indicating the position sought. This is crucial since we have several open positions.
The project started from January 1, 2018, and will last for three years. In the case of interest, the candidates may later seek further employment but this is not necessarily guaranteed.
Closing date for applications: 1 February 2018
Contact: Helger Lipmaa
lead research fellow (research professor)
University of Tartu
helger dot lipmaa at ut dot ee
More information: https://crypto.cs.ut.ee/index.php/Main/2018priviledge
IOHK Research
We offer flexible work style with a chance to work in a very dynamic team with talented people from all around the world.
Review of applications will start immediately and will continue until positions are filled
Closing date for applications: 28 February 2018
More information: https://iohk.io/careers/#op-136094-research-fellow
Ruhr-Universität Bochum
Profile:
All candidates with a PhD degree in cryptography or data security are encouraged to apply. You should have proven your excellence in research by publications in major international cryptography conferences, for example in the IACR conferences CRYPTO, EUROCRYPT, ASIACRYPT, PKC, and TCC.
The salary will depend on your qualification and will start at approximately 50k Euro (gross/year). There will be sufficient funding for attending conferences and workshops. Funding is available until October 2019, with possible extensions. Excellent group atmosphere.
Application material:
Letter of motivation, CV (incl. list of publications).
Feel free to contact me (Eike Kiltz) for any further question.
Closing date for applications: 4 February 2018
Contact: Eike Kiltz
More information: http://www.crypto.rub.de/resgroups/foc/index.html.en
Jérôme Courtois, Lokman Abbas-Turki, Jean-Claude Bajard
Yu-Ao Chen, Xiao-Shan Gao
Qiong Huang, Hongbo Li
Liran Lerman, Stjepan Picek, Nikita Veshchikov, Olivier Markowitch
Xiao Wang, Dov Gordon, Jonathan Katz
A practical instantiation of our protocol has excellent concrete parameters: for storing an $N$-element array of arbitrary size data blocks with statistical security parameter $\lambda$, the servers each store $4N$ encrypted blocks, the client stores $\lambda+2 \log N$ blocks, and the total communication per logical access is roughly $10\log N$ encrypted blocks.
Stjepan Picek, Ioannis Petros Samiotis, Annelie Heuser, Jaehun Kim, Shivam Bhasin, Axel Legay
Moni Naor, Benny Pinkas, Eyal Ronen
Users choosing weak passwords do not only compromise themselves, but the whole eco system. For example, common and default passwords in IoT devices were exploited by hackers to create botnets and mount severe attacks on large Internet services, such as the Mirai botnet DDoS attack.
We present a method to help protect the Internet from such large scale attacks. We enable a server to identify popular passwords (heavy hitters), and publish a list of over-popular passwords that must be avoided. This filter ensures that no single password can be used to comprise a large percentage of the users. The list is dynamic and can be changed as new users are added or when current users change their passwords. We apply maliciously secure two-party computation and differential privacy to protect the users' password privacy. Our solution does not require extra hardware or cost, and is transparent to the user.
The construction is secure even against a malicious coalition of devices which tries to manipulate the protocol in order to hide the popularity of some password that the attacker is exploiting. We show a proof-of-concept implementation and analyze its performance.
Our construction can also be used in any setting where one would desire to privately learn heavy hitters in the presence of an active malicious adversary. For example, learning the most popular sites accessed by the TOR network.
Cagdas Calik, Meltem Sonmez Turan, Rene Peralta
Benny Applebaum, Barak Arkis
We initiate the study of such $d$-uniform access structures, and view them as a useful scaled-down version of general access structures. Our main result shows that, for constant $d$, any $d$-uniform access structure admits a secret sharing scheme with a *constant* asymptotic information ratio of $c_d$ that does not grow with the number of servers $n$. This result is based on a new construction of $d$-party Conditional Disclosure of Secrets (Gertner et al., JCSS '00) for arbitrary predicates over $n$-size domain in which each party communicates at most four bits per secret bit.
In both settings, previous results achieved non-constant information ratio which grows asymptotically with $n$ even for the simpler (and widely studied) special case of $d=2$. Moreover, our results provide a unique example for a natural class of access structures $F$ that can be realized with information rate smaller than its bit-representation length $\log |F|$ (i.e., $\Omega( d \log n)$ for $d$-uniform access structures) showing that amortization can beat the representation size barrier.
Our main result applies to exponentially long secrets, and so it should be mainly viewed as a barrier against amortizable lower-bound techniques. We also show that in some natural simple cases (e.g., low-degree predicates), amortization kicks in even for quasi-polynomially long secrets. Finally, we prove some limited lower-bounds, point out some limitations of existing lower-bound techniques, and describe some applications to the setting of private simultaneous messages.