IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
14 February 2018
University College Cork, Ireland
The School of CSIT has 26 full-time academic staff and offers degrees at bachelors, masters and doctoral level. It has very close engagement with industry sponsors, including those in the cluster of over 20 cyber-security companies that are based in Cork. The School has a strong research track record, and ranked very highly in the recent Research Quality Review. Professors in the School have leadership roles in three large-scale national research centres: CONNECT – Research Centre for Future Networks; Insight – Centre for Data Analytics; and Lero – Irish Software Research Centre. For further information on the School, please visit https://www.ucc.ie/en/compsci/
Appointment may be made on the Professorial Salary Scale: €111,196 – €140,962 (Scale B), €109,129-€133,980 (Scale A). In all instances the successful appointment will be at the first point of the scale. For an information package including full details of the post, selection criteria and application process see https://www.ucc.ie/hr/vacancies
Closing date for applications: 6 March 2018
Contact: Informal enquiries can be made, in confidence, to the Head of School, Professor Cormac J. Sreenan, head (at) cs.ucc.ie
More information: https://goo.gl/biAAB7
SECAN LAB, University of Luxembourg, Luxembourg
For further details and how to apply, please visit https://secan-lab.uni.lu/jobs
For further information or for an informal discussion, please contact us by email: secanlab.jobs (at) uni.lu
Closing date for applications: 24 February 2018
Contact: secanlab.jobs (at) uni.lu
More information: https://secan-lab.uni.lu/jobs
Ruhr-University Bochum
- security and safety in autonomous systems
- side-channel prevention on the processor level
- formal methods for security and privacy
- applied cryptography in software and hardware
Successful applicands for the open positions will become part of the Horst Görtz Institute for IT-Security (HGI), one of the largest research centers in IT-Security within Europe.
Candidates are invited to apply until February 28. Please include in your application a motivation letter, CV and transcript of records.
For any additional information, please contact Tim Güneysu
Closing date for applications: 28 February 2018
Contact: Tim Güneysu
Chair for Security Engineering,
Ruhr Universität Bochum
Universitätsstr. 150
44780 Bochum
+49 234 32 24626
tim.gueneysu (at) rub.de
Bram Cohen, Krzysztof Pietrzak
The construction proposed by [MMV'13] is based on a hash function and can be proven secure in the random oracle model, or assuming inherently sequential hash-functions, which is a new standard model assumption introduced in their work.
In a proof of sequential work, a prover gets a "statement" $\chi$, a time parameter $N$ and access to a hash-function $H$, which for the security proof is modelled as a random oracle. Correctness requires that an honest prover can make a verifier accept making only $N$ queries to $H$, while soundness requires that any prover who makes the verifier accept must have made (almost) $N$ sequential queries to $H$. Thus a solution constitutes a proof that $N$ time passed since $\chi$ was received. Solutions must be publicly verifiable in time at most polylogarithmic in $N$.
The construction of [MMV'13] is based on "depth-robust" graphs, and as a consequence has rather poor concrete parameters. But the major drawback is that the prover needs not just $N$ time, but also $N$ space to compute a proof.
In this work we propose a proof of sequential work which is much simpler, more efficient and achieves much better concrete bounds. Most importantly, the space required can be as small as $\log(N)$ (but we get better soundness using slightly more memory than that).
An open problem stated by [MMV'13] that our construction does not solve either is achieving a "unique" proof, where even a cheating prover can only generate a single accepting proof. This property would be extremely useful for applications to blockchains.
Lorenzo Grassi, Christian Rechberger
In this paper we present new techniques to analyze this special set of inputs that is so versatile, and report on new properties. Classically, in differential cryptanalysis, statements about the probability distribution of output differences, like mean or variance, are of interest. So far such statements where only possible for up to 4 rounds of AES. In this paper we consider the probabilistic distribution of the number of different pairs of corresponding ciphertexts that lie in certain subspaces after 5 rounds. We rigorously prove that the following two properties (independent of any key or constant additions) hold for 5 rounds of the AES permutation: the mean value is bigger for AES than for a random permutation; the variance is approximately by a factor 36 higher for AES than for a random permutation. While the distinguisher based on the variance is (almost) independent of the details of the S-Box and of the MixColumns matrix, the mean value distinguisher does depend on the details of the S-Box and may give rise to a new design criterion for S-Boxes.
Of independent interest is the technique that we developed for this rigorous analysis. To the best of our knowledge this seems to be the first time that such a precise differential analysis was performed. Practical implementations and verification confirm our analysis.
Christoph Dobraunig, Maria Eichlseder, Lorenzo Grassi, Virginie Lallemand, Gregor Leander, Eik List, Florian Mendel, Christian Rechberger
Sanjam Garg, Peihan Miao, Akshayaram Srinivasan
Ken Goss, Wei Jiang
Zhi Hu, Lin Wang, Chang-An Zhao
Houssem Maghrebi, Emmanuel Prouff
Kamil Kluczniak, Man Ho Au
Payment systems like ZCash attempt to offer much stronger anonymity by hiding the origin, destination and value of a payment. The ZCash system is able to offer strong anonymity, mainly due to use of Zero-Knowledge Succinct Non-interactive Arguments of Knowledge (ZK-SNARK) of arithmetic circuit satisfiability. One drawback of ZCash is that the arithmetic circuit is rather large, thus requires a large common reference string and complex prover for the ZK-SNARK. In fact, the memory and prover complexity is dominated by the ZK-SNARK in use and is mainly determined by the complexity of the circuit.
In this paper we design a Decentralized Anonymous Payment system (DAP), functionally similar to ZCash, however with significantly smaller arithmetic circuits, thus greatly reducing the memory and prover complexity of the system. Our construction is based on algebraic primitives, from the realm of elliptic curve and lattice based cryptography, which satisfiability might be efficiently verified by an arithmetic circuit.
Vincent Grosso
Chen-Dong Ye, Tian Tian
Benjamin Grégoire, Kostas Papagiannopoulos, Peter Schwabe, Ko Stoffelen
Felix Wegener, Amir Moradi
Yi-Hsiu Chen, Kai-Min Chung, Jyun-Jie Liao
Miruna Rosca, Damien Stehl\'{e}, Alexandre Wallet
We show that there exist reductions between all of these six problems that incur limited parameter losses. More precisely: we prove that the (decision/search) dual to primal reduction from Lyubashevsky et al. [EUROCRYPT~2010] and Peikert [SCN~2016] can be implemented with a small error rate growth for all rings (the resulting reduction is non-uniform polynomial time); we extend it to polynomial-time reductions between (decision/search) primal RLWE and PLWE that work for a family of polynomials f that is exponentially large as a function of deg f (the resulting reduction is also non-uniform polynomial time); and we exploit the recent technique from Peikert et al. [STOC~2017] to obtain a search to decision reduction for RLWE for arbitrary number fields. The reductions incur error rate increases that depend on intrinsic quantities related to K and f.
12 February 2018
University of South Florida and Florida Atlantic University
The areas of interest are
- Lattice based cryptography.
- Isogeny-based cryptography.
- Cryptocurrencies.
- Classical and quantum cryptanalysis.
The person recruited at USF will report to Dr. Jean-Francois Biasse. They will work on fundamental aspects of the aforementioned topics and be hired by the Mathematics department. The annual salary will be $47,659
The person recruited at FAU will report to Dr Reza Azarderakhsh. They will work on efficient implementations related to the topics of interests, with an emphasis on hardware solutions. They will be hired by the Department of Computer and Electrical Engineering and Computer Science. The annual salary will be $50,000.
If you are interested in either position, please send a CV and a 1 page research statement to usf.fau.crypto.postdoc (at) gmail.com.
To ensure full consideration, please send your application material by March 12th 2018. However, we will consider applications until the positions are filled.
Closing date for applications: 1 July 2018
11 February 2018
RSA Cryptography is the world's most widely used public-key cryptography method for securing communication on the Internet. Introduced in 1977 by MIT colleagues Rivest, Shamir and Adleman, RSA Cryptography is instrumental to the growth of e-commerce and is used in almost all Internet-based transactions to safeguard sensitive data such as credit card numbers.
They will be formally inducted on May 3 in Washington DC.
The National Inventors Hall of Fame (NIHF) is an American not-for-profit organization which recognizes individual inventors who hold a U.S. patent of highly significant technology. Founded in 1973, its primary mission is to "honor the people responsible for the great technological advances that make human, social and economic progress possible."