International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

21 February 2018

IoTeX
Job Posting Job Posting

IoTeX is a young blockchain startup located at Silicon Valley, USA. IoTeX is building the next generation blockchain platform for IoT (Internet-of-Things) with focus on scalability, privacy and enabling of autonomous device coordination. IoTeX, while still in stealth mode, is a well-funded company in blockchain sector and has partnered with leading players in IoT space.

We are looking for a talent cryptography and distributed systems engineer to work on various aspects of the core IoTeX blockchain technologies, with emphasis on the design, analysis and implementation of innovative and efficient cryptographic algorithms and protocols that improve on the scalability, security and privacy of existing blockchain methodologies and pave the way for securing a wide range of Internet of Things (IoT) applications with IoTex blockchains.

Requirements

  • Eligible to work in the US
  • Master’s or PhD in cryptography, mathematics, computer science, or related fields
  • Solid background in cryptographic algorithms and protocols such as elliptic curve cryptography, digital signature, commitment scheme, zero-knowledge proof, secure multiparty computation, etc.
  • Experience designing novel cryptographic primitives and protocols
  • Experience drafting and validating security specification and proofs
  • Experience implementing cryptographic primitives and protocols in various platforms using C/C++, Golang or Python

Bonus

  • Cryptocurrency and blockchain technology
  • Smart contracts
  • Security and privacy for distributed systems
  • Experience designing novel cryptographic primitives and protocols
  • Security and privacy for various IoT systems (e.g., wireless sensor networks, RFID systems, smart grid, vehicular ad-hoc networks, etc.)

Review of applications will start immediately and will continue until positions are filled.

Closing date for applications: 31 May 2018

Contact: To apply, please send your CV and in English to hello (at) iotex.io

More information: https://www.iotex.io/article/careers

Expand
DarkMatter - Abu Dhabi
Job Posting Job Posting
As Senior Vice President of Cryptographic Algorithms and Systems, realisation of your dream will secure the businesses of today from the threats of tomorrow. Whether leading security efforts on our own secure communications suite and blockchain ecosystem, or for outside clients, it pays to keep your guard up at DarkMatter

As SVP Cryptographic Algorithms and Systems, you will:

Manage research and development of crypto-dependent systems for authentication and authorization platforms that leverage blockchain technology designed for constrained devices and critical infrastructure

Anticipate threats and client needs to design and combine algorithms that solve emerging cyber security problems and defend against attack vectors of the future

Lead, develop and inspire a dedicated team of research scientists and engineers to consistently produce high-quality results

Work with potential clients to gather requirements towards commercialization and productizing of our research output

You will lead clients to the cryptographic solutions they’ll need in the future while leading your team in developing libraries and services for their existing algorithms. Our commitment to end-to-end solutions gives you the freedom to make your dreams come to life. Create your own algorithms for enhanced security in each area of our business. Our Test & Validation Labs and Innovation Center are being built to provide both depth of knowledge and a collaborative approach to research and development.

To guard against the threats of the future, you’ll need:

20+ years of technical and leadership experience, including extensive industry experience managing teams of cybersecurity researchers and engineers

Eagerness to oversee the development of cryptographic algorithms, protocols and systems for enterprise-grade cyber security products in mobile, cloud and web

Bachelor’s degree in Engineering, Computer Science, Mathematics or Physics, with a Masters or Ph.D. preferred

Closing date for applications: 18 November 2018

Contact: Sheila Morjaria

More information: https://grnh.se/2wr6cqjn1

Expand
Technical University of Denmark (DTU), Denmark
Job Posting Job Posting
DTU Compute invites talented candidates who have obtained remarkable results during their M.Sc. studies and who have demonstrated promise and potential in their field of study, to apply for PhD scholarships. The starting date is expected to be in the fall 2018 or as soon as possible thereafter.

You can apply for fully funded or partially funded scholarships from DTU Compute. For partially funded DTU Compute scholarships, documentation for the remaining funding must be provided with the application. The purpose of the co-funded scholarships is to increase the total volume of scholarships and to promote innovation in collaboration with external parties.

Our department is an internationally unique academic environment spanning the science disciplines mathematics, statistics and computer science. At the same time, we are an engineering department developing informatics and communication technologies in their broadest sense.

DTU Compute strives to achieve research excellence in its basic science disciplines, to achieve technological leadership in research and innovation, and to address societal challenges in collaboration with partners at DTU and other academic institutions, nationally and internationally, and, equally important, with industries and organizations.

We play a central role in education at all levels of the engineering programs at DTU - both in terms of our scientific disciplines and our didactic innovation.

Projects

Cyber Security - Cyber security examines the methods, techniques and tools for securing computer systems that are accessible through a network, typically the Internet, which is often known as cyberspace.

Qualifications

The ideal PhD student is curious, creative, independent and yet able to collaborate as a team player in a research group. Candidates must hold a M.Sc. degree in engineering or an equivalent degree. Furthermore, good command of the English language is essential.

Closing date for applications: 13 April 2018

Contact: Dr. Christian D. Jensen (cdje (at) dtu.dk), or Dr. Weizhi Meng (weme (at) dtu.dk)

More information: http://www.dtu.dk/job/job?id=9bbc3ae7-6dec-45ed-8e5c-bffbda1099d6

Expand

20 February 2018

Tokyo, Japan, 25 September - 27 September 2018
Event Calendar Event Calendar
Event date: 25 September to 27 September 2018
Submission deadline: 1 April 2018
Notification: 25 May 2018
Expand
Toronto, Canada, 15 October - 19 October 2018
Event Calendar Event Calendar
Event date: 15 October to 19 October 2018
Submission deadline: 8 May 2018
Notification: 23 July 2018
Expand

19 February 2018

Nicola Atzei, Massimo Bartoletti, Tiziana Cimoli, Stefano Lande, Roberto Zunino
ePrint Report ePrint Report
Albeit the primary usage of Bitcoin is to exchange currency, its blockchain and consensus mechanism can also be exploited to securely execute some forms of smart contracts. These are agreements among mutually distrusting parties, which can be automatically enforced without resorting to a trusted intermediary. Over the last few years a variety of smart contracts for Bitcoin have been proposed, both by the academic community and by that of developers. However, the heterogeneity in their treatment, the informal (often incomplete or imprecise) descriptions, and the use of poorly documented Bitcoin features, pose obstacles to the research. In this paper we present a comprehensive survey of smart contracts on Bitcoin, in a uniform framework. Our treatment is based on a new formal specification language for smart contracts, which also helps us to highlight some subtleties in existing informal descriptions, making a step towards automatic verification. We discuss some obstacles to the diffusion of smart contracts on Bitcoin, and we identify the most promising open research challenges.
Expand
Michael Backes, Lucjan Hanzlik, Kamil Kluczniak, Jonas Schneider
ePrint Report ePrint Report
We introduce a new cryptographic primitive called signatures with flexible public key. We divide the key space into equivalence classes induced by a relation $\mathcal{R}$. A signer can efficiently change his key pair to a different representative of the same class, but without a trapdoor it is hard to distinguish if two public keys are related.

This primitive offers a unified approach to the modular construction of signature schemes with privacy-preserving components. Namely, we show how to build the first ring signature scheme in the plain model without trusted setup, where signature size depends only sub-linearly on the number of ring members. Moreover, we show how to combine our primitive with structure-preserving signatures on equivalence classes (SPSEQ) to construct static group signatures and self-blindable certificates. When properly instantiated, the result is a group signature scheme that has a shorter signature size than the current state-of-the-art scheme by Libert, Peters, and Yung from Crypto'15.

In its own right, our primitive has stand-alone applications in the cryptocurrency domain. In particular it enables the straightforward implementation of so-called stealth addresses.
Expand
Sikhar Patranabis, Debdeep Mukhopadhyay
ePrint Report ePrint Report
We present function private public-key predicate encryption schemes from standard cryptographic assumptions, that achieve new lower bounds on the min-entropy of underlying predicate distributions. Existing function private predicate encryption constructions in the public-key setting can be divided into two broad categories. The first category of constructions are based on standard assumptions, but impose highly stringent requirements on the min-entropy of predicate distributions, thereby limiting their applicability in the context of real-world predicates. For example, the statistically function private constructions of Boneh, Raghunathan and Segev (CRYPTO'13 and ASIACRYPT'13) are inherently restricted to predicate distributions with min-entropy roughly proportional to the security parameter $\lambda$. The second category of constructions mandate more relaxed min-entropy requirements, but are either based on non-standard assumptions (such as indistinguishability obfuscation) or are secure in the generic group model. In this paper, we affirmatively bridge the gap between these categories by presenting new public-key constructions for identity-based encryption, hidden-vector encryption, and subspace-membership encryption~(a generalization of inner-product encryption) that are both data and function private under variants of the well-known DBDH, DLIN and matrix DDH assumptions, while relaxing the min-entropy requirement on the predicate distributions to $\omega(\log\lambda)$. In summary, we establish that the minimum predicate entropy necessary for any meaningful notion of function privacy in the public-key setting, is in fact, sufficient, for a fairly rich class of predicates.
Expand
Pascal Sasdrich, René Bock, Amir Moradi
ePrint Report ePrint Report
Masking is one of the predominantly deployed countermeasures in order to prevent side-channel analysis (SCA) attacks. Over the years, various masking schemes have been proposed. However, the implementation of Boolean masking schemes has proven to be difficult in particular for embedded devices due to undisclosed architecture details and device internals. In this article, we investigate the application of Threshold Implementation (TI) in terms of Boolean masking in software using the PRESENT cipher as a case study. Since TI has proven to be a proper solution in order to implement Boolean masking for hardware circuits, we apply the same concept for software implementations and compare it to classical first- and second-order Boolean masking schemes. Eventually, our practical security evaluations reveal that amongst all our considered implementation variants only the TI can provide first-order security while all others still exhibit detectable first-order leakage.
Expand
Stephen D. Miller, Noah Stephens-Davidowitz
ePrint Report ePrint Report
We generalize Banaszczyk's seminal tail bound for the Gaussian mass of a lattice to a wide class of test functions. We therefore obtain quite general transference bounds, as well as bounds on the number of lattice points contained in certain bodies. As examples, we bound the lattice kissing number in $\ell_p$ norms by $e^{(n+o(n))/p}$ for $0 < p \leq 2$, and also give a proof of a new transference bound in the $\ell_1$ norm.
Expand
Sean Bowe, Ariel Gabizon
ePrint Report ePrint Report
We alter the zk-SNARK construction of Groth[Eurocrypt 2016] to obtain a simulation-extractable zk-SNARK with almost identical prover running time. (Simulation extractability is a strong form of adaptive non-malleability.) Our construction requires outputting 5 group elements rather than 3 as in [Groth], and requires the random oracle model.
Expand
Daniel R. L. Brown
ePrint Report ePrint Report
An ECDSA modification with signing equation $s=rk+hd$ has the properties that the signer avoids modular inversion and that passive universal forgery is equivalent to inverting a sum of two functions with freely independent inputs.

Let $\sigma:s\mapsto sG$ and $\rho:R\mapsto -rR$ where $r$ is an integer representation of the point $R$. The free sum of $\rho$ and $\sigma$ is $\nu: (R,s) \mapsto \rho(R)+\sigma(s)$. A RKHD signature $(R,s)$ verifies if and only if $\nu(R,s) = hQ$, where $h$ is the hash of the message and $Q$ is the public key. So RKHD security relies upon, among other things, the assumption that free sum $\nu$ is 1-way (or unforgoable, to be precise).

Other free sums are 1-way under plausible assumptions: elliptic curve discrete logs, integer factoring, and secure small-key Wegman--Carter--Shoup authentication. Yet other free sums of 1-way functions (integer-factoring based) fail to be 1-way. The ease with which these free sums arise hints at the ease determining RKHD security.

RKHD signatures are very similar to ECGDSA (an elliptic curve version Agnew--Mullin--Vanstone signatures): variable-$G$ forgers of the two schemes are algorithmically equivalent. But ECGDSA requires the signer to do one modular inversion, a small implementation security risk.
Expand
Marcos A. Simplicio Jr., Eduardo Lopes Cominetti, Harsh Kupwade Patil, Jefferson E. Ricardini, Leonardo T. D. Ferraz, Marcos Vinicius M. Silva
ePrint Report ePrint Report
Vehicular communication (V2X) technologies are expected to become increasingly common in the future. Although they enable improvements on transportation safety and efficiency, the large scale deployment of V2X requires addressing some challenges. In particular, to prevent abuse by drivers and by the system itself, V2X architectures must: (1) ensure the authenticity of messages, which is usually accomplished by means of digital certification; and (2) preserve the privacy of honest users, so owners of non-revoked certificates cannot be easily identified and tracked by eavesdroppers. A promising design to address these requirements is the Security Credential Management System (SCMS), which is currently among the main candidates for protecting V2X communications in the United States. Even though SCMS provides efficient, scalable and privacy-preserving mechanisms for managing V2X-oriented certificates, in this article we show that its certificate revocation process can be further enhanced. Namely, we present two birthday attacks against SCMS's revocation process, both of which degrade the system's security as time passes and more certificates are revoked. We then describe an alternative design to prevent such security degradation with minimal computational overhead. In complement to these security gains, we also describe a mechanism for improving the flexibility of the revocation procedure, allowing certificates (as well as their owner's privacy) to be temporarily revoked in an efficient manner. This should be useful, for example, to implement suspension mechanisms or to aid in investigations by law-enforcement authorities.
Expand
Yongjun Zhao, Sherman S. M. Chow
ePrint Report ePrint Report
Private set-intersection (PSI) allows a client to only learn the intersection between his/her set $C$ and the set $S$ of another party, while this latter party learns nothing. We aim to enhance PSI in different dimensions, motivated by the use cases of increasingly popular online matchmaking --- Meeting "the one" who possesses all desired qualities and free from any undesirable attributes may be a bit idealistic. Meanwhile, the criteria should be expressed in a succinct form. In this paper, we realize $\mathit{over-}$ (resp. $\mathit{below-}$) threshold PSI, such that the client learns the intersection (or other auxiliary private data) only when $|C \cap S| > t$ (resp. $\leq t$). The threshold corresponds to tunable criteria for (mis-)matching, without marking all possible attributes as desired or not. To the best of our knowledge, our constructions are the very first solution for these two open problems posed by Bradley et al. (SCN '16) and Zhao and Chow (PoPETS '17), without resorting to the asymptotically less efficient generic approach from garbled circuits.

Moreover, we consider an ``outsourced'' setting with a service provider coordinating the PSI execution, instead of having two strangers to be online simultaneously for executing a highly-interactive PSI directly with each other. Outsourcing our two protocols are arguably optimal, namely, the two users perform $O(|C|)$ and $O(1)$ decryptions, for unlocking the private set $C$ and the outcome whether a match has been found.
Expand
Technical University of Denmark (DTU), Denmark
Job Posting Job Posting
With this call Technical University of Denmark (DTU) invites highly talented experienced researchers who have achieved outstanding results in their research while demonstrating excellence and potential in their field to apply for one of the fellowships under the H.C. Ørsted Postdoc programme, co-funded by Marie Sklodowska-Curie Actions.

The programme is named after Hans Christian Ørsted, discoverer of electro-magnetism and founder of the University and achieves the goals of Marie Sklodowska-Curie COFUND by increasing the European-wide mobility possibilities for training and career development of experienced researchers. The Programme will contribute to the researcher’s career development, broadening and deepening individual competencies through exposure to an international and multidisciplinary environment. The Programme is based on incoming mobility and will enable experienced researchers from all over the world to carry out curiosity-driven, bottom-up research projects within all branches of engineering science at DTU.

To enable the unique identification of each application, applicants must assign their application with an acronym.

DTU fully acknowledges the importance of equal opportunities and welcomes applications from all interested candidates irrespective of age, gender, disability, religion or ethnicity.

To further promote equal opportunities, DTU will implement gender blinded reviews. Applicants should refrain from using their names and gender specific pronouns in the research plan (he/she, his/hers etc.). Names and nationality listed in the templates for the research plan and CV will be hidden by the secretariat prior to the external peer review.

Closing date for applications: 23 February 2018

Contact: Dr. Christian D. Jensen (cdje (at) dtu.dk), or Dr. Weizhi Meng

More information: http://www.dtu.dk/english/Research/Research-at-DTU/Postdoc-programmes/H-C-Oersted-COFUND-Postdoc

Expand
Technische Universität Darmstadt, Germany
Job Posting Job Posting
The Engineering Cryptographic Protocols (ENCRYPTO) Group at TU Darmstadt is looking for a research assistant (doctoral researcher / PhD student) in Scalable Cryptographic Protocols.

The ENCRYPTO group is member of the Center for Research in Security and Privacy (CRISP) and the profile area Cybersecurity at TU Darmstadt (CYSEC). We develop methods and tools to optimize and automatically generate cryptographic protocols. See http://encrypto.de for details.

The candidate will do cutting-edge research on cryptographic protocols that scale to real-world problem sizes, including secure multi-party computation and private information retrieval.

The candidate is expected to have a completed Master (or equivalent) degree with excellent grades in IT security, computer science, electrical engineering, mathematics, or a closely related field. Solid knowledge in IT security, applied cryptography, efficient algorithms, circuit design, and excellent programming skills are required. Additional knowledge in cryptographic protocols, parallel computing, compiler construction, programming languages, and software engineering is a plus.

Review of applications starts immediately until the position is filled.

More details and info on how to apply: http://encrypto.de/jobs/CRISP2018

Closing date for applications:

Contact: Thomas Schneider, thomas.schneider (at) crisp-da.de

More information: http://encrypto.de/jobs/CRISP2018

Expand
University of Surrey, Guildford, UK
Job Posting Job Posting
Surrey Centre for Cyber Security (SCCS) is the heart of the cyber security activities across the University of Surrey.It is one of the 14 Academic Centres of Excellence in Cyber Security Research (ACEs-CSR) recognised by the UK Government Communications Headquarters (GCHQ) in partnership with the Engineering and Physical Sciences Research Council (EPSRC).

The student will be based in the Department of Computer Science at the University of Surrey, UK. The PhD project aims at exploring post-quantum cryptography into blockchain technology. The candidate may need to do research on the following areas (but not limited to): blockchain (cryptocurrencies, smart-contracts), distributed consensus protocols, and post-quantum cryptography (signature, encryption). We expect the candidate to undertake not only theoretical-centre research but also some level of implementation.

The candidate should be passionate about applied research and development of cutting-edge security technologies. With a strong desire to work on problems with real-world impact and commercial value, the candidate is expected to conduct high-quality applied research by working closely with a team of security domain experts. (Highly motivated, independent and resourceful team player, strong analytical thinking, interpersonal and problem solving skills)

Entry Requirements

Essential:

1. Bachelor degree in Computer Science, Computer Engineering, Mathematics, Electrical Engineering, or related field (UK equivalent of 2:1 classification or above)

2. Interest in cryptography and information security

3. Adequate programming skills in Java, C/C++, Python

4. Fluent written and verbal communication skills in English

Desirable:

1. Master degree in Computer Science, Computer Engineering, Mathematics, Electrical Engineering, or related field (UK equivalent of Merit classification or above)

2. Knowledge of post-quantum cryptography and block-chain

3. Strong programming skills in Java, C/C++, Python

Closing date for applications: 31 March 2018

Contact: Dr. Kaitai Liang, email: k.liang (at) surrey.ac.uk

More information: http://www.jobs.ac.uk/job/BHD180/phd-opportunity-in-exploring-post-quantum-cryptography-into-block-chain-technology/

Expand
Karlstad University, Sweden
Job Posting Job Posting
Karlstad University, Sweden, has an opening for a full-time PhD position in Computer Science in the fields of computer security, privacy, and computer networking on secure and privacy-preserving networked systems.

The PhD student will work on secure and privacy-preserving networked systems within the research profile High Quality Networked Services in a Mobile World (HITS), funded by the Knowledge Foundation of Sweden, and a recently accepted EU H2020 innovation action. Duties include applied cryptography, reasoning about security and privacy properties of cryptographic systems, and to construct provably secure systems. Experience with secure logging, Certificate Transparency, or blockchain-related systems are of particular relevance. Further, the PhD student is expected to contribute to research across research areas at the Computer Science subject to analyse and engineer networked systems. The networked systems relate to technologies such as software defined networking, programmable data planes, and network middleboxes that analyse network traffic.

The duties will be performed within both national and international research projects with collaborating academic and industry partners. A successful candidate needs to have excellent written and spoken English, a solid background in the previously mentioned technologies and research areas, good programming experience, be strongly motivated to deconstruct highly complex networked systems, and the ability to develop into an independent researcher.

A PhD student in Sweden is employed, pays no fees related to the PhD position, and has a decent monthly salary. The position is limited to four years. If the PhD student takes other research, teaching or administrative tasks besides her/his PhD research, it can be prolonged for up to one more year. Democratic principles, equality and diversity are cornerstones of the University. We value the enriching presence of diverse backgrounds and competencies among students and staff.

Closing date for applications: 11 March 2018

Contact: Tobias Pulls, senior lecturer +46 (0) 54-700 24 75, tobias.pulls (at) kau.se

More information: https://kau.varbi.com/en/what:job/jobID:193337/

Expand

17 February 2018

Panaji, Goa, India, 11 November - 14 November 2018
TCC TCC
Event date: 11 November to 14 November 2018
Submission deadline: 17 May 2018
Notification: 30 August 2018
Expand
Barcelona, Spain, 3 September - 7 September 2018
Event Calendar Event Calendar
Event date: 3 September to 7 September 2018
Submission deadline: 18 April 2018
Notification: 5 June 2018
Expand
◄ Previous Next ►