IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
13 July 2013
Eric Brier, David Naccache, Li-yao Xia
We conjecture that arbitrary $N$-party commutative tasks cannot be performed in $N-1$ time units by exchanging less than $4N-6$ messages and provide computational evidence in favor this conjecture. We also explore the most equitable commutative task protocols.
Alexandra Boldyreva, Jean Paul Degabriele, Kenneth G. Paterson, Martijn Stam
Susan Hohenberger, Amit Sahai, Brent Waters
We build on this result to offer the first *identity-based* aggregate signature scheme that admits unrestricted aggregation. In our construction, an arbitrary-sized set of signatures on identity/message pairs can be aggregated into a single group element, which authenticates the entire set. The identity-based setting has important advantages over regular aggregate signatures in that it eliminates the considerable burden of having to store, retrieve or verify a set of verification keys, and minimizes the total cryptographic overhead that must be attached to a set of signer/message pairs. While identity-based signatures are trivial to achieve, their aggregate counterparts are not. To the best of our knowledge, no prior candidate for realizing unrestricted identity-based aggregate signatures exists in either the standard or random oracle models.
A key technical idea underlying these results is the realization of a hash function with a Naor-Reingold-type structure that is publicly computable using repeated application of the multilinear map. We present our results in a generic ``leveled\'\' multilinear map setting and then show how they can be translated to the GGH graded algebras analogue of multilinear maps.
Marc Joye, Benoit Libert
09 July 2013
Orr Dunkelman, Nathan Keller
an ISO standard and an RFC. Moreover, MISTY1 was selected to be the blueprint on top of which KASUMI, the GSM/3G block cipher, was based. Since its introduction, and especially in recent years, MISTY1 was subjected to extensive cryptanalytic efforts, which resulted in numerous attacks on its reduced variants. Most of these attacks aimed at maximizing the number of attacked rounds, and as a result, their complexities are highly impractical.
In this paper we pursue another direction, by focusing on attacks with a practical time complexity. The best previously-known attacks with practical complexity against MISTY1 could break either 4 rounds (out of 8), or 5 rounds in a modified variant in which some of the FL functions are removed. We present an attack on 5-round MISTY1 with all the FL functions present whose time complexity is 2^38 encryptions. When the FL functions are removed, we present a devastating (and experimentally verified) related-key attack on the full 8-round variant, requiring only 2^18 data and time.
While our attacks clearly do not compromise the security of the full
MISTY1, they expose several weaknesses in MISTY1\'s components, and
improve our understanding of its security. Moreover, future designs which rely on MISTY1 as their base, should take these issues into close consideration.
Deutsche Telekom Chair, Goethe University Frankfurt, Germany, EEA
We are looking for people with advanced knowledge and special skills in at least three of the following areas:
- Network and System Security
- Privacy-Enhancing Technologies and data protection
- Identity Management
- Mobile Platforms, Smartcards and Trusted Computing
- Mobile Application Development (e.g. in Android, etc.)
- Cryptography
- Programming languages and experiences in software projects
- Administration skills in different platforms (e.g. UNIX, Linux, Windows)
- Web technologies and development
- Project management
The position is available immediately and has a fixed-term of 3 years with an extension option.
Deadline for applications: 2013-07-31
Contact for applications: Prof. Dr. Kai Rannenberg, bewerbungen(at)m-chair(dot)net
Documents recommended to be submitted: personal statement of purpose, current resume, official references, list of publications, official test scores
More Information: http://www.m-chair.net/wps/wse/home/rannenberg/career/
Atlanta, United States, October 14
Notification: 23 August 2013
From October 14 to October 14
Location: Atlanta, United States
More Information: http://www.vizsec.org/
Dubai, United Arab Emirates, October 23 - October 25
Notification: 15 September 2013
From October 23 to October 25
Location: Dubai, United Arab Emirates
More Information: http://sdiwc.net/conferences/2013/dipecc2013/
07 July 2013
Université Paris II Panthéon-Assas, PRES Sorbonne Universités, France, European Union
The candidates will work on the following topics:
Thesis 1 - Faut and side-channel attacks.
Thesis 2 - Formal proofs of hardware and software implementations.
Thesis 3 - Lightweight cryptography (theory and practice).
Thesis 4 - Embedded equipment securit.
Due to employment visa constraints, the candidates must be of EU citizenship or Swiss.
The candidate will be based in the Paris area with access to very advanced laboratory equipment.
05 July 2013
Jooyoung Lee
University of Twente, The Netherlands
We search for a candidate with a strong background in practical system level security. The candidate is expected to support supervision of PhD students, contribute to our on-going projects, and also contribute to future project proposals to strengthen our research profile. Our group is member of multiple national and European research projects with strong links to industry. One example is the currently ongoing CRISALIS FP7 project (http://www.crisalisproject.eu/).
Successful candidates must hold a PhD degree in computer science or a closely related discipline and have demonstrated their excellence by top-class publications.
Please submit your application via the link provided below including:
- motivation letter specifically addressing our position,
- full curriculum vitae including a list of all courses and marks,
- publication list incl. a one-page summary of your PhD thesis,
- two recommendation letters (or alternatively the names and email addresses of two references).
The position will be closed as soon as a suitable candidate is found.
03 July 2013
Redmond, USA, February 20 - February 21
From February 20 to February 21
Location: Redmond, USA
More Information: http://research.microsoft.com/en-us/events/mpcworkshop/
Topic: A Coding-Theoretic Approach to Cryptanalysis
Category: foundations
Description: In this thesis we study the applicability of coding-theoretic algorithms to cryptanalysis and provide new insights into the practical security of different cryptographic primitives. We introduce a new generalised framework for the class of \"Information Set Decoding\" (ISD) algorithms. By applying the so-called representation technique, we design a new ISD algorithm which asymptotically achieves an exponential improvement over all known methods. Within the generalised ISD framework we provide a rigorous formal proof of superiority of the new algorithm for arbitrary code rates 0[...]
Jiangtao Han, Haining Fan
Roberto Avanzi, Billy Bob Brumley
Mihir Bellare, Sriram Keelveedhi, Thomas Ristenpart
02 July 2013
Rikke Bendlin, Sara Krehbiel, Chris Peikert
operations in lattice cryptography, namely, generating a hard lattice
$\\Lambda$ together with a ``strong\'\' trapdoor, and sampling from a
discrete Gaussian distribution over a desired coset of $\\Lambda$ using
the trapdoor. These are the central operations of many cryptographic
schemes: for example, they are exactly the key-generation and signing
operations (respectively) for the GPV signature scheme, and they are
the public parameter generation and private key extraction operations
(respectively) for the GPV IBE. We also provide a protocol for
trapdoor delegation, which is used in lattice-based hierarchical IBE
schemes. Our work therefore directly transfers all these systems to
the threshold setting.
Our protocols provide information-theoretic (i.e., statistical)
security against adaptive corruptions in the UC framework, and they
are private and robust against an
optimal number of semi-honest or malicious parties. Our Gaussian
sampling protocol is both noninteractive and efficient, assuming
either a trusted setup phase (e.g., performed as part of key
generation) or a sufficient amount of interactive but offline
precomputation, which can be performed before the inputs to the
sampling phase are known.
B. Skoric, J.-J. Oosterwijk, J. Doumen
We introduce a new score function for non-binary bias-based traitor tracing. It has three special properties that have long been sought after:
(i) The expected score of an innocent user is zero in each content position.
(ii) The variance of an innocent user\'s score is~1 in each content position.
(iii) The expectation of the coalition\'s score does not depend on the
collusion strategy.
We also find a continuous bias distribution that optimizes the asymptotic (large coalition) performance.
In the case of a binary alphabet our scheme reduces exactly to the
symmetrized Tardos traitor tracing system.
Unfortunately, the asymptotic fingerprinting rate
of our new scheme decreases with growing alphabet size.
We regret to inform you that this grail has holes.
Valentina Banciu, Simon Hoerder, Dan Page
Dan Boneh, Craig Gentry, Shai Halevi, Frank Wang, David J. Wu
additively homomorphic system as well as Brakerski\'s somewhat homomorphic cryptosystem. Finally, we show that the additional homomorphic properties of the Brakerski cryptosystem allow us to handle queries involving several thousand elements over a million-record database in just a few minutes, far outperforming the implementation using the additively homomorphic system.