IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
30 August 2013
Christian Hanser, Daniel Slamanig
Myungsun Kim, Abedelaziz Mohaisen, Jung Hee Cheon, Yongdae Kim
We analyze the computational and communication complexities of our construction, and show that it is much more efficient than the existing protocols in the literature.
Finally, we show that our basic protocol is efficiently transformed into a stronger protocol secure in the presence of malicious adversaries, together with performance and security analysis.
Ivica Nikolic, Lei Wang, Shuang Wu
cryptographic primitive in parallel to the execution of the operations. The result of the division are two primitives that have smaller input sizes and thus require lower attack complexities.
However, the division is not completely independent and the sub-primitives depend (output of one is the input for the other) mutually on a certain number of bits. When the number of such bits is relatively small, we show a technique based on three classical meet-in-the-middle attacks that can recover the secret key of the cipher faster than an exhaustive search. We apply our findings to the lightweight block cipher KLEIN and show attacks on 10/11/13 rounds of KLEIN-64/-80/-96.
Our approach requires only one or two pairs of known plaintexts and always recovers the secret key.
Nethanel Gelernter, Amir Herzberg
anonymity - strongest-possible anonymity requirements and
adversaries. We begin with rigorous definition of anonymity
against wide range of computationally-bounded attackers,
including eavesdroppers, malicious peers, malicious destina-tions, and their combinations. Following the work of Hevia and Micciancio [15], our definition is generic, and captures dierent notions of anonymity (e.g., unobservability and sender anonymity).
We then study the feasibility of ultimate anonymity. We
show there is a protocol satisfying this requirement, but with
absurd (although polynomial) inefficiency and overhead. We
show that such inefficiency and overhead is unavoidable for
`ultimate anonymity\'. We then present a slightly-relaxed
requirement and present feasible protocols for it.
Takakazu Satoh
bilinear pairing on the Jacobian variety of a hyperelliptic curve.
We prove that, for supersingular elliptic curves with embedding degree
two, square of the Ate pairing is nothing but the Weil pairing.
Using the formula, we develop an X-coordinate only pairing inversion method.
However, the algorithm is still infeasible for cryptographic size problems.
Nethanel Gelernter, Amir Herzberg
gossipers, we want to schedule a cyclic calendar
of meetings between all of them, such that: (1) each gossiper communicates
(gossips) only once a day, with one other gossiper, (2) in every (n 1) consecutive
days, each gossiper meets all other gossipers, and (3) every gossip, initiated by
any gossiper, will reach all gossipers within k = log(n) days.
In this paper we study the above stated meet-all gossipers problem, by den-ing and constructing the Gossip Latin Square (GLS), a combinatorial structure
which solves the problem.
Nethanel Gelernter, Amir Herzberg
unobservable, anonymous reporting to an untrusted destination,
with low latency and overhead. DURP provably ensures strong
anonymity properties, as required for some applications (and not
provided by existing systems and practical designs, e.g., Tor),
specifically:
Provable unobservability against global eavesdropper and
malicious participants.
Provable source anonymity against a malicious destination.
Probable-innocence against a malicious destination which is
also a global eavesdropper.
DURP design is a modular combination of two modules: a
queuing module, ensuring fixed rates for certain events, together
with an anonymization module, which can use either Onion-Routing (DURP^OR) or Crowds (DURP^Crowds). We present anal-ysis, backed by simulation results, of the network properties and
performance of DURP, and show it has reasonable overhead. We
also use the analysis results to create an optimized version of
DURP.
Sujoy Sinha Roy, Junfeng Fan, Ingrid Verbauwhede
We present detailed experimental results to support our claims made in this paper.
Feng Zhang, Yanbin Pan, Gengran Hu
Amir Herzberg, Shay Nachmani
bounded by the credit allocated to this partner. The protocol supports expiration times for payment orders, and realistic network queuing delay.We achieve this using model and techniques from the Quality of Service area to guarantee delays and avoid payment order expiration. We present rigorous security proof.
Arnis Parsovs
Riham AlTawy, Aleksandar Kircanski, Amr M. Youssef
Jérémy Jean, María Naya-Plasencia, Thomas Peyrin
Sareh Emami, San Ling, Ivica Nikolic, Josef Pieprzyk, Huaxiong Wang
To overcome the exponential (in the state and key sizes) computational complexity we use truncated differences, however as the key schedule is not nibble oriented, we switch to actual differences and apply early abort techniques to prune the tree-based search.
With a new method called extended split approach we are able to make the whole search feasible and we implement and run it in real time.
Our approach targets the PRESENT-80 cipher however, with small modifications can be reused for other lightweight ciphers as well.
Cécile Delerablée, Tancrède Lepoint, Pascal Paillier, Matthieu Rivain
{white-box} cryptography really aims to achieve and which security properties are expected from white-box programs in applications. This paper builds a first step towards a practical answer to this question by translating folklore intuitions behind white-box cryptography into concrete security notions. Specifically, we introduce the notion of white-box compiler that turns a symmetric encryption scheme into randomized white-box programs, and we capture several desired security properties such as one-wayness, incompressibility and traceability for white-box programs. We also give concrete examples of white-box compilers that already achieve some of these notions. Overall, our results open new perspectives on the design of white-box programs that securely implement symmetric encryption.
Teng Guo, Feng Liu, ChuanKun Wu, ChingNung Yang, Wen Wang, YaWei Ren
that any k shadow images can be used to reconstruct the secret image
exactly. In 2002, for (k; n)-TSISS, Thien and Lin reduced the size of each
shadow image to 1/k of the original secret image. Their main technique
is by adopting all coefficients of a (k-1)-degree polynomial to embed the secret pixels. This benet of small shadow size has drawn many researcher\'s attention and their technique has been extensively used in
the following studies. In this paper, we rst show that this technique
is neither information theoretic secure nor computational secure. Furthermore, we point out the security defect of previous (k; n)-TSISSs for
sharing textual images, and then fix up this security defect by adding an
AES encryption process. At last, we prove that this new (k; n)-TSISS is
computational secure.
Christian Forler, Stefan Lucks, Jakob Wenzel
some keys does not help to break others).
Farzaneh Abed, Eik List, Stefan Lucks, Jakob Wenzel
Boris Skoric, Niels de Vreede
One of the oldest known helper data schemes is the Code Offset Method (COM).
We propose an extension of the COM: the helper data is accompanied by many instances of fake helper data that is drawn from the same distribution as the real one.
While the adversary has no way to distinguish between them, the legitimate party has more information and *can* see the difference.
We use an LDPC code in order to improve the efficiency of the legitimate party\'s selection procedure.
Our construction provides a new kind of trade-off: more effective use of the source entropy, at the price of increased helper data storage.
We give a security analysis in terms of Shannon entropy and order-2 Renyi entropy.
Somindu C. Ramanna, Palash Sarkar
Type-3 pairings with adaptive security based on standard assumptions. Previous constructions
of anonymous HIBE schemes did not simultaneously achieve all these features.
The new construction uses dual pairing vector spaces using an identity hash earlier used by Boneh, Boyen and Goh.
The proof of security follows dual system approach based on decisional subspace assumptions
which are implied by Symmetric eXternal Diffie-Hellman (SXDH) assumption in Type-3 pairing groups.