IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
19 September 2013
Sylvain Duquesne, Nadia El Mrabet, Emmanuel Fouotsa
Ate pairing and its variations on the special Jacobi quartic elliptic curve
Y^2 = dX^4 +Z^4. We improve the doubling and addition steps in Miller\'s
algorithm to compute the Tate pairing. We use the birational equivalence
between Jacobi quartic curves and Weierstrass curves, together with a
specific point representation to obtain the best result to date among
curves with quartic twists. For the doubling and addition steps in Miller\'s
algorithm for the computation of the Tate pairing, we obtain a theoretical
gain up to 27% and 39%, depending on the embedding degree and the
extension field arithmetic, with respect to Weierstrass curves [2] and
previous results on Jacobi quartic curves [3]. Furthermore and for the
first time, we compute and implement Ate, twisted Ate and optimal
pairings on the Jacobi quartic curves. Our results are up to 27% more
ecient, comparatively to the case of Weierstrass curves with quartic
twists [2].
Daehyun Strobel, Benedikt Driessen, Timo Kasper, Gregor Leander, Da
3060 G2 that relies on an undisclosed, proprietary protocol to mutually authenticate transponders and locks. For assessing the security of the system, several tasks have to be performed: By decapsulating the used microcontrollers with acid and circumventing their read-out protection with UV-C light, the complete program code and data contained in door lock and transponder are extracted. As a second major step, the multi-pass challenge-response protocol and corresponding cryptographic primitives are recovered via low-level reverse-engineering. The primitives turn out to be based on DES in combination with a proprietary construction.
Our analysis pinpoints various security vulnerabilities that enable practical key-recovery attacks. We present two different approaches for unauthorizedly gaining access to installations. Firstly, an attacker having physical access to a door lock can extract a master key, allowing to mimic transponders, in altogether 30 minutes. A second, purely logical attack exploits an implementation flaw in the protocol and works solely via the wireless interface. As the only prerequisite, a valid ID of a transponder needs to be known (or guessed). After executing a few (partial) protocol runs in the vicinity of a door lock, and some seconds of computation, an adversary obtains all of the transponder\'s access rights.
Daniel J. Bernstein, Yun-An Chang, Chen-Mou Cheng, Li-Ping Chou, Nadia Heninger, Tanja Lange, Nicko van Som
These 184 keys include 103 keys that share primes and that are efficiently factored by a batch-GCD computation. This is the same type of computation that was used last year by two independent teams (USENIX Security 2012: Heninger, Durumeric, Wustrow, Halderman; Crypto 2012: Lenstra, Hughes, Augier, Bos, Kleinjung, Wachter) to factor tens of thousands of cryptographic keys on the Internet.
The remaining 81 keys do not share primes. Factoring these 81 keys requires taking deeper advantage of randomness-generation failures: first using the shared primes as a springboard to characterize the failures, and then using Coppersmith-type partial-key-recovery attacks. This is the first successful public application of Coppersmith-type attacks to keys found in the wild.
Florian Mendel, Thomas Peyrin, Martin Schläffer, Lei Wang, Shuang Wu
Sanjam Garg, Craig Gentry, Shai Halevi, Mariana Raykova
The technical tools that we develop in this work also imply virtual black box obfuscation of a new primitive that we call a \\emph{dynamic point function}. This primitive may be of independent interest.
Martin R. Albrecht, Robert Fitzpatrick, Florian G ̈opfert
18 September 2013
Florida State University, Tallahassee, Florida, Southern USA
FSU is classified as a Carnegie Research I university. Its primary role is to serve as a center for advanced graduate and professional studies while emphasizing research and providing excellence in undergraduate education.
Screening will begin January 1, 2014 and will continue until the position is filled. Please apply online with curriculum vitae, statements of teaching and research philosophy, and the names of five references, at
http://www.cs.fsu.edu/positions/apply.html
Questions can be e-mailed to Prof. Mike Burmester, Faculty Search Committee Chair, recruitment (at) cs.fsu.edu or to Prof. Robert van Engelen, Department Chair, chair (at) cs.fsu.edu.
The Florida State University is a Public Records Agency and an Equal Opportunity/Access/Affirmative Action employer, committed to diversity in hiring.
University of Haifa, Israel
University of Warsaw, Poland, European Union
Job profile: All candidates with background in theoretical computer science and mathematics are encouraged to apply and will be carefully considered. Knowledge of Polish is not required, but a good knowledge of English is essential.
Successful candidates can start from 10.2013. Funding is available until 5.2015 (extensions are possible depending on the funding availability)
University of Warsaw, Poland, European Union
All candidates with background in theoretical computer science and mathematics are encouraged to apply and will be carefully considered. Knowledge of Polish is not required, but a good knowledge of English is essential.
Successful candidates can start from 10.2013. Funding is available until 5.2015 (extensions are possible depending on the funding availability)
Stipend: 3000 PLN / month
University of Warsaw, Poland, European Union
All candidates with PhD in cryptography are encouraged to apply and will be carefully considered. Knowledge of Polish is not required, but a good knowledge of English is essential.
Successful candidates can start from 10.2013. Funding is available until 5.2015 (extensions are possible depending on the funding availability)
Wollongong, Australia, July 7 - July 9
Notification: 13 April 2014
From July 7 to July 9
Location: Wollongong, Australia
More Information: https://ssl.informatics.uow.edu.au/acisp2014/
14 September 2013
Vladimir Antipkin
standard for one and a half decade. Cryptographic strength of MASH-1 hash function is based on
factorization problem of an RSA modulus along with redundancy in the input blocks of compression
functions. Despite of this, we are able to introduce two large classes of moduli which allow
practical time collision finding algorithm for MASH-1. In one case even multicollisions of
arbitrary length can be constructed.
Andrea Forte, Juan Garay, Trevor Jim, Yevgeniy Vahlis
The user views data on a closely-held personal device, such as a pair of smart glasses with a camera and heads-up display, or a smartphone. The decrypted data is displayed as an image overlay on the personal device--a form of augmented reality. The user\'s inputs are protected through randomization.
EyeDecrypt consists of three main components: a visualizable encryption scheme; a dataglyph-based visual encoding scheme for the ciphertexts generated by the encryption scheme; and a randomized input and augmented reality scheme that protects user inputs without harming usability. We describe all aspects of EyeDecrypt, from security definitions, constructions and formal analysis, to implementation details of a prototype developed on a smartphone.
Jung Woo Kim, Jin Hong, Kunsoo Park
Liam Keliher, Anthony Z. Delaney
Carmit Hazay, Arpita Patra
A primary building block in designing adaptively secure protocols is a non-committing encryption or NCE that implements secure communication channels in the presence of adaptive corruptions. Current NCE constructions require a number of public key operations that grows linearly with the length of the message. Furthermore, general two-party protocols require a number of NCE calls that is linear in the circuit size (or otherwise the protocol is not round efficient). As a result the number of public key operations is inflated and depends on the circuit size as well.
In this paper we study the two-party setting in which at most one of the parties is adaptively corrupted, which we believe is the right security notion in the two-party setting. We study the feasibility of (1) NCE with constant number of public key operations for any message space. (2) Oblivious transfer with constant number of public key operations for any sender\'s input space, and (3) constant round secure computation protocols with a number of NCE calls, and an overall number of public key operations, that are independent of the circuit size. Our study demonstrates that such primitives indeed exist in the presence of single corruptions, while this is not the case for fully adaptive security (where both parties may get corrupted).
Yuan Tian, Rongxin Sun, Xueyong Zhu
Mark D. Ryan
Michael Shantz, Edlyn Teske