International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

16 December 2013

SANJIT CHATTERJEE AND M. PREM LAXMAN DAS
ePrint Report ePrint Report
At Eurocrypt\'12, Pandey and Rouselakis~\\cite{PR12} proposed the notion of property preserving symmetric encryption ({\\PPE}).

They defined several security notions for {\\PPE} and studied their relationship. They also proposed a concrete scheme which preserves

the orthogonality of encrypted vectors. The proposed construction is claimed to achieve the strongest security notion

of property preserving encryption, called {\\LoR} security. In this work, we take a critical look at the three security theorems in the context of {\\PPE} from~\\cite{PR12}. In particular, we show

that the Pandey-Rouselakis construction does not even satisfy the weakest notion of security for {\\PPE}. We also note that

their separation results between different notions of security for {\\PPE} stand vacuous in the absence of any concrete example. We fill up this gap in the separation results of~\\cite{PR12} by suggesting an example construction of

{\\PPE}.

Expand
Vikram Singh
ePrint Report ePrint Report
This paper analyses provable security proofs, using the EDL signature scheme as its case study, and interprets their benefits and drawbacks when applied to the real world.

Provable security has been an area of contention. Some, such as Koblitz and Menezes, give little credit to the potential extra security provided and argue that it is a distracting goal. However, others believe that an algorithm with a security proof is superior to one without it, and are prepared to accept the impact to performance that their use might involve. Goldreich has been notable for his defence of the security proof, and for his opposition to the view of Koblitz and Menezes.

This paper is designed to help the reader make their own decisions on security proofs. We achieve this by giving an introduction to the typical security model used, then give a description of the EDL signature scheme and its tight reduction to the CDH problem in the Random Oracle Model, then analyse the proof\'s assumptions, meaning, validity and overhead for real world security.

Expand
Emil Stefanov, Charalampos Papamanthou, Elaine Shi
ePrint Report ePrint Report
Dynamic Searchable Symmetric Encryption (DSSE) enables a client to encrypt his document collection in a way that it is still searchable and efficiently updatable. However, all DSSE constructions that have been presented in the literature so far come with several problems: Either they leak a significant amount of information (e.g., hashes of the keywords contained in the updated document) or are inefficient in terms of space or search/update time (e.g., linear in the number of documents).

In this paper we revisit the DSSE problem. We propose the first DSSE scheme that achieves the best of both worlds, i.e., both small leakage and efficiency. In particular, our DSSE scheme leaks significantly less information than any other previous DSSE construction and supports both updates and searches in sublinear time in the worst case, maintaining at the same time a data structure of only linear size. We finally provide an implementation of our construction, showing its practical efficiency.

Expand
Fabrice Benhamouda, David Pointcheval
ePrint Report ePrint Report
While password-authenticated key exchange (or PAKE) protocols have

been deeply studied, a server corruption remains the main threat, with

many concrete cases nowadays. Verifier-based PAKE (or VPAKE)

protocols, initially called Augmented-PAKE, have been proposed to

limit the impact of any leakage. However, no satisfactory security

model has ever been proposed to quantify the actual security of a

protocol in the standard model. The unique model proposed so far is an

ideal functionality in the universal composability (UC) framework, but

is only meaningful in idealized models.

In this paper, we first enhance the Bellare-Pointcheval-Rogaway

game-based model for PAKE to VPAKE protocols, and then propose the

first game-based security model for both PAKE and VPAKE protocols that

additionally handles related passwords. It also allows a VPAKE

protocol to be secure in the standard model. We then propose several

VPAKE candidates which involve smooth projective hash functions and

multi-linear maps.

Expand
Ahto Buldas, Andres Kroonmaa, Risto Laanoja
ePrint Report ePrint Report
Keyless Signatures Infrastructure (KSI) is a globally distributed system for providing time-stamping and server-supported digital signature services. Global per-second hash trees are created and their root hash values published.

We discuss some service quality issues that arise in practical implementation of the service and present solutions for avoiding single points of failure and guaranteeing a service with reasonable and stable delay. Guardtime AS has been operating a KSI Infrastructure for 5 years. We summarize how the KSI Infrastructure is built, and the lessons learned during the operational period of the service.

Expand
Thomas Shrimpton, R. Seth Terashima
ePrint Report ePrint Report
We present the Protected-IV construction (PIV) a simple, modular method for building variable-input-length tweakable ciphers. At our level of abstraction, many interesting design opportunities surface. For example, an obvious pathway to building beyond birthday-bound secure tweakable ciphers with performance competitive with existing birthday-bound-limited constructions. As part of our design space exploration, we give two fully instantiated PIV constructions, TCT1 and TCT2; the latter is fast and has beyond birthday-bound security, the former is faster and has birthday-bound security. Finally, we consider a generic method for turning a VIL tweakable cipher (like PIV) into an authenticated encryption scheme that admits associated data, can withstand nonce-misuse, and allows for multiple decryption error messages. Thus, the method offers robustness even in the face of certain sidechannels, and common implementation mistakes.

Expand
Max Planck Institute for Software Systems, Saarbrücken, Germany
Job Posting Job Posting
The security and privacy group (S&P) group at the Max Planck Institute for Software Systems is currently offering postdoc positions under the supervision of Michael Backes. The S&P group collaborates closely with the Center for IT-Security, Privacy and Accountability (CISPA) at Saarland University.

Please refer to the link below for a full description of the open positions.

Expand
Chalmers University of Technology, Sweden
Job Posting Job Posting
We are looking for an excellent PhD candidate to work in the area of information and communication security with a focus on authentication problems in constrained settings. This is particularly important for applications involving mobile phones, wireless communication and RFID systems, which suffer from restrictions in terms of power resources, network connectivity, computational capabilities, as well as potential privacy issues. The overall aim of the project will be to develop nearly optimal algorithms for achieving security and privacy while minimising resource use.

More concretely, part of the research will involve the analysis and development of authentication protocols in specific settings. This will include investigating resistance of both existing and novel protocols against different types of attacks, theoretically and experimentally. In addition to investigating established settings, such as RFID authentication, the research will also explore more general authentication problems, such as those that arise in the context of trust in social networks, smartphone applications and collaborative data processing. This will be done by grounding the work in a generalised decision-making framework. The project should result in the development of theory and authentication mechanisms for noisy, constrained settings that strike an optimal balance between reliable authentication, privacy-preservation and resource consumption. Some previous research related to this research project can be found here: http://lasecwww.epfl.ch/~katerina/Publications.html

Qualifications

Applicants for the position shall have a Master’s Degree or corresponding in Computer Science, Informatics, Telecommunications, Information Security and Cryptography or in a related discipline. A master\\\'s degree in information security and cryptography is a bonus.

Experience in one or more of cryptography, probability and statistics, decision and game theory are ben

Expand
June 1
Event Calendar Event Calendar
Submission: 31 December 2013
Notification: 1 February 2014
From June 1 to June 1
More Information: http://www.computer.org/portal/web/peerreviewmagazines/computer
Expand

11 December 2013

Ali El Kaafarani, Essam Ghadafi, Dalia Khader
ePrint Report ePrint Report
Attribute-based signatures allow a signer owning a set of attributes to anonymously sign a message w.r.t.\\ some signing policy. A recipient of the signature is convinced that a signer with a set of attributes satisfying the signing policy has indeed produced the signature without learning the identity of the signer or which set of attributes was used in the signing.

Traceable attribute-based signatures add anonymity revocation mechanisms to attribute-based signatures whereby a special tracing authority equipped with a secret key is capable of revealing the identity of the signer. Such a feature is important in settings where accountability and abuse prevention are required.

In this work, we first provide a formal security model for traceable attribute-based signatures. Our focus is on the more practical case where attribute management is distributed among different authorities rather than relying on a single central authority.

By specializing our model to the single attribute authority setting, we overcome some of the shortcomings of the existing model for the same setting.

Our second contribution is a generic construction for the primitive which achieves a strong notion of security. Namely, it achieves CCA anonymity and its security is w.r.t.\\ adaptive adversaries. Moreover, our framework permits expressive signing polices.

Finally, we provide some instantiations of the primitive whose security reduces to falsifiable intractability assumptions and without relying on idealized assumptions.

Expand
Institute for Security in Information Technology, Technische Universitaet Muenchen; Munich (Germany)
Job Posting Job Posting
We are part of the electrical engineering and information technology department at TUM. We develop new technologies, to counteract new threats in hardware security. Due to the increasing complexity of integrated and embedded systems, designing tools to support the hardware design of such secure devices is a challenging task and in our focus. Also research on PUFs and architectures for secure embedded systems is carried out at our Institute. To ensure security in the long term we research new attacks on secure elements.

To advance the Development of Tools for the Design of Secure Embedded Systems, we are searching for the closest possible point in time a

Research Assistant (m/f)

for a full time position.

Your Tasks:

  • Participation in industry-related research projects with focus on development and implementation of new approaches and tools to support designers in the design of secure embedded systems.
  • Tutor for labs and/or lectures

You:

  • finished your master’s degree in Electrical Engineering or Computer Sciences or equivalent with outstanding grades.
  • have strong focus on security.
  • are autonomous, can work in teams and are highly motivated.
  • like to work with students.
  • should have practical or theoretical previous knowledge on embedded systems and/or circuit design. You are also experienced in programming and have good mathematical skills.

We offer

a position as research assistant which includes the ability to carry out a PhD thesis. With your research, you contribute to one of our main fields.

The position as research assistant is initially offered for a limited time of 2.5 years. It is paid according to TV-L E13.

TUM aims at increasing the percentage of women. Therefore, qualified women

Expand

10 December 2013

Simon Fraser University, Burnaby, Canada, North America
Job Posting Job Posting
Department of Mathematics at Simon Fraser University invites applications for up to two tenure-track positions at the Assistant Professor level starting September 1, 2014.

For one of the positions we welcome applications from researchers working in algebra or geometry, especially in subareas that complement the expertise of our current faculty. Application areas of particular interest are cryptography, communication and computation.

Expand

09 December 2013

Boston University, Boston, MA, USA
Job Posting Job Posting

A university-funded post-doc position is available in the RISCS center and the BU Security Group (BUsec), in the Department of Computer Science at Boston University. The successful candidates will have an established research track record in one or more of the following areas: systems security, network security, applied cryptography, or cybersecurity technology policy or law. The position is funded for one year, with an option to extend to two years based on performance and availability of funds. Tentative start date is September 2014, but earlier start dates are also possible.

The BU Security Group does research in cryptography and security within the Department of Computer Science. The BU Center for Reliable Information Systems & Cyber Security (RISCS) takes a multidisciplinary approach to security by bring together experts across several discipline. Both the group and the Center also benefit from collaboration with the vibrant cryptography, security, and tech policy community in the Boston area.

Expand
October 1 - October 15
Event Calendar Event Calendar
Submission: 15 February 2014
Notification: 15 May 2014
From October 1 to October 15
More Information: http://iot-journal.weebly.com/uploads/1/8/8/0/18809834/ieee_iot_journal_si_iot_security_cfp.pdf
Expand
Philips Research, Eindhoven, the Netherlands
Job Posting Job Posting
Philips Research in Eindhoven NL) is searching for a Digital Security Expert. Please visit the Philips career website for the full vacancy description.

Your Responsibilities

Most of our products are becoming connected to the cyber space. We are looking for top scientists with a strong mathematical background for strengthening our competences in digital cryptography and security and who can help us to build and offer competitive trusted solutions and services in Healthcare, Lifestyle and Lighting.

Your challenges and responsibilities will be:

- Inventing and validating in industrial project teams new digital security technologies for use in Philips products and services, making use of the Internet of Things and Cloud Computing;

- Creating innovation impact with your results in terms of intellectual property creation or research transfers into the business;

- Keeping our digital security competence at world-class level;

- Contributing to our research roadmap by new ideas and winning new proposals;

- Working together with external partners.

Your Team

For more insights you can visit: http://www.research.philips.com/

We are looking for

The successful candidate has/is:

- A PhD in mathematics or computer science and a strong inclination to cryptography, preferably proven by relevant scientific results;

- Proven practical skills in computer simulation, system architecting and computer programming;

- Practical experiences in industry;

- A strong team playing attitude, expressed in taking the lead where appropriate, building on each other’s strengths and working in a cooperative way;

- A self-propelled enthusiast with a can-do mentality.Takes ownership for making it happen;

- Good communication skills and fluent in English.

Expand

06 December 2013

Yitao Duan
ePrint Report ePrint Report
Large-scale storage systems often attempt to achieve two seemingly conflicting goals: (1) the systems need to reduce the copies of redundant data to save space, a process called deduplication; and (2) users demand encryption of their data to ensure privacy. Conventional encryption makes deduplication on ciphertexts ineffective, as it destroys data redundancy. A line of work, originated from Convergent

Encryption [28], and evolved into Message Locked Encryption [12], strives to solve this problem. The latest work, DupLESS [11], proposes a server-aided architecture that provides the strongest privacy. The DupLESS architecture relies on a key server to help the clients generate encryption keys that result in convergent ciphertexts. In this paper, we first provide a rigorous proof of security, in the random oracle model, for the DupLESS architecture which is lacking in the original paper. Our proof shows that using additional secret, other than the data itself, for generating encryption keys achieves the best possible security under current deduplication paradigm.We then introduce a distributed protocol that eliminates the need for a key server and allows less managed systems such as P2P systems to enjoy the high security level. Implementation and evaluation show that the scheme is both robust and practical.

Expand
Michael Backes, Aniket Kate, Sebastian Meiser, Tim Ruffing
ePrint Report ePrint Report
Indistinguishability-based definitions of cryptographic primitives such as encryption, commitments, and zero-knowledge proofs are proven to be impossible to realize in scenarios where parties only have access to non-extractable sources of randomness (Dodis et al., FOCS 2004). In this work we demonstrate that it is, nevertheless, possible to quantify this secrecy loss for non-extractable sources such as the (well-studied) Santha-Vazirani (SV) sources. In particular, to establish meaningful security guarantees in scenarios where such imperfect randomness sources are used, we define and study differential indistinguishability, a generalization of indistinguishability inspired by the notion of differential privacy.

We analyze strengths and weaknesses of differential indistinguishability both individually as well as under composition, and we interpret the resulting differential security guarantees for encryption, commitments, and zero-knowledge proofs.

Surprisingly, indistinguishability with uniform randomness carries over to differential indistinguishability with SV randomness: We show that all primitives that are secure under a traditional indistinguishibility-based definition are differentially secure when they use (a bounded amount of) SV randomness instead of uniform randomness.

Expand
Sarah Ibrahimi, Boris Skoric, Jan-Jaap Oosterwijk
ePrint Report ePrint Report
We study the asymptotic-capacity-achieving score function that was recently proposed by Oosterwijk et al. for bias-based traitor tracing codes. For the bias function we choose the Dirichlet distribution with a cutoff. Using Bernstein\'s inequality and Bennett\'s inequality, we upper bound the false positive and false negative error probabilities. From these bounds we derive sufficient conditions for the scheme parameters. We solve these conditions in the limit of large coalition size $c_0$ and obtain asymptotic solutions for the cutoff, the sufficient code length and the corresponding accusation threshold.

The code length converges to its asymptote approximately as $c_0^{-1/2}$, which is faster than the $c_0^{-1/3}$ of Tardos\' score function.

Expand
Pablo Rauzy, Sylvain Guilley
ePrint Report ePrint Report
In our paper at PROOFS 2013, we formally studied a few known countermeasures to protect CRT-RSA against the BellCoRe fault injection attack. However, we left Vigilant\'s countermeasure and its alleged repaired version by Coron et al. as future work, because the arithmetical framework of our tool was not sufficiently powerful. In this paper we bridge this gap and then use the same methodology to formally study both versions of the countermeasure. We obtain surprising results, which we believe demonstrate the importance of formal analysis in the field of implementation security. Indeed, the original version of Vigilant\'s countermeasure is actually broken, but not as much as Coron et al. thought it was. As a consequence, the repaired version they proposed can be simplified. It can actually be simplified even further as two of the nine modular verifications happen to be unnecessary. Fortunately, we could formally prove the simplified repaired version to be resistant to the BellCoRe attack, which was considered a \"challenging issue\" by the authors of the countermeasure themselves.

Expand
Susumu Kiyoshima, Yoshifumi Manabe, Tatsuaki Okamoto
ePrint Report ePrint Report
We present the first general MPC protocol that satisfies the following: (1) the construction is black-box, (2) the protocol is universally composable in the plain model, and (3) the number of rounds is constant. The security of our protocol is proven in angel-based UC security under the assumption of the existence of one-way functions that are secure against sub-exponential-time adversaries and constant-round semi-honest oblivious transfer protocols that are secure against quasi-polynomial-time adversaries. We obtain the MPC protocol by constructing a constant-round CCA-secure commitment scheme in a black-box way under the assumption of the existence of one-way functions that are secure against sub-exponential-time adversaries. To justify the use of such a sub-exponential hardness assumption in obtaining our constant-round CCA-secure commitment scheme, we show that if black-box reductions are used, there does not exist any constant-round CCA-secure commitment scheme under any falsifiable polynomial-time hardness assumptions.

Expand
◄ Previous Next ►