IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
26 January 2014
Topic: Secret Sharing-based Group Key Establishment
Category: (no category)
Description: Group applications permit multiple users to share resources or perform collaborative tasks while providing differentiate rights or responsibilities within the group. Examples include text communication, audio, video or web conferences, data sharing or collaborative computing.\r\n\r\n
\r\nSecurity represents an important aspect for group applications. It is a challenging task to deal with, especially when the group size is large and the members are spread across different (location or networks) areas, with diverse protection mechanisms. In order to obtain the main cryptographic properties as confidentiality, authenticity and integrity it is usually required that the group members previously share a common secret group key. This is achieved as theoutput of a group key establishment protocol.\r\n\r\n
\r\nThe thesis restricts to group key establishment protocols based on secret sharing, a primitive that divides a secret into multiple shares such that only authorized subset of shares allow reconstruction. Although secret sharing brings several advantages when it is used as a building block of group key establishment protocols, two important shortcomings currently exist: (1) several insecure proposals were published in the last years and (2) very few constructions rely on a security proof. We address both this issues in the present work.\r\n\r\n
\r\nThe first part of the dissertation focuses on the underlying secret sharing schemes. We review a non-classical approach of secret sharing, dene a new visual secret sharing scheme and analyze the possibility of malicious manufacturing of the sharing device. The second part of the thesis concentrates on group key establishment constructions that use secret sharing. We introduce a multitude of attacks against recent protocols and therefore highlight the necessity of security proofs. We review the properties that impose a sufficient level of security and briefly analyze the formal models of security. Finally, we introduc[...]
24 January 2014
MICROSOFT RESEARCH, Redmond, Washington USA
Post-docs and interns will be in residence at Microsoft Research Redmond, the main campus of Microsoft\\\'s basic research division with over four hundred researchers in dozens of areas of computer science research. Researchers benefit from close proximity to Microsoft product units, collaborative relations and joint seminars with University of Washington, and an active research environment. For more information about MSR Redmond and the Cryptography group see: http://research.microsoft.com/aboutmsr/labs/redmond/ and http://research.microsoft.com/crypto/
The post-doctoral positions offer a competitive salary, benefits, and a relocation allowance. The term is for two years; the start date is July 1, 2014. Post-docs will report to Dr. Kristin Lauter, Research Manager for the MSR Crypto Group. Internships for graduate students will be for 10-12 weeks in Summer 2014, with flexible start date.
Vienna, Austria, July 14 - July 16
Notification: 21 April 2014
From July 14 to July 16
Location: Vienna, Austria
More Information: http://dbsec2014.sba-research.org
22 January 2014
Li Xi
port various signature schemes including Direct Anonymous Attestation
(DAA), U-Prove and Schnorr signature. This signature primitive is im-
plemented by several APIs. In this paper, we show these DAA-related
APIs can be used as a static Diffie-Hellman oracle thus the security
strength of these signature schemes can be weakened by 14-bit. We pro-
pose a novel property of DAA called forward anonymity and show how
to utilize these DAA-related APIs to break forward anonymity. Then we
propose new APIs which not only remove the Static Diffie-Hellman oracle
but also support the forward anonymity, thus significantly improve the
security of DAA and the other signature schemes supported by TPM2.0.
We prove the security of our new APIs under the discrete logarithm
assumption in the random oracle model. We prove that DAA satisfy for-
ward anonymity using the new APIs under the Decision Diffie-Hellman
assumption. Our new APIs are almost as efficient as the original APIs
in TPM2.0 specification and can support LRSW-DAA and SDH-DAA
together with U-Prove as the original APIs.
Elena Dubrova
21 January 2014
Longjiang Qu, Shaojing Fu, Qingping Dai, Chao Li
be represented as the sum of two bent functions. This problem was
recently presented by N. Tokareva in studying the number of bent
functions. Firstly, many functions, such as
quadratic Boolean functions, Maiorana-MacFarland bent functions,
partial spread functions etc, are proved to be able to be
represented as the sum of two bent functions. Methods to construct
such functions from low dimension ones are also introduced. N.
Tokareva\'s main hypothesis is proved for $n\\leq 6$. Moreover,
two hypotheses which are equivalent to N. Tokareva\'s main hypothesis
are presented. These hypotheses may lead to new ideas or methods to
solve this problem. At last, necessary and sufficient conditions on
the problem when the sum of several bent functions is again a bent
function are given.
Neha tirthani, Ganesan
In this research paper, we have contemplated a design for cloud architecture which ensures secured movement of data at client and server end. We have used the non breakability of Elliptic curve cryptography for data encryption and Diffie Hellman Key Exchange mechanism for connection establishment. The proposed encryption mechanism uses the combination of linear and elliptical cryptography methods. It has three security checkpoints: authentication, key generation and encryption of data.
Daniel R. L. Brown
This report focuses on the IKA of two-pass MQV, without key confirmation. Arguably, implicit key authentication is the most essential security objective in authenticated key agreement. The report examines various necessary or sufficient formal conditions under which MQV may provide IKA.
Incidentally, this report defines, relies on, and inter-relates various conditions on the key deriviation function and Diffie--Hellman groups. While it should be expected that most such definitions and results are already well-known, a reader interested in these topics may be interested in this report as a kind of review, even if they have no interest in MQV whatsoever.
Aveiro, Portugal, September 25 - September 26
Notification: 23 May 2014
From September 25 to September 26
Location: Aveiro, Portugal
More Information: http://cms2014.web.ua.pt
20 January 2014
Mohsen Alimomeni, Reihaneh Safavi-Naini
gaming, gambling, and computer science in general. True random number generators
need an entropy source which is a physical source with inherent uncertainty, to ensure
unpredictability of the output. In this paper we propose a new indirect approach to
collecting entropy using human errors in the game play of a user against a computer. We
argue that these errors are due to a large set of factors and provide a good source of
randomness. To show the viability of this proposal, we design and implement a game,
conduct a user study in which we collect user input in the game, and extract randomness
from it. We measure the rate and the quality of the resulting randomness that clearly
show effectiveness of the approach. Our work opens a new direction for construction of
entropy sources that can be incorporated into a large class of video games.
Yalin Chen1, Jue-Sam Chou*2
Vivien Dubois
17 January 2014
Lichun Li, Michael Militzer, Anwitaman Datta
Jintai Ding, Chengdong Tao
the fully homomorphic encryption schemes, which are based on the approximate common divisors problem, in polynomial time in terms of the system parameter $\\lambda$.
Mehdi Tibouchi
Recently, Bernstein, Hamburg, Krasnova and Lange proposed a partial solution to this problem in the form of Elligator: an algorithm for representing around half of the points on a large class of elliptic curves as close to uniform random strings. Their proposal has the advantage of being very efficient, but suffers from several limitations:
* Since only a subset of all elliptic curve points can be encoded as a string, their approach only applies to cryptographic protocols transmitting points that are rerandomizable in some sense.
* Supported curves all have non-trivial $2$-torsion, so that Elligator cannot be used with prime-order curves, ruling out standard ECC parameters and many other cryptographically interesting curves such as BN curves.
* For indistinguishability to hold, transmitted points have to be uniform in the whole set of representable points; in particular, they cannot be taken from a prime order subgroup, which, in conjunction with the non-trivial $2$-torsion, rules out protocols that require groups of prime order.
In this paper, we propose an approach to overcome all of these limitations. The general idea is as follows: whereas Bernstein et al. represent an elliptic curve point P as the bit string \\iota^{-1}(P), where \\iota is an injective encoding to the curve (which is only known to exist for some curve families, and reaches only half of all possible points), we propose to use a randomly sampled preimage of P under an admissible encoding of the form f^{\\otimes 2}: (u,v)\\mapsto f(u)+f(v), where f is essentially any algebraic encoding. Such encodings f exist for all elliptic curves, and the corresponding admissible encodings f^{\\otimes 2} are essentially surjective, inducing a close to uniform distribution on the curve.
As a result, our bit string representation is somewhat less compact (about twice as long as Elligator), but it has none of the limitations above, and can be computed quite efficiently when the function f is suitably chosen.
15 January 2014
Boaz Tsaban
of a number of problems in noncommutative-algebraic cryptography.
In contrast to the linear centralizer method of \\cite{LinCent}, the new method is
very simple: In order to solve linear equations on matrices
restricted to matrix groups, solve them over the generated
algebras. We name this approach the \\emph{algebraic span method}.
The resulting algorithms are have substantially better performance than those of \\cite{LinCent}.
These algorithms constitute cryptanalyses of the motivating protocols that
cannot be foiled by changing the distributions used in the protocols, and are
practical for most affordable parameter settings.
Zhengjun Cao, Ruizhong Wei, Xiaodong Lin
14 January 2014
Yarkin Doroz, Yin Hu, Berk Sunar