IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
18 July 2014
Daniel Augot, Pierre-Alain Fouque, Pierre Karpman
The mappings are derived from linear codes over a small field (typically $F^{2^4}$) with a high dimension (typically 16) and a high minimum distance. This results in diffusion matrices with equally high dimension and a large branch number.
Because we aim for parameters for which no MDS code is known to exist, we propose to use more flexible algebraic-geometry codes.
We present two simple yet efficient algorithms for the software implementation of matrix-vector multiplication in this context, and derive conditions on the generator matrices of the codes to yield efficient encoders. We then specify an appropriate code and use its automorphisms as well as random sampling to find good such matrices.
We provide concrete examples of parameters and implementations, and the corresponding assembly code. We also give performance figures in an example of application which show the interest of our approach.
15 July 2014
The School of Informatics, University of Edinburgh, UK
Areas of particular interest are applied cryptography, systems/network security, human factors for security and privacy, and information Assurance.
Both positions are full-time and permanent. The start date is 1st October 2014, or a later date by negotiation.
We also have PhD positions, which are recruited continually.
The School of Informatics at Edinburgh is the largest informatics School in the UK, enjoying a city centre location in a modern building in the beautiful capital city of Scotland.
Please visit the web page for full details.
14 July 2014
IBM Research - Zurich, Switzerland
Candidates will perform scientific research in the areas mentioned above under the direct guidance of the permanent researchers in our team. Their main task will consist of publishing at respected academic conferences and journals. They will also collaborate with international partners in EU research projects and occasionally implement prototypes of cryptographic protocols.
PhD student candidates must have a Master degree or equivalent in computer science, mathematics, electrical engineering, or related disciplines. Knowledge of basic cryptography is required, proven experience in the form of theses or published papers is a strong asset.
Post-Doc candidates must have a PhD degree in cryptography. All candidates must be fluent in spoken and written English; knowledge of German is not required.
IBM Research - Zurich offers a stimulating international research environment among experts in computer science, physics, and mathematics. The laboratory is located in Rüschlikon, Switzerland, at 10km from the city of Zurich and on the coast of Lake Zurich. A competitive salary will be offered, adjusted to the high local living standards.
The positions will remain open until suitable candidates have been hired.
October 31
Notification: 3 April 2015
From October 31 to October 31
More Information: http://tinyurl.com/qykzlrp
11 July 2014
Scottsdale, Arizona, United States of America, November 3
Notification: 25 August 2014
From November 3 to November 3
Location: Scottsdale, Arizona, United States of America
More Information: http://www.trusted-workshop.de
10 July 2014
University of Twente, The Netherlands
The Centre for Telematics and Information Technology (CTIT) at the University of Twente invites applications for a 4-year PhD position in cryptographic protocol design.
In the course of the PhD project, the PhD student will deal with cryptographic concepts such as Homomorphic Encryption, Functional Encryption, and Secure Multiparty Computation. The research focus of the project is on the design and evaluation of new cryptographic protocols for specific application scenarios.
The PhD candidate will be expected to do active and internationally visible research which will be supervised by Dr. Andreas Peter from the Services, Cybersecurity and Safety Group of the University of Twente. The PhD candidate will be appointed for a period of four years, at the end of which he/she must have completed a PhD thesis. During this period, the PhD student has the opportunity to broaden his/her knowledge by joining international exchange programs, to participate in national and international conferences and workshops, and to visit other research institutes and universities worldwide.
Successful candidates must hold an outstanding M.Sc. degree (or equivalent) from the university study of Computer Science, Mathematics, or similar, obtained within the last two years. The topic of the master thesis should ideally have relevance to cryptography. Applications from students that are about to finish their master thesis will be accepted as well. Further requirements include excellent skills in the English language, firm knowledge in cryptography and basic programming skills. Early experiences with scientific publications are of advantage.
The position will be closed as soon as a suitable candidate is found. Applications must include:
- CV and academic transcript (with grades)
- motivation letter (including a description of prior
Bucharest, Romania, July 21 - July 24
Location: Bucharest, Romania
More Information: http://www.cs.bris.ac.uk/cryptosummerschool/
Singapore, Singapore, April 14 - April 17
Notification: 22 December 2014
From April 14 to April 17
Location: Singapore, Singapore
More Information: http://icsd.i2r.a-star.edu.sg/asiaccs15/
İstanbul, Turkey, March 8 - March 11
Notification: 16 January 2015
From March 8 to March 11
Location: İstanbul, Turkey
More Information: http://light-sec.org/fse2015/
09 July 2014
Massimo Chenal, Qiang Tang
In this paper, we continue this line of research and show that most existing somewhat homomorphic encryption schemes are not IND-CCA1 secure. In fact, we show that these schemes suffer from key recovery attacks (stronger than a typical IND-CCA1 attack), which allow an adversary to recover the private keys through a number of decryption oracle queries. The schemes, that we study in detail, include those by Brakerski and Vaikuntanathan at Crypto 2011 and FOCS 2011, and that by Gentry, Sahai and Waters at Crypto 2013. We also develop a key recovery attack that applies to the somewhat homomorphic encryption scheme by van Dijk et al., and our attack is more efficient and conceptually simpler than the one developed by Zhang et al.. Our key recovery attacks also apply to the scheme by Brakerski, Gentry and Vaikuntanathan at ITCS 2012, and we also describe a key recovery attack for the scheme developed by Brakerski at Crypto 2012.
Tian Tian, Wen-Feng Qi
Georg Fuchsbauer
After formally defining constrained VRFs, we derive instantiations from the multilinear-maps-based constrained PRFs by Boneh and Waters, yielding a VRF with constrained keys for any set that can be decided by a polynomial-size circuit. Our VRFs have the same function values as the Boneh-Waters PRFs and are proved secure under the same hardness assumption, showing that verifiability comes at no cost. Constrained (functional) VRFs were stated as an open problem by Boyle et al.
08 July 2014
Jaiganesh Balasundaram
Cong Chen, Thomas Eisenbarth, Ingo von Maurich, Rainer Steinwandt
Xiaofeng Wang, Chen Xu, Guo Li, Hanling Lin
Jesper Buus Nielsen, Daniele Venturi, Angela Zottarel
leakage-resilient signatures secure against existential forgeries,
where the signature is much shorter than the leakage bound.
Current models of leakage-resilient signatures against existential
forgeries demand that the adversary cannot produce a new valid
message/signature pair $(m, \\sigma)$ even after receiving some
$\\lambda$ bits of leakage on the signing key. If $\\vert \\sigma \\vert
\\le \\lambda$, then the adversary can just choose to leak a valid
signature $\\sigma$, and hence signatures must be larger than the
allowed leakage, which is impractical as the goal often is to have
large signing keys to allow a lot of leakage.
We propose a new notion of leakage-resilient signatures against
existential forgeries where we demand that the adversary cannot
produce $n = \\lfloor \\lambda / \\vert \\sigma \\vert \\rfloor + 1$
distinct valid message/signature pairs
$(m_1, \\sigma_1), \\ldots, (m_n, \\sigma_n)$ after receiving
$\\lambda$ bits of leakage. If $\\lambda =
0$, this is the usual notion of existential unforgeability. If $1
Khoongming Khoo, Thomas Peyrin, Axel Y. Poschmann, Huihui Yap
Paolo Palmieri, Luca Calderoni, Dario Maio
Georg T. Becker
However, PUFs have shown to be vulnerable to model building attacks if the attacker has access to challenge and response pairs. In these model building attacks, machine learning is used to determine the internal parameters of the PUF to build an accurate software model. Nevertheless, PUFs are still a promising building block and several protocols and designs have been proposed that are believed to be resistant against machine learning attacks. In this paper we take a closer look at a two such protocols, one based on reverse fuzzy extractors[15] and one based on pattern matching [15,17]. We show that it is possible to attack these protocols using machine learning despite the fact that an attacker does not have access to direct challenge and response pairs. The introduced attacks demonstrate that even highly obfuscated responses or helper data can be used to attack PUF protocols.
Hence, our work shows that even protocols in which it would be computationally infeasible to compute enough challenge and response pairs for a direct machine learning attack can be attacked using machine learning.