IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
20 August 2014
Hongda Li, Qihua Niu, Guifang Huang
Sanjit Chatterjee, Alfred Menezes
Vikram Singh
Aaram Yun
Melissa Chase, Emily Shen
``pattern\'\' string $p$, find all occurrences of $p$ as a substring of $s$.
We formalize the security properties desired in this type of setting by defining a type of encryption called \\emph{queryable
encryption}. In a queryable encryption scheme, a user can encrypt a
message $M$ under a secret key, and using the secret key can
generate tokens for queries $q$. Applying a token for a query $q$
to an encryption of $M$ gives the answer to the query $q$ on $M$. We consider security against both honest-but-curious and malicious adversaries, and define properties guaranteeing both the correctness of the user\'s results and the privacy of the user\'s data. Following the line of work started by \\cite{CGKO06}, to allow for efficient constructions, we allow the protocol to leak some information about the user\'s data, however we ensure that this leakage can be precisely captured in the definition. In addition, we allow the query protocol to involve a small constant number of rounds of interaction.
We construct a queryable encryption scheme for pattern matching queries that is correct and secure in the malicious model. Our construction is based on efficient symmetric-key building blocks and scales well with the size of the input: encryption of a data string of length $n$ with security parameter $\\lambda$ takes $O(n)$ time and produces a ciphertext of size $O(n\\lambda)$, and a query for a pattern string of length $m$ that occurs $k$ times takes $O(m+k)$ time and three rounds of communication.
Mehrdad Majzoobi, Akshat Kharaya, Farinaz Koushanfar, Srinivas Devadas
on field programmable gate arrays (FPGAs). We introduce a high resolution programmable delay logic (PDL) that is implemented
by harnessing the FPGA lookup-table (LUT) internal structure. PDL allows automatic fine tuning of delays that
can mitigate the timing skews caused by asymmetries in interconnect routing and systematic variations. To thwart the arbiter metastability problem, we present and analyze methods for majority voting of responses. A method to classify and group challenges into different robustness sets is introduced that enhances the corresponding responses\' stability in the face of operational variations. The trade-off between response stability and response entropy (uniqueness) is investigated through comprehensive measurements. We exploit the correlation between the impact of temperature and power supply on responses and perform less costly power measurements to predict the temperature impact on PUF. The measurements are performed on 12 identical Virtex 5 FPGAs across 9 different accurately controlled operating temperature and voltage supply points. A database of challenge response pairs (CRPs) are collected and made openly available for the research community.
IACR 2014 Election
The 2014 election is being held to fill three of nine IACR Director positions. The election will again be run electronically and further information will be available on the IACR website.Nominations Are Now Open
Nominations are due by October 10, 2014. A nomination form is available at the elections page.Election of Directors
The directors whose terms are expiring are- Josh Benaloh (director)
- Shai Halevi (director)
- Moti Yung (director)
Election Committee
- Michel Abdalla (Returning Officer)
- Anna Lysyanskaya
- Bart Preneel (Chair)
Daniel Genkin, Itamar Pipman, Eran Tromer
Through suitable cryptanalysis and signal processing, we have extracted 4096-bit RSA keys and 3072-bit ElGamal keys from laptops, via each of these channels, as well as via power analysis and electromagnetic probing. Despite the GHz-scale clock rate of the laptops and numerous noise sources, the full attacks require a few seconds of measurements using Medium Frequency signals (around 2 MHz), or one hour using Low Frequency signals (up to 40 kHz).
Debrup Chakraborty, Palash Sarkar
is to construct suitable modes of operations of a block cipher to achieve the relevant goals. A variety
of schemes suitable for specific applications are presented. While none of the schemes are built completely from scratch,
there is a common unifying framework which connects them. All the schemes described have been implemented and the implementation
details are publicly available. Performance figures are presented when the block cipher is the AES and the Intel AES-NI
instructions are used. These figures suggest that the constructions presented here compare well with previous works
such as the famous OCB mode of operation. In terms of features, the constructions provide several new offerings which
are not present in earlier works. This work significantly widens the range of choices of an actual designer of
cryptographic system.
Partha Sarathi Roy, Avishek Adhikari, Rui Xu, Kirill Morozov, Kouichi Sakurai
Christopher Mann, Daniel Loebenberger
Peeter Laud
19 August 2014
Washington DC Metro Area, USA, May 5 - May 7
Notification: 16 January 2015
From May 5 to May 7
Location: Washington DC Metro Area, USA
More Information: http://www.hostsymposium.org/
18 August 2014
Aarhus University
We are looking for an applicant committed to playing an active part in continuously building strong research collaborations between the Department of Computer Science at Aarhus University (http://www.cs.au.dk) and IIIS at Tsinghua University, Beijing. In particular, the successful applicant will spend significant time at IIIS, with funding for such visits being part of the position.
The applicant should have a background in at least one of the four focus areas of CTIC: Computational complexity theory, cryptography, quantum information theory or algorithmic game theory.
CTIC is a collaboration between the Department of Computer Science at Aarhus University, Denmark and IIIS at Tsinghua University, Beijing, China. The center leaders are Andrew Chi-Chih Yao, Tsinghua University and Peter Bro Miltersen, Aarhus University. More information about CTIC can be found at the center website: http://ctic.au.dk/.
Salary depends on seniority as agreed between the Danish Ministry of Finance and the Confederation of Professional Unions.
The application should be in English and include a curriculum vitae, degree certificate, a complete list of publications, a statement of future research plans and information about research activities.
Please apply by email to Katrine Aakjær Nielsen at katnie (at) cs.au.dk.
For more information on the position, you may contact Peter Bro Miltersen at bromille (at) cs.au.dk.
Kuala Lumpur, Malaysia, October 27 - October 29
From October 27 to October 29
Location: Kuala Lumpur, Malaysia
More Information: http://sdiwc.net/conferences/eeetem2015/
16 August 2014
Dubai, UAE, January 28 - January 30
Notification: 20 January 2015
From January 28 to January 30
Location: Dubai, UAE
More Information: http://sdiwc.net/conferences/dipdmwc2015/
15 August 2014
Stephan Neumann, Christian Feier, Perihan Sahin, Sebastian Fach
14 August 2014
Nagravision, Cheseaux - Switzerland
• Capture security needs at business level, define appropriate security target for the system, and build threat analysis, detailed security requirements.
• Define system’ security architecture: select / design appropriate solutions, techniques and technologies to meet the targeted security level.
• Work with experts, designers and developers to review detailed design and implementations
• Plan and coordinate security evaluations of the products with internal attack laboratory or external provider of security assessment.
• Follow evolutions in security related technologies such as cryptography, attacks techniques, security evaluation methodologies…
• Act as a thought leader across the department, providing deep expertise on one or some domain of expertise on security related topics and serving as an internal reference point your specialization.
• Follow evolution of the CAS/DRM product ecosystem regarding standards and technical trends so as to anticipate changes.
• Contribute to the Nagravision patent portofolio and innovation by designing new security mechanism and approaches
Profile
• Strong skills in applied cryptography and security protocols, with the ability to define new ones.
• Strong skills in extended areas of software security techniques, white box cryptography, hardening.
• A strong interest and some previous experience in the area of hacking and security are mandatory
• Transversal knowledge of CAS/DRM products with a focus on connected systems. Good understanding of their architecture and security foundation
• Previous experience or knowledge in one or some of the following area is a strong plus:
o Previous experience in the development of embedded system and a good understanding of low level software and hardware mechanism.
o Knowledge of related formalism and methodologies such as Common Criteria.
13 August 2014
Craig Gentry
Shlomi Dolev, Niv Giboa, Ximing Li
Consider a dealer that wants to repeatedly compute functions on a long file with the assistance of $m$ servers. The dealer does not wish to leak either the input file or the result of the computation to any of the servers. We investigate this setting given two constraints. The dealer is allowed to share each symbol of the input file among the servers and is allowed to halt the computation at any point. However, the dealer is otherwise stateless. Furthermore, each server is not allowed any communication beyond the shares of the inputs that it receives and the information it provides to the dealer during reconstruction.
We present a protocol in this setting for generalized string matching, including wildcards. We also present solutions for identifying other regular languages, as well as particular context free and context sensitive languages. The results can be described by a newly defined {\\em accumulating automata} and {\\em cascaded equations automata} which may be of an independent interest. As an application of {\\em accumulating automata} and {\\em cascaded equations automata}, secure and private repeated computations on a secret shared file among communicationless clouds are presented.