IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
15 September 2014
Sofia, Bulgaria, April 26 - April 30
Notification: 8 January 2015
From April 26 to April 30
Location: Sofia, Bulgaria
More Information: https://www.cosic.esat.kuleuven.be/eurocrypt_2015/index.shtml
14 September 2014
Southern Illinois University Carbondale, USA
The Interdisciplinary Research (IR) Lab in the Department of Computer Science at Southern Illinois University Carbondale (SIUC) is looking for talented and highly motivated PhD students.
The IR Lab explores interesting and exciting research areas on the intersection of computer and social sciences ranging from computer security and privacy, applied cryptography, game theory, big data analysis and software development to economics, psychology and cognitive science. Our interdisciplinary setting provides attractive and flexible research environment for brilliant and creative PhD candidates.
Currently, there are many active projects in the IR lab among which are: computational models of trust and influence mimicking human reasoning, securely computable economic model, game theory and economic aspects of security and privacy, design and analysis of sealed-bid auction protocols, and computational models of collaboration by social networks analysis and mining.
The successful candidates perform research on the aforementioned projects based on their experience and research interests. They must have strong background in Computer Science and/or Mathematics. They are expected to publish articles in well-known conferences and journals. Although all applications will be carefully evaluated, candidates with prior publications as well as research experience in the following areas are specifically encouraged to apply: secret sharing, secure multiparty computation, rational cryptography, game theory and computational or mathematical modeling.
Financial support and tuition waiver are provided for these positions and they will remain open until filled.
12 September 2014
Mohammad Wazid
Yossi Azar, Seny Kamara, Ishai Menache, Mariana Raykova, Bruce Shepherd
resistant to cross-VM attacks without relying on single-tenancy or on
assumptions about the cloud\'s servers. In a cross-VM attack (which have
been demonstrated recently in Amazon EC2) an adversary launches malicious
virtual machines (VM) that perform side-channel attacks against co-located VMs
in order to recover their contents.
We propose a formal model in which to design and analyze \\emph{secure}
VM placement algorithms, which are online vector bin packing
algorithms that simultaneously satisfy certain optimization
constraints and notions of security. We introduce and formalize several notions
of security, establishing formal connections between them. We also introduce a
new notion of efficiency for online bin packing algorithms that better captures
their cost in the setting of cloud computing.
Finally, we propose a secure placement algorithm that achieves our strong
notions of security when used with a new cryptographic mechanism we refer to as
a shared deployment scheme.
11 September 2014
Yehuda Lindell
Masao KASAHARA
However most of the proposed MPKC are proved not secure.
In this paper, we propose a new class of MPKC based on Reed-Solomon code, referred to as K(XI)RSE(2)PKC.
In Appendix, we present another class of MPKC referred to as K(X)RSE(2)PKC over $\\mathbb{F}_2$.
Both K(X)RSE(2)PKC and K(XI)RSE(2)PKC yield the coding rate of 1.0.
We show that the proposed schemes can be sufficiently secure against various attacks, including Gr\\\"obner basis attack.
10 September 2014
Singapore, Singapore, April 14
Notification: 31 January 2015
From April 14 to April 14
Location: Singapore, Singapore
More Information: http://icsd.i2r.a-star.edu.sg/cpss15/
Here is a brief update on IACR matters as of CRYPTO 2014.
\r\n\r\n\r\n***Communications and website
\r\n\r\nFirst of all, I would like to thank Christopher Wolf for his service\r\nand dedication to the IACR in his role as Newsletter Editor (later,\r\nCommunications Secretary). From 2009 until this summer, he has led\r\nthe communications and publicity activities of the IACR and made the\r\nwebsite an interesting and interactive experience.
\r\n\r\nThe Board of Directors has appointed Mike Rosulek (Oregon State\r\nUniversity, US) as the Communications Secretary; Yu Yu (Shanghai Jiao\r\nTong University, CN) also joins the communications team and serves as\r\none of the webmasters.
\r\n\r\n\r\n\r\n***Cryptography Research Fund for Students
\r\n\r\nThanks to the generous donation of 1 Mio. USD from Cryptography\r\nResearch Inc. (a division of Rambus) the IACR has created the\r\n*Cryptography Research Fund for Students.*
\r\n\r\nThe fund aims at promoting cryptology to students and supporting\r\nscholarly work in the field. With its help, the IACR can greatly\r\nincrease its support for students in cryptology through:
\r\n\r\n1) Waiving the registration fee for student speakers at EUROCRYPT,\r\n CRYPTO, ASIACRYPT and, now, also at CHES, FSE, TCC and PKC;
\r\n\r\n2) Expanding its support for Cryptology Schools (see below);
\r\n\r\n3) Further activities, as coordinated by an Endowment Committee that\r\n oversees the fund. (Please contact its chair, Greg Rose, with more\r\n ideas.)
\r\n\r\nThe IACR has created an investment fund with a conservative strategy\r\nso that this program can be funded in perpetuity. Combined with a\r\nsmaller commitment from the IACR, the sum in the fund can support the\r\nongoing activities detailed above as well as let the capital keep\r\nup with inflation.
\r\n\r\n\r\n\r\n***Parallel sessions
\r\n\r\nIn response to the growth of the field over the last years, the Board\r\nin 2011 sent a message to Program Chairs and Program Committees of the\r\nthree main conferences asking them \"to accept substantially more\r\npapers than used to be the case and to work with their General Chair\r\nfor the logistics to make this possible.\" As one can see from the\r\npublication statistics over the recent years\r\n(http://www.iacr.org/publications/statistics.html) the message has\r\nbeen received partially, but not uniformly implemented. As of today,\r\nthe Board believes that this effort should go further. During the\r\nrecent meeting at CRYPTO, a majority of the Board expressed the opinion\r\nthat a program of, say, 60 or more talks should be arranged at least\r\npartially in parallel sessions.
\r\n\r\nHence, during its meeting at CRYPTO, the Board has decided to ask the\r\nProgram Chairs and Committees of the three IACR conferences in 2015\r\n\"to have parallel sessions for a significant part of the program.\" It\r\nis intended for 2015 only. At a discussion during the membership\r\nmeeting, a vote indicated a clear majority in favor of this change for\r\n2015, but there was also a significant minority against. After\r\nASIACRYPT 2015 a referendum among the IACR membership will be held for\r\ndeciding whether the format should be kept like this.
\r\n\r\nPer IACR\'s policy, Program Chairs and Committees are responsible for\r\nthe scientific program; the General Chairs are responsible for the\r\nlogistics and the organization. The Board guides these processes and\r\nensures continuity across IACR\'s activities.
\r\n\r\n\r\n\r\n***Cryptology Schools
\r\n\r\nThe Board has approved funding for the first three IACR Cryptology\r\nSchools, which take place later this year and next year.
\r\n\r\n1) School on Cryptographic Attacks (http://attackschool.di.uminho.pt/)\r\n 13-17 October 2014, Porto, Portugal
\r\n\r\n2) School on Design and Security of Cryptographic Algorithms and Devices,\r\n 5-10 July 2015 (tentative), location to be decided.
\r\n\r\n3) Asian Workshop on Symmetric Key Cryptography - Cryptology School,\r\n 19-22 December 2014, Chennai, India (http://ask2014.iiitd.ac.in/)
\r\n\r\nSee the website http://www.iacr.org/schools/ for more information.
\r\n\r\n\r\n\r\n***Elections
\r\n\r\nThere will be elections for three IACR Director positions later this\r\nyear; nominations are now open and due by October 10, 2014. Please\r\nconsider running and see the announcement on the website:\r\n http://www.iacr.org/elections/2014/
\r\n\r\n\r\nRegards,
\r\n\r\n Christian Cachin\r\n IACR President\r\n
Topic: On Side-Channel Attacks and the Application of Algorithmic Countermeasures
Category: implementation
Topic: Statistical methods for non-profiled differential side-channel analysis: Theory and evaluation
Category: (no category)
Description:
\r\nDifferential side-channel analysis (DSCA) aims at recovering cryptographically-secured secret information by exploiting the relationship between the physically-observable characteristics of a device and the data manipulated inside it. Prior knowledge about this relationship (obtained, perhaps, by detailed examination of an equivalent device) is known to greatly enhance attack success. What may be achieved with little or no prior knowledge at all is less clear. Strategies designed on such a basis have been loosely termed `generic\', but the scenarios in which these are possible without some meaningful knowledge on the leakage appear rare.\r\n
\r\n\r\n\r\nIn this thesis we formalise the notion of `generic DSCA\' in order to understand it better and to make concrete statements about when and in what sense it is possible. We confirm that the range of scenarios to which it may be applied truly is limited---requiring that the device at some stage implements a predictable function which is non-injective and sufficiently nonlinear (e.g. the DES S-Box transformations).\r\n
\r\n\r\n\r\nWe explore popular proposals based on mutual information and other non-parametric statistics. To facilitate meaningful comparisons we first introduce a theoretic evaluation framework to enable like-for-like comparisons between different methods and avoid the pit-falls of (necessarily estimator-dependent) empirical comparisons. One of the lessons learned by employing this framework is that mutual information is indeed optimal in some information-theoretic sense (as was initially supposed) and that it is the added burden of estimation which makes it a poor choice in all but the most unusual of leakage scenarios.\r\n
\r\n\r\n\r\nWe also analyse linear regression-based methods and their use as `generic\' strategies. Applied in this way, they are restricted to the same limited scope as any other such strategy. However, we identify a unique feature of the way they operate whi[...]
09 September 2014
Shenghui Su, Shuwang Lu
Christian Hanser, Daniel Slamanig
More precisely, we consider messages to be (representatives of) equivalence classes on vectors of group elements (coming from a single prime order group), which are determined by the mutual ratios of the discrete logarithms of the representative\'s vector components. By multiplying each component with the same scalar, a different representative of the same equivalence class is obtained.
We propose a definition of such a signature scheme, a security model and give an efficient construction, which we prove secure in the SXDH setting, where EUF-CMA security is proven against generic forgers in the generic group model and the so called class hiding property is proven under the DDH assumption.
As a second contribution, we use the proposed signature scheme to build an efficient multi-show attribute-based anonymous credential system (ABC) that allows to encode an arbitrary number of attributes. This is -- to the best of our knowledge -- the first ABC system that provides constant-size credentials and constant-size showings. To allow an efficient construction in combination with the proposed signature scheme, we also introduce a new, efficient, randomizable polynomial commitment scheme. Aside from these two building blocks, the credential system requires a very short and constant-size proof of knowledge to provide freshness in the showing protocol. We present our ABC system along with a suitable security model and rigorously prove its security.
Carmit Hazay, Hila Zarosim
Our starting point is the semi-honest protocol from FaustHV13 (ICALP 2013) that offers a simulation based secure protocol for outsourced pattern matching in the random oracle setting with optimal workload. In this work we study whether the random oracle is necessary for protocols with minimal interaction that meet the optimal communication/computation bounds in the query phase. We answer this question negatively and demonstrate a lower bound on the communication or the computational overhead in this phase. We further abstract the security properties of the underlying cryptographic primitive that enables to obtain private outsourced database search with minimal interaction. For a large class of search functionalities the communication complexity of our protocol meets the above lower bound.
Sebastien Tiran, Guillaume Reymond, Jean-Baptiste Rigaud, Driss Aboulkassimi, Benedikt Gierlichs, Mathieu Carbone, Gilles Ducharme, Philipp
Jan Camenisch, Stephan Krenn, Anja Lehmann, Gert Læssøe Mikkelsen, Gregory Neven, Michael Østergaard Pedersen
Fang Song
This work proposes a general framework to study which classical security proofs can be restored in the quantum setting. Basically, we split a security proof into (a sequence of) classical security reductions, and investigate what security reductions are ``quantum-friendly\'\'. We characterize sufficient conditions such that a classical reduction can be ``lifted\'\' to the quantum setting.
We then apply our lifting theorems to post-quantum signature schemes. We are able to show that the classical generic construction of hash-tree based signatures from one-way functions and and a more efficient variant proposed in~\\cite{BDH11} carry over to the quantum setting. Namely, assuming existence of (classical) one-way functions that are resistant to efficient quantum inversion algorithms, there exists a quantum-secure signature scheme. We note that the scheme in~\\cite{BDH11} is a promising (post-quantum) candidate to be implemented in practice and our result further justifies it. Actually, to obtain these results, we formalize a simple criteria, which is motivated by many classical proofs in the literature and is straightforward to check. This makes our lifting theorem easier to apply, and it should be useful elsewhere to prove quantum security of proposed post-quantum cryptographic schemes. Finally we demonstrate the generality of our framework by showing that several existing works (Full-Domain hash in the quantum random-oracle model~\\cite{Zha12ibe} and the simple hybrid arguments framework in~\\cite{HSS11}) can be reformulated under our unified framework.
08 September 2014
CWI / University of Amsterdam
The Institute for Logic, Language & Computation (ILLC) at the University of Amsterdam, and the Centrum Wiskunde & Informatica (CWI) are looking for a PhD candidate in the area of quantum cryptography.
The aim of the PhD project is to develop new quantum-cryptographic protocols (beyond the task of key distribution) and explore their limitations. An example of an active research is position-based quantum cryptography. Another aspect is to investigate the security of classical cryptographic schemes against quantum adversaries (post-quantum cryptography).
Full-time appointment is on a temporary basis for a period of four years. For the first two years the PhD candidate will be appointed at the ILLC, University of Amsterdam, initially for a period of 18 months and then, on positive evaluation, for a further six months. During the final two years, the PhD candidate will be employed by the Centrum Wiskunde and Informatica (CWI). On the basis of a full-time appointment (38 hours per week), the gross monthly salary amounts to €2,083 during the first year, rising to €2,664 during the fourth year.
Requirements:
- a Master\'s degree with excellent grades in computer science, mathematics or physics with outstanding results or a comparable degree;
- candidates with a strong background in cryptography or quantum information are preferred;
- demonstrated research abilities by completion of an (undergraduate) research project;
- good academic writing and presentation skills;
- good social and organisational skills.
05 September 2014
Zhigang Chen, Jian Wang, ZengNian Zhang , Xinxia Song
Oscar Garcia-Morchon, Ronald Rietman, Ludo Tolhuizen, Domingo Gomez-Perez, Jaime Gutierrez
security of the scheme: the HI problem, which is related to the
well-known noisy interpolation problem, and the apparently novel MMO problem, presented at ISSAC\'14.
HIMMO is non-interactive: nodes in a network can directly generate a common key without exchanging messages. Each node in the network has an identifier, and a trusted third pay (TTP) provides it with secret keying material---linked to the node identifier---in a secure way.
A node that wishes to communicate with another node uses its own secret keying material and the identity of the other node to generate a common pairwise key.
HIMMO allows for efficient operation with respect to both the amount of stored keying material and the key computation time, which is especially relevant for resource-constrained devices.
It has similar operational characteristics as previous ID-based symmetric key establishment methods, but has superior resistance against attacks in which multiple colluding or compromised nodes co-operate to obtain information on keys between other non-colluding or non-compromised nodes.
Christina Boura, Mar\\\'ia Naya-Plasencia, Valentin Suder