ECDH Key-Extraction via Low-Bandwidth Electromagnetic Attacks on PCs
Removing the Strong RSA Assumption from Arguments over the Integers
A subfield lattice attack on overstretched NTRU assumptions: Cryptanalysis of some FHE and Graded Encoding Schemes
Server Notaries: A Complementary Approach to the Web PKI Trust Model
Fully-Secure Lattice-Based IBE as Compact as PKE
Collecting relations for the Number Field Sieve in $GF(p^6)$
Robust Password-Protected Secret Sharing
Simpira: A Family of Efficient Permutations Using the AES Round Function
Tightly-Secure Pseudorandom Functions via Work Factor Partitioning
Oblivious Transfer from Any Non-Trivial Elastic Noisy Channels via Secret Key Agreement
Lightweight Multiplication in GF(2^n) with Applications to MDS Matrices
Circuit-ABE from LWE: Unbounded Attributes and Semi-Adaptive Security
Circular Security Counterexamples for Arbitrary Length Cycles from LWE
Interactive Oracle Proofs
<![CDATA[Efficiently Computing Data-Independent Memory-Hard Functions]]>by 0$. In particular when $\tau=1$ this shows that the goal of constructing an iMHF with AT-complexity $\Theta(\sigma^2 * \tau)$ is unachievable.
Along the way we prove a lemma upper-bounding the depth-robustness of any DAG which may prove to be of independent interest.
]]>
The Magic of ELFs
On the Composition of Two-Prover Commitments, and Applications to Multi-Round Relativistic Commitments
On the (In)security of SNARKs in the Presence of Oracles
Scalable and Secure Logistic Regression via Homomorphic Encryption
<![CDATA[Three's Compromised Too: Circular Insecurity for Any Cycle Length from (Ring-)LWE]]>by 2$ the only known
counterexamples are based on strong general-purpose obfuscation
assumptions.
In this work we construct $k$-circular security counterexamples for
any $k \geq 2$ based on (ring-)LWE. Specifically:
\begin{itemize}
\item for any constant $k=O(1)$, we construct a counterexample based on
$n$-dimensional (plain) LWE for $\poly(n)$ approximation factors;
\item for any $k=\poly(\lambda)$, we construct one based on degree-$n$
ring-LWE for at most subexponential $\exp(n^{\varepsilon})$ factors.
\end{itemize}
Moreover, both schemes are $k'$-circular insecure for
$2 \leq k' \leq k$.
Notably, our ring-LWE construction does not immediately translate to
an LWE-based one, because matrix multiplication is not commutative. To
overcome this, we introduce a new ``tensored'' variant of LWE which
provides the desired commutativity, and which we prove is actually
equivalent to plain LWE.
]]>
Fast Multiparty Multiplications from shared bits
Computing Private Set Operations with Linear Complexities
Fully Anonymous Transferable Ecash
Access Control Encryption: Enforcing Information Flow with Cryptography
Fully homomorphic encryption must be fat or ugly?
Open Sesame: The Password Hashing Competition and Argon2
Speed Optimizations in Bitcoin Key Recovery Attacks
Breaking the Sub-Exponential Barrier in Obfustopia
Signature Schemes with Efficient Protocols and Dynamic Group Signatures from Lattice Assumptions
On the Complexity of Scrypt and Proofs of Space in the Parallel Random Oracle Model
Attribute-Based Fully Homomorphic Encryption with a Bounded Number of Inputs
Haraka - Efficient Short-Input Hashing for Post-Quantum Applications
A Maiorana-McFarland Construction of a GBF on Galois ring
Provable Security Evaluation of Structures against Impossible Differential and Zero Correlation Linear Cryptanalysis
Obfuscation without Multilinear Maps
Tightly Secure CCA-Secure Encryption without Pairings
Valiant's Universal Circuit is Practical
Cryptanalysis of the Full Spritz Stream Cipher
On the Security of the Algebraic Eraser Tag Authentication Protocol
Spectral characterization of iterating lossy mappings
On the Hardness of LWE with Binary Error: Revisiting the Hybrid Lattice-Reduction and Meet-in-the-Middle Attack
On Linear Hulls and Trails in Simon
Safely Exporting Keys from Secure Channels: On the security of EAP-TLS and TLS Key Exporters
Intel SGX Explained
Cryptanalysis of ring-LWE based key exchange with key share reuse
Truncated Differential Analysis of Round-Reduced RoadRunneR Block Cipher
NSEC5 from Elliptic Curves: Provably Preventing DNSSEC Zone Enumeration with Shorter Responses
Non-Interactive Plaintext (In-)Equality Proofs and Group Signatures with Verifiable Controllable Linkability
A Cryptographic Analysis of the TLS 1.3 draft-10 Full and Pre-shared Key Handshake Protocol
Cryptanalysis of PRINCE with Minimal Data
Protect both Integrity and Confidentiality in Outsourcing Collaborative Filtering Computations
Non-Interactive Verifiable Secret Sharing For Monotone Circuits
Multidimensional Meet in the Middle Cryptanalysis of KATAN
New Efficient and Flexible Algorithms for Secure Outsourcing of Bilinear Pairings
Weaknesses in Hadamard Based Symmetric Key Encryption Schemes
On the Power of Secure Two-Party Computation
MU-ORAM: Dealing with Stealthy Privacy Attacks in Multi-User Data Outsourcing Services
Downgrade Resilience in Key-Exchange Protocols
Reverse-Engineering the S-Box of Streebog, Kuznyechik and STRIBOBr1
Domain-Specific Pseudonymous Signatures Revisited
Verification Methods for the Computationally Complete Symbolic Attacker Based on Indistinguishability
Octonion Algebra and Noise-Free Fully Homomorphic Encryption (FHE) Schemes
OPFE: Outsourcing Computation for Private Function Evaluation
Linear Hull Attack on Round-Reduced Simeck with Dynamic Key-guessing Techniques
A note on Tensor Simple Matrix Encryption Scheme
Unconditionally Secure Revocable Storage: Tight Bounds, Optimal Construction, and Robustness
Analysing and Exploiting the Mantin Biases in RC4
Verifiable Dynamic Symmetric Searchable Encryption: Optimality and Forward Security
Accountable Privacy for Decentralized Anonymous Payments
Topology-based Plug-and-Play Key-Setup
Secure positioning and quantum non-local correlations
Implementing a Toolkit for Ring-LWE Based Cryptography in Arbitrary Cyclotomic Number Fields
Strong Continuous Non-malleable Encoding Schemes with Tamper-Detection
Neeva: A Lightweight Hash Function
An Efficient Lattice-Based Signature Scheme with Provably Secure Instantiation
Truncated Differential Based Known-Key Attacks on Round-Reduced Simon
Threshold-optimal DSA/ECDSA signatures and an application to Bitcoin wallet security
Better Security for Functional Encryption for Inner Product Evaluations
Trap Me If You Can -- Million Dollar Curve
Cryptanalysis of a public key cryptosystem based on Diophantine equations via weighted LLL reduction
Unclonable encryption revisited ($4 \times 2 = 8$)
Secure Comparator: a ZKP-Based Authentication System
From Identification to Signatures, Tightly: A Framework and Generic Transforms
Fully Leakage-Resilient Codes
Collusion Resistant Aggregation from Convertible Tags
Practical Order-Revealing Encryption with Limited Leakage
Practical, Predictable Lattice Basis Reduction
Comparison of TERO-cell implementations and characterisation on SRAM FPGAs
Area-Efficient Hardware Implementation of the Optimal Ate Pairing over BN curves.
Watermarking Cryptographic Capabilities
Practical Witness Encryption for Algebraic Languages And How to Reply an Unknown Whistleblower
ARMed SPHINCS -- Computing a 41KB signature in 16KB of RAM
Cryptanalysis of GGH15 Multilinear Maps
One-Key Compression Function Based MAC with BBB Security
Encryption Switching Protocols
Building Single-Key Beyond Birthday Bound Message Authentication Code
Private Processing of Outsourced Network Functions: Feasibility and Constructions
A Cryptographic Analysis of the TLS 1.3 Handshake Protocol Candidates
On the Hardness of Learning with Rounding over Small Modulus
Predictable Arguments of Knowledge
Compositions of linear functions and applications to hashing
The self-blindable U-Prove scheme from FC'14 is forgeable
Detecting Mobile Application Spoofing Attacks by Leveraging User Visual Similarity Perception
A Brief Comparison of Simon and Simeck
Cliptography: Clipping the Power of Kleptographic Attacks
Homomorphic Signature Schemes - A survey
Computing Elliptic Curve Discrete Logarithms with Improved Baby-step Giant-step Algorithm
Extractable Witness Encryption and Timed-Release Encryption from Bitcoin
Authentication Key Recovery on Galois Counter Mode (GCM)
Randomizing scalar multiplication using exact covering systems of congruences
Efficient Unlinkable Sanitizable Signatures from Signatures with Re-Randomizable Keys
Succinct Garbled RAM
PAC Learning of Arbiter PUFs
Computationally binding quantum commitments
<![CDATA[Cryptanalysis of GGH Map]]>by 2$. GGH map has two classes of applications, which are applications with public tools for encoding and with hidden tools for encoding. In this paper, we show that applications of GGH map with public tools for encoding are not secure, and that one application of GGH map with hidden tools for encoding is not secure. On the basis of weak-DL attack presented by the authors themselves, we present several efficient attacks on GGH map, aiming at multipartite key exchange (MKE) and the instance of witness encryption (WE) based on the hardness of 3-exact cover (3XC) problem. First, we use special modular operations, which we call modified encoding/zero-testing to drastically reduce the noise. Such reduction is enough to break MKE. Moreover, such reduction negates $K$-GMDDH assumption, which is a basic security assumption. The procedure involves mostly simple algebraic manipulations, and rarely needs to use any lattice-reduction tools. The key point is our special tools for modular operations. Second, under the condition of public tools for encoding, we break the instance of WE based on the hardness of 3XC problem. To do so, we not only use modified encoding/zero-testing, but also introduce and solve ``combined 3XC problem'', which is a problem that is not difficult to solve. In contrast with the assumption that multilinear map cannot be divided back, this attack includes a division operation, that is, solving an equivalent secret from a linear equation modular some principal ideal. The quotient (the equivalent secret) is not small, so that modified encoding/zero-testing is needed to reduce size. This attack is under an assumption that some two vectors are co-prime, which seems to be plausible. Third, for hidden tools for encoding, we break the instance of WE based on the hardness of 3XC problem. To do so, we construct level-2 encodings of 0, which are used as alternative tools for encoding. Then, we break the scheme by applying modified encoding/zero-testing and combined 3XC, where the modified encoding/zero-testing is an extended version. This attack is under two assumptions, which seem to be plausible. Finally, we present cryptanalysis of two simple revisions of GGH map, aiming at MKE. We show that MKE on these two revisions can be broken under the assumption that $2^{K}$ is polynomially large. To do so, we further extend our modified encoding/zero-testing.
]]>
Adaptively Secure Unrestricted Attribute-Based Encryption with Subset Difference Revocation in Bilinear Groups of Prime Order
Key Recovery for LWE in Polynomial Time
<![CDATA[Exploring the Resilience of Some Lightweight Ciphers Against Profiled Single Trace Attacks]]>by
<![CDATA[Multi-Input Functional Encryption in the Private-Key Setting: Stronger Security from Weaker Assumptions]]>by
<![CDATA[From Related-Key Distinguishers to Related-Key-Recovery on Even-Mansour Constructions]]>by
<![CDATA[Faulty Clock Detection for Crypto Circuits Against Differential Fault Analysis Attack]]>by
<![CDATA[The Bitcoin Backbone Protocol: Analysis and Applications]]>by
<![CDATA[Secure and Oblivious Maximum Bipartite Matching Size Algorithm with Applications to Secure Fingerprint Identification]]>by
<![CDATA[Towards Optimally Efficient Secret-Key Authentication from PRG]]>by
<![CDATA[Multi-target DPA attacks: Pushing DPA beyond the limits of a desktop computer]]>by
<![CDATA[Handycipher: a Low-tech, Randomized, Symmetric-key Cryptosystem]]>by
<![CDATA[(Efficient) Universally Composable Oblivious Transfer Using a Minimal Number of Stateless Tokens]]>by
<![CDATA[Profiling DPA: Efficacy and efficiency trade-offs]]>by
<![CDATA[Revisiting Key Schedule's Diffusion In Relation With Round Function's Diffusion]]>by