---
_id: '2047'
abstract:
- lang: eng
  text: Following the publication of an attack on genome-wide association studies
    (GWAS) data proposed by Homer et al., considerable attention has been given to
    developing methods for releasing GWAS data in a privacy-preserving way. Here,
    we develop an end-to-end differentially private method for solving regression
    problems with convex penalty functions and selecting the penalty parameters by
    cross-validation. In particular, we focus on penalized logistic regression with
    elastic-net regularization, a method widely used to in GWAS analyses to identify
    disease-causing genes. We show how a differentially private procedure for penalized
    logistic regression with elastic-net regularization can be applied to the analysis
    of GWAS data and evaluate our method’s performance.
acknowledgement: This research was partially supported by BCS- 0941518 to the Department
  of Statistics at Carnegie Mellon University.
alternative_title:
- LNCS
arxiv: 1
author:
- first_name: Fei
  full_name: Yu, Fei
  last_name: Yu
- first_name: Michal
  full_name: Rybar, Michal
  id: 2B3E3DE8-F248-11E8-B48F-1D18A9856A87
  last_name: Rybar
- first_name: Caroline
  full_name: Uhler, Caroline
  id: 49ADD78E-F248-11E8-B48F-1D18A9856A87
  last_name: Uhler
  orcid: 0000-0002-7008-0216
- first_name: Stephen
  full_name: Fienberg, Stephen
  last_name: Fienberg
citation:
  ama: 'Yu F, Rybar M, Uhler C, Fienberg S. Differentially-private logistic regression
    for detecting multiple-SNP association in GWAS databases. In: Domingo Ferrer J,
    ed. <i>Lecture Notes in Computer Science (Including Subseries Lecture Notes in
    Artificial Intelligence and Lecture Notes in Bioinformatics)</i>. Vol 8744. Springer;
    2014:170-184. doi:<a href="https://doi.org/10.1007/978-3-319-11257-2_14">10.1007/978-3-319-11257-2_14</a>'
  apa: 'Yu, F., Rybar, M., Uhler, C., &#38; Fienberg, S. (2014). Differentially-private
    logistic regression for detecting multiple-SNP association in GWAS databases.
    In J. Domingo Ferrer (Ed.), <i>Lecture Notes in Computer Science (including subseries
    Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)</i>
    (Vol. 8744, pp. 170–184). Ibiza, Spain: Springer. <a href="https://doi.org/10.1007/978-3-319-11257-2_14">https://doi.org/10.1007/978-3-319-11257-2_14</a>'
  chicago: Yu, Fei, Michal Rybar, Caroline Uhler, and Stephen Fienberg. “Differentially-Private
    Logistic Regression for Detecting Multiple-SNP Association in GWAS Databases.”
    In <i>Lecture Notes in Computer Science (Including Subseries Lecture Notes in
    Artificial Intelligence and Lecture Notes in Bioinformatics)</i>, edited by Josep
    Domingo Ferrer, 8744:170–84. Springer, 2014. <a href="https://doi.org/10.1007/978-3-319-11257-2_14">https://doi.org/10.1007/978-3-319-11257-2_14</a>.
  ieee: F. Yu, M. Rybar, C. Uhler, and S. Fienberg, “Differentially-private logistic
    regression for detecting multiple-SNP association in GWAS databases,” in <i>Lecture
    Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence
    and Lecture Notes in Bioinformatics)</i>, Ibiza, Spain, 2014, vol. 8744, pp. 170–184.
  ista: 'Yu F, Rybar M, Uhler C, Fienberg S. 2014. Differentially-private logistic
    regression for detecting multiple-SNP association in GWAS databases. Lecture Notes
    in Computer Science (including subseries Lecture Notes in Artificial Intelligence
    and Lecture Notes in Bioinformatics). PSD: Privacy in Statistical Databases, LNCS,
    vol. 8744, 170–184.'
  mla: Yu, Fei, et al. “Differentially-Private Logistic Regression for Detecting Multiple-SNP
    Association in GWAS Databases.” <i>Lecture Notes in Computer Science (Including
    Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)</i>,
    edited by Josep Domingo Ferrer, vol. 8744, Springer, 2014, pp. 170–84, doi:<a
    href="https://doi.org/10.1007/978-3-319-11257-2_14">10.1007/978-3-319-11257-2_14</a>.
  short: F. Yu, M. Rybar, C. Uhler, S. Fienberg, in:, J. Domingo Ferrer (Ed.), Lecture
    Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence
    and Lecture Notes in Bioinformatics), Springer, 2014, pp. 170–184.
conference:
  end_date: 2014-09-19
  location: Ibiza, Spain
  name: 'PSD: Privacy in Statistical Databases'
  start_date: 2014-09-17
date_created: 2018-12-11T11:55:24Z
date_published: 2014-01-01T00:00:00Z
date_updated: 2024-11-04T13:35:21Z
day: '01'
department:
- _id: KrPi
- _id: CaUh
doi: 10.1007/978-3-319-11257-2_14
editor:
- first_name: Josep
  full_name: Domingo Ferrer, Josep
  last_name: Domingo Ferrer
external_id:
  arxiv:
  - '1407.8067'
intvolume: '      8744'
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: http://arxiv.org/abs/1407.8067
month: '01'
oa: 1
oa_version: Submitted Version
page: 170 - 184
project:
- _id: 25636330-B435-11E9-9278-68D0E5697425
  grant_number: 11-NSF-1070
  name: Genome-wide Analysis of Root Traits
publication: Lecture Notes in Computer Science (including subseries Lecture Notes
  in Artificial Intelligence and Lecture Notes in Bioinformatics)
publication_status: published
publisher: Springer
publist_id: '5004'
quality_controlled: '1'
scopus_import: 1
status: public
title: Differentially-private logistic regression for detecting multiple-SNP association
  in GWAS databases
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 8744
year: '2014'
...
---
_id: '2258'
abstract:
- lang: eng
  text: "In a digital signature scheme with message recovery, rather than transmitting
    the message m and its signature σ, a single enhanced signature τ is transmitted.
    The verifier is able to recover m from τ and at the same time verify its authenticity.
    The two most important parameters of such a scheme are its security and overhead
    |τ| − |m|. A simple argument shows that for any scheme with “n bits security”
    |τ| − |m| ≥ n, i.e., the overhead is lower bounded by the security parameter n.
    Currently, the best known constructions in the random oracle model are far from
    this lower bound requiring an overhead of n + logq h , where q h is the number
    of queries to the random oracle. In this paper we give a construction which basically
    matches the n bit lower bound. We propose a simple digital signature scheme with
    n + o(logq h ) bits overhead, where q h denotes the number of random oracle queries.\r\n\r\nOur
    construction works in two steps. First, we propose a signature scheme with message
    recovery having optimal overhead in a new ideal model, the random invertible function
    model. Second, we show that a four-round Feistel network with random oracles as
    round functions is tightly “public-indifferentiable” from a random invertible
    function. At the core of our indifferentiability proof is an almost tight upper
    bound for the expected number of edges of the densest “small” subgraph of a random
    Cayley graph, which may be of independent interest.\r\n"
alternative_title:
- LNCS
author:
- first_name: Eike
  full_name: Kiltz, Eike
  last_name: Kiltz
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Mario
  full_name: Szegedy, Mario
  last_name: Szegedy
citation:
  ama: Kiltz E, Pietrzak KZ, Szegedy M. Digital signatures with minimal overhead from
    indifferentiable random invertible functions. 2013;8042:571-588. doi:<a href="https://doi.org/10.1007/978-3-642-40041-4_31">10.1007/978-3-642-40041-4_31</a>
  apa: 'Kiltz, E., Pietrzak, K. Z., &#38; Szegedy, M. (2013). Digital signatures with
    minimal overhead from indifferentiable random invertible functions. Presented
    at the CRYPTO: International Cryptology Conference, Santa Barbara, CA, United
    States: Springer. <a href="https://doi.org/10.1007/978-3-642-40041-4_31">https://doi.org/10.1007/978-3-642-40041-4_31</a>'
  chicago: Kiltz, Eike, Krzysztof Z Pietrzak, and Mario Szegedy. “Digital Signatures
    with Minimal Overhead from Indifferentiable Random Invertible Functions.” Lecture
    Notes in Computer Science. Springer, 2013. <a href="https://doi.org/10.1007/978-3-642-40041-4_31">https://doi.org/10.1007/978-3-642-40041-4_31</a>.
  ieee: E. Kiltz, K. Z. Pietrzak, and M. Szegedy, “Digital signatures with minimal
    overhead from indifferentiable random invertible functions,” vol. 8042. Springer,
    pp. 571–588, 2013.
  ista: Kiltz E, Pietrzak KZ, Szegedy M. 2013. Digital signatures with minimal overhead
    from indifferentiable random invertible functions. 8042, 571–588.
  mla: Kiltz, Eike, et al. <i>Digital Signatures with Minimal Overhead from Indifferentiable
    Random Invertible Functions</i>. Vol. 8042, Springer, 2013, pp. 571–88, doi:<a
    href="https://doi.org/10.1007/978-3-642-40041-4_31">10.1007/978-3-642-40041-4_31</a>.
  short: E. Kiltz, K.Z. Pietrzak, M. Szegedy, 8042 (2013) 571–588.
conference:
  end_date: 2013-08-22
  location: Santa Barbara, CA, United States
  name: 'CRYPTO: International Cryptology Conference'
  start_date: 2013-08-18
date_created: 2018-12-11T11:56:37Z
date_published: 2013-01-01T00:00:00Z
date_updated: 2021-01-12T06:56:21Z
day: '01'
ddc:
- '000'
- '004'
department:
- _id: KrPi
doi: 10.1007/978-3-642-40041-4_31
ec_funded: 1
file:
- access_level: open_access
  checksum: 18a3f602cb41de184dc0e16a0e907633
  content_type: application/pdf
  creator: system
  date_created: 2018-12-12T10:09:20Z
  date_updated: 2020-07-14T12:45:35Z
  file_id: '4744'
  file_name: IST-2016-685-v1+1_658.pdf
  file_size: 493175
  relation: main_file
file_date_updated: 2020-07-14T12:45:35Z
has_accepted_license: '1'
intvolume: '      8042'
language:
- iso: eng
month: '01'
oa: 1
oa_version: Submitted Version
page: 571 - 588
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication_status: published
publisher: Springer
publist_id: '4688'
pubrep_id: '685'
quality_controlled: '1'
scopus_import: 1
series_title: Lecture Notes in Computer Science
status: public
title: Digital signatures with minimal overhead from indifferentiable random invertible
  functions
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 8042
year: '2013'
...
---
_id: '2259'
abstract:
- lang: eng
  text: "The learning with rounding (LWR) problem, introduced by Banerjee, Peikert
    and Rosen at EUROCRYPT ’12, is a variant of learning with errors (LWE), where
    one replaces random errors with deterministic rounding. The LWR problem was shown
    to be as hard as LWE for a setting of parameters where the modulus and modulus-to-error
    ratio are super-polynomial. In this work we resolve the main open problem and
    give a new reduction that works for a larger range of parameters, allowing for
    a polynomial modulus and modulus-to-error ratio. In particular, a smaller modulus
    gives us greater efficiency, and a smaller modulus-to-error ratio gives us greater
    security, which now follows from the worst-case hardness of GapSVP with polynomial
    (rather than super-polynomial) approximation factors.\r\n\r\nAs a tool in the
    reduction, we show that there is a “lossy mode” for the LWR problem, in which
    LWR samples only reveal partial information about the secret. This property gives
    us several interesting new applications, including a proof that LWR remains secure
    with weakly random secrets of sufficient min-entropy, and very simple constructions
    of deterministic encryption, lossy trapdoor functions and reusable extractors.\r\n\r\nOur
    approach is inspired by a technique of Goldwasser et al. from ICS ’10, which implicitly
    showed the existence of a “lossy mode” for LWE. By refining this technique, we
    also improve on the parameters of that work to only requiring a polynomial (instead
    of super-polynomial) modulus and modulus-to-error ratio.\r\n"
alternative_title:
- LNCS
author:
- first_name: Joel F
  full_name: Alwen, Joel F
  id: 2A8DFA8C-F248-11E8-B48F-1D18A9856A87
  last_name: Alwen
- first_name: Stephan
  full_name: Krenn, Stephan
  id: 329FCCF0-F248-11E8-B48F-1D18A9856A87
  last_name: Krenn
  orcid: 0000-0003-2835-9093
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Daniel
  full_name: Wichs, Daniel
  last_name: Wichs
citation:
  ama: 'Alwen JF, Krenn S, Pietrzak KZ, Wichs D. Learning with rounding, revisited:
    New reduction properties and applications. 2013;8042(1):57-74. doi:<a href="https://doi.org/10.1007/978-3-642-40041-4_4">10.1007/978-3-642-40041-4_4</a>'
  apa: 'Alwen, J. F., Krenn, S., Pietrzak, K. Z., &#38; Wichs, D. (2013). Learning
    with rounding, revisited: New reduction properties and applications. Presented
    at the CRYPTO: International Cryptology Conference, Santa Barbara, CA, United
    States: Springer. <a href="https://doi.org/10.1007/978-3-642-40041-4_4">https://doi.org/10.1007/978-3-642-40041-4_4</a>'
  chicago: 'Alwen, Joel F, Stephan Krenn, Krzysztof Z Pietrzak, and Daniel Wichs.
    “Learning with Rounding, Revisited: New Reduction Properties and Applications.”
    Lecture Notes in Computer Science. Springer, 2013. <a href="https://doi.org/10.1007/978-3-642-40041-4_4">https://doi.org/10.1007/978-3-642-40041-4_4</a>.'
  ieee: 'J. F. Alwen, S. Krenn, K. Z. Pietrzak, and D. Wichs, “Learning with rounding,
    revisited: New reduction properties and applications,” vol. 8042, no. 1. Springer,
    pp. 57–74, 2013.'
  ista: 'Alwen JF, Krenn S, Pietrzak KZ, Wichs D. 2013. Learning with rounding, revisited:
    New reduction properties and applications. 8042(1), 57–74.'
  mla: 'Alwen, Joel F., et al. <i>Learning with Rounding, Revisited: New Reduction
    Properties and Applications</i>. Vol. 8042, no. 1, Springer, 2013, pp. 57–74,
    doi:<a href="https://doi.org/10.1007/978-3-642-40041-4_4">10.1007/978-3-642-40041-4_4</a>.'
  short: J.F. Alwen, S. Krenn, K.Z. Pietrzak, D. Wichs, 8042 (2013) 57–74.
conference:
  end_date: 2013-08-22
  location: Santa Barbara, CA, United States
  name: 'CRYPTO: International Cryptology Conference'
  start_date: 2013-08-18
date_created: 2018-12-11T11:56:37Z
date_published: 2013-01-01T00:00:00Z
date_updated: 2021-01-12T06:56:21Z
day: '01'
ddc:
- '000'
- '004'
department:
- _id: KrPi
doi: 10.1007/978-3-642-40041-4_4
ec_funded: 1
file:
- access_level: open_access
  checksum: 16d428408a806b8e49eecc607deab115
  content_type: application/pdf
  creator: system
  date_created: 2018-12-12T10:11:55Z
  date_updated: 2020-07-14T12:45:35Z
  file_id: '4912'
  file_name: IST-2016-684-v1+1_098.pdf
  file_size: 587898
  relation: main_file
file_date_updated: 2020-07-14T12:45:35Z
has_accepted_license: '1'
intvolume: '      8042'
issue: '1'
language:
- iso: eng
month: '01'
oa: 1
oa_version: Published Version
page: 57 - 74
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication_status: published
publisher: Springer
publist_id: '4687'
pubrep_id: '684'
quality_controlled: '1'
scopus_import: 1
series_title: Lecture Notes in Computer Science
status: public
title: 'Learning with rounding, revisited: New reduction properties and applications'
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 8042
year: '2013'
...
---
_id: '2260'
abstract:
- lang: eng
  text: "Direct Anonymous Attestation (DAA) is one of the most complex cryptographic
    protocols deployed in practice. It allows an embedded secure processor known as
    a Trusted Platform Module (TPM) to attest to the configuration of its host computer
    without violating the owner’s privacy. DAA has been standardized by the Trusted
    Computing Group and ISO/IEC.\r\n\r\nThe security of the DAA standard and all existing
    schemes is analyzed in the random-oracle model. We provide the first constructions
    of DAA in the standard model, that is, without relying on random oracles. Our
    constructions use new building blocks, including the first efficient signatures
    of knowledge in the standard model, which have many applications beyond DAA.\r\n"
alternative_title:
- LNCS
article_processing_charge: No
author:
- first_name: David
  full_name: Bernhard, David
  last_name: Bernhard
- first_name: Georg
  full_name: Fuchsbauer, Georg
  id: 46B4C3EE-F248-11E8-B48F-1D18A9856A87
  last_name: Fuchsbauer
- first_name: Essam
  full_name: Ghadafi, Essam
  last_name: Ghadafi
citation:
  ama: Bernhard D, Fuchsbauer G, Ghadafi E. Efficient signatures of knowledge and
    DAA in the standard model. 2013;7954:518-533. doi:<a href="https://doi.org/10.1007/978-3-642-38980-1_33">10.1007/978-3-642-38980-1_33</a>
  apa: 'Bernhard, D., Fuchsbauer, G., &#38; Ghadafi, E. (2013). Efficient signatures
    of knowledge and DAA in the standard model. Presented at the ACNS: Applied Cryptography
    and Network Security, Banff, AB, Canada: Springer. <a href="https://doi.org/10.1007/978-3-642-38980-1_33">https://doi.org/10.1007/978-3-642-38980-1_33</a>'
  chicago: Bernhard, David, Georg Fuchsbauer, and Essam Ghadafi. “Efficient Signatures
    of Knowledge and DAA in the Standard Model.” Lecture Notes in Computer Science.
    Springer, 2013. <a href="https://doi.org/10.1007/978-3-642-38980-1_33">https://doi.org/10.1007/978-3-642-38980-1_33</a>.
  ieee: D. Bernhard, G. Fuchsbauer, and E. Ghadafi, “Efficient signatures of knowledge
    and DAA in the standard model,” vol. 7954. Springer, pp. 518–533, 2013.
  ista: Bernhard D, Fuchsbauer G, Ghadafi E. 2013. Efficient signatures of knowledge
    and DAA in the standard model. 7954, 518–533.
  mla: Bernhard, David, et al. <i>Efficient Signatures of Knowledge and DAA in the
    Standard Model</i>. Vol. 7954, Springer, 2013, pp. 518–33, doi:<a href="https://doi.org/10.1007/978-3-642-38980-1_33">10.1007/978-3-642-38980-1_33</a>.
  short: D. Bernhard, G. Fuchsbauer, E. Ghadafi, 7954 (2013) 518–533.
conference:
  end_date: 2013-06-28
  location: Banff, AB, Canada
  name: 'ACNS: Applied Cryptography and Network Security'
  start_date: 2013-06-25
cryptoeprintid: 1
das_tickbox: '1'
date_created: 2018-12-11T11:56:37Z
date_published: 2013-06-01T00:00:00Z
date_updated: 2026-06-22T14:11:25Z
day: '01'
department:
- _id: KrPi
doi: 10.1007/978-3-642-38980-1_33
external_id:
  cryptoeprintid:
  - 2012/475
intvolume: '      7954'
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: http://eprint.iacr.org/2012/475
month: '06'
oa: 1
oa_version: Submitted Version
page: 518 - 533
publication_status: published
publisher: Springer
publist_id: '4686'
quality_controlled: '1'
scopus_import: '1'
series_title: Lecture Notes in Computer Science
status: public
title: Efficient signatures of knowledge and DAA in the standard model
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 7954
year: '2013'
...
---
_id: '2274'
abstract:
- lang: eng
  text: "Proofs of work (PoW) have been suggested by Dwork and Naor (Crypto'92) as
    protection to a shared resource. The basic idea is to ask the service requestor
    to dedicate some non-trivial amount of computational work to every request. The
    original applications included prevention of spam and protection against denial
    of service attacks. More recently, PoWs have been used to prevent double spending
    in the Bitcoin digital currency system.\r\n\r\nIn this work, we put forward an
    alternative concept for PoWs -- so-called proofs of space (PoS), where a service
    requestor must dedicate a significant amount of disk space as opposed to computation.
    We construct secure PoS schemes in the random oracle model, using graphs with
    high &quot;pebbling complexity&quot; and Merkle hash-trees. "
author:
- first_name: Stefan
  full_name: Dziembowski, Stefan
  last_name: Dziembowski
- first_name: Sebastian
  full_name: Faust, Sebastian
  last_name: Faust
- first_name: Vladimir
  full_name: Kolmogorov, Vladimir
  id: 3D50B0BA-F248-11E8-B48F-1D18A9856A87
  last_name: Kolmogorov
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
citation:
  ama: Dziembowski S, Faust S, Kolmogorov V, Pietrzak KZ. <i>Proofs of Space</i>.
    IST Austria; 2013.
  apa: Dziembowski, S., Faust, S., Kolmogorov, V., &#38; Pietrzak, K. Z. (2013). <i>Proofs
    of Space</i>. IST Austria.
  chicago: Dziembowski, Stefan, Sebastian Faust, Vladimir Kolmogorov, and Krzysztof
    Z Pietrzak. <i>Proofs of Space</i>. IST Austria, 2013.
  ieee: S. Dziembowski, S. Faust, V. Kolmogorov, and K. Z. Pietrzak, <i>Proofs of
    Space</i>. IST Austria, 2013.
  ista: Dziembowski S, Faust S, Kolmogorov V, Pietrzak KZ. 2013. Proofs of Space,
    IST Austria,p.
  mla: Dziembowski, Stefan, et al. <i>Proofs of Space</i>. IST Austria, 2013.
  short: S. Dziembowski, S. Faust, V. Kolmogorov, K.Z. Pietrzak, Proofs of Space,
    IST Austria, 2013.
date_created: 2018-12-11T11:56:42Z
date_published: 2013-11-28T00:00:00Z
date_updated: 2025-09-23T09:55:25Z
day: '28'
ddc:
- '530'
department:
- _id: VlKo
- _id: KrPi
file:
- access_level: open_access
  checksum: 37b61637b62fc079d9141c59d9f1a94f
  content_type: application/pdf
  creator: system
  date_created: 2018-12-12T10:16:11Z
  date_updated: 2020-07-14T12:45:36Z
  file_id: '5197'
  file_name: IST-2016-671-v1+1_796.pdf
  file_size: 405870
  relation: main_file
file_date_updated: 2020-07-14T12:45:36Z
has_accepted_license: '1'
language:
- iso: eng
month: '11'
oa: 1
oa_version: Published Version
publication_status: published
publisher: IST Austria
publist_id: '4670'
pubrep_id: '671'
related_material:
  record:
  - id: '1675'
    relation: later_version
    status: public
scopus_import: 1
status: public
title: Proofs of Space
type: report
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
year: '2013'
...
---
_id: '2291'
abstract:
- lang: eng
  text: "Cryptographic access control promises to offer easily distributed trust and
    broader applicability, while reducing reliance on low-level online monitors. Traditional
    implementations of cryptographic access control rely on simple cryptographic primitives
    whereas recent endeavors employ primitives with richer functionality and security
    guarantees. Worryingly, few of the existing cryptographic access-control schemes
    come with precise guarantees, the gap between the policy specification and the
    implementation being analyzed only informally, if at all. In this paper we begin
    addressing this shortcoming. Unlike prior work that targeted ad-hoc policy specification,
    we look at the well-established Role-Based Access Control (RBAC) model, as used
    in a typical file system. In short, we provide a precise syntax for a computational
    version of RBAC, offer rigorous definitions for cryptographic policy enforcement
    of a large class of RBAC security policies, and demonstrate that an implementation
    based on attribute-based encryption meets our security notions. We view our main
    contribution as being at the conceptual level. Although we work with RBAC for
    concreteness, our general methodology could guide future research for uses of
    cryptography in other access-control models. \r\n"
article_processing_charge: No
author:
- first_name: Anna
  full_name: Ferrara, Anna
  last_name: Ferrara
- first_name: Georg
  full_name: Fuchsbauer, Georg
  id: 46B4C3EE-F248-11E8-B48F-1D18A9856A87
  last_name: Fuchsbauer
- first_name: Bogdan
  full_name: Warinschi, Bogdan
  last_name: Warinschi
citation:
  ama: 'Ferrara A, Fuchsbauer G, Warinschi B. Cryptographically enforced RBAC. In:
    IEEE; 2013:115-129. doi:<a href="https://doi.org/10.1109/CSF.2013.15">10.1109/CSF.2013.15</a>'
  apa: 'Ferrara, A., Fuchsbauer, G., &#38; Warinschi, B. (2013). Cryptographically
    enforced RBAC (pp. 115–129). Presented at the CSF: Computer Security Foundations,
    New Orleans, LA, United States: IEEE. <a href="https://doi.org/10.1109/CSF.2013.15">https://doi.org/10.1109/CSF.2013.15</a>'
  chicago: Ferrara, Anna, Georg Fuchsbauer, and Bogdan Warinschi. “Cryptographically
    Enforced RBAC,” 115–29. IEEE, 2013. <a href="https://doi.org/10.1109/CSF.2013.15">https://doi.org/10.1109/CSF.2013.15</a>.
  ieee: 'A. Ferrara, G. Fuchsbauer, and B. Warinschi, “Cryptographically enforced
    RBAC,” presented at the CSF: Computer Security Foundations, New Orleans, LA, United
    States, 2013, pp. 115–129.'
  ista: 'Ferrara A, Fuchsbauer G, Warinschi B. 2013. Cryptographically enforced RBAC.
    CSF: Computer Security Foundations, 115–129.'
  mla: Ferrara, Anna, et al. <i>Cryptographically Enforced RBAC</i>. IEEE, 2013, pp.
    115–29, doi:<a href="https://doi.org/10.1109/CSF.2013.15">10.1109/CSF.2013.15</a>.
  short: A. Ferrara, G. Fuchsbauer, B. Warinschi, in:, IEEE, 2013, pp. 115–129.
conference:
  end_date: 2013-09-28
  location: New Orleans, LA, United States
  name: 'CSF: Computer Security Foundations'
  start_date: 2013-09-26
cryptoeprintid: 1
das_tickbox: '1'
date_created: 2018-12-11T11:56:48Z
date_published: 2013-09-01T00:00:00Z
date_updated: 2026-06-22T14:11:49Z
day: '01'
department:
- _id: KrPi
doi: 10.1109/CSF.2013.15
external_id:
  cryptoeprintid:
  - 2013/492
  isi:
  - '000335225600008'
isi: 1
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: http://eprint.iacr.org/2013/492
month: '09'
oa: 1
oa_version: Submitted Version
page: 115 - 129
publication_status: published
publisher: IEEE
publist_id: '4637'
quality_controlled: '1'
scopus_import: '1'
status: public
title: Cryptographically enforced RBAC
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
year: '2013'
...
---
_id: '2940'
abstract:
- lang: eng
  text: "A chain rule for an entropy notion H(.) states that the entropy H(X) of a
    variable X decreases by at most l if conditioned on an l-bit string A, i.e., H(X|A)&gt;=
    H(X)-l. More generally, it satisfies a chain rule for conditional entropy if H(X|Y,A)&gt;=
    H(X|Y)-l.\r\n\r\nAll natural information theoretic entropy notions we are aware
    of (like Shannon or min-entropy) satisfy some kind of chain rule for conditional
    entropy. Moreover, many computational entropy notions (like Yao entropy, unpredictability
    entropy and several variants of HILL entropy) satisfy the chain rule for conditional
    entropy, though here not only the quantity decreases by l, but also the quality
    of the entropy decreases exponentially in l. However, for \r\nthe standard notion
    of conditional HILL entropy (the computational equivalent of min-entropy) the
    existence of such a rule was unknown so far.\r\n\r\nIn this paper, we prove that
    for conditional HILL entropy no meaningful chain rule exists, assuming the existence
    of one-way permutations: there exist distributions X,Y,A, where A is a distribution
    over a single bit, but  $H(X|Y)&gt;&gt;H(X|Y,A)$, even if we simultaneously allow
    for a massive degradation in the quality of the entropy.\r\n\r\nThe idea underlying
    our construction is based on a surprising connection between the chain rule for
    HILL entropy and deniable encryption. "
alternative_title:
- LNCS
author:
- first_name: Stephan
  full_name: Krenn, Stephan
  id: 329FCCF0-F248-11E8-B48F-1D18A9856A87
  last_name: Krenn
  orcid: 0000-0003-2835-9093
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Akshay
  full_name: Wadia, Akshay
  last_name: Wadia
citation:
  ama: 'Krenn S, Pietrzak KZ, Wadia A. A counterexample to the chain rule for conditional
    HILL entropy, and what deniable encryption has to do with it. In: Sahai A, ed.
    Vol 7785. Springer; 2013:23-39. doi:<a href="https://doi.org/10.1007/978-3-642-36594-2_2">10.1007/978-3-642-36594-2_2</a>'
  apa: 'Krenn, S., Pietrzak, K. Z., &#38; Wadia, A. (2013). A counterexample to the
    chain rule for conditional HILL entropy, and what deniable encryption has to do
    with it. In A. Sahai (Ed.) (Vol. 7785, pp. 23–39). Presented at the TCC: Theory
    of Cryptography Conference, Tokyo, Japan: Springer. <a href="https://doi.org/10.1007/978-3-642-36594-2_2">https://doi.org/10.1007/978-3-642-36594-2_2</a>'
  chicago: Krenn, Stephan, Krzysztof Z Pietrzak, and Akshay Wadia. “A Counterexample
    to the Chain Rule for Conditional HILL Entropy, and What Deniable Encryption Has
    to Do with It.” edited by Amit Sahai, 7785:23–39. Springer, 2013. <a href="https://doi.org/10.1007/978-3-642-36594-2_2">https://doi.org/10.1007/978-3-642-36594-2_2</a>.
  ieee: 'S. Krenn, K. Z. Pietrzak, and A. Wadia, “A counterexample to the chain rule
    for conditional HILL entropy, and what deniable encryption has to do with it,”
    presented at the TCC: Theory of Cryptography Conference, Tokyo, Japan, 2013, vol.
    7785, pp. 23–39.'
  ista: 'Krenn S, Pietrzak KZ, Wadia A. 2013. A counterexample to the chain rule for
    conditional HILL entropy, and what deniable encryption has to do with it. TCC:
    Theory of Cryptography Conference, LNCS, vol. 7785, 23–39.'
  mla: Krenn, Stephan, et al. <i>A Counterexample to the Chain Rule for Conditional
    HILL Entropy, and What Deniable Encryption Has to Do with It</i>. Edited by Amit
    Sahai, vol. 7785, Springer, 2013, pp. 23–39, doi:<a href="https://doi.org/10.1007/978-3-642-36594-2_2">10.1007/978-3-642-36594-2_2</a>.
  short: S. Krenn, K.Z. Pietrzak, A. Wadia, in:, A. Sahai (Ed.), Springer, 2013, pp.
    23–39.
conference:
  end_date: 2013-03-06
  location: Tokyo, Japan
  name: 'TCC: Theory of Cryptography Conference'
  start_date: 2013-03-03
date_created: 2018-12-11T12:00:27Z
date_published: 2013-01-29T00:00:00Z
date_updated: 2025-09-18T11:37:22Z
day: '29'
ddc:
- '000'
department:
- _id: KrPi
doi: 10.1007/978-3-642-36594-2_2
ec_funded: 1
editor:
- first_name: Amit
  full_name: Sahai, Amit
  last_name: Sahai
file:
- access_level: open_access
  checksum: beb0cc1c0579da2d2e84394230a5da78
  content_type: application/pdf
  creator: dernst
  date_created: 2019-01-22T14:11:11Z
  date_updated: 2020-07-14T12:45:54Z
  file_id: '5875'
  file_name: 2013_LNCS_Krenn.pdf
  file_size: 414823
  relation: main_file
file_date_updated: 2020-07-14T12:45:54Z
has_accepted_license: '1'
intvolume: '      7785'
language:
- iso: eng
month: '01'
oa: 1
oa_version: Submitted Version
page: 23 - 39
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication_status: published
publisher: Springer
publist_id: '3795'
quality_controlled: '1'
related_material:
  record:
  - id: '1479'
    relation: later_version
    status: public
scopus_import: 1
status: public
title: A counterexample to the chain rule for conditional HILL entropy, and what deniable
  encryption has to do with it
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 7785
year: '2013'
...
---
_id: '502'
abstract:
- lang: eng
  text: 'Blind signatures allow users to obtain signatures on messages hidden from
    the signer; moreover, the signer cannot link the resulting message/signature pair
    to the signing session. This paper presents blind signature schemes, in which
    the number of interactions between the user and the signer is minimal and whose
    blind signatures are short. Our schemes are defined over bilinear groups and are
    proved secure in the common-reference-string model without random oracles and
    under standard assumptions: CDH and the decision-linear assumption. (We also give
    variants over asymmetric groups based on similar assumptions.) The blind signatures
    are Waters signatures, which consist of 2 group elements. Moreover, we instantiate
    partially blind signatures, where the message consists of a part hidden from the
    signer and a commonly known public part, and schemes achieving perfect blindness.
    We propose new variants of blind signatures, such as signer-friendly partially
    blind signatures, where the public part can be chosen by the signer without prior
    agreement, 3-party blind signatures, as well as blind signatures on multiple aggregated
    messages provided by independent sources. We also extend Waters signatures to
    non-binary alphabets by proving a new result on the underlying hash function. '
author:
- first_name: Olivier
  full_name: Blazy, Olivier
  last_name: Blazy
- first_name: Georg
  full_name: Fuchsbauer, Georg
  id: 46B4C3EE-F248-11E8-B48F-1D18A9856A87
  last_name: Fuchsbauer
- first_name: David
  full_name: Pointcheval, David
  last_name: Pointcheval
- first_name: Damien
  full_name: Vergnaud, Damien
  last_name: Vergnaud
citation:
  ama: Blazy O, Fuchsbauer G, Pointcheval D, Vergnaud D. Short blind signatures. <i>Journal
    of Computer Security</i>. 2013;21(5):627-661. doi:<a href="https://doi.org/10.3233/JCS-130477">10.3233/JCS-130477</a>
  apa: Blazy, O., Fuchsbauer, G., Pointcheval, D., &#38; Vergnaud, D. (2013). Short
    blind signatures. <i>Journal of Computer Security</i>. IOS Press. <a href="https://doi.org/10.3233/JCS-130477">https://doi.org/10.3233/JCS-130477</a>
  chicago: Blazy, Olivier, Georg Fuchsbauer, David Pointcheval, and Damien Vergnaud.
    “Short Blind Signatures.” <i>Journal of Computer Security</i>. IOS Press, 2013.
    <a href="https://doi.org/10.3233/JCS-130477">https://doi.org/10.3233/JCS-130477</a>.
  ieee: O. Blazy, G. Fuchsbauer, D. Pointcheval, and D. Vergnaud, “Short blind signatures,”
    <i>Journal of Computer Security</i>, vol. 21, no. 5. IOS Press, pp. 627–661, 2013.
  ista: Blazy O, Fuchsbauer G, Pointcheval D, Vergnaud D. 2013. Short blind signatures.
    Journal of Computer Security. 21(5), 627–661.
  mla: Blazy, Olivier, et al. “Short Blind Signatures.” <i>Journal of Computer Security</i>,
    vol. 21, no. 5, IOS Press, 2013, pp. 627–61, doi:<a href="https://doi.org/10.3233/JCS-130477">10.3233/JCS-130477</a>.
  short: O. Blazy, G. Fuchsbauer, D. Pointcheval, D. Vergnaud, Journal of Computer
    Security 21 (2013) 627–661.
date_created: 2018-12-11T11:46:50Z
date_published: 2013-11-22T00:00:00Z
date_updated: 2021-01-12T08:01:09Z
day: '22'
department:
- _id: KrPi
doi: 10.3233/JCS-130477
intvolume: '        21'
issue: '5'
language:
- iso: eng
month: '11'
oa_version: None
page: 627 - 661
publication: Journal of Computer Security
publication_status: published
publisher: IOS Press
publist_id: '7318'
quality_controlled: '1'
scopus_import: 1
status: public
title: Short blind signatures
type: journal_article
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 21
year: '2013'
...
---
_id: '2937'
abstract:
- lang: eng
  text: Developers building cryptography into security-sensitive applications face
    a daunting task. Not only must they understand the security guarantees delivered
    by the constructions they choose, they must also implement and combine them correctly
    and efficiently. Cryptographic compilers free developers from this task by turning
    high-level specifications of security goals into efficient implementations. Yet,
    trusting such tools is hard as they rely on complex mathematical machinery and
    claim security properties that are subtle and difficult to verify. In this paper
    we present ZKCrypt, an optimizing cryptographic compiler achieving an unprecedented
    level of assurance without sacrificing practicality for a comprehensive class
    of cryptographic protocols, known as Zero-Knowledge Proofs of Knowledge. The pipeline
    of ZKCrypt integrates purpose-built verified compilers and verifying compilers
    producing formal proofs in the CertiCrypt framework. By combining the guarantees
    delivered by each stage, ZKCrypt provides assurance that the output implementation
    securely realizes the abstract proof goal given as input. We report on the main
    characteristics of ZKCrypt, highlight new definitions and concepts at its foundations,
    and illustrate its applicability through a representative example of an anonymous
    credential system.
acknowledgement: This work was partially funded by National Funds through the FCT
  - Fundação para a Ciência e a Tecnologia (Portuguese Foundation for Science and
  Technology) within project ENI-AC/2224/2009, by ENIAC Joint Undertaking under grant
  agreement number 120224, European Projects FP7-256980 NESSoS and FP7-229599 AMAROUT,
  Spanish National project TIN2009-14599 DESAFIOS 10, and Madrid Regional project
  S2009TIC-1465 PROMETIDOS.
article_processing_charge: No
author:
- first_name: José
  full_name: Almeida, José
  last_name: Almeida
- first_name: Manuel
  full_name: Barbosa, Manuel
  last_name: Barbosa
- first_name: Endre
  full_name: Bangerter, Endre
  last_name: Bangerter
- first_name: Gilles
  full_name: Barthe, Gilles
  last_name: Barthe
- first_name: Stephan
  full_name: Krenn, Stephan
  id: 329FCCF0-F248-11E8-B48F-1D18A9856A87
  last_name: Krenn
  orcid: 0000-0003-2835-9093
- first_name: Santiago
  full_name: Béguelin, Santiago
  last_name: Béguelin
citation:
  ama: 'Almeida J, Barbosa M, Bangerter E, Barthe G, Krenn S, Béguelin S. Full proof
    cryptography: Verifiable compilation of efficient zero-knowledge protocols. In:
    <i>Proceedings of the 2012 ACM Conference on Computer and Communications Security</i>.
    ACM; 2012:488-500. doi:<a href="https://doi.org/10.1145/2382196.2382249">10.1145/2382196.2382249</a>'
  apa: 'Almeida, J., Barbosa, M., Bangerter, E., Barthe, G., Krenn, S., &#38; Béguelin,
    S. (2012). Full proof cryptography: Verifiable compilation of efficient zero-knowledge
    protocols. In <i>Proceedings of the 2012 ACM conference on Computer and communications
    security</i> (pp. 488–500). Raleigh, NC, USA: ACM. <a href="https://doi.org/10.1145/2382196.2382249">https://doi.org/10.1145/2382196.2382249</a>'
  chicago: 'Almeida, José, Manuel Barbosa, Endre Bangerter, Gilles Barthe, Stephan
    Krenn, and Santiago Béguelin. “Full Proof Cryptography: Verifiable Compilation
    of Efficient Zero-Knowledge Protocols.” In <i>Proceedings of the 2012 ACM Conference
    on Computer and Communications Security</i>, 488–500. ACM, 2012. <a href="https://doi.org/10.1145/2382196.2382249">https://doi.org/10.1145/2382196.2382249</a>.'
  ieee: 'J. Almeida, M. Barbosa, E. Bangerter, G. Barthe, S. Krenn, and S. Béguelin,
    “Full proof cryptography: Verifiable compilation of efficient zero-knowledge protocols,”
    in <i>Proceedings of the 2012 ACM conference on Computer and communications security</i>,
    Raleigh, NC, USA, 2012, pp. 488–500.'
  ista: 'Almeida J, Barbosa M, Bangerter E, Barthe G, Krenn S, Béguelin S. 2012. Full
    proof cryptography: Verifiable compilation of efficient zero-knowledge protocols.
    Proceedings of the 2012 ACM conference on Computer and communications security.
    CCS: Conference on Computer and Communications Security, 488–500.'
  mla: 'Almeida, José, et al. “Full Proof Cryptography: Verifiable Compilation of
    Efficient Zero-Knowledge Protocols.” <i>Proceedings of the 2012 ACM Conference
    on Computer and Communications Security</i>, ACM, 2012, pp. 488–500, doi:<a href="https://doi.org/10.1145/2382196.2382249">10.1145/2382196.2382249</a>.'
  short: J. Almeida, M. Barbosa, E. Bangerter, G. Barthe, S. Krenn, S. Béguelin, in:,
    Proceedings of the 2012 ACM Conference on Computer and Communications Security,
    ACM, 2012, pp. 488–500.
conference:
  end_date: 2012-10-18
  location: Raleigh, NC, USA
  name: 'CCS: Conference on Computer and Communications Security'
  start_date: 2012-10-16
date_created: 2018-12-11T12:00:26Z
date_published: 2012-10-01T00:00:00Z
date_updated: 2025-07-10T11:52:23Z
day: '01'
department:
- _id: KrPi
doi: 10.1145/2382196.2382249
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://eprint.iacr.org/2012/258
month: '10'
oa: 1
oa_version: Submitted Version
page: 488 - 500
publication: Proceedings of the 2012 ACM conference on Computer and communications
  security
publication_status: published
publisher: ACM
publist_id: '3798'
quality_controlled: '1'
scopus_import: '1'
status: public
title: 'Full proof cryptography: Verifiable compilation of efficient zero-knowledge
  protocols'
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
year: '2012'
...
---
_id: '2974'
abstract:
- lang: eng
  text: "We construct a perfectly binding string commitment scheme whose security
    is based on the learning parity with noise (LPN) assumption, or equivalently,
    the hardness of decoding random linear codes. Our scheme not only allows for a
    simple and efficient zero-knowledge proof of knowledge for committed values (essentially
    a Σ-protocol), but also for such proofs showing any kind of relation amongst committed
    values, i.e. proving that messages m_0,...,m_u, are such that m_0=C(m_1,...,m_u)
    for any circuit C.\r\n\r\nTo get soundness which is exponentially small in a security
    parameter t, and when the zero-knowledge property relies on the LPN problem with
    secrets of length l, our 3 round protocol has communication complexity O(t|C|l
    log(l)) and computational complexity of O(t|C|l) bit operations. The hidden constants
    are small, and the computation consists mostly of computing inner products of
    bit-vectors."
acknowledgement: "We are grateful to Petros Mol for helpful discussions on the reduction
  for the hardness of the xLPN problem.\r\n"
alternative_title:
- LNCS
author:
- first_name: Abhishek
  full_name: Jain, Abhishek
  last_name: Jain
- first_name: Stephan
  full_name: Krenn, Stephan
  id: 329FCCF0-F248-11E8-B48F-1D18A9856A87
  last_name: Krenn
  orcid: 0000-0003-2835-9093
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Aris
  full_name: Tentes, Aris
  last_name: Tentes
citation:
  ama: 'Jain A, Krenn S, Pietrzak KZ, Tentes A. Commitments and efficient zero knowledge
    proofs from learning parity with noise. In: Wang X, Sako K, eds. Vol 7658. Springer;
    2012:663-680. doi:<a href="https://doi.org/10.1007/978-3-642-34961-4_40">10.1007/978-3-642-34961-4_40</a>'
  apa: 'Jain, A., Krenn, S., Pietrzak, K. Z., &#38; Tentes, A. (2012). Commitments
    and efficient zero knowledge proofs from learning parity with noise. In X. Wang
    &#38; K. Sako (Eds.) (Vol. 7658, pp. 663–680). Presented at the ASIACRYPT: Theory
    and Application of Cryptology and Information Security, Beijing, China: Springer.
    <a href="https://doi.org/10.1007/978-3-642-34961-4_40">https://doi.org/10.1007/978-3-642-34961-4_40</a>'
  chicago: Jain, Abhishek, Stephan Krenn, Krzysztof Z Pietrzak, and Aris Tentes. “Commitments
    and Efficient Zero Knowledge Proofs from Learning Parity with Noise.” edited by
    Xiaoyun Wang and Kazue Sako, 7658:663–80. Springer, 2012. <a href="https://doi.org/10.1007/978-3-642-34961-4_40">https://doi.org/10.1007/978-3-642-34961-4_40</a>.
  ieee: 'A. Jain, S. Krenn, K. Z. Pietrzak, and A. Tentes, “Commitments and efficient
    zero knowledge proofs from learning parity with noise,” presented at the ASIACRYPT:
    Theory and Application of Cryptology and Information Security, Beijing, China,
    2012, vol. 7658, pp. 663–680.'
  ista: 'Jain A, Krenn S, Pietrzak KZ, Tentes A. 2012. Commitments and efficient zero
    knowledge proofs from learning parity with noise. ASIACRYPT: Theory and Application
    of Cryptology and Information Security, LNCS, vol. 7658, 663–680.'
  mla: Jain, Abhishek, et al. <i>Commitments and Efficient Zero Knowledge Proofs from
    Learning Parity with Noise</i>. Edited by Xiaoyun Wang and Kazue Sako, vol. 7658,
    Springer, 2012, pp. 663–80, doi:<a href="https://doi.org/10.1007/978-3-642-34961-4_40">10.1007/978-3-642-34961-4_40</a>.
  short: A. Jain, S. Krenn, K.Z. Pietrzak, A. Tentes, in:, X. Wang, K. Sako (Eds.),
    Springer, 2012, pp. 663–680.
conference:
  end_date: 2012-12-06
  location: Beijing, China
  name: 'ASIACRYPT: Theory and Application of Cryptology and Information Security'
  start_date: 2012-12-02
date_created: 2018-12-11T12:00:38Z
date_published: 2012-12-01T00:00:00Z
date_updated: 2021-01-12T07:40:11Z
day: '01'
ddc:
- '004'
- '005'
department:
- _id: KrPi
doi: 10.1007/978-3-642-34961-4_40
ec_funded: 1
editor:
- first_name: Xiaoyun
  full_name: Wang, Xiaoyun
  last_name: Wang
- first_name: Kazue
  full_name: Sako, Kazue
  last_name: Sako
file:
- access_level: open_access
  checksum: ab879537385efc4cb4203e7ef0fea17b
  content_type: application/pdf
  creator: system
  date_created: 2018-12-12T10:14:00Z
  date_updated: 2020-07-14T12:45:58Z
  file_id: '5048'
  file_name: IST-2016-721-v1+1_513.pdf
  file_size: 482570
  relation: main_file
file_date_updated: 2020-07-14T12:45:58Z
has_accepted_license: '1'
intvolume: '      7658'
language:
- iso: eng
month: '12'
oa: 1
oa_version: Submitted Version
page: 663 - 680
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication_status: published
publisher: Springer
publist_id: '3730'
pubrep_id: '721'
scopus_import: 1
status: public
title: Commitments and efficient zero knowledge proofs from learning parity with noise
tmp:
  image: /images/cc_by.png
  legal_code_url: https://creativecommons.org/licenses/by/4.0/legalcode
  name: Creative Commons Attribution 4.0 International Public License (CC-BY 4.0)
  short: CC BY (4.0)
type: conference
user_id: 3E5EF7F0-F248-11E8-B48F-1D18A9856A87
volume: 7658
year: '2012'
...
---
_id: '3250'
abstract:
- lang: eng
  text: The Learning Parity with Noise (LPN) problem has recently found many applications
    in cryptography as the hardness assumption underlying the constructions of &quot;provably
    secure&quot; cryptographic schemes like encryption or authentication protocols.
    Being provably secure means that the scheme comes with a proof showing that the
    existence of an efficient adversary against the scheme implies that the underlying
    hardness assumption is wrong. LPN based schemes are appealing for theoretical
    and practical reasons. On the theoretical side, LPN based schemes offer a very
    strong security guarantee. The LPN problem is equivalent to the problem of decoding
    random linear codes, a problem that has been extensively studied in the last half
    century. The fastest known algorithms run in exponential time and unlike most
    number-theoretic problems used in cryptography, the LPN problem does not succumb
    to known quantum algorithms. On the practical side, LPN based schemes are often
    extremely simple and efficient in terms of code-size as well as time and space
    requirements. This makes them prime candidates for light-weight devices like RFID
    tags, which are too weak to implement standard cryptographic primitives like the
    AES block-cipher. This talk will be a gentle introduction to provable security
    using simple LPN based schemes as examples. Starting from pseudorandom generators
    and symmetric key encryption, over secret-key authentication protocols, and, if
    time admits, touching on recent constructions of public-key identification, commitments
    and zero-knowledge proofs.
alternative_title:
- LNCS
author:
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
citation:
  ama: 'Pietrzak KZ. Cryptography from learning parity with noise. In: Vol 7147. Springer;
    2012:99-114. doi:<a href="https://doi.org/10.1007/978-3-642-27660-6_9">10.1007/978-3-642-27660-6_9</a>'
  apa: 'Pietrzak, K. Z. (2012). Cryptography from learning parity with noise (Vol.
    7147, pp. 99–114). Presented at the SOFSEM: Current Trends in Theory and Practice
    of Computer Science, Špindlerův Mlýn, Czech Republic: Springer. <a href="https://doi.org/10.1007/978-3-642-27660-6_9">https://doi.org/10.1007/978-3-642-27660-6_9</a>'
  chicago: Pietrzak, Krzysztof Z. “Cryptography from Learning Parity with Noise,”
    7147:99–114. Springer, 2012. <a href="https://doi.org/10.1007/978-3-642-27660-6_9">https://doi.org/10.1007/978-3-642-27660-6_9</a>.
  ieee: 'K. Z. Pietrzak, “Cryptography from learning parity with noise,” presented
    at the SOFSEM: Current Trends in Theory and Practice of Computer Science, Špindlerův
    Mlýn, Czech Republic, 2012, vol. 7147, pp. 99–114.'
  ista: 'Pietrzak KZ. 2012. Cryptography from learning parity with noise. SOFSEM:
    Current Trends in Theory and Practice of Computer Science, LNCS, vol. 7147, 99–114.'
  mla: Pietrzak, Krzysztof Z. <i>Cryptography from Learning Parity with Noise</i>.
    Vol. 7147, Springer, 2012, pp. 99–114, doi:<a href="https://doi.org/10.1007/978-3-642-27660-6_9">10.1007/978-3-642-27660-6_9</a>.
  short: K.Z. Pietrzak, in:, Springer, 2012, pp. 99–114.
conference:
  end_date: 2012-01-27
  location: Špindlerův Mlýn, Czech Republic
  name: 'SOFSEM: Current Trends in Theory and Practice of Computer Science'
  start_date: 2012-01-21
corr_author: '1'
date_created: 2018-12-11T12:02:15Z
date_published: 2012-02-19T00:00:00Z
date_updated: 2024-10-09T20:54:42Z
day: '19'
department:
- _id: KrPi
doi: 10.1007/978-3-642-27660-6_9
intvolume: '      7147'
language:
- iso: eng
month: '02'
oa_version: None
page: 99 - 114
publication_status: published
publisher: Springer
publist_id: '3407'
quality_controlled: '1'
scopus_import: 1
status: public
title: Cryptography from learning parity with noise
type: conference
user_id: 3E5EF7F0-F248-11E8-B48F-1D18A9856A87
volume: 7147
year: '2012'
...
---
_id: '3279'
abstract:
- lang: eng
  text: "We show a hardness-preserving construction of a PRF from any length doubling
    PRG which improves upon known constructions whenever we can put a non-trivial
    upper bound q on the number of queries to the PRF. Our construction requires only
    O(logq) invocations to the underlying PRG with each query. In comparison, the
    number of invocations by the best previous hardness-preserving construction (GGM
    using Levin's trick) is logarithmic in the hardness of the PRG. For example, starting
    from an exponentially secure PRG {0,1} n → {0,1} 2n, we get a PRF which is exponentially
    secure if queried at most q = exp(√n)times and where each invocation of the PRF
    requires Θ(√n) queries to the underlying PRG. This is much less than the Θ(n)
    required by known constructions. \r\n"
acknowledgement: Supported by the European Research Council under the European Union’s
  Seventh Framework Programme (FP7/2007-2013) / ERC Starting Grant (259668-PSPC)
alternative_title:
- LNCS
author:
- first_name: Abhishek
  full_name: Jain, Abhishek
  last_name: Jain
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Aris
  full_name: Tentes, Aris
  last_name: Tentes
citation:
  ama: 'Jain A, Pietrzak KZ, Tentes A. Hardness preserving constructions of pseudorandom
    functions. In: Vol 7194. Springer; 2012:369-382. doi:<a href="https://doi.org/10.1007/978-3-642-28914-9_21">10.1007/978-3-642-28914-9_21</a>'
  apa: 'Jain, A., Pietrzak, K. Z., &#38; Tentes, A. (2012). Hardness preserving constructions
    of pseudorandom functions (Vol. 7194, pp. 369–382). Presented at the TCC: Theory
    of Cryptography Conference, Taormina, Sicily, Italy: Springer. <a href="https://doi.org/10.1007/978-3-642-28914-9_21">https://doi.org/10.1007/978-3-642-28914-9_21</a>'
  chicago: Jain, Abhishek, Krzysztof Z Pietrzak, and Aris Tentes. “Hardness Preserving
    Constructions of Pseudorandom Functions,” 7194:369–82. Springer, 2012. <a href="https://doi.org/10.1007/978-3-642-28914-9_21">https://doi.org/10.1007/978-3-642-28914-9_21</a>.
  ieee: 'A. Jain, K. Z. Pietrzak, and A. Tentes, “Hardness preserving constructions
    of pseudorandom functions,” presented at the TCC: Theory of Cryptography Conference,
    Taormina, Sicily, Italy, 2012, vol. 7194, pp. 369–382.'
  ista: 'Jain A, Pietrzak KZ, Tentes A. 2012. Hardness preserving constructions of
    pseudorandom functions. TCC: Theory of Cryptography Conference, LNCS, vol. 7194,
    369–382.'
  mla: Jain, Abhishek, et al. <i>Hardness Preserving Constructions of Pseudorandom
    Functions</i>. Vol. 7194, Springer, 2012, pp. 369–82, doi:<a href="https://doi.org/10.1007/978-3-642-28914-9_21">10.1007/978-3-642-28914-9_21</a>.
  short: A. Jain, K.Z. Pietrzak, A. Tentes, in:, Springer, 2012, pp. 369–382.
conference:
  end_date: 2012-03-21
  location: Taormina, Sicily, Italy
  name: 'TCC: Theory of Cryptography Conference'
  start_date: 2012-03-19
date_created: 2018-12-11T12:02:25Z
date_published: 2012-05-04T00:00:00Z
date_updated: 2021-01-12T07:42:21Z
day: '04'
department:
- _id: KrPi
doi: 10.1007/978-3-642-28914-9_21
ec_funded: 1
intvolume: '      7194'
language:
- iso: eng
main_file_link:
- url: http://www.iacr.org/archive/tcc2012/tcc2012-index.html
month: '05'
oa_version: None
page: 369 - 382
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication_status: published
publisher: Springer
publist_id: '3367'
quality_controlled: '1'
scopus_import: 1
status: public
title: Hardness preserving constructions of pseudorandom functions
type: conference
user_id: 3E5EF7F0-F248-11E8-B48F-1D18A9856A87
volume: 7194
year: '2012'
...
---
_id: '3280'
abstract:
- lang: eng
  text: 'The (decisional) learning with errors problem (LWE) asks to distinguish &quot;noisy&quot;
    inner products of a secret vector with random vectors from uniform. The learning
    parities with noise problem (LPN) is the special case where the elements of the
    vectors are bits. In recent years, the LWE and LPN problems have found many applications
    in cryptography. In this paper we introduce a (seemingly) much stronger adaptive
    assumption, called &quot;subspace LWE&quot; (SLWE), where the adversary can learn
    the inner product of the secret and random vectors after they were projected into
    an adaptively and adversarially chosen subspace. We prove that, surprisingly,
    the SLWE problem mapping into subspaces of dimension d is almost as hard as LWE
    using secrets of length d (the other direction is trivial.) This result immediately
    implies that several existing cryptosystems whose security is based on the hardness
    of the LWE/LPN problems are provably secure in a much stronger sense than anticipated.
    As an illustrative example we show that the standard way of using LPN for symmetric
    CPA secure encryption is even secure against a very powerful class of related
    key attacks. '
acknowledgement: Supported by the European Research Council under the European Union’s
  Seventh Framework Programme (FP7/2007-2013) / ERC Starting Grant (259668-PSPC).
alternative_title:
- LNCS
author:
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
citation:
  ama: 'Pietrzak KZ. Subspace LWE. In: Vol 7194. Springer; 2012:548-563. doi:<a href="https://doi.org/10.1007/978-3-642-28914-9_31">10.1007/978-3-642-28914-9_31</a>'
  apa: 'Pietrzak, K. Z. (2012). Subspace LWE (Vol. 7194, pp. 548–563). Presented at
    the TCC: Theory of Cryptography Conference, Taormina, Sicily, Italy: Springer.
    <a href="https://doi.org/10.1007/978-3-642-28914-9_31">https://doi.org/10.1007/978-3-642-28914-9_31</a>'
  chicago: Pietrzak, Krzysztof Z. “Subspace LWE,” 7194:548–63. Springer, 2012. <a
    href="https://doi.org/10.1007/978-3-642-28914-9_31">https://doi.org/10.1007/978-3-642-28914-9_31</a>.
  ieee: 'K. Z. Pietrzak, “Subspace LWE,” presented at the TCC: Theory of Cryptography
    Conference, Taormina, Sicily, Italy, 2012, vol. 7194, pp. 548–563.'
  ista: 'Pietrzak KZ. 2012. Subspace LWE. TCC: Theory of Cryptography Conference,
    LNCS, vol. 7194, 548–563.'
  mla: Pietrzak, Krzysztof Z. <i>Subspace LWE</i>. Vol. 7194, Springer, 2012, pp.
    548–63, doi:<a href="https://doi.org/10.1007/978-3-642-28914-9_31">10.1007/978-3-642-28914-9_31</a>.
  short: K.Z. Pietrzak, in:, Springer, 2012, pp. 548–563.
conference:
  end_date: 2012-03-21
  location: Taormina, Sicily, Italy
  name: 'TCC: Theory of Cryptography Conference'
  start_date: 2012-03-19
corr_author: '1'
date_created: 2018-12-11T12:02:26Z
date_published: 2012-05-04T00:00:00Z
date_updated: 2024-10-21T06:02:59Z
day: '04'
department:
- _id: KrPi
doi: 10.1007/978-3-642-28914-9_31
ec_funded: 1
intvolume: '      7194'
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: http://www.iacr.org/archive/tcc2012/71940166/71940166.pdf
month: '05'
oa: 1
oa_version: Submitted Version
page: 548 - 563
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication_status: published
publisher: Springer
publist_id: '3366'
quality_controlled: '1'
scopus_import: '1'
status: public
title: Subspace LWE
type: conference
user_id: 3E5EF7F0-F248-11E8-B48F-1D18A9856A87
volume: 7194
year: '2012'
...
---
_id: '3281'
abstract:
- lang: eng
  text: 'We consider the problem of amplifying the &quot;lossiness&quot; of functions.
    We say that an oracle circuit C*: {0,1} m → {0,1}* amplifies relative lossiness
    from ℓ/n to L/m if for every function f:{0,1} n → {0,1} n it holds that 1 If f
    is injective then so is C f. 2 If f has image size of at most 2 n-ℓ, then C f
    has image size at most 2 m-L. The question is whether such C* exists for L/m ≫
    ℓ/n. This problem arises naturally in the context of cryptographic &quot;lossy
    functions,&quot; where the relative lossiness is the key parameter. We show that
    for every circuit C* that makes at most t queries to f, the relative lossiness
    of C f is at most L/m ≤ ℓ/n + O(log t)/n. In particular, no black-box method making
    a polynomial t = poly(n) number of queries can amplify relative lossiness by more
    than an O(logn)/n additive term. We show that this is tight by giving a simple
    construction (cascading with some randomization) that achieves such amplification.'
acknowledgement: "We would like to thank Oded Goldreich and Omer Rein- gold for discussions
  at an early stage of this project, and Scott Aaronson for clarifications regarding
  the collision problem.\r\n"
alternative_title:
- LNCS
author:
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Alon
  full_name: Rosen, Alon
  last_name: Rosen
- first_name: Gil
  full_name: Segev, Gil
  last_name: Segev
citation:
  ama: 'Pietrzak KZ, Rosen A, Segev G. Lossy functions do not amplify well. In: Vol
    7194. Springer; 2012:458-475. doi:<a href="https://doi.org/10.1007/978-3-642-28914-9_26">10.1007/978-3-642-28914-9_26</a>'
  apa: 'Pietrzak, K. Z., Rosen, A., &#38; Segev, G. (2012). Lossy functions do not
    amplify well (Vol. 7194, pp. 458–475). Presented at the TCC: Theory of Cryptography
    Conference, Taormina, Sicily, Italy: Springer. <a href="https://doi.org/10.1007/978-3-642-28914-9_26">https://doi.org/10.1007/978-3-642-28914-9_26</a>'
  chicago: Pietrzak, Krzysztof Z, Alon Rosen, and Gil Segev. “Lossy Functions Do Not
    Amplify Well,” 7194:458–75. Springer, 2012. <a href="https://doi.org/10.1007/978-3-642-28914-9_26">https://doi.org/10.1007/978-3-642-28914-9_26</a>.
  ieee: 'K. Z. Pietrzak, A. Rosen, and G. Segev, “Lossy functions do not amplify well,”
    presented at the TCC: Theory of Cryptography Conference, Taormina, Sicily, Italy,
    2012, vol. 7194, pp. 458–475.'
  ista: 'Pietrzak KZ, Rosen A, Segev G. 2012. Lossy functions do not amplify well.
    TCC: Theory of Cryptography Conference, LNCS, vol. 7194, 458–475.'
  mla: Pietrzak, Krzysztof Z., et al. <i>Lossy Functions Do Not Amplify Well</i>.
    Vol. 7194, Springer, 2012, pp. 458–75, doi:<a href="https://doi.org/10.1007/978-3-642-28914-9_26">10.1007/978-3-642-28914-9_26</a>.
  short: K.Z. Pietrzak, A. Rosen, G. Segev, in:, Springer, 2012, pp. 458–475.
conference:
  end_date: 2012-03-21
  location: Taormina, Sicily, Italy
  name: 'TCC: Theory of Cryptography Conference'
  start_date: 2012-03-19
date_created: 2018-12-11T12:02:26Z
date_published: 2012-05-04T00:00:00Z
date_updated: 2024-10-21T06:03:00Z
day: '04'
department:
- _id: KrPi
doi: 10.1007/978-3-642-28914-9_26
intvolume: '      7194'
language:
- iso: eng
main_file_link:
- url: http://www.iacr.org/archive/tcc2012/tcc2012-index.html
month: '05'
oa_version: None
page: 458 - 475
publication_status: published
publisher: Springer
publist_id: '3365'
quality_controlled: '1'
scopus_import: '1'
status: public
title: Lossy functions do not amplify well
type: conference
user_id: 3E5EF7F0-F248-11E8-B48F-1D18A9856A87
volume: 7194
year: '2012'
...
---
_id: '3282'
abstract:
- lang: eng
  text: 'Traditionally, symmetric-key message authentication codes (MACs) are easily
    built from pseudorandom functions (PRFs). In this work we propose a wide variety
    of other approaches to building efficient MACs, without going through a PRF first.
    In particular, unlike deterministic PRF-based MACs, where each message has a unique
    valid tag, we give a number of probabilistic MAC constructions from various other
    primitives/assumptions. Our main results are summarized as follows: We show several
    new probabilistic MAC constructions from a variety of general assumptions, including
    CCA-secure encryption, Hash Proof Systems and key-homomorphic weak PRFs. By instantiating
    these frameworks under concrete number theoretic assumptions, we get several schemes
    which are more efficient than just using a state-of-the-art PRF instantiation
    under the corresponding assumption. For probabilistic MACs, unlike deterministic
    ones, unforgeability against a chosen message attack (uf-cma ) alone does not
    imply security if the adversary can additionally make verification queries (uf-cmva
    ). We give an efficient generic transformation from any uf-cma secure MAC which
    is &quot;message-hiding&quot; into a uf-cmva secure MAC. This resolves the main
    open problem of Kiltz et al. from Eurocrypt''11; By using our transformation on
    their constructions, we get the first efficient MACs from the LPN assumption.
    While all our new MAC constructions immediately give efficient actively secure,
    two-round symmetric-key identification schemes, we also show a very simple, three-round
    actively secure identification protocol from any weak PRF. In particular, the
    resulting protocol is much more efficient than the trivial approach of building
    a regular PRF from a weak PRF. © 2012 International Association for Cryptologic
    Research.'
acknowledgement: Supported by the European Research Council under the European Union’s
  Seventh Framework Programme (FP7/2007-2013) / ERC Starting Grant (259668-PSPC)
alternative_title:
- LNCS
author:
- first_name: Yevgeniy
  full_name: Dodis, Yevgeniy
  last_name: Dodis
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Eike
  full_name: Kiltz, Eike
  last_name: Kiltz
- first_name: Daniel
  full_name: Wichs, Daniel
  last_name: Wichs
citation:
  ama: 'Dodis Y, Pietrzak KZ, Kiltz E, Wichs D. Message authentication, revisited.
    In: Vol 7237. Springer; 2012:355-374. doi:<a href="https://doi.org/10.1007/978-3-642-29011-4_22">10.1007/978-3-642-29011-4_22</a>'
  apa: 'Dodis, Y., Pietrzak, K. Z., Kiltz, E., &#38; Wichs, D. (2012). Message authentication,
    revisited (Vol. 7237, pp. 355–374). Presented at the EUROCRYPT: Theory and Applications
    of Cryptographic Techniques, Cambridge, UK: Springer. <a href="https://doi.org/10.1007/978-3-642-29011-4_22">https://doi.org/10.1007/978-3-642-29011-4_22</a>'
  chicago: Dodis, Yevgeniy, Krzysztof Z Pietrzak, Eike Kiltz, and Daniel Wichs. “Message
    Authentication, Revisited,” 7237:355–74. Springer, 2012. <a href="https://doi.org/10.1007/978-3-642-29011-4_22">https://doi.org/10.1007/978-3-642-29011-4_22</a>.
  ieee: 'Y. Dodis, K. Z. Pietrzak, E. Kiltz, and D. Wichs, “Message authentication,
    revisited,” presented at the EUROCRYPT: Theory and Applications of Cryptographic
    Techniques, Cambridge, UK, 2012, vol. 7237, pp. 355–374.'
  ista: 'Dodis Y, Pietrzak KZ, Kiltz E, Wichs D. 2012. Message authentication, revisited.
    EUROCRYPT: Theory and Applications of Cryptographic Techniques, LNCS, vol. 7237,
    355–374.'
  mla: Dodis, Yevgeniy, et al. <i>Message Authentication, Revisited</i>. Vol. 7237,
    Springer, 2012, pp. 355–74, doi:<a href="https://doi.org/10.1007/978-3-642-29011-4_22">10.1007/978-3-642-29011-4_22</a>.
  short: Y. Dodis, K.Z. Pietrzak, E. Kiltz, D. Wichs, in:, Springer, 2012, pp. 355–374.
conference:
  end_date: 2012-04-19
  location: Cambridge, UK
  name: 'EUROCRYPT: Theory and Applications of Cryptographic Techniques'
  start_date: 2012-04-15
date_created: 2018-12-11T12:02:27Z
date_published: 2012-03-10T00:00:00Z
date_updated: 2024-10-21T06:02:59Z
day: '10'
ddc:
- '000'
- '004'
department:
- _id: KrPi
doi: 10.1007/978-3-642-29011-4_22
ec_funded: 1
file:
- access_level: open_access
  checksum: 8557c17a8c2586d06ebfe62d934f5c5f
  content_type: application/pdf
  creator: system
  date_created: 2018-12-12T10:14:23Z
  date_updated: 2020-07-14T12:46:06Z
  file_id: '5074'
  file_name: IST-2016-686-v1+1_059.pdf
  file_size: 372292
  relation: main_file
file_date_updated: 2020-07-14T12:46:06Z
has_accepted_license: '1'
intvolume: '      7237'
language:
- iso: eng
month: '03'
oa: 1
oa_version: Submitted Version
page: 355 - 374
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication_status: published
publisher: Springer
publist_id: '3364'
pubrep_id: '686'
quality_controlled: '1'
scopus_import: '1'
status: public
title: Message authentication, revisited
tmp:
  image: /images/cc_by.png
  legal_code_url: https://creativecommons.org/licenses/by/4.0/legalcode
  name: Creative Commons Attribution 4.0 International Public License (CC-BY 4.0)
  short: CC BY (4.0)
type: conference
user_id: 3E5EF7F0-F248-11E8-B48F-1D18A9856A87
volume: 7237
year: '2012'
...
---
_id: '2048'
abstract:
- lang: eng
  text: Leakage resilient cryptography attempts to incorporate side-channel leakage
    into the black-box security model and designs cryptographic schemes that are provably
    secure within it. Informally, a scheme is leakage-resilient if it remains secure
    even if an adversary learns a bounded amount of arbitrary information about the
    schemes internal state. Unfortunately, most leakage resilient schemes are unnecessarily
    complicated in order to achieve strong provable security guarantees. As advocated
    by Yu et al. [CCS’10], this mostly is an artefact of the security proof and in
    practice much simpler construction may already suffice to protect against realistic
    side-channel attacks. In this paper, we show that indeed for simpler constructions
    leakage-resilience can be obtained when we aim for relaxed security notions where
    the leakage-functions and/or the inputs to the primitive are chosen non-adaptively.
    For example, we show that a three round Feistel network instantiated with a leakage
    resilient PRF yields a leakage resilient PRP if the inputs are chosen non-adaptively
    (This complements the result of Dodis and Pietrzak [CRYPTO’10] who show that if
    a adaptive queries are allowed, a superlogarithmic number of rounds is necessary.)
    We also show that a minor variation of the classical GGM construction gives a
    leakage resilient PRF if both, the leakage-function and the inputs, are chosen
    non-adaptively.
acknowledgement: "Sebastian Faust acknowledges support from the Danish National Research
  Foundation and The National Science Foundation of China (under the grant 61061130540)
  for the Sino-Danish Center for the Theory of Interactive Computation, within part
  of this work was performed; and from the CFEM research center, supported by the
  Danish Strategic Research Council. \r\nSupported by the European Research Council/ERC
  Starting Grant 259668-PSPC.\r\n"
alternative_title:
- LNCS
article_processing_charge: No
author:
- first_name: Sebastian
  full_name: Faust, Sebastian
  last_name: Faust
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
- first_name: Joachim
  full_name: Schipper, Joachim
  id: 7BE863D4-E9CF-11E9-9EDB-90527418172C
  last_name: Schipper
citation:
  ama: 'Faust S, Pietrzak KZ, Schipper J. Practical leakage-resilient symmetric cryptography.
    In: <i>Conference Proceedings CHES 2012</i>. Vol 7428. Springer; 2012:213-232.
    doi:<a href="https://doi.org/10.1007/978-3-642-33027-8_13">10.1007/978-3-642-33027-8_13</a>'
  apa: 'Faust, S., Pietrzak, K. Z., &#38; Schipper, J. (2012). Practical leakage-resilient
    symmetric cryptography. In <i>Conference proceedings CHES 2012</i> (Vol. 7428,
    pp. 213–232). Leuven, Belgium: Springer. <a href="https://doi.org/10.1007/978-3-642-33027-8_13">https://doi.org/10.1007/978-3-642-33027-8_13</a>'
  chicago: Faust, Sebastian, Krzysztof Z Pietrzak, and Joachim Schipper. “Practical
    Leakage-Resilient Symmetric Cryptography.” In <i>Conference Proceedings CHES 2012</i>,
    7428:213–32. Springer, 2012. <a href="https://doi.org/10.1007/978-3-642-33027-8_13">https://doi.org/10.1007/978-3-642-33027-8_13</a>.
  ieee: S. Faust, K. Z. Pietrzak, and J. Schipper, “Practical leakage-resilient symmetric
    cryptography,” in <i>Conference proceedings CHES 2012</i>, Leuven, Belgium, 2012,
    vol. 7428, pp. 213–232.
  ista: 'Faust S, Pietrzak KZ, Schipper J. 2012. Practical leakage-resilient symmetric
    cryptography. Conference proceedings CHES 2012. CHES: Cryptographic Hardware and
    Embedded Systems, LNCS, vol. 7428, 213–232.'
  mla: Faust, Sebastian, et al. “Practical Leakage-Resilient Symmetric Cryptography.”
    <i>Conference Proceedings CHES 2012</i>, vol. 7428, Springer, 2012, pp. 213–32,
    doi:<a href="https://doi.org/10.1007/978-3-642-33027-8_13">10.1007/978-3-642-33027-8_13</a>.
  short: S. Faust, K.Z. Pietrzak, J. Schipper, in:, Conference Proceedings CHES 2012,
    Springer, 2012, pp. 213–232.
conference:
  end_date: 2012-09-12
  location: Leuven, Belgium
  name: 'CHES: Cryptographic Hardware and Embedded Systems'
  start_date: 2012-09-09
das_tickbox: '1'
date_created: 2018-12-11T11:55:25Z
date_published: 2012-09-01T00:00:00Z
date_updated: 2026-07-07T13:05:30Z
day: '01'
department:
- _id: KrPi
doi: 10.1007/978-3-642-33027-8_13
ec_funded: 1
intvolume: '      7428'
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: http://www.iacr.org/archive/ches2012/74280211/74280211.pdf
month: '09'
oa: 1
oa_version: Preprint
page: 213 - 232
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication: Conference proceedings CHES 2012
publication_status: published
publisher: Springer
publist_id: '5003'
quality_controlled: '1'
scopus_import: '1'
status: public
title: Practical leakage-resilient symmetric cryptography
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 7428
year: '2012'
...
---
_id: '2049'
abstract:
- lang: eng
  text: "We propose a new authentication protocol that is provably secure based on
    a ring variant of the learning parity with noise (LPN) problem. The protocol follows
    the design principle of the LPN-based protocol from Eurocrypt’11 (Kiltz et al.),
    and like it, is a two round protocol secure against active attacks. Moreover,
    our protocol has small communication complexity and a very small footprint which
    makes it applicable in scenarios that involve low-cost, resource-constrained devices.\r\n\r\nPerformance-wise,
    our protocol is more efficient than previous LPN-based schemes, such as the many
    variants of the Hopper-Blum (HB) protocol and the aforementioned protocol from
    Eurocrypt’11. Our implementation results show that it is even comparable to the
    standard challenge-and-response protocols based on the AES block-cipher. Our basic
    protocol is roughly 20 times slower than AES, but with the advantage of having
    10 times smaller code size. Furthermore, if a few hundred bytes of non-volatile
    memory are available to allow the storage of some off-line pre-computations, then
    the online phase of our protocols is only twice as slow as AES.\r\n"
acknowledgement: "Supported by the European Research Council / ERC Starting Grant
  (259668- PSPC)\r\nWe would like to thank the anonymous referees of this confer-
  ence and those of the ECRYPT Workshop on Lightweight Cryptography for very useful
  comments, and in particular for the suggestion that the scheme is somewhat vulnerable
  to a man-in-the-middle attack whenever an adversary observes two reader challenges
  that are the same. We hope that the attack we described in Appendix A corresponds
  to what the reviewer had in mind. We also thank Tanja Lange for pointing us to the
  pa- per of [Kir11] and for discussions of some of her recent work. "
alternative_title:
- LNCS
article_processing_charge: No
author:
- first_name: Stefan
  full_name: Heyse, Stefan
  last_name: Heyse
- first_name: Eike
  full_name: Kiltz, Eike
  last_name: Kiltz
- first_name: Vadim
  full_name: Lyubashevsky, Vadim
  last_name: Lyubashevsky
- first_name: Christof
  full_name: Paar, Christof
  last_name: Paar
- first_name: Krzysztof Z
  full_name: Pietrzak, Krzysztof Z
  id: 3E04A7AA-F248-11E8-B48F-1D18A9856A87
  last_name: Pietrzak
  orcid: 0000-0002-9139-1654
citation:
  ama: 'Heyse S, Kiltz E, Lyubashevsky V, Paar C, Pietrzak KZ. Lapin: An efficient
    authentication protocol based on ring-LPN. In: <i>Conference Proceedings FSE 2012</i>.
    Vol 7549. Springer; 2012:346-365. doi:<a href="https://doi.org/10.1007/978-3-642-34047-5_20">10.1007/978-3-642-34047-5_20</a>'
  apa: 'Heyse, S., Kiltz, E., Lyubashevsky, V., Paar, C., &#38; Pietrzak, K. Z. (2012).
    Lapin: An efficient authentication protocol based on ring-LPN. In <i>Conference
    proceedings FSE 2012</i> (Vol. 7549, pp. 346–365). Washington, DC, USA: Springer.
    <a href="https://doi.org/10.1007/978-3-642-34047-5_20">https://doi.org/10.1007/978-3-642-34047-5_20</a>'
  chicago: 'Heyse, Stefan, Eike Kiltz, Vadim Lyubashevsky, Christof Paar, and Krzysztof
    Z Pietrzak. “Lapin: An Efficient Authentication Protocol Based on Ring-LPN.” In
    <i>Conference Proceedings FSE 2012</i>, 7549:346–65. Springer, 2012. <a href="https://doi.org/10.1007/978-3-642-34047-5_20">https://doi.org/10.1007/978-3-642-34047-5_20</a>.'
  ieee: 'S. Heyse, E. Kiltz, V. Lyubashevsky, C. Paar, and K. Z. Pietrzak, “Lapin:
    An efficient authentication protocol based on ring-LPN,” in <i>Conference proceedings
    FSE 2012</i>, Washington, DC, USA, 2012, vol. 7549, pp. 346–365.'
  ista: 'Heyse S, Kiltz E, Lyubashevsky V, Paar C, Pietrzak KZ. 2012. Lapin: An efficient
    authentication protocol based on ring-LPN. Conference proceedings FSE 2012. FSE:
    Fast Software Encryption, LNCS, vol. 7549, 346–365.'
  mla: 'Heyse, Stefan, et al. “Lapin: An Efficient Authentication Protocol Based on
    Ring-LPN.” <i>Conference Proceedings FSE 2012</i>, vol. 7549, Springer, 2012,
    pp. 346–65, doi:<a href="https://doi.org/10.1007/978-3-642-34047-5_20">10.1007/978-3-642-34047-5_20</a>.'
  short: S. Heyse, E. Kiltz, V. Lyubashevsky, C. Paar, K.Z. Pietrzak, in:, Conference
    Proceedings FSE 2012, Springer, 2012, pp. 346–365.
conference:
  end_date: 2012-03-21
  location: Washington, DC, USA
  name: 'FSE: Fast Software Encryption'
  start_date: 2012-03-19
das_tickbox: '1'
date_created: 2018-12-11T11:55:25Z
date_published: 2012-03-01T00:00:00Z
date_updated: 2026-07-07T13:06:19Z
day: '01'
department:
- _id: KrPi
doi: 10.1007/978-3-642-34047-5_20
ec_funded: 1
intvolume: '      7549'
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: http://www.iacr.org/archive/fse2012/75490350/75490350.pdf
month: '03'
oa: 1
oa_version: Preprint
page: 346 - 365
project:
- _id: 258C570E-B435-11E9-9278-68D0E5697425
  call_identifier: FP7
  grant_number: '259668'
  name: Provable Security for Physical Cryptography
publication: Conference proceedings FSE 2012
publication_status: published
publisher: Springer
publist_id: '5002'
quality_controlled: '1'
scopus_import: '1'
status: public
title: 'Lapin: An efficient authentication protocol based on ring-LPN'
type: conference
user_id: 2DF688A6-F248-11E8-B48F-1D18A9856A87
volume: 7549
year: '2012'
...
