Applied Cryptography and Network Security: 12th

By Ioana Boureanu, Philippe Owesarski, Serge Vaudenay

This e-book constitutes the refereed complaints of the twelfth overseas convention on utilized Cryptography and community protection, ACNS 2014, held in Lausanne, Switzerland, in June 2014. The 33 revised complete papers incorporated during this quantity have been rigorously reviewed and chosen from 147 submissions. they're prepared in topical sections on key trade; primitive development; assaults (public-key cryptography); hashing; cryptanalysis and assaults (symmetric cryptography); community protection; signatures; process defense; and safe computation.

Let X be a set {(pk , CT , m)|pk ∈ PKS ; CT ∈ CT S ; m ∈ MS }, Lm be a set {(pk , CT , m)|(pk , sk ) ← Gen (1κ ); Dec sk (CT ) = m} and L be a set ∪m∈MS Lm . We use a family of SPHFs H = {Hhk } such that for every hk in the key space KS , Hhk : X → {0, 1}3κ and F : KS × PKS ×CT S → PS where PS is the projection key space. Each authority generates reference string ρi ← K(1κ ) for SENIZK. The multi-strings is ρ := (ρ1 , . . , ρn ) where ρi is generated by i-th authority. Protocol Execution. The initiator A generates a randomness r ∈ {0, 1}∗ and a publickey (pk , sk ) ← Gen (1κ ), and computes the ciphertext CT = Enc pk (pw; r ) with the password pw.

In particular the state of an instance ΠPi includes the following variables (initialized as null): – sidiP : the session identifier which is the ordered concatenation of all messages sent and received by ΠPi ; – pidiP : the partner identifier whom ΠPi believes it is interacting (pidiP P); – acciP : a Boolean variable corresponding to whether ΠPi accepts or rejects at the end of the execution. 1 Partnered parties must accept and conclude with the common session key. 1 The exception of the final message for matching of sid is needed to rule out a trivial attack that an adversary forwards all messages except the final one.

3. 2 Universally Composable Three-Move PAKE in Multi-string Model Katz and Vaikuntanathan [13] propose a UC one-round PAKE scheme (the KV2 scheme) in the CRS model. The KV2 scheme achieves the UC security by adding a simulationsound NIZK (SSNIZK) proof that proves that 1) there exists a hash key which is the plaintext of a ciphertext, and 2) a projection key is generated from the hash key. We also can apply our technique to the KV2 scheme. Fig. 4 shows a high-level overview of the UC protocol. We use the family of SPHFs H = {Hhk } that is constructed in [13].

