Applied Cryptography and Network Security: 12th by Ioana Boureanu, Philippe Owesarski, Serge Vaudenay PDF

By Ioana Boureanu, Philippe Owesarski, Serge Vaudenay

ISBN-10: 3319075357

ISBN-13: 9783319075358

ISBN-10: 3319075365

ISBN-13: 9783319075365

This e-book constitutes the refereed court cases of the twelfth foreign convention on utilized Cryptography and community protection, ACNS 2014, held in Lausanne, Switzerland, in June 2014. The 33 revised complete papers incorporated during this quantity have been conscientiously reviewed and chosen from 147 submissions. they're prepared in topical sections on key alternate; primitive building; assaults (public-key cryptography); hashing; cryptanalysis and assaults (symmetric cryptography); community defense; signatures; procedure protection; and safe computation.

B sends trans2 := 30 K. Yoneyama B||hp||pk||CT ||π to A. Upon receiving B||hp||pk||CT ||π, A sets label := trans1 ||B||hp||pk, and verifies π with pk, CT, label and ρ. If π is invalid, A aborts. Otherwise, A derives ˆ = Enclabel rA ||τA ||S KA = hhp (pk , CT , pw, r ), computes the ciphertext CT pk (pw; rA ), and ˆ checks whether CT CT . If so, A aborts. Otherwise, A sends τA to B and outputs the session key S KA . Upon receiving τA , B checks whether τA τB . If so, B aborts. Otherwise, B outputs the session key S KB .

Trapdoor information helps to extract the passwords from adversary-generated messages, and the simulator can check the validity of adversary-generated messages in later. Next, we modify the output of Execute oracle so that all proofs π and pi are changed to simulated proofs by the algorithm S E in the definition of multi-string SENIZK proof, ciphertexts CT and CT are changed to encryptions of a fake password, and Hhk (pk , CT , pw) is changed to random. Since honest authorities are majority, these changes are indistinguishable from extraction zero-knowledge of SENIZK, CPA security and smoothness of SPHF, respectively.

