|
David Freeman, U.C. Berkeley, USA
Title: Constructing Pairing-Friendly Elliptic Curves for Cryptography
Elliptic curves with small embedding degree and large prime-order subgroup are key ingredients for implementing pairing-based cryptographic systems. Such "pairing-friendly" curves are rare and thus require specific constructions.
In this talk, we will describe a single coherent framework that encompasses all of the constructions of pairing-friendly curves currently existing in the literature. We find that the methods that produce the most efficient curves are limited to small embedding degrees, while the methods that work for all embedding degrees usually produce curves with less than optimal efficiency.
We will also survey recent developments in the field, including curves with composite-order subgroups, variable CM discriminants, and pairing-friendly hyperelliptic curves.
This talk will include joint work with M. Scott and E. Teske.
|
|
Kris Gaj, George Mason University, USA
Title: Factoring in Hardware
Difficulty of factoring large integers is at the core of the security of
RSA, one of the most commonly used cryptographic algorithms protecting
majority of the today's on-line financial transactions. Most recently, an
effort has started in the open cryptographic community to estimate the
difficulty and cost of factoring RSA keys, using hardware based on Field
Programmable Gate Arrays (FPGAs) and/or Application Specific Integrated
Circuits (ASICs).
In this talk, we will summarize the progress in this
area reported during two editions of the Special-purpose Hardware for
Attacking Cryptographic Systems (SHARCS) workshop held in Europe since
2005.
We will then describe a research project conducted at George Mason
University aimed at optimizing and implementing three special purpose
factoring methods, rho, p-1, and ECM (Elliptic Curve Method). These
methods can be applied in series to the outputs of the sieving phase of the Number Field Sieve, the best currently known general-purpose method
of factoring large integers, in order to fully factor intermediate
results in the range of 200-350 bits, which are already likely to contain
only relatively small prime factors. A timing comparison to optimized
software implementations will be presented, as well as a comparison in terms
of
the performance to cost ratio among the FPGA, ASIC, and microprocessor
technologies.
We will discuss state of the art high-performance reconfigurable computers based on FPGAs, their programming environments,
and the first results of porting our designs to selected machines of
this type.
We will also estimate the potential advantage of using special-purpose hardware machines based on ASICs over
general-purpose computers based on FPGAs and/or
microprocessors.
|
|
Tatsuaki Okamoto, NTT, Japan
Title: Anonymous Credential and Optimistic Fair Exchange
Lecture 1.
Anonymous credential is one of the most important notions to counter some of
the privacy problems about identity certificates. The basic properties of
anonymous credential systems are unforgeability, anonymity and
unlinkability. The existing most efficient anonymous credential schemes
are based on the Strong RSA assumption or the LRSW assumption. In my
talk, I will introduce another efficient anonymous credential system based
on the Strong DH assumption.
Lecture 2.
Optimistic fair exchange protocols allow
two involved parties to either each party get the other's item or neither
party does, where a Trusted Third Party (TTP) is not invoked when two
involved parties perform the protocol correctly. We now consider protocols
that exchange a digital signature and digital data. In my talk, I introduce
a general ``optimistic'' fair exchange protocol which is applicable to
any secure digital signatures. I then present the definition of an ideal
functionality of fair exchange protocols in the universal composability (UC)
framework, and show that our protocol satisfies the UC security. This is
a joint work with Norio Akagi, Yoshifumi Manabe and Yusuke Okada.
|
|
차재춘, ICU, Korea
Title: An elementary tutorial on provable security
We give an elementary introduction to provable security aimed at graduate students starting cryptography with mathematical background.
We start with preliminaries on randomized computation, and then discuss basic ideas on formal definitions of security, primitive hard problems, and the reduction method. Based on this, we illustrate an example of security proof using random oracle model.
|
|
차영태, secui.com, Korea
Title: 네트워크 보안기술 동향
본 발표에서는 네트워크 보안의 동향과, 멀티미디어 통신에서의 보안의 필요성 증가에 대해 논의 한다.
|
|
천정희, 김성욱, 서울대학교, Korea
Title: 성긴 지수 이산로그 문제(Low Hamming Weight Discrete
Logarithm Problem)
Coppersmith가 제안한 성긴 지수 이산로그 문제에 대한 알고리즘은 대칭 분할
시스템(symmetric splitting system)을 이용하고 있다. 이와 다르게 지수를 비대칭적으로 분할하는 알고리즘을 설계하고 이를 유럽 표준으로 제안된 GPS인증 알고리즘 공격에 적용해본다. 또한 비대칭적 분할
시스템(asymmetric splitting system)을 구성할 때 분할의 최적화 방안에 대해
알아본다.
|
|
한상근, KAIST, Korea
Title: ARIA에 대한 대수적 공격
ARIA에 대한 대수적 공격의 현실성을 알아본다. 특히, SAT solver를
이용한 공격과 XL 알고리즘을 구현하고, 이 공격 방법들에 대한 현실성에 대해 논의한다.
|
|
한종욱, ETRI, Korea
Title: 홈네트워크 기술동향 및 보안이슈
IT839의 한 분야로 정부의 주도하에 추진되어왔던 홈네트워크분야의 기술동향에 대해서 살펴본다. 홈네트워크를 구성하는 유무선 네트워크기술,
정보가전기기, 미들웨어기술 등에 대해서 설명하고, 통신사업자 중심의 홈네트워크 시범사업과 건설사 중심의 홈네트워크 단지 현황 등을 살펴본다.
마지막으로 홈네트워크에서 발생 가능한 보안이슈 및 관련 연구현황에 대해서 설명한다.
|
|
홍득조, KAIST, 고려대학교
Title: 해쉬함수 분석 도구 개발
Wang의 해쉬함수 분석 논리를 기초로 자동화된 해쉬함수 분석 도구를 개발하여 실제 해쉬함수에 적용하고, 이의 응용으로써 메시지인증에 사용되는
HMAC에 대한 키복구 공격과 APOP, EAP 등의 인증프로토콜 패스워드 복구 공격을 수행한다.
|
|