David Freeman, U.C. Berkeley, USA

Title: Constructing Pairing-Friendly Elliptic Curves for Cryptography

Elliptic curves with small embedding degree and large prime-order subgroup are key ingredients for implementing pairing-based cryptographic systems.  Such "pairing-friendly" curves are rare and thus require specific constructions.

In this talk, we will describe a single coherent framework that encompasses all of the constructions of pairing-friendly curves currently existing in the literature.  We find that the methods that produce the most efficient curves are limited to small embedding degrees, while the methods that work for all embedding degrees usually produce curves with less than optimal efficiency.

We will also survey recent developments in the field, including curves with composite-order subgroups, variable CM discriminants, and pairing-friendly hyperelliptic curves.

This talk will include joint work with M. Scott and E. Teske.

 

Kris Gaj, George Mason University, USA

Title: Factoring in Hardware

Difficulty of factoring large integers is at the core of the security of RSA, one of the most commonly used cryptographic algorithms protecting majority of the today's on-line financial transactions. Most recently, an effort has started in the open cryptographic community to estimate the difficulty and cost of factoring RSA keys, using hardware based on Field Programmable Gate Arrays (FPGAs) and/or Application Specific Integrated Circuits (ASICs).

In this talk, we will summarize the progress in this area reported during two editions of the Special-purpose Hardware for Attacking Cryptographic Systems (SHARCS) workshop held in Europe since 2005.

We will then describe a research project conducted at George Mason University aimed at optimizing and implementing three special purpose factoring methods, rho, p-1, and ECM (Elliptic Curve Method). These methods can be applied in series to the outputs of the sieving phase of the Number Field Sieve, the best currently known general-purpose method of factoring large integers, in order to fully factor intermediate results in the range of 200-350 bits, which are already likely to contain only relatively small prime factors. A timing comparison to optimized software implementations will be presented, as well as a comparison in terms of the performance to cost ratio among the FPGA, ASIC, and microprocessor technologies.

We will discuss state of the art high-performance reconfigurable computers based on FPGAs, their programming environments, and the first results of porting our designs to selected machines of this type.

We will also estimate the potential advantage of using special-purpose hardware machines based on ASICs over general-purpose computers based on FPGAs and/or microprocessors.

 

Tatsuaki Okamoto, NTT, Japan

Title: Anonymous Credential and Optimistic Fair Exchange

Lecture 1.

Anonymous credential is one of the most important notions to counter some of the privacy problems about identity certificates. The basic properties of anonymous credential systems are unforgeability, anonymity and unlinkability. The existing most efficient anonymous credential schemes are based on the Strong RSA assumption or the LRSW assumption. In my talk, I will introduce another efficient anonymous credential system based on the Strong DH assumption.  

Lecture 2.

Optimistic fair exchange protocols allow two involved parties to either each party get the other's item or neither party does, where a Trusted Third Party (TTP) is not invoked when two involved parties perform the protocol correctly. We now consider protocols that exchange a digital signature and digital data. In my talk, I introduce a general ``optimistic'' fair exchange protocol which is applicable to any secure digital signatures. I then present the definition of an ideal functionality of fair exchange protocols in the universal composability (UC) framework, and show that our protocol satisfies the UC security. This is a joint work with Norio Akagi, Yoshifumi Manabe and Yusuke Okada.

 

차재춘, ICU, Korea

Title: An elementary tutorial on provable security

We give an elementary introduction to provable security aimed at graduate students starting cryptography with mathematical background.

We start with preliminaries on randomized computation, and then discuss basic ideas on formal definitions of security, primitive hard problems, and the reduction method.  Based on this, we illustrate an example of security proof using random oracle model.

 

차영태, secui.com, Korea

Title: 네트워크 보안기술 동향

본 발표에서는 네트워크 보안의 동향과, 멀티미디어 통신에서의 보안의 필요성 증가에 대해 논의 한다.

 

천정희, 김성욱, 서울대학교, Korea

Title: 성긴 지수 이산로그 문제(Low Hamming Weight Discrete Logarithm Problem)

Coppersmith가 제안한 성긴 지수 이산로그 문제에 대한 알고리즘은 대칭 분할 시스템(symmetric splitting system)을 이용하고 있다. 이와 다르게 지수를 비대칭적으로 분할하는 알고리즘을 설계하고 이를 유럽 표준으로 제안된 GPS인증 알고리즘 공격에 적용해본다. 또한 비대칭적 분할 시스템(asymmetric splitting system)을 구성할 때 분할의 최적화 방안에 대해 알아본다.

 

한상근, KAIST, Korea

Title: ARIA에 대한 대수적 공격

ARIA에 대한 대수적 공격의 현실성을 알아본다. 특히, SAT solver를 이용한 공격과 XL 알고리즘을 구현하고, 이 공격 방법들에 대한 현실성에 대해 논의한다.

 

한종욱, ETRI, Korea

Title: 홈네트워크 기술동향 및 보안이슈

IT839의 한 분야로 정부의 주도하에 추진되어왔던 홈네트워크분야의 기술동향에 대해서 살펴본다. 홈네트워크를 구성하는 유무선 네트워크기술, 정보가전기기, 미들웨어기술 등에 대해서 설명하고, 통신사업자 중심의 홈네트워크 시범사업과 건설사 중심의 홈네트워크 단지 현황 등을 살펴본다. 마지막으로 홈네트워크에서 발생 가능한 보안이슈 및 관련 연구현황에 대해서 설명한다.

 

홍득조, KAIST, 고려대학교

Title: 해쉬함수 분석 도구 개발

Wang의 해쉬함수 분석 논리를 기초로 자동화된 해쉬함수 분석 도구를 개발하여 실제 해쉬함수에 적용하고, 이의 응용으로써 메시지인증에 사용되는 HMAC에 대한 키복구 공격과 APOP, EAP 등의 인증프로토콜 패스워드 복구 공격을 수행한다.