
Information Security and Privacy
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
More details
Other editions
Additional editions

Content
- Title Page
- Preface
- Organization
- Table of Contents
- Fundamentals
- Optimal Boundsfor Multi-Prime F-Hiding Assumption
- Introduction
- Background
- Our Contributions
- Preliminaries
- Previous Works
- Howgrave-Graham Method
- KOS Method
- Herrmann Method
- Our New Algorithm
- The Case of Two Variables
- The Case of k Variables
- Optimizing k
- Discussions
- Full Description of Our Algorithm
- References
- Small Examples
- A Small Example for KOS Method
- A Small Example for Herrmann Method
- Sufficient Condition for Ephemeral Key-Leakage Resilient Tripartite Key Exchange
- Introduction
- The Model and Security Definitions
- Sufficient Condition for Secure Tripartite Protocols
- Admissible Polynomials
- Proposed 3KE Protocol
- Security
- Conclusion
- References
- A Game-Theoretic Perspective on Oblivious Transfer
- Introduction
- Background
- This Work
- Models and Definitions
- Cryptographic Security
- Game-Theoretic Concepts
- Game-Theoretic Perspective
- Game-Theoretic Security
- Equivalence of the Two Security Definitions
- Cryptographic Security Implies Game-Theoretic Security
- Game-Theoretic Security Implies Cryptographic Security
- References
- Faster Algorithm for Solving Hard Knapsacks for Moderate Message Length
- Introduction
- Preliminaries
- Notation
- Asymptotic Values of Binomials and Multinomials
- Basic Principle of BCJ Algorithm beckereuro
- Decomposing Knapsack
- Decomposing Knapsack into Eight Subknapsacks
- Analyzing Detailed Running Time of BCJ Algorithm
- Details of Every Step
- Running Time of BCJ Algorithm
- Our Algorithm
- Details of Every Step
- Running Time of Our Algorithm
- Comparison between BCJ Algorithm and Our Algorithm
- Extensions in More Decompositions
- Concluding Remarks
- References
- List Algorithm
- Accelerating the Secure Distributed Computation of the Mean by a Chebyshev Expansion
- Introduction
- Privacy Preserving Computation of the Mean
- Acceleration of the Computation of the Mean by a Chebyshev Expansion
- The New Protocol
- Computation and Communication Overhead
- Conclusion
- References
- Sub-protocols
- Cryptanalysis
- Security Analysis of the Lightweight Block Ciphers XTEA, LED and Piccolo
- Introduction
- Target Ciphers
- Description of XTEA
- Description of LED
- Description of Piccolo
- Meet-in-the-Middle Attacks
- Meet-in-the-Middle Attacks on Lightweight Block Ciphers
- Security of XTEA against MITM Attack
- Security of LED against MITM Attack
- Security of Piccolo against MITM Attack
- Discussion
- Security against Speed-up Keysearch Based on MITM Attack
- Comparison with Other Cryptanalysis Results
- Conclusion
- References
- Improved Known-Key Distinguishers on Feistel-SP Ciphers and Application to Camellia
- Introduction
- Preliminaries
- Previous and Related Work
- Previous Rebound Attack on Feistel-SP Ciphers
- New Known-Key Distinguishers on Feistel-SP Ciphers
- Flaw of Previous 7-Round Collisions for (N,c)=(64,8)
- Improved 5-Round Inbound Phase with 2c Computations
- 4-Sums on Compression Function Modes
- Applications to Camellia and Its Hashing Modes
- Specification of Camellia
- Applications to Camellia Hashing Modes
- Experiments and Generated Data
- Concluding Remarks
- References
- Low Data Complexity Attack on Reduced Camellia-256
- Introduction
- Preliminaries
- Notations
- Brief Description of Camellia
- 7-Round Meet-in-the-Middle Distinguisher with FL Layer
- Lu et al.'s Higher-Order MITM Distinguishers
- 7-Round Meet-in-the-Middle Distinguisher
- Meet-in-the-Middle Attack on 12-Round Camellia-256 with Low Data Complexity
- Conclusion
- References
- Proof of Observation 1
- Lu et al.'s 6-Round Distinguisher
- Cryptanalysis of RSA with a Small Parameter
- Introduction
- New Attack by Applying Shanks' Method
- Baby-Step Giant-Step Method
- Cryptanalysis on RSA Schemes of Sun et al.
- New Attack by Applying Pollard's Method
- Pollard's $\rho$ Method
- Cryptanalysis on RSA schemes of Sun et al.
- Conclusion
- References
- An Algebraic Broadcast Attack against NTRU
- Introduction
- Preliminaries
- The Learning with Errors Problem
- NTRU
- Transforming NTRU into Its Linear Form
- A Broadcast Attack against NTRU
- The Basic Algorithm for LWE with Bounded Errors
- The Broadcast Attack against NTRU-1998
- The Broadcast Attack against NTRU-2001 with an Odd dg
- The Broadcast Attack against NTRU-2005
- Analysis of the Attacks
- Improving the Attack
- Conclusion
- References
- Some Results for IEEE 1363.1 Standard
- Message Authentication Codes and Hash Functions
- Analysis of Indirect Message Injection for MAC Generation Using Stream Ciphers
- Introduction
- MAC Generation
- MAC Generation Phases
- Forgery Attacks on MAC Generation
- MAC Generation Using Indirect Message Injection
- General Structure for AE Algorithms
- Structure of the Integrity Algorithm
- Optional Processes
- Current Proposals Using This Model
- 128-EIA3 Version 1.4
- 128-EIA3 Version 1.5
- Grain-128a
- Sfinks
- Forgery Attacks
- Security of the Accumulation Process
- Security Considerations for the Masking Vector A0F
- Security Analysis of Existing Ciphers
- Conclusion
- References
- Weimar-DM: A Highly Secure Double-Length Compression Function
- Introduction
- Preliminaries
- Basic Notions
- Security Notions for Double Length Compression Functions
- Collision Security Analysis of Weimar-DM
- Security Results
- Proof of Theorem 1
- Preimage Security Analysis of Weimar-DM
- Security Results
- Proof of Theorem 2
- Discussion and Conclusion
- References
- Related Work
- Public Key Cryptography
- An Efficient IND-CCA2 Secure Variant of the Niederreiter Encryption Schemein the Standard Model
- Introduction
- Preliminaries
- Notation
- Definition of the Security Notions
- Security Assumptions
- Variant of the Niederreiter Cryptosystem
- Proposed Scheme
- Proof for the Security of the System
- Parameters
- Comparison with Other Schemes
- Conclusion
- References
- Zero-Knowledge Protocols for the McEliece Encryption
- Introduction
- Our Contributions
- Related Works
- Discussion of Our Contributions
- Preliminaries
- Security Assumptions
- McEliece Cryptosystem
- Proof of Plaintext Knowledge
- Verifiable Encryption
- Commitments
- PPK for McEliece Encryption
- Extensions
- Verifiable McEliece Encryption
- Conclusion
- References
- Effort-Release Public-Key Encryption from Cryptographic Puzzles
- Introduction
- Cryptographic Puzzles
- Difficult Key Encapsulation Mechanism
- Definition: Difficult KEM
- A Difficult Key Encapsulation Mechanism from Puzzles
- Effort-Release Public Key Encryption
- Effort-Release Hybrid PKE
- Constructions of Effort-Release Hybrid PKE
- Conclusion
- References
- Leakage-Resilience of Stateless/Stateful Public-Key Encryption from Hash Proofs
- Introduction
- Preliminaries
- Models
- Leakage-Resilient CCA2 Stateless Public-Key Encryption
- Leakage-Resilient CCA2 Stateful Public-Key Encryption
- Symmetric Encryption
- Generic Constructions from Hash Proof Systems
- The Construction of a 1-Universal -key-Leakage Extractor HPS
- The Construction of Stateless Public-Key Encryption
- The Construction of Stateful Public-Key Encryption
- Conclusion
- References
- How to Fix Two RSA-Based PVSS Schemes-Exploration and Solution
- Introduction
- Background
- Publicly Verifiable Secret Sharing
- The Two RSA-Based PVSS Schemes in Boudot1999 and Fujisaki1998
- The Concern Raised in Peng2011E
- Secure and Efficient PVSS Based on RSA Encryption
- Avoiding Too Large Integers
- More Efficient Specification of PROOF[ ]
- Conclusion
- References
- Digital Signatures
- Relation between Verifiable Random Functions and Convertible Undeniable Signatures, and New Constructions
- Introduction
- Background
- Our Contributions
- Definitions
- Zero-Knowledge Protocols for Generalized DDH and Non-DDH
- Relation between SCUS and VRF
- SCUS from VRF: A Generic Construction
- Concrete Instantiations
- VRF from Unique SCUS
- A New Probabilistic SCUS with Neat Converters and Signatures
- References
- Generalized First Pre-image Tractable Random Oracle Model and Signature Schemes
- Introduction
- Related Work
- The Generalization of FPT-ROM
- Separation for the Security of Signature Schemes
- Separation for the Security of Encryption Schemes
- Generic Transformation for Signatures in GFPT-ROM
- Hash-and-Sign Signatures
- Transformation
- Application and Comparison
- Conclusion
- References
- A Short Non-delegatable Strong Designated Verifier Signature
- Introduction
- Contribution
- Related Works
- Organizations
- Preliminaries
- Assumptions
- SDVS
- The SDVS Scheme
- Proofs
- Unforgeability
- Non-transferability
- Privacy of Signer's Identity (PSI)
- Non-delegatability
- Comparison
- References
- Encryption Algorithm Implementation
- Deterministic Identity Based Signature Scheme and Its Application for Aggregate Signatures
- Introduction
- Generic Model
- Security Model
- Existential Unforgeability of D-IBS
- Existential Unforgeability of IBAS
- Deterministic Identity Based Signature Scheme (D-IBS)
- Existential Unforgeability of D-IBS
- Identity Based Aggregate Signature Scheme from RSA (IBAS)
- Conclusion
- References
- Fully Leakage-Resilient Signatures with Auxiliary Inputs
- Introduction
- Security Models for Leakage-Resilient Signatures
- Selective Auxiliary Input Model for Unforgeability
- Classes of Auxiliary Input Functions
- Building Blocks
- Second-Preimage Resistant
- Statistical Non-interactive Witness-Indistinguishable Proof
- Admissible Hash Functions
- Commitment Scheme
- Statistically Hiding Tag-based Commitment Scheme with Extraction
- Construction
- Efficient Instantiation
- Building Blocks
- Efficiency Analysis
- Fully Leakage-Resilient Signatures with Selective Continuous Auxiliary Input
- References
- Identity-Based and Attribute-Based Cryptography
- Adaptive CCA Broadcast Encryption with Constant-Size Secret Keys and Ciphertexts
- Introduction
- Related Work
- Our Contributions
- Preliminaries
- Dynamic Broadcast Encapsulation
- The BDHE and GBDHE Assumptions
- Universal One-Way Hash Function
- An Efficient Selective CCA Broadcast Encryption
- Inclusive-Exclusive Broadcast Encryption
- Achieving Adaptive CCA Security
- The OBDHE Assumption
- The GKEA Assumption
- Adaptive CCA Security
- Comparison
- Concluding Remarks
- References
- A Generic Construction of Accountable Decryption and Its Applications
- Introduction
- Related Work
- Accountable Decryption
- Scheme Definition
- Security Definition
- A Generic Construction
- Notation
- Proposed Construction
- Applications
- A Full-Fledged Predicate Encryption Scheme with Accountable Decryption
- PEKS with Verifiable Test
- Conclusion
- References
- Threshold Ciphertext Policy Attribute-Based Encryption with Constant Size Ciphertexts
- Introduction
- Our Contributions.
- Preliminaries
- Bilinear Groups
- Hardness Assumption
- Syntax of CP-ABE Scheme
- Security Model for CP-ABE
- The Proposed CP-ABE Schemes
- Construction I: CPA Secure CP-ABE
- Construction II: CCA Secure CP-ABE
- Security Analysis and Performance
- Security Analysis
- Performance Comparison
- Conclusions
- References
- Correctness of CP-ABE
- Fully Private Revocable Predicate Encryption
- Introduction
- Our Contributions
- Dual Pairing Vector Spaces and Assumptions
- Revocable Predicate Encryption: Model and Definitions
- Syntax
- Definitions of Attribute-Hiding and Full-Hiding in RPE
- An RPE Scheme with Attribute Hiding (AH-RPE)
- An RPE Scheme with Full Hiding (FH-RPE)
- Conclusion
- References
- Anonymous ID-Based Proxy Re-Encryption
- Introduction
- Our Contributions
- Related Work
- Preliminaries
- Definitions for Single-Use Unidirectional AIBPRE
- Security Models for Single-Use Unidirectional AIBPRE
- Bilinear Groups
- Complexity Assumptions
- The Proposed Scheme
- A Wrong Design
- Description of the Proposal
- Security Analysis
- Conclusion
- References
- Lattice-Based Cryptography
- On the Optimality of Lattices for the Coppersmith Technique
- Introduction
- Preliminaries
- Framework for the Coppersmith Technique
- Analysis for Canonical Initial Polynomials
- Computation from Non-canonical Polynomials
- Technical Preliminaries
- From a Non-canonical Polynomial
- Tightness of Our Analysis
- Justifications from Computer Experiments
- Concluding Remarks
- References
- Revocable Identity-Based Encryption from Lattices
- Introduction
- Our Results
- Related Work
- Definitions
- Notation
- Syntax of RIBE
- Background on Lattices
- Integer Lattices
- The Gram-Schmidt Norm and Trapdoors for Lattices
- Discrete Gaussians
- Sampling Algorithms
- The LWE Hardness Assumption
- Encoding Identities as Matrices
- Lattice RIBE
- The Binary-Tree Data Structure
- The Agrawal et al. IBE Scheme
- Intuition of Our Construction
- Our RIBE Scheme
- Parameters, Correctness and Security
- Open Problem
- References
- Lightweight Cryptography
- On Area, Time, and the Right Trade-Off
- Introduction
- Area and Time: The Obvious Trade-Off?
- This Paper
- Area and Time for present
- The Trade-Off for cryptoGPS
- Implementations of the Mult-Variant
- Area and Time for cryptoGPS
- Conclusion
- References
- Short Papers
- Analysis of Xorrotation with Application to an HC-128 Variant
- Introduction
- Contributions of This Paper
- Biased and RX-Specific Probability Distributions
- Reviewing Distinguishers and Relative Entropy
- The Divergence of Probabilistically Biased Distributions
- RX-Induced Probability Distributions
- Application to HC-128
- Notation and Review of HC-128
- A New HC-128 Variant Distinguisher
- Conclusions
- References
- Private Fingerprint Matching
- Introduction
- Our Contributions
- Related Work
- Preliminaries
- Notation
- Homomorphic Encryption Schemes
- Fingerprint Minutiae and Fingerprint Matching
- Aided Computation
- The Private Fingerprint Matching Protocol
- Concluding Remarks
- References
- Minimizing Information Leakage of Tree-Based RFID Authentication Protocols Using AlternateTree-Walking
- Introduction
- Limitations of Privacy Leakage Measurement
- Comparison of Experiments
- Leakage Results of Current Protocols
- Alternate Tree-Walking (ATW)
- The ATW Protocol
- Other Considerations
- Conclusion
- References
- ICAF: A Context-Aware Framework for Access Control
- Introduction
- Research Motivation
- Related Work
- A Context-Aware Framework for Access Control
- Representation and Modeling of Context
- Representation of Situation
- Representation of Context-Aware Access Policies
- ICAF Prototype
- Conclusion
- References
- Non-malleable Instance-Dependent Commitmentin the Standard Model
- Introduction
- Motivation
- Contribution
- Preliminaries
- Notations
- Definitions
- Instance-Non-malleable IDC
- Construction
- Conclusions
- References
- Author Index
System requirements
File format: PDF
Copy protection: Watermark-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Use the free software Adobe Reader, Adobe Digital Editions, or any other PDF viewer of your choice (see eBook Help).
- Tablet/Smartphone (Android; iOS): Install the free app Adobe Digital Editions or another reading app for eBooks, e.g., PocketBook (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Watermark-DRM, a „soft” copy protection. This means that there are no technical restrictions to prevent illegal distribution. However, there is a personalised watermark embedded in the eBook that can be used to identify the purchaser of the eBook in the event of misuse and to provide evidence for legal purposes.
For more information, see our eBook Help page.