The Experts below are selected from a list of 7671 Experts worldwide ranked by ideXlab platform

Dennis Hofheinz - One of the best experts on this subject based on the ideXlab platform.

  • GNUC: A New Universal Composability Framework
    Journal of Cryptology, 2015
    Co-Authors: Dennis Hofheinz, Victor Shoup
    Abstract:

    We put forward a framework for the modular design and analysis of multi-party protocols. Our framework is called “GNUC” (with the recursive meaning “GNUC’s Not UC”), already alluding to the similarity to Canetti’s Universal Composability (UC) framework. In particular, like UC, we offer a universal Composition Theorem, as well as a Theorem for composing protocols with joint state. We deviate from UC in several important aspects. Specifically, we have a rather different view than UC on the structuring of protocols, on the notion of polynomial-time protocols and attacks, and on corruptions. We will motivate our definitional choices by explaining why the definitions in the UC framework are problematic, and how we overcome these problems. Our goal is to offer a framework that is largely compatible with UC, such that previous results formulated in UC carry over to GNUC with minimal changes. We exemplify this by giving explicit formulations for several important protocol tasks, including authenticated and secure communication, as well as commitment and secure function evaluation.

  • Polynomial Runtime and Composability
    Journal of Cryptology, 2013
    Co-Authors: Dennis Hofheinz, Dominique Unruh, Jörn Müller-quade
    Abstract:

    We devise a notion of polynomial runtime suitable for the simulation-based security analysis of multi-party cryptographic protocols. Somewhat surprisingly, straightforward notions of polynomial runtime lack expressivity for reactive tasks and/or lead to an unnatural simulation-based security notion. Indeed, the problem has been recognized in previous works, and several notions of polynomial runtime have already been proposed. However, our new notion, dubbed reactive polynomial time , is the first to combine the following properties: it is simple enough to support simple security/runtime analyses, it is intuitive in the sense that all intuitively feasible protocols and attacks (and only those) are considered polynomial-time, it supports secure Composition of protocols in the sense of a universal Composition Theorem. We work in the Universal Composability (UC) protocol framework. We remark that while the UC framework already features a universal Composition Theorem, we develop new techniques to prove secure Composition in the case of reactively polynomial-time protocols and attacks.

  • Some (in)sufficient conditions for secure hybrid encryption
    Information and Computation, 2010
    Co-Authors: Javier Herranz, Dennis Hofheinz, Eike Kiltz
    Abstract:

    AbstractIn hybrid public key encryption (PKE), first a key encapsulation mechanism (KEM) is used to fix a random session key that is then fed into a highly efficient data encapsulation mechanism (DEM) to encrypt the actual message. A well-known Composition Theorem states that if both the KEM and the DEM have a high enough level of security (i.e., security against chosen-ciphertext attacks), then so does the hybrid PKE scheme. It is not known if these strong security requirements on the KEM and DEM are also necessary, nor if such general Composition Theorems exist for weaker levels of security.Using six different security notions for KEMs, 10 for DEMs, and six for PKE schemes, we completely characterize in this work which combinations lead to a secure hybrid PKE scheme (by proving a Composition Theorem) and which do not (by providing counterexamples). Furthermore, as an independent result, we revisit and extend prior work on the relations among security notions for KEMs and DEMs

  • ISC - On the notion of statistical security in simulatability definitions
    Lecture Notes in Computer Science, 2005
    Co-Authors: Dennis Hofheinz, Dominique Unruh
    Abstract:

    We investigate the definition of statistical security (i.e., security against unbounded adversaries) in the framework of reactive simulatability. This framework allows to formulate and analyze multi-party protocols modularly by providing a Composition Theorem for protocols. However, we show that the notion of statistical security, as defined by Backes, Pfitzmann and Waidner for the reactive simulatability framework, does not allow for secure Composition of protocols. This in particular invalidates the proof of the Composition Theorem. We give evidence that the reason for the non-composability of statistical security is no artifact of the framework itself, but of the particular formulation of statistical security. Therefore, we give a modified notion of statistical security in the reactive simulatability framework. We prove that this notion allows for secure Composition of protocols. As to the best of our knowledge, no formal definition of statistical security has been fixed for Canetti's universal composability framework, we believe that our observations and results can also help to avoid potential pitfalls there.

  • CSFW - Polynomial runtime in simulatability definitions
    18th IEEE Computer Security Foundations Workshop (CSFW'05), 1
    Co-Authors: Dennis Hofheinz, Jörn Müller-quade, Dominique Unruh
    Abstract:

    We elaborate on the problem of polynomial runtime in simulatability definitions for multiparty computation. First, the need for a new definition is demonstrated by showing which problems occur with common definitions of polynomial runtime. Then, we give a definition which captures in an intuitive manner what it means for a protocol or an adversary to have polynomial runtime. We show that this notion is suitable for simulatability definitions for multiparty computation. In particular, a Composition Theorem is shown for this notion.

Zhihan Zhao - One of the best experts on this subject based on the ideXlab platform.

Gaston M Nguerekata - One of the best experts on this subject based on the ideXlab platform.

Yongkui Chang - One of the best experts on this subject based on the ideXlab platform.

Victor Shoup - One of the best experts on this subject based on the ideXlab platform.

  • GNUC: A New Universal Composability Framework
    Journal of Cryptology, 2015
    Co-Authors: Dennis Hofheinz, Victor Shoup
    Abstract:

    We put forward a framework for the modular design and analysis of multi-party protocols. Our framework is called “GNUC” (with the recursive meaning “GNUC’s Not UC”), already alluding to the similarity to Canetti’s Universal Composability (UC) framework. In particular, like UC, we offer a universal Composition Theorem, as well as a Theorem for composing protocols with joint state. We deviate from UC in several important aspects. Specifically, we have a rather different view than UC on the structuring of protocols, on the notion of polynomial-time protocols and attacks, and on corruptions. We will motivate our definitional choices by explaining why the definitions in the UC framework are problematic, and how we overcome these problems. Our goal is to offer a framework that is largely compatible with UC, such that previous results formulated in UC carry over to GNUC with minimal changes. We exemplify this by giving explicit formulations for several important protocol tasks, including authenticated and secure communication, as well as commitment and secure function evaluation.

  • a Composition Theorem for universal one way hash functions
    Theory and Application of Cryptographic Techniques, 2000
    Co-Authors: Victor Shoup
    Abstract:

    In this paper we present a new scheme for constructing universal one-way hash functions that hash arbitrarily long messages out of universal one-way hash functions that hash fixed-length messages. The new construction is extremely simple and is also very efficient, yielding shorter keys than previously proposed Composition constructions.