Machine Theory

This booklet constitutes the refereed complaints of the twelfth foreign convention on utilized Cryptography and community safety, ACNS 2014, held in Lausanne, Switzerland, in June 2014. The 33 revised complete papers integrated during this quantity have been conscientiously reviewed and chosen from 147 submissions. they're equipped in topical sections on key alternate; primitive building; assaults (public-key cryptography); hashing; cryptanalysis and assaults (symmetric cryptography); community protection; signatures; method safety; and safe computation.

26 K. Yoneyama Common private input : password pw = pwAB Common reference string : pk, pk Party A (Initiator) Party B (Responder) r ← {0, 1}∗ trans1 := A||CT CT = Enc pk (pw; r ) −−−−−−−−−−−−−−−−→ rA ||τA ||S KA = hhp (pk , CT , pw, r ) label := trans1 ||B||hp ˆ = Enclabel CT pk (pw; rA ) ˆ if CT CT , abort output S KA hk ← KS hp = F(hk, pk , CT ) rB ||τB ||S KB = Hhk (pk , CT , pw) label := trans1 ||B||hp trans2 := B||hp||CT ←−−−−−−−−−−−−−−−−−−− CT = Enclabel pk (pw; r B ) trans3 := A||τA −−−−−−−−−−−−−−→ if τA τB , abort output S KB Fig.

Enc will be stored in the variable STA. 2 Security Analysis Theorem 2. Assume that the KE protocol without long-term key is (t, KE )secure (Definition 1), the public key encryption scheme PKE is (qpke , t, PKE )secure (IND-CCA2), and the hash function CRHF is (t, CRHF )-secure and the one-time authentication code scheme OTMAC is deterministic and (t, OTMAC )secure. Then the above protocol is a (t , )-secure AKE protocol in the sense of Definition 6 with t ≈ t and qpke ≥ d and holds that ≤2 CRHF + d · (2 · PKE +2 OTMAC +2 KE ) + (d )2 · KE .

We construct a (concurrently secure) three-move PAKE scheme in the MS model (justly without random oracles) based on the Groce-Katz PAKE scheme. The main ingredient of our scheme is the multi-string simulation-extractable non-interactive zero-knowledge proof that provides both the simulation-extractability and the extraction zero-knowledge property even if minority authorities are malicious. This work can be seen as a milestone toward constant round PAKE schemes in the plain model. Keywords: authenticated key exchange, password, multi-string model, concurrent security.

