Showing posts with label rub. Show all posts
Showing posts with label rub. Show all posts

Friday, October 28, 2016

soft skills, hard facts

Within the ECRYPT-NET program we have the chance to learn effective communication of scientific results. Although often regarded as "soft skills", thus indicating their lesser value compared to the classical "hard skills", these methods are versatile. Obtaining them means being able to apply the techniques to either written or oral presentations.

In particular at the School on Design for a secure Internet of Things our oral presentation training started with practical sessions. Classical topics like how to deal with stage fright and non-verbal communication such as body language were demonstrated and different ways to know and connect to the audience were addressed.
Among others, we spoke detailed about posture, use of voice, articulation on the one hand and style, amount of information per presentation slide as well as how to present in a lively way yet giving a memorable take-home message on the other hand.

Later this year, during the Cloud Summer School recently in Leuven we had the chance to actively participate the practical training session on academic writing to concisely yet accurately convey future research findings. Our trainer taught us how to chop-up long, unwieldy sentences into more easly digestible ones by reorganizing competing foci and effectively conveying the essence. Showing worked examples from our area and even some excerpts of our own texts definitely helped in understanding the concepts.
There, all of us ECRYPT-NET early stage researchers gave their (possibly first, big) presentation and we received feedback from the board and our individual supervisors. The combined, but especially the individual, feedback of good choices and less fortunate formulations were brought up.

As we'll have more and more tasks to work on as a group coming up in our career, developing an efficient work-flow for joint-documents is not to be considered wasted effort and time. Thus, soon we'll have the chance to obtain more soft-skills that can turn out to be useful in a dynamic setting.
I want to take the opportunity to organize a workshop as a follow-up event of the upcoming Passwords2016-conference for us ESRs. The plan is to have a day of sessions and meetings in Bochum on Thursday, 8.12.:

It'll be co-located with the 11th International Conference on Passwords, where you can listen to the Long Story of Password (Re-)use, learn Password Hardening techniques, debate whether new Password Management strategies based on Episodic Memories or Through Use of Mnemonics is revolutionary and find out about the Hopes and Fears of Mobile Device Security.
About 100 international participants from academia, companies, ... will come and follow the conference program, which is a mix
of classical talks and more practical "hackers sessions", showing attacks in the real-world setting.

Unfortunately there is no detailed program available yet, but soon for sure.
However, the registration is open now until 2016-11-30.
For those interested to join this event, try to save some € by obtaining the early bird offer (only until 2016-10-31).

Ruhr-University seen from Beckmanns Hof
All other fellows are warmly invited to come on Wednesday, 7.12 after the Passwords2016-talks for a first ECRYPT-NET get-together in Bochum and our program tailored to the upcoming writing project.
Thursday, 8.12 is the main day which we will start off by a workshop followed by project-oriented brainstorming and group discussions.
We'll have an expert training on collaborative creative writing and group
communication (in English), working in nice atmosphere close to Bochum's botanical gardens.

In short, in this workshop the focus lies on how to get things done, collaboratively. The technical aspect will be covered by a git repository with the projects' skeleton, that I set up here on a RUB-Server, where one can get a git account even as a RUB-external.
If you need a refresher, reread Ralph's blog post about git basics.

I am looking forward welcoming all of you here.

Sunday, March 27, 2016

FSE 2016 and DISC workshop

This is part two of a two-part blog post collaboratively written by Matthias and Ralph.

FSE 2016


From 20. to 23. March the 23rd International Conference on Fast Software Encryption (FSE) took place in Bochum, Germany at the Ruhr University Bochum. The conference focus on fast and secure primitives for symmetric cryptography.


The conference was split in 9 sessions. 

Session 1: Operating Modes


This session was on operating modes and the following three papers were presented:

The paper "A MAC Mode for Lightweight Block Ciphers" was presented by Atul Luykx, where he presented a new MAC mode called LightMAC that focus on extending the lifetime of a symmetric key. 

Session 2: Stream-Cipher Cryptanalysis

This session was on stream-cipher cryptanalysis and the following two papers were presented:

The paper "Cryptanalysis of the Full Spritz Stream Cipher" was presented by Subhadeep Banik where he presented an improved state recovery attack that takes advantage of a special state, that when entered all even values in the permutation are mapped to even values and all odd values to odd values. 

Session 3: Components

This session was on components and the following three papers were presented: 
Siang Meng Sim presented the paper on "Lightweight MDS Generalized Circulant Matrices" where they showed left circulant MDS matrixes of order $\le$ 8.

Session 4: Side-Channels and Implementations

This session was on side-channels and implementations and the following three papers were presented: 
Pascal Sasdrich presented the paper "White-Box Cryptography in the Gray Box - A Hardware Implementation and its Side Channels. In his talk he presented the first AES white-box implementation in hardware and provided results of a practical gray-box (side-channel) analysis. 

Session 5: Automated Tools for Cryptanalysis

This session was on automated tools for cryptanalysis and the following three papers were presented: 

Vesselin Velichkov presented the paper "Automatic Search for the Best Trails in ARX: Applicaton to Block Cipher Speck where they present a new automatic search tool tha applies Matsui's algorithm with optimal results. Then they searched for differential trails in Speck and presented new bounds on the security of Speck regadring to differential cryptanalysis.

Session 6: Designs

This session was on designs and the following two papers were presented: 

Jeremey Jean presented the paper on Efficient Design Strategies Based on the AES Round Function. In their paper they present cascaded iterations of the AES round function together with intermediate XOR's which achives a high performance. 

Invited Talk: On White-Box Cryptography

The invited talk on white-box cryptography was given by Henri Gilbert from ANSSI, France. 

Session 7: Block-Cipher Cryptanalysis

This session was on block-cipher cryptanalysis and the following five papers were presented: 

  • Bit-Based Division Property and Application to Simon Family
  • Algebraic Insights into the Secret Feistel Network
  • Integrals go Statistical: Cryptanalysis of Full Skipjack Variants
  • Note on Impossible Differential Attacks
  • Improved Linear Hull Attack on Round-Reduced Simon with Dynamic Key-guessing Techniques

Rump Session

The rump session consisted of several short talks for a few minutes. 

Thomas Peyrin presented a new block cipher called Skinny that is based on the TWEAKEY framework. Skinny has an AES like design and achives better performance than SIMON and other lightweight designs. 

Jeremy Jean presented a website with standardized figures for ciphers in his talk about TikZ for Cryptographers. He aimed that every cryptographer should use this standardized figures in their papers. 

Christian Rechberger presented the FHEMPCZK-Cipher Zoo where one could compare ciphers for Fully Hommomorphic Encryption (FHE), Multi Party Computation (MPC) and Zero Knowledge (ZK).

Session 8: Foundations and Theory


This session was on foundations and theory and the following four papers were presented:
  • Modeling Random Oracles under Unpredictable Queries
  • Practical Order-Revealing Encryption with Limited Leakage
  • Strengthening the Known-Key Security Notion for Block Ciphers
  • Related-Key Almost Universal Hash Functions: Definitions, Constructions and Applications

Session 9: Authenticated-Encryption and Hash Function Cryptanalysis


This session was on authenticated-encryption and hash function cryptanalysis and the following three papers were presented:
  • Key Recovery Attack against 2.5-round $\pi$-Cipher
  • Cryptanalysis of Reduced NORX
  • Analysis of the Kupyna-256 Hash Function
Yu Sasaki presented the Cryptanalysis of Reduced NORX, where they present state and key recovery attacks on the core permutation which is reduced to 2 out of 4 rounds. 

DISC workshop


After FSE, the Directions in Symmetric Cryptography (DISC) workshop for PhD students and young post-docs took place at the Ruhr University Bochum.

The workshop was divided into 5 working groups of 5 to 9 participants, who got the opportunity to work together for one and a half day on a specific topic. Furthermore, the goal was to meet some other people that are working in the same area and to build some research collaborations.

Topic 1: How to design a bad key schedule

The goal of this topic was to approach key schedule design from the opposite direction: Can we design a key schedule -- seemingly harmless -- that has a decremental effect on the block cipher's security. Is it even possible to hide back doors in the key schedule only?

Topic 2: The TWEAKEY framework - New Designs and Cryptanalysis of STK

The TWEAKEY framework was introduced at ASIACRYPT 2014 as a more general design idea for a tweak/key (tweakey) scheduling. In this framework, one does not to separate between key and tweak material. The authors proposed a specific instance called superposition TWEAKEY (STK) and designed three tweakable block ciphers Joltik-BC, Deoxys-BC and Kiasu-BC based on this idea. This topic was both about cryptanalysis of the STK construction and thinking about design alternatives.

TOPIC 3: Distinguishing block ciphers: Is the attack space covered?

Block cipher cryptanalysis relies to a large degree on the existence of efficient distinguishers. In this topic, we want to discuss and explore possible directions where novel cryptanalytic techniques might be found or alternatively find arguments why new techniques are unlikely to be found.

TOPIC 4: How reliable are our assumption in statistical attacks?

In symmetric cryptanalysis, statistical attacks such as differential and linear cryptanalysis, boomerang attacks or differential-linear attacks, play an important role in the security evaluations of block ciphers. These attack inherently rely on varying independence or randomization assumptions that are necessary to estimate their success probability. Is it possible to determine criteria when these assumptions will fail or hold? Can we sometimes remove the assumptions or substitute them with
weaker variants? Can we give heuristic arguments for their validity to increase our faith in them?

TOPIC 5: Resistance against cryptanalytic attacks: What can we prove?

Unlike algorithms in public-key schemes, block ciphers are usually not based on hard-problems. To estimate the security, block ciphers are instead evaluated against the range of known attack vectors. Both from the designers and evaluators perspective it would be desirable to have proofs against larger classes of attacks. Even finding good heuristic formulas that determine the number of rounds
needed for security would be large step forward. In this topic, we would like to discuss design, evaluation and proof strategies that might help us to move towards this goal.



Friday, March 18, 2016

Spring School on Symmetric Cryptography

This is part one of a two-part blog post collaboratively written by Matthias and Ralph.

The Spring School on Symmetric Cryptography takes place at Beckmanns Hof just one minute south of Ruhr University Bochum.
The Spring school, which can be seen as a supplementary event for FSE 2016 next week, lies literally on the verge of the botanical garden of Bochum!

The Spring School's program covers lectures on the theory of "Boolean Functions" and "Statistical Models" in symmetric cryptography. Additionally there are exercises to gain a firm understanding thereof which were compiled by Anne Canteaut and Celine Blondeau.
The theoretical part is supplemented by the more practically oriented talks of the invited researchers Joan Daemen and Ventzi Nikov.


For the lecture on "Boolean Functions" Anne Canteaut preferred a sympathetic, old-fashioned presentation with chalk on black board in the lecture hall over an overhead presentation in the modern seminar room.

The topic ranged from Boolean functions and their algebraic normal form to the interpretation as Reed–Muller codes. Then the Walsh transform was introduced as a tool to analyze and approximate Boolean functions by linear ones.


In the lecture on "Statistical Models" Celine Blondeau (lecture notes here)
reminded us of basic probability distributions well known to statisticians and we explored some of their uses in cryptography. The discussion lead us from Binomial-, Poisson-, Normal- over Chi-Square- and Hypergeometric distributions to the study of Kullback-Leibler divergence and the applications for i.e. Linear attacks, Differential attacks and Impossible differential cryptanalysis. She also gave directions of ongoing work in that field.



The advantages of "Permutation Based Cryptography" were presented by Keccak (SHA-3) and Rijndael (AES) (co-)designer Joan Daemen.


The talk about "Threshold Implementations" by Ventzi Nikov covered techniques to decompose (non-linear) functions to separate the inputs from intermediate results and masking.
The key-values are masked by splitting up function inputs into separate shares such that knowledge of less than all shares does not allow to recover the value.

Matthias and Ralph will stay tuned for some S-Box theory and the statistical wrap-up on Saturday morning and the slides and recorded videos of this Spring School will soon be available at the official website.

Friday, December 18, 2015

Codes and Coding

Dear readers, hi fellows,
as my master's thesis was about Linear Codes and Applications in Cryptography I'd like to provide some content of it in a nutshell and to give some recommendations of software that I used in the course of writing it.

multiple scientific fields are involved (created using TikZ)
Modern cryptography covers among others the three areas privacy, authentication and integrity of messages. The aim of coding theory on the other hand described by one word is reliability - adding redundancy to messages in order to detect transmission errors. Both fields cover seemingly different areas in the field of digital information processing.

The motivation of my thesis was to showcase the combination of multiple scientific fields within coding theory and modern cryptography and to explore how they interact in the domain mentioned above and why they are a good choice.


In the center of attention stood the McEliece public-key cryptosystem, it's variation (Niederreiter's cryptosystem) and generalizations to other code classes after those code classes of interest were introduced and discussed.

The McEliece public-key cryptosystem was published in 1978, is based on disguising a special code as a general code and it is of interest back then and today because it seems to stand solid in the so-called post-quantum era, when a powerful quantum computer is available to attackers. More than 35 years ago the original code parameters: codeword length $n = 1024$, code dimension (or message bits) $k = 524$ and error-correcting capability $t = 50$ were proposed for the binary code underlying the McEliece public-key cryptosystem for $2^64$ bit security. To achieve the a reasonable security level today they have been adjusted to $n = 6960, k = 5413, t = 119$ because of attacks that were explored since then.

Given the number $t$ of erroneous positions and a general code $C$, the task of decoding $y = c + e$ is to find a codeword $c \in C$ of Hamming weight or number of non-zero entries: $w(y-c) = w(e) = t$. In the complexity theoretic literature the result is that this problem is NP-complete - there is no algorithm known that fulfills this task in polynomial time depending on the input size (length of $y$ respectively $c$).

The choice to use a Goppa codes as private key, which is multiplied by permutation matrices to obtain the public key looking as if it was a general code, was due to performance reasons when decoding messages thanks to Patterson's algorithm.

Interestingly many attacks are not applicable to the class of binary Goppa codes that McEliece's scheme was based on but on similar schemes and generalizations allowing other alphabets or other structures - binary Goppa codes were seemingly proposed with foresight.

In spite of some advantages and the - so far - quantum computer resistant attacks the biggest drawback of public-key cryptosystems based on codes are rather long public keys compared to other schemes. If one adds a security margin, under the assumption of a working quantum computer performing the general attack through the application of Grover's algorithm, the public key size is as big as 1 MB.


In the thesis I implemented the fast algorithm (by N. J. Patterson) for algebraically decoding binary Goppa codes in Sage and demonstrated the full functionality of the system in yet another chapter giving an example. Since I was writing it all up in $\LaTeX$, using sagetex even allowed the computation and insertion of the results into the $\verb!.tex!$ file one the fly when the document is being compiled!

My recommendation (to my fellows) for researching, analyzing, developing & testing of algorithms in a structured manner with the ability to create nice plots and documents rather easily is to give Sage or Spyder a try. Even though it might not be a necessity in your research to actually code something, playing around with these tools already available is instructive and worth a try.

Sage is available online or offline via installation and it is a good choice if you need access to i.e. number theory. Maybe the aforementioned Spyder is preferable if a somewhat more automated handling even closer to the programming language Python of the implemented primitive at hand is needed in your case.

Autumnal Bochum around Oct 31
As usual, a little plurivalent:
Happy Coding and Happy Halloween - because $Dec(25) = Oct(31)$, right?!


Friday, November 6, 2015

Hello World! from Matthias

Hello World!

I am ESR5 and I am from Austria. I also go by the name ɱatthias ɱinihold and I have just started as one of the 15 fellows of the ring also known as early stage researchers in the ECRYPT-NET programme :-).


My background is mathematics, but I was always interested in the practical application side of say algebraic number theory and thus I enrolled in courses about cryptography and wrote my bachelor’s thesis at TU Vienna having a look into the Advanced Encryption Standard AES. Then my master’s thesis was about "Linear Codes and Applications in Cryptography" with some examples coded in Sage and the showcase of how multiple scientific fields - ranging from computational complexity theory and discrete mathematics to quantum physics - are combined in cryptography, making it an interesting and interdisciplinary field.


I'm glad to be part of an experienced team here at Ruhr-Universität Bochum under the supervision of Alexander May. The working title for my research as ESR5 @ ECRYPT-NET and thus my PhD-Thesis is Fully Homomorphic Encryption. Additionally to thoroughly dive into that I hope to learn and develop further skills and expertise in related fields over the next 3 years here.


In the caves of Is Zuddas (Sardinia)
In my opinion the exciting part of the ECRYPT-NET project with all it's international participants is that it has the opportunity to shape the future of transparent, easy to use yet secure cryptography accessible to a broad range of people thus taking an important role in our information society.


I am looking forward to working in this dynamic team and maybe this project provides the right environment, guidance and feedback to bring to light gems and fascinating structures within the next 3 years such as the rare aragonites people joining the trip to Is Zuddas (Sardinia) could marvel at recently, metaphorically speaking.


Followers are welcome and to all my fellows, see you soon at our next meeting(s)!


"I'll be back!" (Arnold Schwarzenegger)

Friday, October 30, 2015

A simple "hallo" from Erik

Continuing with the theme of introducing ourselves, my name is Erik Boss. I am one of the ESRs from Ruhr-Universität Bochum. I grew up in a fairly small town called Duiven located in the east of the Netherlands. I completed my Bachelor's and Master's degrees at the Radboud University Nijmegen. The latter of which specializing in computer security.

Only deciding right at the end of my studies to pursue a PhD, I applied for one of the ESR positions at the RUB and moved to Germany three months later. Which, so far, has been an interesting experience.

Within the context of ECRYPT-NET, I will be combining my expertise with software-related security with the experience located at the RUB in embedded security. What I will be looking at primarily is the automatic verification of hardware specifications in order to detect, prevent and/or measure side-channel leakages. This allows me combine many areas of computer security as well as some ideas from computer science in general.

Overall, I am grateful for the opportunity provided by this project to do something which is fun and fulfilling and maybe even useful to the world at large. Already I have met some great people within the context of ECRYPT-NET and I am looking forward to seeing everyone again in Tenerife.