Showing posts with label workshop. Show all posts
Showing posts with label workshop. Show all posts

Friday, October 28, 2016

soft skills, hard facts

Within the ECRYPT-NET program we have the chance to learn effective communication of scientific results. Although often regarded as "soft skills", thus indicating their lesser value compared to the classical "hard skills", these methods are versatile. Obtaining them means being able to apply the techniques to either written or oral presentations.

In particular at the School on Design for a secure Internet of Things our oral presentation training started with practical sessions. Classical topics like how to deal with stage fright and non-verbal communication such as body language were demonstrated and different ways to know and connect to the audience were addressed.
Among others, we spoke detailed about posture, use of voice, articulation on the one hand and style, amount of information per presentation slide as well as how to present in a lively way yet giving a memorable take-home message on the other hand.

Later this year, during the Cloud Summer School recently in Leuven we had the chance to actively participate the practical training session on academic writing to concisely yet accurately convey future research findings. Our trainer taught us how to chop-up long, unwieldy sentences into more easly digestible ones by reorganizing competing foci and effectively conveying the essence. Showing worked examples from our area and even some excerpts of our own texts definitely helped in understanding the concepts.
There, all of us ECRYPT-NET early stage researchers gave their (possibly first, big) presentation and we received feedback from the board and our individual supervisors. The combined, but especially the individual, feedback of good choices and less fortunate formulations were brought up.

As we'll have more and more tasks to work on as a group coming up in our career, developing an efficient work-flow for joint-documents is not to be considered wasted effort and time. Thus, soon we'll have the chance to obtain more soft-skills that can turn out to be useful in a dynamic setting.
I want to take the opportunity to organize a workshop as a follow-up event of the upcoming Passwords2016-conference for us ESRs. The plan is to have a day of sessions and meetings in Bochum on Thursday, 8.12.:

It'll be co-located with the 11th International Conference on Passwords, where you can listen to the Long Story of Password (Re-)use, learn Password Hardening techniques, debate whether new Password Management strategies based on Episodic Memories or Through Use of Mnemonics is revolutionary and find out about the Hopes and Fears of Mobile Device Security.
About 100 international participants from academia, companies, ... will come and follow the conference program, which is a mix
of classical talks and more practical "hackers sessions", showing attacks in the real-world setting.

Unfortunately there is no detailed program available yet, but soon for sure.
However, the registration is open now until 2016-11-30.
For those interested to join this event, try to save some € by obtaining the early bird offer (only until 2016-10-31).

Ruhr-University seen from Beckmanns Hof
All other fellows are warmly invited to come on Wednesday, 7.12 after the Passwords2016-talks for a first ECRYPT-NET get-together in Bochum and our program tailored to the upcoming writing project.
Thursday, 8.12 is the main day which we will start off by a workshop followed by project-oriented brainstorming and group discussions.
We'll have an expert training on collaborative creative writing and group
communication (in English), working in nice atmosphere close to Bochum's botanical gardens.

In short, in this workshop the focus lies on how to get things done, collaboratively. The technical aspect will be covered by a git repository with the projects' skeleton, that I set up here on a RUB-Server, where one can get a git account even as a RUB-external.
If you need a refresher, reread Ralph's blog post about git basics.

I am looking forward welcoming all of you here.

Monday, May 9, 2016

Grias eich in Wien!

Grias eich in Wien!

I'm glad to see many of my ECRYPT-NET fellows in Vienna, the city I finished my Master's program in, these days. Apart from EUROCRYPT, this working week actually already started on Sunday with "A Workshop About Cryptographic Standards" where questions like "How can we establish confidence in cryptographic standards?" were dealt with

The conference will be followed by a workshop about cryptographic protocols for small devices" on Friday.

So, let's dive into one of the 3 main annual crypto conferences of the IACR, where researchers present their recent results in both theoretical and applied cryptography... and stay tuned for posts, comments about our experiences at these events!

Until then, maybe you use the chance to explore Vienna after the numerous talks. Inspired as in Marie-Sarah's blog-post, here are a few phrases presented in the locally spoken "Austrian German" dialect in ascending difficulty and descending relevance for the daily life in the city. For help with the correct pronunciation feel free to approach us - Ralph and me - the two Austrian ECRYPT-NET fellows.

English German Austrian (aka proper German)
Hi, Hello Hi, Hallo Grias di, Servus
Good night Gute Nacht Guade Nocht
Goodbye Auf Wiedersehen Pfiad di
How's it going? Wie geht's? Oida?
What's up? What's happening? Was geht? Oida!
Yes Ja Jo
No Nein Na
Please Bitte Bitt sche
Thank you Danke Daung sche
1 one eins oans
2 two zwei zwoa
3 three drei drei
4 four vier vier
5 five fünf fünf
6 six sechs seggs
7 seven sieben siebm
8 eight acht ocht
9 nine neun nei
10 ten zehn zehn
You're welcome Bitte schön, gerne Setz di her scheid da a Brot owa, nimm da a G'söchts
Sorry Entschuldigung Tuat ma lad
Sorry, I do not understand you Wie Bitte? Wos is?
What is your name? Wie heißen Sie? (formal)
Wie heißt du? (informal)
Wie haßt'n du? (informal)
My name is... Ich heiße... I bin da/die ...
Where are you from? Von wo sind Sie? (formal)
Von wo bist du? Wo kommst du her? (informal)
Wo kimmstn du her? (informal)
I am from... Ich bin aus... I bin aus...
You look beautiful Du siehst hübsch aus. Schnitzerl!
Do you speak English? Sprechen Sie Englisch? (formal)
Sprichst du Englisch? (informal)
Red'st du Englisch?
Where is (the bathroom)?
(the train station)?
Wo ist (die Toilette)?
(die Zugstation)?
Wo isn's Heisl?
(da Baunhof)
Let's go! Los geht's! Geh mas on!
Cool! Cool! Leiwand!
Bon appétit! Mahlzeit! Mohlzeit!
A schnitzel and a beer, please Ein Schnitzel und ein Bier, bitte S'ansa Menü, bitte.
Cheers! Prost! (Zum Wohl!) Zaum, zaum, zaum, zaum: Prooost!
Check, please Zahlen bitte (Die Rechnung bitte) Zohln/Zoin, bitt schen!
How is the weather tomorrow? Könnten Sie mir bitte Ihre Kenntnis der Wettervorhersage mitteilen? Wie wird'n s'Weda?
Leave me alone. Seriously! Lassen Sie mich in Ruhe. Hau' ab! Loss mi ång'lahnt. Wüst a Gnackwatschn?
How to order a traditional (midnight-) snack: Hotdog & beer, fast. Einen Käsekrainerhotdog, ein Endstück Brot und eine Dose Ottakringer (16.Bezirk) Bier bitte. Zeitnah - wenn Sie so gnädig wären! A Eitrige im Präserl, an Buggl und an 16er-Blech. Oba Jennifer!

Good luck! ... und pfiat eich!

Friday, December 4, 2015

Workshop on Lattice Cryptography

It is the day after AsiaCrypt 2015 and there are two workshops being held in Auckland. The one which is most relevant for my research is that on Lattice Based Cryptography; which consists of four talks. One by Jung Hee Cheon on "Multilinear Maps and Their Cryptanalysis", one by Amit Sahai on "Obfuscation", one by Fre Vercauteren on "Weak Instances of RLWE" and one by Martin Albrecht on "Small Secret LWE".


Cheon first described a very naive version of multi-linear maps and then went on to show how this can be attacked by creating non-trivial encodings of zero, and then taking greatest common divisors. Then he went on to generalise this naive scheme to the CLT scheme (which is a bit like the DGHV FHE scheme). The naive attack does not apply to CLT as the dimension increased, meaning taking naive greatest common divisors would not work. Cheon then showed how to extend the naive attack to the CLT case by turning the gcd extraction into an eigenvalue extraction problem. This done by building quadratic forms which represent encodings of zero. The result is that for the CLT scheme one can break the equivalent of the DLP problem.
Cheon then went on to present the GGH scheme, which is a bit like the NTRU FHE scheme; except the instead of encrypting via c=[(m+r*p)/z] for an integer p, one encodes via c=[(m+r*g)/z] for a polynomial g which generates the ideal lattice <g>. Modifying the prior attack in this situation allows us to recover a basis of this ideal. But finding a short vector in this lattice can be hard. However, by utilizing encodings of zero one can actually solve the equivalent of the CDH problem.
Both attacks rely heavily on the presence of encodings of zero. So the attacks do not apply to situations in which one does not publish such encodings; i.e. applications such as indistinguishability Obfuscation (iO).






Amit Sahai then gave an introduction to iO; he motivated it via an analogy of an attacker who captures your brain and is able to read and tamper with every neuron, yet we still do not want the attacker to know what we are thinking about. This is the problem which obfuscation tries to solve in the computing realm. Martin pointed out that this would be a great way to produce malware!

Amit then put Multi-Party Computation within this analogy. He suggested we can think of MPC as protecting our brain against the tampering adversary, by dividing the brain up into portions. As long as one portion is kept out of the adversaries control we can use MPC to protect our thoughts. Obfuscation tries to do the same, without there needing to be an honest part of the brain.

Any program which is suitable for obfuscation must be unlearnable from query access to the program. Since otherwise the adversary could learn the program from the input/output behaviour. However, black-box obfuscation has been shown to be impossible; essentially because their are contrived programs which are unlearnable but for which one cannot produce an obfuscation, since any obfuscated program has an explicit attack against it.

This is why iO as a concept was presented; since it at least seems possible to achieve. The idea is that if you have two equivalent programs and we obfuscate one of them, then the adversary cannot tell which one we obfuscated. One way of thinking of this is as a psuedo-canonicalizer. The question is what useful can one do if we could create an obfuscator which satisfied the iO definition. Amit gave the application of building demo versions of software, without needing to re-engineer the software.



Fre Vercauteren then discussed a more in depth analysis of a paper from CRYPTO this year on Weak Instances of Ring-LWE. The CRYPTO paper gave instances where decision Ring-LWE was easy, but search appeared to be hard. However, Fre's talk showed that the search problem was in fact easy from the start, and thus the CRYPTO paper was less surprising than it at first seemed to be. As with all things on Ring-LWE the question arises as to how to choose the error distributions.

Fre spend the first part of his talk discussing the geometry of number fields, and in particular the Minkowski embedding. The Ring-LWE problem generates errors according to a discrete Gaussian distribution in the Minkowski embedding, Poly-LWE is to generate the errors according to a discrete Gaussian in the polynomial embedding.

Eisentrager et al discussed cases for which Poly-LWE was easy, these were then extended by Elias et al to special cases of decision Ring-LWE. They did this by mapping the special Ring-LWE instance to a special Poly-LWE instance.This is done by pulling back the problem from Ring-LWE to Poly-LWE via the matrix which defines the Minkowski embedding. The Poly-LWE attack requires that q is larger than f(1), and hence q will "kind of show up" in the coefficients of the defining polynomial f. So the fields being attacked, are very special indeed.


(This post originally appeared in the BristolCrypto blog)

Monday, July 13, 2015

WISE 2015 - Workshop on Implementation: Security and Evaluation

On behalf of the ECRYPT CSA european initiative, CryptoExperts organizes a workshop on the security of cryptographic implementations. The workshop will be held on September 11, 2015 in the heart of Paris, two days before CHES, with a scientific program centered around the following themes:
  • attack models and evaluation methodologies,
  • present and future certification schemes and standardization,
  • implementation security proofs and their automatization.


The workshop will be composed of invited presentations as well as a discussion panel aiming at building a vision of the current trends in the field and their expected evolutions in the future. The security of cryptographic implementations is a key topic in Europe, with both scientific and economic impacts. The purpose of this ECRYPT CSA workshop is to consult the academic, industrial and gov-related scientific communities to build the future european research roadmap in this strategic area.

Registration is free, but mandatory. Please register before August 31.