Download Advances in Cryptology — ASIACRYPT 2001: 7th International by Craig Gentry, Jakob Jonsson, Jacques Stern, Michael Szydlo PDF

By Craig Gentry, Jakob Jonsson, Jacques Stern, Michael Szydlo (auth.), Colin Boyd (eds.)

The origins of the Asiacrypt sequence of meetings may be traced again to 1990, whilst the ?rst Auscrypt convention was once held, even though the identify Asiacrypt was once ?rst used for the 1991 convention in Japan. beginning with Asiacrypt 2000, the convention is now one in every of 3 annual meetings prepared through the Inter- tional organization for Cryptologic examine (IACR). the continued good fortune of Asiacrypt is in no small half as a result of e?orts of the Asiacrypt steerage C- mittee (ASC) and the robust aid of the IACR Board of administrators. there have been 153 papers submitted to Asiacrypt 2001 and 33 of those have been authorised for inclusion in those complaints. The authors of each paper, even if accredited or no longer, made a valued contribution to the luck of the convention. Sending out rejection noti?cations to such a lot of demanding operating authors is among the so much disagreeable projects of this system Chair. The evaluate technique lasted a few 10 weeks and consisted of an preliminary refe- eing part by way of an intensive dialogue interval. My heartfelt thank you visit all individuals of this system Committee who installed severe quantities of time to provide their professional research and reviews at the submissions. All papers have been reviewed by way of no less than 3 committee participants; in lots of circumstances, rather for these papers submitted via committee contributors, extra reports have been obt- ned. expert stories have been supplied by way of a military of exterior reviewers with no whom our judgements might were even more di?cult.

The (i, j) entry in this matrix is just the coefficient in the j’th relation of the term corresponding to row i. The diagonal entries of the matrix P are all equal to p, and the diagonal entries of the matrix E correspond to the bounds on the terms associated with each row. Specifically, if the term which is associated with row i is bounded by B, then entry (i, i) in E is equal to 1/B. That is, the row corresponding to the constant term has diagonal entry 1, rows corresponding to i have diagonal entries 1/2m−k , and rows corresponding to 0 j have diagonal entries 1/22(m−k) .

The standard HNP is as follows: let α ∈ Zp be a hidden random number. Given msbk (α · xi mod p) for random x1 , . . , xn ∈ Zp the problem is to find α. The standard, HNP can be efficiently solved when k = O( |p|), and this solution forms the basis of the bit-security result in [4] (as well as an attack on weak versions of the Digital Signature Algorithm (DSA), see [13]). This is in contrast to MIHNP which appears to be hard even when k is a constant fraction of |p|. 2 Approximate Modular Inversion Problems We introduce several variants of the basic MIHNP and study their properties.

261, pp. 515–534, 1982. 15. M. Naor, O. Reingold, “Number theoretic constructions of efficient pseudo random functions”, Proc. FOCS ’97. pp. 458–467. 16. A. Ta-Shma, D. Zuckerman, and S. Safra, “Extractors from Reed-Muller Codes”, FOCS, 2001. Secure Human Identification Protocols Nicholas J. Hopper and Manuel Blum Computer Science Department, Carnegie Mellon University, 5000 Forbes Ave. edu Abstract. One interesting and important challenge for the cryptologic community is that of providing secure authentication and identification for unassisted humans.

