Those are the lawsuits of Eurocrypt 2007, the twenty sixth Annual IACR EurocryptConference. The convention was once backed via the foreign organization forCryptologic study (IACR; see, this yr in cooperation withthe examine team on arithmetic utilized to Cryptography at UPC and theResearch crew on details protection at UMA. The Eurocrypt 2007 ProgramCommittee (PC) consisted of 24 individuals whose names are indexed at the nextpage.The notebook selected a number of guidelines: 0 computer papers - no application Committeemember may publish papers; not obligatory anonymity - authors may perhaps decide upon toanonymize their papers or now not. nameless papers have been handled as traditional, i.e.,the author’s id used to be now not published to the computer. The submission software program usedwas “Web Submission and overview software program” written and maintained by way of ShaiHalevi. there have been 173 papers submitted to the convention and the computer chose33 of them. every one paper was once assigned to at the least 3 computing device participants, who eitherhandled it themselves or assigned it to an exterior referee. After the studies weresubmitted, the committee deliberated either on-line for numerous weeks and finallyin a face-to-face assembly held in Paris. as well as notification of the decisionof the committee, authors acquired stories. Our objective was once to supply meaningfulcomments to authors of all papers (both these chosen for this system andthose now not selected). The default for any record given to the committee was once thatit will be on hand to the authors besides.

Strings A1 and B1 are distinct n-bit constants. For an even-length sting S we let S L and S R be its left and right half. Right: Illustration of the algorithm acting on a three-block messsage X = X1 X2 X3 . The resulting hash is H(X) = V3 W3 . The darkened edge of the box representing the blockcipher indicates the input that is the key. ) In n n n this paper we consider MDC-2 using a blockcipher E: {0, 1} ×{0, 1} → {0, 1} with equal-length blocks and keys. We make this assumption for simplicity, while preserving contemporary applicability: eliminating “bit-dropping” makes the algorithm cleaner, while the usage of MDC-2 that people nowadays envisage is with the blockcipher AES-128 [30].

In the ideal-cipher model the underlying primitive, a blockcipher E, is modeled as a family of random permutations {EK } with a random permutation chosen independently for each key K. The adversary may make a query EK (X) to discover the corresponding value Y = EK (X), or the adversary may make a −1 −1 query EK (Y ) so as to learn the corresponding value X = EK (Y ) for which EK (X) = Y . We are interested in the chance that an adversary can find a collision, namely a pair of distinct messages that collide under MDC2E , by asking q queries.

Jean-S´ebastien Coron, Yevgeniy Dodis, C´ecile Malinaud, and Prashant Puniya. Merkle-damg˚ ard revisited : How to construct a hash function. In Advances in Cryptology — CRYPTO ’05, volume 3621 of Lecture Notes in Computer Science, pages 430–448, 2005. 5. Yevgeniy Dodis and Jonathan Katz. Chosen-ciphertext security of multiple encryption. In TCC, pages 188–209, 2005. 6. Shimon Even and Oded Goldreich. On the power of cascade ciphers. ACM Trans. Comput. , 3(2):108–116, 1985. 7. Danny Harnik, Joe Kilian, Moni Naor, Omer Reingold, and Alon Rosen.

