Advances in Cryptology — EUROCRYPT ’97: International by Johan Borst, Lars R. Knudsen, Vincent Rijmen (auth.), Walter

By Johan Borst, Lars R. Knudsen, Vincent Rijmen (auth.), Walter Fumy (eds.)

EUROCRYEVr '97, the fifteenth annual EUROCRYPT convention at the concept and alertness of cryptographic options, used to be equipped and backed via the foreign organization for Cryptologic examine (IACR). The IACR organizes sequence of foreign meetings every year, the EUROCRYPT assembly in Europe and CRWTO within the usa. The heritage of EUROCRYFT begun 15 years in the past in Germany with the Burg Feuerstein Workshop (see Springer LNCS 149 for the proceedings). It was once because of Thomas Beth's initiative and difficult paintings that the seventy six individuals from 14 nations collected in Burg Feuerstein for the 1st open assembly in Europe dedicated to modem cryptography. i'm proud to were one of many individuals and nonetheless fondly be mindful my first encounters with a number of the celebrities in cryptography. given that these early days the convention has been held in a distinct position in Europe every year (Udine, Paris, Linz, Linkoping, Amsterdam, Davos, Houthalen, Aarhus, Brighton, Balantonfiired, Lofthus, Perugia, Saint-Malo, Saragossa) and it has loved a gentle development, because the moment convention (Udine, 1983) the IACR has been concerned, because the Paris assembly in 1984, the identify EUROCRYPT has been used. For its fifteenth anniversary, EUROCRYPT ultimately lower back to Germany. The medical software for EUROCRYPT '97 used to be prepare via a 18-member application committee whch thought of 104 high quality submissions. those court cases include the revised models of the 34 papers that have been permitted for presentation. furthermore, there have been invited talks through Ernst Bovelander and by way of Gerhard Frey.

Example text

Given t faulty runs of the protocol one can recover the secret s1, . . , st in the tame it takes t o perform O(nt + t 2 ) modular muitiplieations. Proof. Suppose that due to a miraculous fault, one of the bits of the register holding the value r is flipped while the device is waiting for Bob to send it the set S. In this case, Bob receives the correct value r2 mod N , however y is computed incorrectly by the device. Due to the fault, the device outputs: iES where E is the value added to the register as a result of the fault.

Induced faults When an adversary has physical access t o a device she may try t o purposely induce hardware faults. For instance, one may attempt to attack * Also at Princeton University. Supported in part by NSF CCR-9304718. W. ): Advances in Cryptology - EUROCRYPT '97, LNCS 1233, pp. 37-51, 1997. 0Springer-Verlag Berlin Heidelberg 1997 38 a tamper-resistant device by deliberately causing it to malfunction. We show that the erroneous values computed by the device enable the adversary to extract the secret stored on it.

318-328, 1995. 17. R. Rivest, A . Shaniir & L. Adleman, A method f o r obtaining digital signatures and public-key cryptosystems, CACM, vol. 21, no. 2 , pp. 120-126, 1978. 18. A. Salomaa, Public-key cryptography, EATCS Monographs on theoretical computer science, vol. 23, Springer-Verlag, page 66, 1990. 19. A. Shamir, A n e f i c i e n t identification scheme based o n permuted kernels, LNCS, Advances in Cryptology, Proceedings of Crypt,o’89, Springer-Verlag, pp. 606-609. 20. G. Simmons, Contemporary cryptology : The science of information integrity, IEEE Press, pp.

