Advances in Cryptology – EUROCRYPT 2013: 32nd Annual by Sanjam Garg, Craig Gentry, Shai Halevi (auth.), Thomas

By Sanjam Garg, Craig Gentry, Shai Halevi (auth.), Thomas Johansson, Phong Q. Nguyen (eds.)

This publication constitutes the lawsuits of the thirty second Annual foreign convention at the thought and functions of Cryptographic recommendations, EUROCRYPT 2013, held in Athens, Greece, in may possibly 2013. The forty-one complete papers incorporated during this quantity have been rigorously reviewed and chosen from 201 submissions. They take care of cryptanalysis of hash features, side-channel assaults, quantity conception, lattices, public key encryption, electronic signatures, homomorphic cryptography, quantum cryptography, garage, instruments, and safe computation.

Subspace LWE. In: Cramer, R. ) TCC 2012. LNCS, vol. 7194, pp. 548–563. : Lossy trapdoor functions and their applications. In: STOC, pp. : On lattices, learning with errors, random linear codes, and cryptography. In: STOC, pp. 84–93 (2005) A Toolkit for Ring-LWE Cryptography Vadim Lyubashevsky1, , Chris Peikert2, , and Oded Regev3, 1 INRIA and École Normale Supérieure, Paris 2 Georgia Institute of Technology 3 Courant Institute, New York University Abstract. Recent advances in lattice cryptography, mainly stemming from the development of ring-based primitives such as ring-LWE, have made it possible to design cryptographic schemes whose efficiency is competitive with that of more traditional number-theoretic ones, along with entirely new applications like fully homomorphic encryption.

Let q = q(n) = poly(n) be a prime modulus and let χ be any distribution over Zq . Assume there exists a PPT-distinguisher D that distinguishes DLWE(n, m, q, χ) with non-negligible advantage, then there exists a PPT-adversary A that inverts LWE(n, m, q, χ) with non-negligible success-probability. Finally, we need a matrix-version of Problem 2. g. [ACPS09]). Lemma 1. Let m(n), k(n) = poly(n). Assume that DLWE(n, m, q, χ) is pseudorandom. Then the distribution (A, AX + E) is also pseudorandom, where and X ∈ Zn×k are chosen uniformly at random and E is chosen A ∈ Zm×n q q according to Ψ¯αm×k .

LNCS, vol. 7785, pp. 579–598. : Aggregate and verifiably encrypted signatures from multilinear maps without random oracles. -S. ) ISA 2009. LNCS, vol. 5576, pp. 750–759. : Cryptosystems based on pairing. : Hypercubic lattice reduction and analysis of ggh and ntru signatures. In: Biham, E. ) EUROCRYPT 2003. LNCS, vol. 2656, pp. 433–448. edu Abstract. The hardness of the Learning-With-Errors (LWE) Problem has become one of the most useful assumptions in cryptography. It exhibits a worst-to-average-case reduction making the LWE assumption very plausible.

