MPI-INF Logo
Campus Event Calendar

Event Entry

What and Who

PhD Application Talk: On key-dependent Encryption

Mathias Berg
Talk
AG 1, AG 2, AG 3, AG 4, AG 5, SWS, RG1, RG2  
MPI Audience
English

Date, Time and Location

Monday, 29 October 2007
08:00
480 Minutes
E1 4
024
Saarbrücken

Abstract

We tackle the question whether it is safe to encrypt a key with itself, or more generally, to allow key cycles. We permit situations where several keys encrypt each other in such a way that cyclic dependencies may occur between them. If an encryption scheme satisfies the criteria of key-dependent message (KDM) security, it will resist passive attacks in the presence of such key cycles. We prove that the traditional security definition for passive attacks (IND-CPA Security) is insufficient in the presence of key cycles, even if we only allow cycles of an arbitrary minimum length. We also show weakened forms of KDM security for two encryption schemes including ElGamal.

Contact

IMPRS
-225
--email hidden
passcode not visible
logged in users only

Lourdes Lara-Tapia, 10/26/2007 18:59 -- Created document.