# Advances in Cryptology - ASIACRYPT 2013: 19th International by Charanjit S. Jutla, Arnab Roy (auth.), Kazue Sako, Palash

By Charanjit S. Jutla, Arnab Roy (auth.), Kazue Sako, Palash Sarkar (eds.)

The two-volume set LNCS 8269 and 8270 constitutes the refereed court cases of the nineteenth overseas convention at the concept and alertness of Cryptology and knowledge, Asiacrypt 2013, held in Bengaluru, India, in December 2013. The fifty four revised complete papers awarded have been conscientiously chosen from 269 submissions. they're equipped in topical sections named: zero-knowledge, algebraic cryptography, theoretical cryptography, protocols, symmetric key cryptanalysis, symmetric key cryptology: schemes and research, side-channel cryptanalysis, message authentication codes, signatures, cryptography dependent upon actual assumptions, multi-party computation, cryptographic primitives, research, cryptanalysis and passwords, leakage-resilient cryptography, two-party computation, hash functions.

Wt×s Then it computes a rank s matrix of dimension (t+s)×s whose columns Is×s Wt×s = 0t×s . form a complete basis for the null-space of A, which means A · Is×s Now statistically, the CRS in Game G0 is indistinguishable from the one where we substitute D +b−1 ·W for D, where D itself is an independent random matrix. With this substitution, the CRSp and CRSv can be represented as ⎤ ⎡ W D D b · s×s + s×s ⎦ 0 I · g2 = A · s×s , CRS(n+s)×s =⎣ CRSt×s p v 0 −b · Is×s Now we show that if an eﬃcient adversary can produce a “proof” p for which the above pairing test holds and yet the candidate l is not in LA , then it implies an eﬃcient adversary that can break DDH in group G2 .

Since, there are three components, and one variable (see the appendix for details), the QA-NIZK requires only two group elements under SXDH. References 1. : Relations among notions of security for public-key encryption schemes. In: Krawczyk, H. ) CRYPTO 1998. LNCS, vol. 1462, pp. 26–45. Springer, Heidelberg (1998) 2. : Random oracles are practical: A paradigm for designing eﬃcient protocols. In: Ashby, V. ) ACM CCS 1993, pp. 62–73. ACM Press (November 1993) 3. : Non-interactive zero-knowledge and its applications (extended abstract).

E. R, S, u + H, and the two proof elements) under the SXDH assumption. Dual-System Fully Secure IBE. It is well-known that Identity Based Encryption (IBE) implies signature schemes (due to Naor), but the question arises whether the above signature scheme using Cramer-Shoup CCA2-encryption and the related QA-NIZK can be converted into an IBE scheme. To achieve this, we take a hint from Naor’s IBE to Signature Scheme conversion, and let the signatures (on identities) be private keys of the various identities.