# Cryptology and Network Security: 7th International by Robert H. Deng, Jian Weng, Shengli Liu, Kefei Chen (auth.),

By Robert H. Deng, Jian Weng, Shengli Liu, Kefei Chen (auth.), Matthew K. Franklin, Lucas Chi Kwong Hui, Duncan S. Wong (eds.)

This booklet constitutes the refereed court cases of the seventh overseas convention on Cryptology and community protection, CANS 2008, held in Hong-Kong, China, in December 2008.

The 27 revised complete papers offered have been conscientiously reviewed and chosen from seventy three submissions. The papers are equipped in topical sections on cryptosystems, signatures, identity, authentication and key administration, cryptographic algorithms and protocols, circulate ciphers and block ciphers, cryptographic foundations, functions and implementations, in addition to defense in advert hoc networks and instant sensor networks.

**Extra info for Cryptology and Network Security: 7th International Conference, CANS 2008, Hong-Kong, China, December 2-4, 2008. Proceedings**

**Example text**

In the following game, t, n, qES , and qDV denote the number of decryption keys that the adversary A can obtain, the number of total users, the number of encrypt/sign queries, and the number of decrypt/verify queries, respectively. For any probabilistic polynomial time adversary A, if it wins the following game at most negligible advantage Advind ADBE (t, n, qES , qDV , A), we say that the ADBE scheme is (t, n, qES , qDV )-IND-ADBE-s-CCA secure. In the following game, the deﬁnition of Setup and Join phases are the same as the game for DBE in Sect.

If |A| < |B|, then KDF is a pseudorandom generator. Otherwise, KDF may be a non-cryptographic function. Decisional Diffie-Hellman Assumption Definition 1. Let G be a group of order q with a generator g. A DDH distinguisher Alice has success AdvDDHG,g (Alice), defined as Pr[x, y ← ZZ q : A(G, q, g, g x , g y , g xy ) = 1]− Pr[x, y ← ZZ q , z ← ZZ q \ {xy} : A(G, q, g, g x , g y , g z ) = 1] in attacking DDH group G, where the probability is taken over the choice of random variables and over the random coin tosses of Alice.

From this, it easily follows that Pr[F5 ] ≤ εmac , where εkdf is the probability of breaking mac, using resources similar to those of the given adversary. Completing The Proof We have Pr[F3 ] ≤ γ1 Pr[F3 ] = γ1 Pr[F4 ] ≤ γ1 (Pr[F5 ] + εkdf ) ≤ γ1 (εmac + εkdf ) . Finally, | Pr[X0 ] − 1/2| ≤ εddh + εkdf + εenc + γ1 (εmac + εmac + εkdf ) . (3) 4 Why We Cannot Prove CCA2-Security We will now briefly show why this proof technique cannot show that Hybrid Damg˚ard is CCA2-secure in the standard model and “standard” assumptions from KDF, MAC and secret-key cryptosystem.