This ebook constitutes the refereed complaints of the twenty ninth Annual overseas Cryptology convention, CRYPTO 2009, held in Santa Barbara, CA, united states in August 2009.

The 38 revised complete papers provided have been rigorously reviewed and chosen from 213 submissions. Addressing all present foundational, theoretical and learn features of cryptology, cryptography, and cryptanalysis in addition to complicated purposes, the papers are equipped in topical sections on key leakage, hash-function cryptanalysis, privateness and anonymity, interactive proofs and zero-knowledge, block-cipher cryptanalysis, modes of operation, elliptic curves, cryptographic hardness, merkle puzzles, cryptography within the actual international, assaults on signature schemes, mystery sharing and safe computation, cryptography and game-theory, cryptography and lattices, identity-based encryption and cryptographers’ toolbox.

Additional resources for Advances in Cryptology - CRYPTO 2009: 29th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 16-20, 2009. Proceedings

G r ) : r ∈ Zq } . 32 M. Naor and G. Segev The leftover hash lemma guarantees that with overwhelming probability over the choice of C = (u1 , . . , u ) ∈ C \ V it holds that Λsk (C) = i=1 usi i is -close to the uniform distribution over G, even given h = i=1 gisi and any leakage of length λ bits. 3 Comparison The main difference between the two schemes proposed in this section is in their method of extracting randomness from the secret key. In the first proposal an invertible function is applied to the secret key (thus preserving its min-entropy), and then a strong extractor is applied to the resulting value.

Output the pair (sk, pk). – Encryption: On input a message M ∈ {0, 1}m, choose a random C ∈ V together with a corresponding witness w, and a random seed s ∈ {0, 1}t. Let Ψ = Ext (Pub(pk, C, w), s) ⊕ M , and output the ciphertext (C, s, Ψ ). – Decryption: On input a ciphertext (C, s, Ψ ), output the message M = Ψ ⊕ Ext (Λsk (C), s). The correctness of the scheme follows from the property that Λsk (C) = Pub(pk, C, w) for any C ∈ V with witness w. Thus, a decryption of an encrypted plaintext is always the original plaintext.

