By Rosario Gennaro, Daniele Micciancio (auth.), Lars R. Knudsen (eds.)

ISBN-10: 3540435530

ISBN-13: 9783540435532

ISBN-10: 3540460357

ISBN-13: 9783540460350

This e-book constitutes the refereed complaints of the foreign convention at the conception and alertness of Cryptographic innovations, EUROCRYPT 2002, held in Amsterdam, The Netherlands, in April/May 2002.

The 33 revised complete papers provided have been rigorously reviewed and chosen from a complete of 122 submissions. The papers are geared up in topical sections on cryptanalysis, public-key encryption, details concept and new versions, implementational research, movement ciphers, electronic signatures, key alternate, modes of operation, traitor tracing and id-based encryption, multiparty and multicast, and symmetric cryptology.

Public Key 1. Alice’s public key is (x−1 a1 x, . . , x−1 ar x), where x = W (b1 , . . , bs ). 2. Bob’s public key is (y −1 b1 y, . . , y −1 bs y), where y = V (a1 , . . , ar ). Shared key E(x−1 y −1 xy) = (πx−1 y−1 xy , Mx−1 y−1 xy (τ1 , . . , τn ) mod p). Parameter Recommendation in [1]. – The only restriction on p used in the key extractor is that p > n so that one can choose distinct and invertible elements τ1 , . . , τn . One can choose p < 1000. – Take the braid index n = 80 or larger and r = s = 20.

There are two ways this property might be exploited: – To solve a discrete logarithm problem on an elliptic curve E1 over Fqn for which the GHS attack is not eﬀective, one could try to ﬁnd an isogenous curve E2 for which the GHS attack is eﬀective. – It is often possible to construct a ‘weak’ elliptic curve E2 over Fqn for which the GHS attack is particularly successful (this is essentially what was done by [11]). One might ‘hide’ such a curve by taking an isogeny to a curve E1 for which the GHS attack is not eﬀective.

