Advances in Cryptology — EUROCRYPT 2002: International

By Rosario Gennaro, Daniele Micciancio (auth.), Lars R. Knudsen (eds.)

ISBN-10: 3540435530

ISBN-13: 9783540435532

ISBN-10: 3540460357

ISBN-13: 9783540460350

This publication constitutes the refereed complaints of the foreign convention at the idea and alertness of Cryptographic options, EUROCRYPT 2002, held in Amsterdam, The Netherlands, in April/May 2002.
The 33 revised complete papers provided have been rigorously reviewed and chosen from a complete of 122 submissions. The papers are equipped in topical sections on cryptanalysis, public-key encryption, info thought and new types, implementational research, circulate ciphers, electronic signatures, key trade, modes of operation, traitor tracing and id-based encryption, multiparty and multicast, and symmetric cryptology.

Ar ), then we can also use W −1 aW for any word W on ai ’s. Hardness of the List-MSCPs in Permutation Group and in Matrix Group. The MSCP in permutation group is easy. Note that two permutations are conjugate if and only if they have the same cycle decomposition. The MSCP in matrix group is also easy because the equation AX = XC can be considered as a system of homogeneous linear equations in the entries of X. One can use the polynomial time deterministic algorithm by Chistov, Ivanyos, and Karpinski [7].

J. Cryptology, 15, 19–46, 2002. 42 Steven D. Galbraith, Florian Hess, and Nigel P. Smart 11. M. Jacobson, A. Menezes and A. Stein. Solving elliptic curve discrete logarithm problems using Weil descent. J. Ramanujan Math. , 16, No. 3, 231–260, 2001. 12. D. Kohel. Endormorphism rings of elliptic curves over finite fields. Phd Thesis, Berkeley, 1996. 13. R. Lercier. Computing isogenies in F2n . Algorithmic Number Theory SymposiumANTS II, Springer-Verlag LNCS 1122, 197–212, 1996. 14. A. Menezes, T. Okamoto and S.

The commutator KAPs in [1,2] have the following condition in addition to the standard MSCP: x is contained in the subgroup generated by some publicly known braids b1 , . . , bs . This fact is crucial to the Length Attack of J. Hughes et al. [14]. They showed that the KAP is vulnerable to the Length Attack when bj ’s are complicated and x is a product of a small number of b±1 j ’s. And same for ai ’s and y. To defeat the Length Attack, Anshel et al. 4. Our attack of this section is strong when ai ’s and bj ’s are simple and it does not depend on how complicated x and y are.

