An Application of Group Theory in Confidential Network Communications
A new proposal for group key exchange is introduced which proves to be both efficient and secure and compares favorably with state of the art protocols.
Discover
Research tools
Network
Opportunities
Account
Source author record
Davide Schipani appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.
Catalog footprint
Research graph
Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.
BZPEER is loading the nearby papers, people, topics and institutions for this page.
Published work
A new proposal for group key exchange is introduced which proves to be both efficient and secure and compares favorably with state of the art protocols.
In this work we provide a suite of protocols for group key management based on general semigroup actions. Construction of the key is made in a distributed and collaborative way. Examples are provided that may in some cases enhance the security level and communication overheads of previous existing protocols. Security against passive attacks is considered and depends on the hardness of the semigroup action problem in any particular scenario.
Interesting properties of the partitions of a finite field $\mathbb F_q$ induced by the combination of involutions and trace maps are studied. The special features of involutions of the form $\frac{u}{z}$, $u$ being a fixed element of $\mathbb F_q$, are exploited to generate pseudorandom numbers, the randomness resting on the uniform distribution of the images of zero-trace elements among the sets of non-zero trace elements of $\mathbb F_q$.
First a few reformulations of Frankl's conjecture are given, in terms of reduced families or matrices, or analogously in terms of lattices. These lead naturally to a stronger conjecture with a neat formulation which might be easier to attack than Frankl's. To this end we prove an inequality which might help in proving the stronger conjecture.
The multiparty key exchange introduced in Steiner et al.\@ and presented in more general form by the authors is known to be secure against passive attacks. In this paper, an active attack is presented assuming malicious control of the communications of the last two users for the duration of only the key exchange.
In this paper we propose a new protocol to manage multicast key distribution. The protocol is based on the use of orthogonal systems in vector spaces. The main advantage in comparison to other existing multicast key management protocols is that the length and the number of the messages which have to be sent are considerably smaller. This makes the protocol especially attractive when the number of legitimate receivers is large.
Fuzzy vault is a scheme providing secure authentication based on fuzzy matching of sets. A major application is the use of biometric features for authentication, whereby unencrypted storage of these features is not an option because of security concerns. While there is still ongoing research around the practical implementation of such schemes, we propose and analyze here an alternative construction based on subspace codes. This offers some advantages in terms of security, as an eventual discovery of the key does not provide an obvious access to the features. Crucial for an efficient implementation are the computational complexity and the choice of good code parameters. The parameters depend on the particular application, e.g. the biometric feature to be stored and the rate one wants to allow for false acceptance. The developed theory is closely linked to constructions of subspace codes studied in the area of random network coding.
This paper studies a variant of the McEliece cryptosystem able to ensure that the code used as the public key is no longer permutation-equivalent to the secret code. This increases the security level of the public key, thus opening the way for reconsidering the adoption of classical families of codes, like Reed-Solomon codes, that have been longly excluded from the McEliece cryptosystem for security reasons. It is well known that codes of these classes are able to yield a reduction in the key size or, equivalently, an increased level of security against information set decoding; so, these are the main advantages of the proposed solution. We also describe possible vulnerabilities and attacks related to the considered system, and show what design choices are best suited to avoid them.
Explicit monoid structure is provided for the class of canonical subfield preserving polynomials over finite fields. Some classical results and asymptotic estimates will follow as corollaries.
The Rabin public-key cryptosystem is revisited with a focus on the problem of identifying the encrypted message unambiguously for any pair of primes. In particular, a deterministic scheme using quartic reciprocity is described that works for primes congruent 5 modulo 8, a case that was still open. Both theoretical and practical solutions are presented. The Rabin signature is also reconsidered and a deterministic padding mechanism is proposed.
In this paper, we address the problem of achieving efficient code-based digital signatures with small public keys. The solution we propose exploits sparse syndromes and randomly designed low-density generator matrix codes. Based on our evaluations, the proposed scheme is able to outperform existing solutions, permitting to achieve considerable security levels with very small public keys.
Secure storage of noisy data for authentication purposes usually involves the use of error correcting codes. We propose a new model scenario involving burst errors and present for that several constructions.
In 1952, Perron showed that quadratic residues in a field of prime order satisfy certain ad- ditive properties. This result has been generalized in different directions, and our contribution is to provide a further generalization concerning multiplicative quadratic and cubic characters over any finite field. In particular, recalling that a character partitions the multiplicative group of the field into cosets with respect to its kernel, we will derive the number of representations of an element as a sum of two elements belonging to two given cosets. These numbers are then related to the equations satisfied by the polynomial characteristic functions of the cosets. Further, we show a connection, a quasi-duality, with the problem of determining how many elements can be added to each element of a subset of a coset in such a way as to obtain elements still belonging to a subset of a coset.
The paper studies the problem of securely storing biometric passwords, such as fingerprints and irises. With the help of coding theory Juels and Wattenberg derived in 1999 a scheme where similar input strings will be accepted as the same biometric. In the same time nothing could be learned from the stored data. They called their scheme a "fuzzy commitment scheme". In this paper we will revisit the solution of Juels and Wattenberg and we will provide answers to two important questions: What type of error-correcting codes should be used and what happens if biometric templates are not uniformly distributed, i.e. the biometric data come with redundancy. Answering the first question will lead us to the search for low-rate large-minimum distance error-correcting codes which come with efficient decoding algorithms up to the designed distance. In order to answer the second question we relate the rate required with a quantity connected to the "entropy" of the string, trying to estimate a sort of "capacity", if we want to see a flavor of the converse of Shannon's noisy coding theorem. Finally we deal with side-problems arising in a practical implementation and we propose a possible solution to the main one that seems to have so far prevented real life applications of the fuzzy scheme, as far as we know.
A method is described which allows to evaluate efficiently a polynomial in a (possibly trivial) extension of the finite field of its coefficients. Its complexity is shown to be lower than that of standard techniques when the degree of the polynomial is large with respect to the base field. Applications to the syndrome computation in the decoding of cyclic codes, Reed-Solomon codes in particular, are highlighted.
An elementary approach is shown which derives the values of the Gauss sums over $\mathbb F_{p^r}$, $p$ odd, of a cubic character without using Davenport-Hasse's theorem. New links between Gauss sums over different field extensions are shown in terms of factorizations of the Gauss sums themselves, which are then rivisited in terms of prime ideal decompositions. Interestingly, one of these results gives a representation of primes $p$ of the form $6k+1$ by a binary quadratic form in integers of a subfield of the cyclotomic field of the $p$-th roots of unity.
An elementary approach is shown which derives the value of the Gauss sum of a cubic character over a finite field $\mathbb F_{2^s}$ without using Davenport-Hasse's theorem (namely, if $s$ is odd the Gauss sum is -1, and if $s$ is even its value is $-(-2)^{s/2}$).
After revisiting Cantor-Zassenhaus polynomial factorization algorithm, we describe a new simplified version of it, which requires less computational cost. Moreover we show that it is able to find a factor of a fully splitting polynomial of degree $t$ over $\mathbb F_{2^m}$ with $O(\frac{2^m}{3^{t}})$ attempts and over $\mathbb F_{p^m}$ for odd $p$ with $O(\frac{p^m}{2^{t}})$ attempts.
The last decades have seen a growing interest in hash functions that allow some sort of tolerance, e.g. for the purpose of biometric authentication. Among these, the syndrome fuzzy hashing construction allows to securely store biometric data and to perform user authentication without the need of sharing any secret key. This paper analyzes this model, showing that it offers a suitable protection against information leakage and several advantages with respect to similar solutions, such as the fuzzy commitment scheme. Furthermore, the design and characterization of LDPC codes to be used for this purpose is addressed.
The standard algebraic decoding algorithm of cyclic codes $[n,k,d]$ up to the BCH bound $t$ is very efficient and practical for relatively small $n$ while it becomes unpractical for large $n$ as its computational complexity is $O(nt)$. Aim of this paper is to show how to make this algebraic decoding computationally more efficient: in the case of binary codes, for example, the complexity of the syndrome computation drops from $O(nt)$ to $O(t\sqrt n)$, and that of the error location from $O(nt)$ to at most $\max \{O(t\sqrt n), O(t^2\log(t)\log(n))\}$.
Some Rabin signature schemes may be exposed to forgery; several variants are here described to counter this vulnerability. Blind Rabin signatures are also discussed.
An efficient evaluation method is described for polynomials in finite fields. Its complexity is shown to be lower than that of standard techniques when the degree of the polynomial is large enough. Applications to the syndrome computation in the decoding of Reed-Solomon codes are highlighted.
The paper presents several new sufficient conditions, as well as new equivalent criteria for the classical Riemann Hypothesis. Noteworthy are also other statements and remarks about $ζ$ to be found throughout the paper.
We first give a condition on the parameters $s,w$ under which the Hurwitz zeta function $ζ(s,w)$ has no zeros and is actually negative. As a corollary we derive that it is nonzero for $w\geq 1$ and $s\in(0,1)$ and, as a particular instance, the known result that the classical zeta function has no zeros in $(0,1)$.
This paper presents new sufficient and equivalent conditions for the generalized version of the Riemann Hypothesis. The paper derives also statements and remarks concerning zero-free regions, modified Hadamard-product formulas and the behaviour of $|\frac{L(\barχ,s)}{L(χ,1-s)}|$.