By Arjen K. Lenstra, Eric R. Verheul (auth.), Mihir Bellare (eds.)

This publication constitutes the refereed court cases of the 20 th Annual foreign Cryptology convention, CRYPTO 2000, held in Santa Barbara, CA, united states in August 2000. The 32 revised complete papers awarded including one invited contribution have been conscientiously reviewed and chosen from a hundred and twenty submissions. The papers are prepared in topical sections on XTR and NTRU, privateness for databases, safe dispensed computation, algebraic cryptosystems, message authentication, electronic signatures, cryptanalysis, traitor tracing and broadcast encryption, symmetric encryption, to devote or to not devote, protocols, and flow ciphers and Boolean features.

25. We can thus expect k to have around three non zero coefficients. The table below shows the different probabilities of collisions in the different proposed cases. It also gives the average expected number of collisions. 13. 1 will apply. We can see that the attack, as it has currently been described, will fail in cases B, C and D. 3, we generalize our idea to make it work in those cases. In general, k may have more than one coefficient, and we need to enumerate the possible k and compute f = k/m mod p, where m is our decrypted message.

Factoring polynomials with polynomial coefficients. Math. Annalen, 261:515–534, 1982. 11. Joseph H. Silverman. Plaintext awareness and the NTRU PKCS. Technical Report 7, NTRU Cryptosystems, July 1998. 12. Joseph H. Silverman. Estimated breaking times for NTRU lattices. Technical Report 12, NTRU Cryptosystems, March 1999. Privacy Preserving Data Mining Yehuda Lindell1 and Benny Pinkas2 1 2 Department of Computer Science and Applied Math, Weizmann Institute of Science, Rehovot, Israel. il School of Computer Science and Engineering, Hebrew University of Jerusalem, Jerusalem, Israel.

J. Quisquater. Attacks on shamir’s ’rsa for paranoids’. Information Processing Letters, 68:197–199, 1998. html. 6. Chris Hall, Ian Goldberg, and Bruce Schneier. Reaction attacks against several public-key cryptosystems. In G. Goos, J. Hartmanis, and J; van Leeuwen, editors, ICICS’99, volume 1726 of Lecture Notes in Computer Science, pages 2–12. Springer-Verlag, 1999. 7. Jeffrey Hoffstein, Jill Pipher, and Joseph H. Silverman. NTRU: A ring based public key cryptosystem. In ANTS’3, volume 1423 of Lecture Notes in Computer Science, pages 267–288.

