This ebook constitutes the refereed lawsuits of the overseas convention at the concept and functions of Cryptographic recommendations, EUROCRYPT 2003, held in Warsaw, Poland in might 2003.

The 37 revised complete papers offered including invited papers have been conscientiously reviewed and chosen from 156 submissions. The papers are equipped in topical sections on cryptanalysis, safe multi-party verbal exchange, zero-knowledge protocols, foundations and complexity-theoretic safeguard, public key encryption, new primitives, elliptic curve cryptography, electronic signatures, information-theoretic cryptography, and crew signatures.

S. Department of Commerce, 1977. 25. T. Pornin, Optimal resistance against the Davies and Murphy attack, Advances in Cryptology – ASIACRYPT’98, LNCS, vol. 1514, Springer-Verlag, 2000, pp. 148– 159. 26. J. A. Rice, Mathematical statistics and data analysis, Duxbury Press, 1995. 27. D. Siegmund, Sequential analysis – tests and confidence intervals, Springer-Verlag, 1985. 28. S. ch. 29. , An experiment on DES statistical cryptanalysis, 3rd ACM Conference on Computer and Communications Security, ACM Press, 1996, pp.

30,28]) proposes the decorrelation theory as a generic technique for estimating the strength of block ciphers against various kinds of attacks. In these papers, he notably derives bounds on the best advantage of any linear and differential distinguishers, however without using statistical hypothesis testing concepts. As pointed out by many authors, statistical hypothesis tests are convenient in the analysis of statistical problems, since, in certain cases, well-known optimality results (like the Neyman-Pearson lemma, for instance) can be applied.

Junod σn (x1 , . . 2 continue sampling if (x1 , . . , xn ) ∈ An ∪ Bn stop sampling if (x1 , . . , xn ) ∈ An ∪ Bn (18) Sequential Decision Procedures We have seen that Lemma 1 defines the shape of the optimal acceptance region for binary hypothesis testing. Theoretically, if one is able to compute the exact joint probability distribution of the oracle’s responses when it implements both ciphers, one is able to compute the optimal acceptance region A for a generic n-limited distinguisher. A sequential likelihood-ratio test uses exactly the same process to define two types of acceptance regions, denoted A and B, respectively.

