The volume-set, LNCS 8616 and LNCS 8617, constitutes the refereed complaints of the thirty fourth Annual foreign Cryptology convention, CRYPTO 2014, held in Santa Barbara, CA, united states, in August 2014.

The 60 revised complete papers offered in LNCS 8616 and LNCS 8617 have been rigorously reviewed and chosen from 227 submissions. The papers are prepared in topical sections on symmetric encryption and PRFs; formal tools; hash services; teams and maps; lattices; uneven encryption and signatures; aspect channels and leakage resilience; obfuscation; FHE; quantum cryptography; foundations of hardness; number-theoretic hardness; information-theoretic protection; key alternate and safe conversation; 0 wisdom; composable protection; safe computation - foundations; safe computation - implementations.

Ki∗ = kj∗ for some i = j) or transcripts with too many (long) ﬁtting chains, where “too many” depends geometrically on the chain length r, as might be expected. When there are not too many long chains that ﬁt the transcript’s key, indeed, we are in a position to apply the lemma of Chen and Steinberger [8] to show that the probability of obtaining the given transcript in the real world is not far oﬀ from the probability of obtaining the same transcript in the ideal world, as required by (4). The main technical challenge that arises is that of upper bounding the probability of obtaining too many length r chains that ﬁt the key.

K ∗ is the secret key, in which case we send = ⊥. Since the adversary is free to disregard , this modiﬁcation is without loss of generality. Next, we make a second modiﬁcation, namely that if = ⊥ then we forbid the adversary from making any queries. Since can only be ⊥ in the real world this is without loss of generality either (as the adversary already knows which world it is in anyway). Now we make yet another modiﬁcation to the real world, by generating a random permutation π like in the ideal world at the beginning of the experiment.

This is small as long as the scheme uses a minimal amount of randomness, for example 7 bits, resulting in d = 27 = 128. ) A similar analysis can be carried out for the formal surveillance attack. We claim that the subversion is undetectable. Our analysis ﬁrst uses the PRF security of F to replace F (K, ·) with a random function f . The key claim is then the following information theoretic lemma. The proof is in [4]. Lemma 1. Suppose g : D → R. Let b ∈ {0, 1} and δ ∈ D. Let d = |D|. Let p = Pr[δ = δ] where we ﬁrst draw f : g(D) → {0, 1} at random and then draw δ at random from S f,g (b, D) = {δ ∈ D : f (g(δ)) = b}.

