<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Mira Belenkiy</title>
	<atom:link href="http://belenkiy.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://belenkiy.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Tue, 29 Jul 2008 23:31:43 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='belenkiy.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/85344dd06f9cc0573912be33038fd9b2?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Mira Belenkiy</title>
		<link>http://belenkiy.wordpress.com</link>
	</image>
			<item>
		<title>Concurrent Zero-Knowledge</title>
		<link>http://belenkiy.wordpress.com/2008/07/28/concurrent-zero-knowledge/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/28/concurrent-zero-knowledge/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 00:29:02 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[See Fig. 1]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=73</guid>
		<description><![CDATA[Zero-Knowledge is one of the coolest and non-intuitive ideas in modern cryptography.  The idea is that Alice wants to prove that something is true without explaining why.  (Just like a woman, right?).  For example, she knows how to 3-color a particular graph.  She can paint each vertex on the graph red, green, or blue in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=73&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div id="attachment_74" class="wp-caption aligncenter" style="width: 460px"><a href="http://belenkiy.files.wordpress.com/2008/07/002-concurrentzk.jpg"><img class="size-full wp-image-74" src="http://belenkiy.files.wordpress.com/2008/07/002-concurrentzk.jpg?w=450&#038;h=396" alt="Concurrent Zero-Knowledge" width="450" height="396" /></a><p class="wp-caption-text">Concurrent Zero-Knowledge</p></div>
<p>Zero-Knowledge is one of the coolest and non-intuitive ideas in modern cryptography.  The idea is that Alice wants to prove that something is true without explaining why.  (Just like a woman, right?).  For example, she knows how to 3-color a particular graph.  She can paint each vertex on the graph red, green, or blue in such a way that no two adjacent vertices are the same color.  Now she wants to prove to Bob that it is possible to do it.  (For example, Bob is being lazy and doesn&#8217;t want to help out around the house by spending exponential time coloring vertices.  It&#8217;s a very common situation).  So Alice and Bob engage in a protocol in which Alice proves that yes, it is  possible to 3-color the graph.  BUT&#8230;.Bob does not learn how Alice did it.</p>
<p>Ok, that sounds pretty pointless.  Most modern households don&#8217;t have graphs lying around just waiting to be 3-colored.  (Plus there is a very efficient 4-coloring algorithm for planar graphs, so if you&#8217;re willing to invest in a little more paint you can save yourself a lot of clock cycles).</p>
<p>But what if Alice wants to prove she knows her credit card number without actually sending it to FlyByNight.com?  Now Alice can safely purchase shoes on-line without worrying about an unscrupulous merchant stealing her credit card number.</p>
<p>Zero-Knowledge has been around since 1986 (sorry no link, this result is really old).</p>
<p>Oded Goldreich, Silvio Micali, Avi Wigderson: Proofs that Yield Nothing But their Validity and a Methodology of Cryptographic Protocol Design (Extended Abstract) FOCS 1986: 174-187.</p>
<p>The tricky thing about zero-knowledge is actually proving that a protocol is zero-knowledge.  Things get even worse with concurrent zero-knowledge, when Alice might have to prove things to several different people at the same time.  An unscrupulous adversary might take advantage of Alice and use the results of one protocol query to alter a second query.  Here the proofs get really convoluted as the cryptographer tries to rewind multiple simulators.  As they say, the pudding is in the proof.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/73/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/73/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/73/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=73&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/28/concurrent-zero-knowledge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>

		<media:content url="http://belenkiy.files.wordpress.com/2008/07/002-concurrentzk.jpg" medium="image">
			<media:title type="html">Concurrent Zero-Knowledge</media:title>
		</media:content>
	</item>
		<item>
		<title>Endorsed E-Cash</title>
		<link>http://belenkiy.wordpress.com/2008/07/28/endorsed-e-cash-2/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/28/endorsed-e-cash-2/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 00:26:20 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[See Fig. 1]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=67</guid>
		<description><![CDATA[E-Cash is supposed to be the digital equivalent of real cash.  The idea is that Alice can withdraw money from the bank and spend it anonymously.  Later, when the bank looks at its database of deposits and withdrawals, it shouldn&#8217;t be able to link any deposit with any withdrawal.
Of course there is a problem with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=67&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div id="attachment_68" class="wp-caption aligncenter" style="width: 460px"><a href="http://belenkiy.files.wordpress.com/2008/07/001-endorsedecash.jpg"><img class="size-full wp-image-68" src="http://belenkiy.files.wordpress.com/2008/07/001-endorsedecash.jpg?w=450&#038;h=382" alt="Endorsed E-Cash" width="450" height="382" /></a><p class="wp-caption-text">Endorsed E-Cash</p></div>
<p>E-Cash is supposed to be the digital equivalent of real cash.  The idea is that Alice can withdraw money from the bank and spend it anonymously.  Later, when the bank looks at its database of deposits and withdrawals, it shouldn&#8217;t be able to link any deposit with any withdrawal.</p>
<p>Of course there is a problem with this scenario.  Suppose Alice withdraws a digital dollar and then spends it twenty-gadzillion times.  Since Alice stores the digital dollar on her computer, nothing stops her from making those twenty-gadzillion copies.</p>
<p>The standard solution is to embed Alice&#8217;s identity into every e-dollar she withdraws.  If she spends the same e-dollar more than once, the bank can look at the two deposits and determine Alice&#8217;s identity.  For example, suppose we associate a straight line with each e-dollar.  The y-intercept is Alice&#8217;s identity.  The slope is chosen at random during withdrawal.  If Alice spends the e-dollar once, she reveals one point on the line.  That&#8217;s not enough to learn anything about Alice&#8217;s identity.  (Try it at home: point your finger on any random spot on the monitor and count the number of straight lines between your finger and the left hand side of the screen).  If Alice spends the e-dollar a second time, the bank can &#8220;connect the dots&#8221; and follow the line to the y-intercept.</p>
<p>The standard objection is that even if Alice is identified after the fact, Alice fly to the Bahamas long before the bank catches up.  The potential damage is just not worth the on-line privacy goodness.</p>
<p>These practical obligations did not deter me from writing my Ph.D. thesis on e-cash.  One of my favorite results was showing how to do secure fair exchange of e-cash.  When Alice sends Bob her e-dollars (ok, now that we&#8217;re getting technical, I should call them by their official latin name, <em>e-coin</em>, which is easy to remember, because it is like <em>e-coli</em>, only it corrupts you soul and not your stomach), she wants to make sure she gets some sort of receipt back in return.  Bob doesn&#8217;t want to send a receipt until he gets paid.  The solution is to do alot of math in algebraic groups of prime order.</p>
<p>Things get even more interesting when Alice needs to pay more than one e-coin.  Now we do a cool trick and hide all the e-coins in a polynomial of degree N.  Then Alice gives Bob N points on the polynomial.  Just as in the straight line example, Bob doesn&#8217;t learn anything about the e-coins because he only has N points.  He needs N+1 points to interpolate (english: compute) the polynomial.  Then Alice and Bob run the Asokan, Shoup and Waidner fair exchange algorithm for the magic N+1th point.  Alice gets a receipt.  Bob gets N+1 points.  He interpolates, and voila! out comes the pot of e-cash.</p>
<p>You can read more about <a href="http://belenkiy.wordpress.com/2008/07/20/endorsed-e-cash/">Endorsed E-Cash</a> in my IEEE Security and Privacy 2007 publication.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/67/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/67/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/67/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=67&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/28/endorsed-e-cash-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>

		<media:content url="http://belenkiy.files.wordpress.com/2008/07/001-endorsedecash.jpg" medium="image">
			<media:title type="html">Endorsed E-Cash</media:title>
		</media:content>
	</item>
		<item>
		<title>Endorsed E-Cash</title>
		<link>http://belenkiy.wordpress.com/2008/07/20/endorsed-e-cash/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/20/endorsed-e-cash/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 19:27:54 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[crypto]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=19</guid>
		<description><![CDATA[Jan Camenisch, Anna Lysyanskaya and Mira Meyerovich. IEEE Security and Privacy 2007.
Abstract. An electronic cash (e-cash) scheme lets a user withdraw money from a bank and then spend it anonymously. E-cash can be used only if it can be securely and fairly exchanged for electronic goods or services. In this paper, we introduce and realize [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=19&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Jan Camenisch, Anna Lysyanskaya and Mira Meyerovich. IEEE Security and Privacy 2007.</p>
<p>Abstract. An electronic cash (e-cash) scheme lets a user withdraw money from a bank and then spend it anonymously. E-cash can be used only if it can be securely and fairly exchanged for electronic goods or services. In this paper, we introduce and realize endorsed e-cash. An endorsed e-coin consists of a lightweight endorsement <em>x</em> and the rest of the coin which is meaningless without<em> x</em>. We reduce the problem of exchanging e-cash to that of exchanging endorsements. We demonstrate the usefulness of endorsed e-cash by exhibiting simple and efficient solutions to two important problems: (1) optimistic and unlinkable fair exchange of e-cash for digital goods and services; and (2) onion routing with incentives and accountability for the routers. Finally, we show how to represent a set of n endorsements using just one endorsement; this means that the complexity of the fair exchange protocol for <em>n</em> coins is the same as for one coin, making e-cash all the more scalable and suitable for applications. Our fair exchange of multiple e-coins protocol can be applied to fair exchanges of (almost) any secrets.</p>
<p><a href="http://belenkiy.files.wordpress.com/2008/07/ieeesp071.pdf">Published Version</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/19/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/19/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=19&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/20/endorsed-e-cash/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
		<item>
		<title>P-signatures and Noninteractive Anonymous Credentials</title>
		<link>http://belenkiy.wordpress.com/2008/07/20/anoncredentials/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/20/anoncredentials/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 19:23:58 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=29</guid>
		<description><![CDATA[Mira Belenkiy, Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya. TCC 2008.
Abstract. In this paper, we introduce P-signatures. A P-signature scheme consists of a signature scheme, a commitment scheme, and (1) an interactive protocol for obtaining a signature on a committed value; (2) a non − interactive proof system for proving that the contents of a commitment has been [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=29&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Mira Belenkiy, Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya. TCC 2008.</p>
<p><strong>Abstract. </strong>In this paper, we introduce P-signatures. A P-signature scheme consists of a signature scheme, a commitment scheme, and (1) an interactive protocol for obtaining a signature on a committed value; (2) a <em>non</em> − <em>interactive</em> proof system for proving that the contents of a commitment has been signed; (3) a noninteractive proof system for proving that a pair of commitments are commitments to the same value. We give a definition of security for P-signatures and show how they can be realized under appropriate assumptions about groups with a bilinear map. We make extensive use of the powerful suite of non-interactive proof techniques due to Groth and Sahai. Our P-signatures enable, for the first time, the design of a practical non-interactive anonymous credential system whose security does not rely on the random oracle model. In addition, they may serve as a useful building block for other privacy-preserving authentication mechanisms.</p>
<p><a href="http://belenkiy.files.wordpress.com/2008/07/tcc08.pdf">Published Version</a> | <a rel="attachment wp-att-61" href="http://belenkiy.wordpress.com/2008/07/20/anoncredentials/attachment/3842/">Full Version</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/29/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/29/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/29/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=29&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/20/anoncredentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
		<item>
		<title>Delegatable Anonymous Credentials</title>
		<link>http://belenkiy.wordpress.com/2008/07/20/delegcredentials/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/20/delegcredentials/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 19:19:41 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=27</guid>
		<description><![CDATA[Mira Belenkiy, Jan Camenisch, Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya, Hovav Shacham.
Please contact me for a copy.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=27&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Mira Belenkiy, Jan Camenisch, Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya, Hovav Shacham.</p>
<p>Please contact me for a copy.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=27&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/20/delegcredentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
		<item>
		<title>Disjunctive Multi-Level Secret Sharing</title>
		<link>http://belenkiy.wordpress.com/2008/07/20/multi-levelss/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/20/multi-levelss/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 19:18:38 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=24</guid>
		<description><![CDATA[Mira Belenkiy. Cryptology ePrint Archive: Report 2008/018.
Abstract. A disjunctive multi-level secret sharing scheme divides users into different levels. Each level L is associated with a threshold t_L, and a group of users can only recover the secret if, for some L, there are at least t_L users at levels 0&#8230;.L in the group. We present [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=24&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Mira Belenkiy. Cryptology ePrint Archive: Report 2008/018.</p>
<p><strong>Abstract.</strong> A disjunctive multi-level secret sharing scheme divides users into different levels. Each level <em>L</em> is associated with a threshold <em>t_L</em>, and a group of users can only recover the secret if, for some <em>L</em>, there are at least <em>t_L</em> users at levels <em>0&#8230;.L</em> in the group. We present a simple ideal disjunctive multi-level secret sharing scheme &#8212; in fact, the simplest and most direct scheme to date. It is the first polynomial-time solution that allows the dealer to add new users dynamically. Our solution is by far the most efficient; the dealer must perform <em>O(t)</em> field operations per user, where <em>t </em>is the highest threshold in the system. We demonstrate the simplicity of our scheme by extending our construction into a distributed commitment scheme using standard techniques.</p>
<p><a href="http://belenkiy.files.wordpress.com/2008/07/018.pdf">Technical Report</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/24/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/24/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/24/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=24&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/20/multi-levelss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
		<item>
		<title>Making P2P Accountable without Losing Privacy</title>
		<link>http://belenkiy.wordpress.com/2008/07/20/making-p2p-accountable/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/20/making-p2p-accountable/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 19:15:10 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=21</guid>
		<description><![CDATA[Mira Belenkiy, Melissa Chase, Chris Erway, John Jannotti, Alptekin Kupcu, Anna Lysyanskaya, Eric Rachlin. WPES 2007.

Abstract. Peer-to-peer systems have been proposed for a wide variety of applications, including ﬁle-sharing, web caching, distributed computation, cooperative backup, and onion routing. An important motivation for such systems is self-scaling. That is, increased participation increases the capacity of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=21&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Mira Belenkiy, Melissa Chase, Chris Erway, John Jannotti, Alptekin Kupcu, Anna Lysyanskaya, Eric Rachlin. WPES 2007.<br />
<strong><br />
Abstract.</strong> Peer-to-peer systems have been proposed for a wide variety of applications, including ﬁle-sharing, web caching, distributed computation, cooperative backup, and onion routing. An important motivation for such systems is self-scaling. That is, increased participation increases the capacity of the system. Unfortunately, this property is at risk from selﬁsh participants. The decentralized nature of peer-to-peer systems makes accounting difficult. We show that e-cash can be a practical solution to the desire for accountability in peer-to-peer systems while maintaining their ability to self-scale. No less important, e-cash is a natural ﬁt for peer-to-peer systems that attempt to provide (or preserve) privacy for their participants. We show that e-cash can be used to provide  accountability without compromising the existing privacy goals of a peer-to-peer system.</p>
<p>We show how e-cash can be practically applied to a ﬁle sharing application. Our approach includes a set of novel cryptographic protocols that mitigate the computational and communication costs of anonymous e-cash transactions, and system design choices that further reduce overhead and distribute load. We conclude that provably secure, anonymous, and scalable peer-to-peer systems are within reach.</p>
<p><a href="http://belenkiy.files.wordpress.com/2008/07/wpes07.pdf">Published Version</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/21/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/21/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=21&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/20/making-p2p-accountable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
		<item>
		<title>How to Win the Clone Wars: Efficient Periodic n-Times Anonymous Authentication</title>
		<link>http://belenkiy.wordpress.com/2008/07/20/clonewars/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/20/clonewars/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 19:06:27 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=13</guid>
		<description><![CDATA[Jan Camenisch, Susan Hohenberger, Markulf Kohlweiss, Anna Lysyanskaya and Mira Meyerovich. ACM CCS 2006.
Abstract. We create a credential system that lets a user anonymously authenticate at most n times in a single time period. A user withdraws a dispenser of n e-tokens. She shows an etoken to a verifier to authenticate herself; each e-token can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=13&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Jan Camenisch, Susan Hohenberger, Markulf Kohlweiss, Anna Lysyanskaya and Mira Meyerovich. ACM CCS 2006.</p>
<p><strong>Abstract.</strong> We create a credential system that lets a user anonymously authenticate at most <em>n</em> times in a single time period. A user withdraws a dispenser of <em>n</em> e-tokens. She shows an etoken to a verifier to authenticate herself; each e-token can be used only once, however, the dispenser automatically refreshes every time period. The only prior solution to this problem, due to Damgard et al. [29], uses protocols that are a factor of <em>k</em> slower for the user and verifier, where <em>k</em> is the security parameter. Damgard et al. also only support one authentication per time period, while we support <em>n</em>. Because our construction is based on e-cash, we can use existing techniques to identify a cheating user, trace all of her e-tokens, and revoke her dispensers. We also offer a new anonymity service: glitch protection for basically honest users who (occasionally) reuse e-tokens. The verifier can always recognize a reused e-token; however, we preserve the anonymity of users who do not reuse e-tokens too often.</p>
<p><a href="http://belenkiy.files.wordpress.com/2008/07/ccs06.pdf">Published Version</a> | <a href="http://belenkiy.files.wordpress.com/2008/07/ccs06_full.pdf">Full Version</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/13/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/13/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=13&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/20/clonewars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
		<item>
		<title>Siegreich im Klonkrieg: Effiziente, Periodische n-Fach Anonyme Authentifizierung</title>
		<link>http://belenkiy.wordpress.com/2008/07/20/klonkrieg/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/20/klonkrieg/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 18:57:35 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=7</guid>
		<description><![CDATA[Jan Camenisch, Susan Hohenberger, Markulf Kohlweiss, Anna Lysyanskaya and Mira Meyerovich.  D-A-CH Mobility 2006.
See also. How to Win the Clone Wars: Efficient Periodic n-Times Anonymous Authentication. Jan Camenisch, Susan Hohenberger, Markulf Kohlweiss, Anna Lysyanskaya and Mira Meyerovich. ACM CCS 2006.
Abstract. Wie verhindert man, dass ein anonymer Sensor ofter als viermal pro Tag Informationen ubermittelt? Mittels [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=7&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Jan Camenisch, Susan Hohenberger, Markulf Kohlweiss, Anna Lysyanskaya and Mira Meyerovich.  D-A-CH Mobility 2006.</p>
<p><strong>See also.</strong> <a href="http://belenkiy.wordpress.com/2008/07/20/clonewars/">How to Win the Clone Wars: Efficient Periodic n-Times Anonymous Authentication.</a> Jan Camenisch, Susan Hohenberger, Markulf Kohlweiss, Anna Lysyanskaya and Mira Meyerovich. ACM CCS 2006.</p>
<p><strong>Abstract. </strong>Wie verhindert man, dass ein anonymer Sensor ofter als viermal pro Tag Informationen ubermittelt? Mittels E-Cash naturlich! Anonymitat ist insbesondere fur mobile personengebundene Sensoren wesentlich, die andernfalls den Aufenthaltsort ihrer Besitzer preisgeben. Die Einschr ankung der Meldefrequenz ist notig, um die uneingeschr ankte Verbreitung von Roguesensoren zu verhindern.</p>
<p>Wir stellen ein System vor, das es Sensoren erlaubt, Daten bis zu n mal pro Zeitperiode anonym zu authentiﬁzieren. Bei der Initialisierung erhalt der Sensor uber ein Abhebeprotokoll einen E-Token Spender<br />
mit <em>n</em> E-Tokens. Um Daten zu authentiﬁzieren, zeigt der Sensor eines dieser E-Token in einem interaktiven Protokoll mit dem Empfanger. Jedes E-Token kann nur einmal verwendet werden, allerdings werden<br />
Spender pro Zeitperiode automatisch neu aufgefullt. Die einzige bekannte Losung fur dieses Problems<br />
fur <em>n = 1</em>, vorgestellt von Damgard et al. [20], verwendet Protokolle, die um den Faktor<em> k</em> langsamer<br />
sind. Der Sicherheitsparameter k bestimmt dabei die Wahrscheinlichkeit <em>2−k</em>, mit der ein Sensor uner-<br />
kannt zwei Datens atz verschicken kann.</p>
<p><a href="http://belenkiy.files.wordpress.com/2008/07/klonkrieg06.pdf">Published Version</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/7/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/7/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=7&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/20/klonkrieg/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
		<item>
		<title>Provably Secure Steganography with Imperfect Sampling</title>
		<link>http://belenkiy.wordpress.com/2008/07/10/steganography/</link>
		<comments>http://belenkiy.wordpress.com/2008/07/10/steganography/#comments</comments>
		<pubDate>Thu, 10 Jul 2008 02:00:43 +0000</pubDate>
		<dc:creator>harmonicwife</dc:creator>
				<category><![CDATA[Cryptography]]></category>

		<guid isPermaLink="false">http://belenkiy.wordpress.com/?p=4</guid>
		<description><![CDATA[Anna Lysyanskaya and Mira Meyerovich.   PKC 2006.
Abstract. The goal of steganography is to pass secret messages by disguising them as innocent-looking covertexts. Real world stegosystems are often broken because they make invalid assumptions about the system’s ability to sample covertexts. We examine whether it is possible to weaken this assumption. By modeling the covertext [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=4&subd=belenkiy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Anna Lysyanskaya and Mira Meyerovich.   PKC 2006.</p>
<p><strong>Abstract</strong>. The goal of steganography is to pass secret messages by disguising them as innocent-looking covertexts. Real world stegosystems are often broken because they make invalid assumptions about the system’s ability to sample covertexts. We examine whether it is possible to weaken this assumption. By modeling the covertext distribution as a stateful Markov process, we create a sliding scale between real world and provably secure stegosystems. We also show that insufficient knowledge of past states can have catastrophic results.</p>
<p><strong></strong><a href="http://belenkiy.files.wordpress.com/2008/07/pkc06.pdf">Published Version</a> | <a href="http://belenkiy.files.wordpress.com/2008/07/pkc06_full.pdf">Full Version</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/belenkiy.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/belenkiy.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/belenkiy.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/belenkiy.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/belenkiy.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/belenkiy.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/belenkiy.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/belenkiy.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/belenkiy.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/belenkiy.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/belenkiy.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/belenkiy.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=belenkiy.wordpress.com&blog=4177932&post=4&subd=belenkiy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://belenkiy.wordpress.com/2008/07/10/steganography/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f97f9cd462aa1ee82b8bcaa140a0cab8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mira</media:title>
		</media:content>
	</item>
	</channel>
</rss>