By Boaz Barak, Yevgeniy Dodis, Hugo Krawczyk, Olivier Pereira, Krzysztof Pietrzak (auth.), Phillip Rogaway (eds.)

This booklet constitutes the refereed complaints of the thirty first Annual foreign Cryptology convention, CRYPTO 2011, held in Santa Barbara, CA, united states in August 2011. The forty two revised complete papers offered have been rigorously reviewed and chosen from 230 submissions. the amount additionally includes the summary of 1 invited speak. The papers are prepared in topical sections on randomness and its use; computer-assisted cryptographic proofs; outsourcing and delegatin computation; symmetric cryptanalysis and buildings; safe computation: leakage and aspect channels; quantum cryptography; lattices and knapsacks; public-key encryption; symmetric schemes; signatures; obilvious move and mystery sharing; and multivariate and coding-based schemes.

Hypothesis 1. ) is negligible and Prg : {0, 1}k → {0, 1}n(k) is a pseudorandom generator, then Ext defined as Ext (x; s) = Ext(x; Prg(s)) is a computational m-extractor. 1 Counter-Example: Expanding Seeds Is Insecure in General In this section we show that, unfortunately, Hypothesis 1 is wrong in general. Theorem 5 (Hypothesis 1 wrong assuming DDH). e. ) Proof (of Theorem 5). Let G be a prime order p cyclic group with generator g where the DDH problem is hard. Then Prg : Z3p → G 6 defined as Prg(a, b, c) = (g a , g b , g ab , g ac , g bc , g abc ) is a a secure pseudorandom generator [28].

Throughout, negl(k) denotes a negligible function in k. A function τ (·) : N → [0, 1] is overwhelming if 1 − τ (·) is negligible. A function φ : N → [0, 1] is noticeable if for some c > 0 there is an k0 such that φ(k) ≥ 1/k c for all k ≥ k0 . Note that non-negligible is not the same as noticeable. For def example, μ(k) = k mod 2 is non-negligible but not noticeable. def Computational Extractors and PRGs. Recall that with ΔD (X, Y ) = | Pr[D(X) = 1] − Pr[D(Y ) = 1] | we denote the advantage of a circuit D in distinguishing the random variables X and Y .

