Cryptacus Newsletter
Total Page:16
File Type:pdf, Size:1020Kb
SEPTEMBER 2016, NO 1 Cryptacus Newsletter First Cryptacus.eu Newsletter Welcome to this first edition of the monthly Crypta- cus Newsletter, bringing you a quick glimpse into the latest developments in the IoT cryptanalysis area. There are not a lot of contributors to this first edition of the newsletter, for obvious reasons, but we’d love you to send us your contributions for in- coming issues, comments and feedback to [email protected] News from the Chair Castro accepted to be the editor of This month we recommend to by GILDAS AVOINE this newsletter. Thanks, Julio! I hope read the paper Lock It and Still Lose you will keep this newsletter excit- It - On the (In)Security of Automo- ing by regularly sending your news to tive Remote Keyless Entry Systems, Julio. published in the 25th USENIX Se- During Haifa’s meeting, we also curity Symposium (USENIX Security discussed the third grand period. 2016). Cryptacus encountered several diffi- This brilliant piece of work, by culties to launch the third grant pe- our colleague and WG4 leader riod, but this issue should be fixed Flavio Garcia (with David Os- soon. Note that the scientific commit- wald, Timo Kasper and Pierre tee, chaired by Bart Preneel, will pro- Pavlidès) which you can enjoy at pose in the coming days the location http://goo.gl/nkeDB5, has been all Cryptacus’ Management Committee of the next meeting. Right after, the over the news recently, being covered Meeting organised in Haifa, Israel, MC will vote on the grant agreement, at news sites such as The Guardian, was really interesting and useful which is a mandatory step before the Daiy Mail, WIRED, The Register, Busi- (Thanks, Orr!) for the current and next period starts. Short-term scien- ness Insider, Daily Tech, Ars Tech- future activities of our COST Ac- tific missions will then be able to be nica, etc. showing once more why tion. The Management Committee organised again. the work we do can potentially have (MC) decided there to make collab- an enormous societal impact. Con- orations in Cryptacus’ even stronger, gratulations Flavio et al., nice work! Funding News and to spread the information bet- Recommended reading ter among the members of the Ac- tion, and more generally in the sci- entific community. Among the dis- cussed issues, the MC decided to pub- lish a monthly newsletter that in- cludes recent activities of the Action, as well as news from the field (call for papers, open positions, significant publications, etc.). Julio Hernandez- There are a number of interesting Cryptacus Newsletter m Cryptacus.eu B [email protected] Page 1 European calls for H2020 projects Lectureship in the Founda- in our (or closely related) areas in • tion of Pervasive Data Sci- DS-08-2017 explicitly mentions 2017. We will cover in more detail ence at Lancaster University. • Privacy Enhancing Technolo- in future editions of this newsletter They mention areas such as gies in its description, ’to pro- some of these opportunities, but for ’Internet of Things, smart vide users with the functional- now let’s list the most obvious ones: cities/spaces and pervasive ity they require without expos- computing’. It helps of you ing any more information than have interest or, preferably, necessary, and without losing DS-06-2017 has a deadline of a track record as a data sci- • control over their data, to any 25 April 2017 and its topic entist. Salaries from £33,574 third parties.’ but also requests (Cryptography) is spot on. The to £46,414. Permanent posi- contributions in the area of ’Se- call is open to proposals ad- tion. Call closing on the 18th cure Digital Identities’. More vancing in areas such as ho- September 2016. More info info at http://goo.gl/rFofmC momorphic encryption, data at http://goo.gl/ysa0HI. The leakage, authenticated encryp- same folks at Lancaster offer tion, post-quantum, automated There are other interesting calls an additional position as a Lec- proofs for crypto protocols, etc. we will mention in future issues, turer in Cybersecurity (closing But they also explicitly request where we will also provide with more on the 30th September 2016) proposals dealing with the ’In- details on the ones briefly shown ternet of Things, implantable above. We will try to encourage Research Associate or Senior medical devices and sensor and support consortia build-up from • Research Associate in Cryp- nodes that harvest energy from within Cryptacus, involving as many tography at Bristol. This is a the environment’ acknowledg- MC members as possible. Incoming rolling call with only a nominal ing that ’there is a need for MC and WG meetings will include deadline of 18th of December. ultra-lightweight cryptology’ opportunities to create consortia and They’re interested in hiring for and that ’additional means exchange know-how to competitively their prestigious Cryptography to protect privacy in these apply to H2020 calls. applications (e.g. anonymity group in Multi-Party Compu- tation, the evaluation of the in communications) should Open Positions be developed.’ More info at security of cryptographic im- http://goo.gl/Ir8ekC. plementations, cryptography resiliency against real world attacks, design and implemen- DS-07-2017 belongs to the tation tools, etc. Salaries from • group of EU call with an un- £31,656 to £40,082. More info godly deadline in August. I at http://goo.gl/TErYvr imagine many of you have suf- fered this in the past, and how badly it can impact your hol- Proposals for STSMs We would like to include in future idays and relations. For this newsletters open positions related to and the next, the deadline is our are of interest, so please send 24 August 2017. The topic cov- us any employment opportunity you ered is closer to cybersecurity, want to publicize. For the time being, in particular Addressing Ad- we have these: vanced Cyber Security Threats and Threat Actors, and they seek the ’development of novel Lecturer/Associate Professor at approaches for providing or- • the University of Southamp- ganizations the appropriate ton. They explicitly mention situational awareness in rela- Internet of Things as one of tion to cyber security threats’ the areas of expertise they’ll with solutions including ’tech- be happy to appoint a candi- By now, you should be already niques such as anomaly de- date. Call closes on the 20th familiar with what Short Term Scien- tection, visualization tools, big September 2016. Salaries from tific Missions (or STSMs, for Short) data analysis, threat analysis, £36,672 to £60,081 per year. are, but we have a healthy budget for deep-packet inspection, proto- Permanent position. More info them within the Cryptacus project col analysis, etc’. More details at http://goo.gl/uEYSxk and not enough demand. at http://goo.gl/FPs4CD Cryptacus Newsletter m Cryptacus.eu B [email protected] Page 2 This section could be used by any http://bristolcrypto.blogspot.be/, We surely have to mention the of our readers to encourage visitors where you can find multiple blog imminent deadline of RFIDSec2016 to their group or lab. For that, please entries with description of their ac- (venue will be Hong Kong) on 12 send us a very brief description of tivities, and a variety of other inter- September (http://rfidsec2016.org/) your profile and that of the intended esting topics, from their musings to as one of the yearly highlights for visitor, and we’ll publicize it in here their live blogging of some of the our community, but the Mycrypt (on to foster international cooperation main events in the Crypto calendar. the 15th) and Eurocrypt (on Octo- within the COST project. ber 1st), together with ASIACCS (on Event calendar November 1st), Finantial Cryptogra- Blogs and posts to read phy (4th of November) and the FSE (23rd of November) will make for a busy end of the year for most of us. This month, I will highly recom- mend you to actively follow the blog of Bristol Crypto Group at Cryptacus Newsletter m Cryptacus.eu B [email protected] Page 3 OCTOBER 2016, NO 2 Cryptacus Newsletter October’16 Cryptacus Newsletter Welcome to the second edition of the monthly Cryptacus.eu Newsletter, bringing you a quick glimpse into the latest developments in the IoT cryptanalysis area. We’d love you to send us your own contributions for incoming issues, comments and feedback to [email protected] News from the Chair mittee will soon receive an official in- This month we have two items on by GILDAS AVOINE vitation. Any other researcher inter- our list of recommended readings. ested by the cryptanalysis of ubiqui- One of them is an academic paper, tous computing systems is welcome for which we have to thank Han- to participate in these meetings. The dan Kilinç, the other a series of news program will be available on the web- posts describing from different an- site soon. gles the recent massive DDoS attack The Action will then organize a work- suffered by Brian Krebs and others shop, early in 2017. The Action is which apparently exploited a very looking for organizers for this work- large network of compromised IoT shop. If you are interested in organiz- devices. ing this event in your country, please contact Gildas Avoine or Bart Pre- Cryptacus’ management committee neel. 1. Efficient Public-Key Distance approved in September 2016 the Finally, I would like to thank those Bounding Protocol. Consid- yearly work and budget plan. I am who sent information to crypta- ering that products which use glad to inform Cryptacus’ members [email protected] to feed Octo- Distance Bounding protocols that the third grant period is conse- ber’s newsletter.