By Antoine Joux (auth.), Eli Biham (eds.)

This e-book constitutes the refereed complaints of the overseas convention at the idea and purposes of Cryptographic suggestions, EUROCRYPT 2003, held in Warsaw, Poland in might 2003.

The 37 revised complete papers awarded including invited papers have been rigorously reviewed and chosen from 156 submissions. The papers are geared up in topical sections on cryptanalysis, safe multi-party communique, zero-knowledge protocols, foundations and complexity-theoretic protection, public key encryption, new primitives, elliptic curve cryptography, electronic signatures, information-theoretic cryptography, and crew signatures.

E. which gives the optimal decision region A. Lemma 1 (Neyman-Pearson). Let X be a random variable drawn according to a probability distribution D and let be the decision problem corresponding to hypotheses X ← D0 and X ← D1 . For τ ≥ 0, let A be defined by A x∈X : PrX0 [x] ≥τ PrX1 [x] (1) Let α∗ PrX0 A and β ∗ PrX1 [A]. Let B be any other decision region with associated probabilities of error α and β. If α ≤ α∗ , then β ≥ β ∗ . Hence, the Neyman-Pearson lemma indicates that the optimum test (regarding error probabilities) in case of a binary decision problem is the likelihood-ratio test.

Are denoted in bold characters. The fact for a random variable X to follow a distribution D is denoted X ← D, while its probability function is denoted by PrX [x]. Finally, as usual, “iid” means “independent and identically distributed”. g. see [26]). 1 In this paper, we are only dealing with discrete random variables. 1 19 Classical Approach Let D0 and D1 be two different probability distributions defined on the same finite set X . In a binary hypothesis testing problem, one is given an element x ∈ X which was drawn according either to D0 or to D1 and one has to decide which is the case.

T. M. Cover and J. A. Thomas, Information theory, Wiley Series in Telecommunications, Wiley, 1991. 9. D. Davies and S. Murphy, Pairs and triples of DES S-boxes, Journal of Cryptology 8 (1995), no. 1, 1–25. 32 P. Junod 10. H. Gilbert, H. Handschuh, A. Joux, and S. Vaudenay, A statistical attack on RC6, Fast Software Encryption FSE’00, LNCS, vol. 1978, Springer-Verlag, 2000, pp. 65– 74. 11. R. R. Stirzaker, Probability and random processes, Oxford University Press, 2001, 3rd edition. 12. H. Handschuh and H.

