EUROCRYEVr '97, the fifteenth annual EUROCRYPT convention at the idea and alertness of cryptographic strategies, used to be prepared and subsidized by way of the foreign organization for Cryptologic study (IACR). The IACR organizes sequence of foreign meetings every year, the EUROCRYPT assembly in Europe and CRWTO within the usa. The historical past of EUROCRYFT all started 15 years in the past in Germany with the Burg Feuerstein Workshop (see Springer LNCS 149 for the proceedings). It used to be as a result of Thomas Beth's initiative and tough paintings that the seventy six members from 14 nations accumulated in Burg Feuerstein for the 1st open assembly in Europe dedicated to modem cryptography. i'm proud to were one of many members and nonetheless fondly keep in mind my first encounters with a number of the celebrities in cryptography. considering the fact that these early days the convention has been held in a distinct place in Europe every year (Udine, Paris, Linz, Linkoping, Amsterdam, Davos, Houthalen, Aarhus, Brighton, Balantonfiired, Lofthus, Perugia, Saint-Malo, Saragossa) and it has loved a gentle progress, because the moment convention (Udine, 1983) the IACR has been concerned, because the Paris assembly in 1984, the identify EUROCRYPT has been used. For its fifteenth anniversary, EUROCRYPT ultimately again to Germany. The medical software for EUROCRYPT '97 used to be prepare via a 18-member application committee whch thought of 104 fine quality submissions. those court cases comprise the revised types of the 34 papers that have been permitted for presentation. additionally, there have been invited talks by means of Ernst Bovelander and via Gerhard Frey.

Since SHIFT-l(A) = A, this shows that A contains both, even as well as odd elements: simply shift c by an appropriate number of positions. Consider the permutation MUL-(2"-' + 1) E G. MUL-(2'-' + 1) is an involution that fixes every even element and consists of transpositions of the form (x, x + 2"" mod 2"). This can be seen as follows. Let x = 2y + 1 be odd. Then MuL-(T1+ 1)(x) = (2"-' + 1)(2y + 1) = 2 9 + 2"-' + 2y + 1 = x + 2"-' (mod 2"). Further, (2"-' + 1)2 = 1 (mod 2"), which shows that the order of MUL-(2"" + 1) is equal to two.

This would allow one t o break the system without factoring. We have a new type of attack that also avoids directly factoring the modulus. We essentially use the fact that from time to time the hardware performing the computations may introduce errors. There are several models that may enable a malicious adversary t o collect and possibly cause faults. We give a high level description: Transient faults Consider a certification authority (CA) that is constantly generating certificates and sending them out t o clients.

Rivest, A knapsack-type public k e y cryptosystem based o n arithmetic o n f i n i t e fields, IEEE Transactions on Information Theory, vol. IT 34, 1988, pp. 901L909. 5. T. Cusick, A comparison of RSA and the Naccache-Stern public-key cryptosystem, manuscript, October 31, 1995. 6. D. Denning (Robling), Cryptography and data security, Addison-Wesley Publishing Company, p. 148, 1983. 7. Y. Desmedt, W h a t happened with knapsack cryptographic schemes, Performance limits in communication - theory and practice, NATO AS1 series E : Applied sciences, vol.

