By Mike V. D. Burmester, Yvo Desmedt (auth.), Ivan Bjerre Damgård (eds.)

Eurocrypt is a convention dedicated to all facets of cryptologic study, either theoretical and useful, backed through the foreign organization for Cryptologic learn (IACR). Eurocrypt ninety came about in Åarhus, Denmark, in may perhaps 1990. From the eighty five papers submitted, forty two have been chosen for presentation on the convention and for inclusion during this quantity. as well as the formal contributions, brief abstracts of a couple of casual talks are incorporated in those complaints. The lawsuits are prepared into periods on protocols, number-theoretic algorithms, boolean capabilities, binary sequences, implementations, combinatorial schemes, cryptanalysis, new cryptosystems, signatures and authentication, and impromptu talks.

**Extra info for Advances in Cryptology — EUROCRYPT ’90: Workshop on the Theory and Application of Cryptographic Techniques Aarhus, Denmark, May 21–24, 1990 Proceedings**

**Example text**

Mere, the sender has two strings so and s1. Each of the following two events is equally likely to occur at the end of a 1-out-2 Oblivious Transfer: 0 The Receiver learns the string so, and does not get any information about s1. The Receiver learns the string s l , and docs not get any information about SO. 51 The sender has no information on wliich string the receiver gets. It is clear that 1-out-2 Oblivious Transfcr can be used to implement an Oblivious Transfer. CrBpeau [Cr] showed how to achieve a 1-out-2 Oblivious Transfer by using Rabin’s OT, thus establishing their equivalence.

Thc wide applicability of the OT was recognized since the early days of modern cryptography; the papcr by Blum [B2] is a an example of how OT can be used to implement several other protocols. A different flavor of OT, the I - o u t 3 Oblivious Tmnsjcr was later introduced by Even, Goldreich, and Lcmpel [EGL]. Mere, the sender has two strings so and s1. Each of the following two events is equally likely to occur at the end of a 1-out-2 Oblivious Transfer: 0 The Receiver learns the string so, and does not get any information about s1.

Zi, 5 Non-Interactive Perfect Zero-Knowledge Argument s B i t - C o m m i t m e n t i n tlie Public-Key Public-Randomness Model. A bit commitment protocol is a fundamental %-partycryptographic protocol. It allows one party A to hide (commit) onc bit 6 from the other party B and, later, to show (decommit) it to B. Even though B does not know which bit A has committed to, he is guarantced that the bit dccommitted is the bit A originally committed to. If B is poly-time, the bit commitment can be implemented as: A chooses a secure encryption schemc (in the sensc of [GM]) and commits to a bit by encrypting it.