<?xml version="1.0" encoding="UTF-8"?><rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel rdf:about="http://dl.gi.de/handle/20.500.12116/21469">
<title>P128 - Sicherheit 2008 – Sicherheit, Schutz und Zuverlässigkeit. Beiträge der 4. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft für Informatik e.V. (GI)</title>
<link>http://dl.gi.de/handle/20.500.12116/21469</link>
<description/>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/21520"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/21518"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/21521"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/21519"/>
</rdf:Seq>
</items>
<dc:date>2026-07-21T13:27:27Z</dc:date>
</channel>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/21520">
<title>Variants of Bleichenbacher’s Low-Exponent Attack on PKCS#1 RSA Signatures</title>
<link>http://dl.gi.de/handle/20.500.12116/21520</link>
<description>Variants of Bleichenbacher’s Low-Exponent Attack on PKCS#1 RSA Signatures
Kühn, Ulrich; Pyshkin, Andrei; Tews, Erik; Weinmann, Ralf-Philipp
Alkassar, Ammar; Siekmann, Jörg
We give three variants and improvements of Bleichenbacher’s low-exponent attack from CRYPTO 2006 on PKCS#1 v1.5 RSA signatures. For each of these three variants the fake signature representatives are accepted as valid by a flawed implementation. Our attacks work against much shorter keys as Bleichenbacher’s original attack, i.e. even for usual 1024 bit RSA keys. The first two variants can be used to break a certificate chain for vulnerable im- plementations, if the CA uses a public exponent of 3. Such CA certificates are indeed deployed in many browsers like Mozilla, Opera and Konqueror. The third attack works against the Netscape Security Services only, and requires the public exponent 3 to be present in a site’s certificate, not the CA certificate. Using any of these attack vectors, an active adversary can mount a full man-in-the- middle attack on any SSL connection initiated by a vulnerable client.
</description>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/21518">
<title>ANOCAST: Rethinking Broadcast Anonymity in the Case of Wireless Communication</title>
<link>http://dl.gi.de/handle/20.500.12116/21518</link>
<description>ANOCAST: Rethinking Broadcast Anonymity in the Case of Wireless Communication
Adelsbach, André; Greveler, Ulrich; Groß, Stephan; Steinbrecher, Sandra
Alkassar, Ammar; Siekmann, Jörg
In this work we present the ANOCAST environment being an anonymous communication framework based on wireless technology having reached prototype status. By exploiting the availability of current broadcast communication systems (e. g. digital satellites and Wi-Fi) we achieve recipient anonymity and unobservability. We examine our approach by a simulation approach using a prototype implementation, raising several questions concerning its scalability, efficiency and possible application scenarios as well as a discussion on its security accomplishments.The key finding of our work shows that practicability of anonymous communication for the masses can be realised today and the community should rethink the common consensus that enormous traffic overhead jeopardises any practical anonymous communication system.
</description>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/21521">
<title>On an Approach to Compute (at least Almost) Exact Probabilities for Differential Hash Collision Paths</title>
<link>http://dl.gi.de/handle/20.500.12116/21521</link>
<description>On an Approach to Compute (at least Almost) Exact Probabilities for Differential Hash Collision Paths
Gebhardt, Max; Illies, Georg; Schindler, Werner
Alkassar, Ammar; Siekmann, Jörg
This paper presents a new, generally applicable method to compute the probability of given differential (near-)collision paths in Merkle-Damgard-type hash functions. The path probability determines the expected workload to generate a collision (and thus the true risk potential of a particular attack). In particular, if the expected workload appears to be in a borderline region between practical feasibility and non- feasibility (as for SHA-1 collisions, for instance) it is desirable to know these proba- bilities as exact as possible. For MD5 we verified the accuracy of our approach experimentally. Our results underline both that the number of bit conditions only provides a rough estimate for the true path probability and the impact of the IV. An expanded version of this paper can be found online [GIS4].
</description>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/21519">
<title>Using the Concept of Topic Maps for Enhancing Information Privacy in Social Networking Applications</title>
<link>http://dl.gi.de/handle/20.500.12116/21519</link>
<description>Using the Concept of Topic Maps for Enhancing Information Privacy in Social Networking Applications
Weiss, Stefan
Alkassar, Ammar; Siekmann, Jörg
The growth of online social networking applications (SNA) and the economic potential that might be generated by their underlining business models is getting broad attention recently. Public discussions about the information privacy for SNA users have been revived as a result of some privacy-invasive activities taking place such as identity theft, stalking, discrimination, distortion of facts, embarrassment, and many others. One of the problems why these threats to information privacy are not merely theoretical in nature is the apparent loss of control over the personal information provided and the lack of transparency over its usage on the Internet. This paper suggests a privacy-enhancing technology (PET) that adapts the semantic technique concept of a topic map for the use with SNAs. Topic maps in such a setting would provide the user with more transparency over the status of his information privacy when using SNAs and would provide means to exercise choices on particular data sets. The paper explains how a topic map concept would be adapted as PET, which privacy principles it would cover, and how it would generally solve some of the issues of information privacy in online social networks.
</description>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</item>
</rdf:RDF>
