By Juan A. Garay, Rosario Gennaro

The volume-set, LNCS 8616 and LNCS 8617, constitutes the refereed lawsuits of the thirty fourth Annual foreign Cryptology convention, CRYPTO 2014, held in Santa Barbara, CA, united states, in August 2014.

The 60 revised complete papers awarded in LNCS 8616 and LNCS 8617 have been rigorously reviewed and chosen from 227 submissions. The papers are prepared in topical sections on symmetric encryption and PRFs; formal equipment; hash features; teams and maps; lattices; uneven encryption and signatures; facet channels and leakage resilience; obfuscation; FHE; quantum cryptography; foundations of hardness; number-theoretic hardness; information-theoretic safety; key alternate and safe communique; 0 wisdom; composable safety; safe computation - foundations; safe computation - implementations.

Concentration of Measure for the Analysis of Randomized Algorithms. Cambridge University Press (2009) 38. : Quantum Entanglement. Rev. Mod. Phys. 81, 865–942 (2009) 39. : Room-Temperature Quantum Bit Storage Exceeding 39 Minutes Using Ionized Donors in Silicon-28. Science 342(6160), 830–833 (2013) 40. : Single-Shot Readout of Multiple Nuclear Spin Qubits in Diamond under Ambient Conditions. Phys. Rev. Lett. 110, 060502 (2013) How to Eat Your Entropy and Have It Too – Optimal Recovery Strategies for Compromised RNGs Yevgeniy Dodis1, , Adi Shamir2 , Noah Stephens-Davidowitz1 , and Daniel Wichs3, 1 2 Dept.

To prove security, we consider adversaries that make separable measurements (which include LOCC measurements as a special case). The basic idea is to consider the distribution of the messages s and t, conditioned on one particular measurement outcome z obtained by the adversary. Since the adversary is separable, the corresponding POVM element Mz will be a tensor product of n lg q single-qubit operators a=1 Ra (up to normalization). Now, one can imagine a fictional adversary that measures the qubits one at a time, and happens to observe this same string of single-qubit measurement outcomes R1 , R2 , .

Finally, we can take the code C constructed above (for pe = 12 ), and combine it with the OTM construction of Theorem 2, to get the following result: Corollary 1. For any k ≥ 2, and for any small constant 0 < μ 1, there exists an OTM construction that stores two messages s, t ∈ {0, 1} , where = Θ(k 2 ), and has the following properties: 1. The OTM behaves correctly for honest parties. 2. The OTM can be implemented in time polynomial in k. 3. Let 0 < δ 1 be any small constant. Suppose the messages s and t are chosen independently and uniformly at random in {0, 1} .

