首页> 外文会议>Theory of Cryptography Conference >Leakage Resilient One-Way Functions: The Auxiliary-Input Setting
【24h】

Leakage Resilient One-Way Functions: The Auxiliary-Input Setting

机译:泄漏弹性单向功能:辅助输入设置

获取原文

摘要

Most cryptographic schemes are designed in a model where perfect secrecy of the secret key is assumed. In most physical implementations, however, some form of information leakage is inherent and unavoidable. To deal with this, a flurry of works showed how to construct basic cryptographic primitives that are resilient to various forms of leakage. Dodis et al. (FOCS '10) formalized and constructed leakage resilient one-way functions. These are one-way functions / such that given a random image f(x) and leakage g(x) it is still hard to invert f(x). Based on any one-way function, Dodis et al. constructed such a one-way function that is leakage resilient assuming that an attacker can leak any lossy function g of the input. In this work we consider the problem of constructing leakage resilient one-way functions that are secure with respect to arbitrary computationally hiding leakage (a.k.a auxiliary-input). We consider both types of leakage - selective and adaptive - and prove various possibility and impossibility results. On the negative side, we show that if the leakage is an adaptively-chosen arbitrary one-way function, then it is impossible to construct leakage resilient one-way functions. The latter is proved both in the random oracle model (without any further assumptions) and in the standard model based on a strong vector-variant of DDH. On the positive side, we observe that when the leakage is chosen ahead of time, there are leakage resilient one-way functions based on a variety of assumption.
机译:大多数密码方案都是在假设秘密密钥完全保密的模型中设计的。但是,在大多数物理实现中,某些形式的信息泄漏是固有的并且是不可避免的。为了解决这个问题,一系列的工作展示了如何构建对各种形式的泄漏具有弹性的基本密码原语。 Dodis等。 (FOCS '10)正式确定并构建了具有泄漏弹性的单向功能。这些是单向函数,因此在给定随机图像f(x)和泄漏g(x)的情况下,仍然很难反转f(x)。基于任何一种单向函数,Dodis等人。假设攻击者可以泄漏输入的任何有损函数g,则它构造为具有泄漏弹性的单向函数。在这项工作中,我们考虑构造相对于任意计算隐藏泄漏(也称为辅助输入)安全的泄漏弹性单向函数的问题。我们考虑两种类型的泄漏-选择性泄漏和自适应泄漏,并证明各种可能性和不可能的结果。从消极的一面,我们表明,如果泄漏是自适应选择的任意单向函数,那么就不可能构造具有泄漏弹性的单向函数。后者在随机预言模型(没有任何进一步假设)和基于DDH的强矢量变量的标准模型中都得到了证明。从积极的一面,我们观察到,当提前选择泄漏时,基于各种假设,就会存在具有弹性的单向泄漏函数。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号