【24h】

Public-Seed Pseudorandom Permutations

机译:公共种子伪随机排列

获取原文

摘要

This paper initiates the study of standard-model assumptions on permutations - or more precisely, on families of permutations indexed by a public seed. We introduce and study the notion of a public-seed pseudorandom permutation (psPRP), which is inspired by the UCE notion by Bellare, Hoeing, and Keelveedhi (CRYPTO '13). It considers a two-stage security game, where the first-stage adversary is known as the source, and is restricted to prevent trivial attacks - the security notion is consequently parameterized by the class of allowable sources. To this end, we define in particular unpredictable and reset-secure sources analogous to similar notions for UCEs. We first study the relationship between psPRPs and UCEs. To start with, we provide efficient constructions of UCEs from psPRPs for both reset-secure and unpredictable sources, thus showing that most applications of the UCE framework admit instantiations from psPRPs. We also show a converse of this statement, namely that the five-round Feistel construction yields a psPRP for reset-secure sources when the round function is built from UCEs for reset-secure sources, hence making psPRP and UCE equivalent notions for such sources. In addition to studying such reductions, we suggest generic instantiations of psPRPs from both block ciphers and (keyless) permutations, and analyze them in ideal models. Also, as an application of our notions, we show that a simple modification of a recent highly-efficient garbling scheme by Bellare et al. (S&P '13) is secure under our psPRP assumption.
机译:本文启动了关于置换的标准模型假设的研究,或更确切地说,是对由公共种子索引的置换家族的研究。我们引入并研究了公共种子伪随机置换(psPRP)的概念,该概念受Bellare,Hoeing和Keelveedhi(CRYPTO '13)的UCE观念的启发。它考虑了一个分为两个阶段的安全游戏,其中第一阶段的对手被称为源,并且被限制为防止琐碎的攻击-因此,安全概念由允许的源类别进行参数化。为此,我们特别定义了类似于UCE的类似概念的不可预测且复位安全的源。我们首先研究psPRP和UCE之间的关系。首先,我们为重置安全和不可预测的源提供了来自psPRP的UCE的高效构造,因此表明,UCE框架的大多数应用都允许来自psPRP的实例化。我们还证明了这一说法的反面,即当轮功能由针对重置安全源的UCE构建时,五轮Feistel构造会为针对重置安全源产生psPRP,因此使此类源成为psPRP和UCE等效概念。除了研究这种减少之外,我们还建议从分组密码和(无密钥)排列中对psPRP进行通用实例化,并在理想模型中对其进行分析。另外,作为我们概念的应用,我们表明Bellare等人对最近的高效赌博方案进行了简单的修改。 (ps&P '13)在我们的psPRP假设下是安全的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号