首页> 外文会议>IACR International Conference on Practice and Theory of Public-Key Cryptography >Limits on the Efficiency of (Ring) LWE Based Non-interactive Key Exchange
【24h】

Limits on the Efficiency of (Ring) LWE Based Non-interactive Key Exchange

机译:(Ring)基于LWE的非交互式密钥交换效率的限制

获取原文

摘要

LWE based key-exchange protocols lie at the heart of post-quantum public-key cryptography. However, all existing protocols either lack the non-interactive nature of Diffie-Hellman key-exchange or polynomial LWE-modulus, resulting in unwanted efficiency overhead. We study the possibility of designing non-interactive LWE-based protocols with polynomial LWE-modulus. To this end, 1. We identify and formalize simple non-interactive and polynomial LWE-modulus variants of existing protocols, where Alice and Bob simultaneously exchange one or more (ring) LWE samples with polynomial LWE-modulus and then run individual key reconciliation functions to obtain the shared key. 2. We point out central barriers and show that such non-interactive key-exchange protocols are impossible if: (1) the reconciliation functions first compute the inner product of the received LWE sample with their private LWE secret. This impossibility is information theoretic. (2) One of the reconciliation functions does not depend on the error of the transmitted LWE sample. This impossibility assumes hardness of LWE. 3. We give further evidence that progress in either direction, of giving an LWE-based NIKE protocol or proving impossibility of one will lead to progress on some other well-studied questions in cryptography. Overall, our results show possibilities and challenges in designing simple (ring) LWE-based non-interactive key exchange protocols.
机译:基于LWE的密钥交换协议是后量子公共密钥加密技术的核心。但是,所有现有协议都缺乏Diffie-Hellman密钥交换的非交互性或多项式LWE模,从而导致不必要的效率开销。我们研究了设计具有多项式LWE模量的基于非交互式LWE的协议的可能性。为此,1.我们确定并规范化现有协议的简单非交互和多项式LWE模量变体,其中Alice和Bob同时交换具有多项式LWE模数的一个或多个(环状)LWE样本,然后运行各个关键和解功能获取共享密钥。 2.我们指出了中心障碍,并证明在以下情况下,这种非交互式密钥交换协议是不可能的:(1)对帐函数首先计算接收到的LWE样本及其私有LWE秘密的内积。这种不可能是信息论。 (2)调节功能之一不取决于传输的LWE样本的误差。这种可能性假设为LWE的硬度。 3.我们提供了进一步的证据,证明在基于LWE的NIKE协议或证明不可能的任一方向上取得进展将导致在密码学上其他一些经过充分研究的问题上取得进展。总体而言,我们的结果表明,在设计基于LWE的简单(环形)非交互密钥交换协议时可能会遇到挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号