【24h】

Sustainable Pseudo-random Number Generator

机译:可持续的伪随机数生成器

获取原文
获取原文并翻译 | 示例

摘要

Barak and Halevi (BH) have proposed an efficient architecture for robust pseudorandom generators that ensure resilience in the presence of attackers with partial knowledge or partial controls of the generators' entropy resources. The BH scheme is constructed from the Barak, Shaltiel and Tromer's randomness extractor and its security is formalized in the simulation-based framework. The BH model however, does not address the scenario where an attacker completely controls the generators' entropy resources with no knowledge of the internal state. Namely, the BH security model does not consider the security of bad-refresh conditioned on compromised = false. The security of such a case is interesting since if the output of the protocol conditioned on compromised = false looks random to the attacker, then the proposed scheme is secure even if the attacker completely controls entropy resources (recall that attackers with partial knowledge or partial controls of the generators' entropy resources in the BH model). The BH scheme is called sustainable if the above mentioned security requirement is guaranteed. This paper studies the sustainability of the BH pseudorandom generator and makes the following two contributions: in the first fold, a new notion which we call sustainable pseudorandom generator which extends the security definition of the BH's robust scheme is introduced and formalized in the simulation paradigm; in the second fold, we show that the BH's robust scheme achieves the sustainability under the joint assumptions that the underlying stateless function G is a cryptographic pseudorandom number generator and the output of the underlying randomness extractor extract () is statistically close to the uniform distribution.
机译:Barak和Halevi(BH)提出了一种有效的体系结构,用于鲁棒的伪随机生成器,可以确保在攻击者对生成器的熵资源有部分了解或部分控制的情况下具有弹性。 BH方案由Barak,Shaltiel和Tromer的随机性提取器构造而成,其安全性已在基于仿真的框架中形式化。但是,BH模型无法解决攻击者完全不了解内部状态而完全控制生成器的熵资源的情况。即,BH安全性模型不考虑以crimated = false为条件的不良刷新的安全性。这种情况的安全性很有趣,因为如果条件为妥协=假的协议的输出对攻击者而言是随机的,则即使攻击者完全控制了熵资源,所提出的方案也是安全的(回想起具有部分知识或部分控制权的攻击者BH模型中生成器的熵资源的数量)。如果上述安全要求得到保证,则BH计划被称为可持续计划。本文研究了BH伪随机生成器的可持续性,并做出了以下两点贡献:第一,在模拟范式中引入并正式化了一个新概念,称为可持续伪随机生成器,该概念扩展了BH鲁棒方案的安全性定义;在第二折中,我们表明在联合假设下,BH的鲁棒方案实现了可持续性,该假设是基础无状态函数G是密码伪随机数生成器,并且基础随机性提取器extract()的输出在统计上接近于均匀分布。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号