arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

复合阶域上抗泄漏Shamir秘密共享的部分去随机化

Partial Derandomization for Leakage-Resilient Shamir's Secret Sharing over Composite Order Fields

S. Venkitesh

arXiv 2607.28757首次发表:更新:

AI 中文总结

该研究在复合阶域上构造抗泄漏Shamir秘密共享的显式评估点,通过部分去随机化评估点,降低随机性消耗,在受限参数范围实现对单块泄漏的完美统计安全,改进了现有相关方案。

AI 中文摘要

我们在复合阶域上构造抗泄漏Shamir秘密共享的显式评估点问题上取得了进展。此前,Maji等人(EUROCRYPT 2024)证明,随机评估点可在复合阶域$\boldsymbol{\text{F}}_{p^d}$上生成Shamir秘密共享方案,该方案对物理位泄漏具有统计安全性。随后,Nguyen(EUROCRYPT 2025)确立了二分性:域$\boldsymbol{\text{F}}_{p^d}$上基于线性码的秘密共享方案,对此类泄漏要么具有统计安全性,要么完全不安全。基于Nguyen的二分性,我们对评估点进行了部分去随机化,在受限参数范围内改进了Maji等人的结果。我们用简单固定有理函数$\boldsymbol{\text{\textit{Φ}}}$的迭代$\boldsymbol{x_j = \text{\textit{Φ}}^j(x_0)}$替代$n$个独立评估点的随机选择,其中初始点$\boldsymbol{x_0 \boldsymbol{\text{∈}} \boldsymbol{\text{F}}_{p^d}^*}$是随机选取的,因此评估点中的随机性从$\boldsymbol{nd \boldsymbol{\text{log}} p}$比特降至$\boldsymbol{d \boldsymbol{\text{log}} p}$比特。我们的构造适用于$\boldsymbol{n = O(d/\boldsymbol{\text{log}}_p d)}$的范围,以及任意重构阈值$\boldsymbol{k \boldsymbol{\text{≥}} 2}$;实际上,该方案对单块泄漏具有完美安全性(统计距离恰好为零)。我们的技术是利用有理迭代不同极点的部分分式非退化论证。

英文摘要

We make progress on the question of constructing explicit evaluation places for leakage-resilient Shamir's secret sharing, over composite order fields. Previously, Maji et al. (EUROCRYPT 2024) showed that random evaluation places yield Shamir's secret sharing over the composite order field $\mathbb{F}_{p^d}$ that is statistically secure against physical-bit leakage. Later, Nguyen (EUROCRYPT 2025) established a dichotomy that linear code-based secret-sharing scheme over the field $\mathbb{F}_{p^d}$ is either statistically secure or completely insecure against such leakage. Building upon Nguyen's dichotomy, we present a partial derandomization of evaluation places, improving upon the Maji et al. result for a restricted regime of parameters. We replace the random choice of $n$ independent evaluation places by the iterates $x_j = Φ^j(x_0)$ of a simple fixed rational function $Φ$, where the initial point $x_0 \in \mathbb{F}_{p^d}^*$ is randomly chosen. The randomness in the evaluation places thus drops from $nd \log p$ bits to $d\log p$ bits. Our construction is valid for the regime $n = O(d/\log_p d)$, and any reconstruction threshold $k \ge 2$; in fact, the scheme attains perfect security (statistical distance exactly zero) against single-block leakage. Our technique is a partial fraction nondegeneracy argument that exploits the distinct poles of the rational iterates.

CommentsA preliminary version of this work is due to appear at ITC 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑