arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.01390cs.CR

Pivot:基于同构群作用的主动可验证阈值不经意伪随机函数

Pivot: Proactive and Verifiable Threshold Oblivious Pseudorandom Functions From Isogeny Group Actions

Abhinav Sharma, Vikas Srivastava

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出基于同构群作用的主动可验证阈值不经意伪随机函数PIVOT,解决现有同构阈值OPRF易受移动攻击的问题,支持密钥份额刷新等功能,保障长期安全并实现分布式私有查找服务。

中文摘要 AI 辅助

不经意伪随机函数(OPRF)允许客户端在不向服务器泄露自身输入的情况下,对该私有输入执行带密钥的伪随机函数计算。在阈值OPRF中,秘密密钥被分发至n个服务器,任意不少于t个服务器的合格集合可完成计算,而少于t个密钥份额则不会泄露密钥的任何信息。然而,现有的基于同构的阈值OPRF主要针对静态腐败模型设计:若密钥份额在服务全生命周期内保持有效,移动攻击者可随时间入侵不同服务器,从同一密钥共享状态积累t个份额,最终恢复主密钥。我们提出PIVOT(主动同构可验证不经意阈值伪随机函数),这是一种基于有效同构群作用的无经销商阈值VOPRF框架。PIVOT定期刷新服务器密钥份额,且无需改变主密钥、公钥或此前生成的OPRF输出。该构造结合了Shamir秘密共享、加法同态系数承诺、序贯拉格朗日加权群作用,以及将已认证份额与其对应同构作用关联的联合零知识关系。它还支持协调的周期转换、公开可验证的追责、安全擦除,以及在可能不同阈值下的委员会重新共享。我们形式化了长生命周期主动阈值VOPRF的功能,证明了分布式密钥生成、阈值计算、主动刷新和委员会重新共享的正确性,并在向量化和一次以上隐藏群作用假设下提供了基于模拟的安全性分析。作为应用,我们描述了一种分布式私有查找服务,其加密数据库在重复的份额更新和委员会迁移过程中保持有效。

英文摘要

Oblivious pseudorandom functions (OPRFs) allow a client to evaluate a keyed pseudorandom function on a private input without revealing that input to the server. In a threshold OPRF, the secret key is distributed among (n) servers so that any qualified set of at least (t) servers can complete an evaluation, while fewer than (t) shares reveal no information about the key. Existing isogeny-based threshold OPRFs, however, are primarily designed for static corruption models. If the same shares remain valid throughout the lifetime of the service, a mobile adversary can compromise different servers over time, accumulate (t) shares from the same sharing state, and eventually recover the master key. We introduce PIVOT (Proactive Isogeny-based Verifiable Oblivious Threshold PRF), a dealerless threshold VOPRF framework based on effective isogeny group actions. PIVOT periodically refreshes the server shares without changing the master key, public key, or previously generated OPRF outputs. The construction combines Shamir secret sharing, additively homomorphic coefficient commitments, sequential Lagrange-weighted group actions, and joint zero-knowledge relations that link certified shares to their corresponding isogeny actions. It also supports coordinated epoch transitions, publicly verifiable blame, secure erasure, and committee resharing under a possibly different threshold. We formalize the functionality of a long-lived proactive threshold VOPRF, prove the correctness of distributed key generation, threshold evaluation, proactive refresh, and committee resharing, and provide a simulation-based security analysis under the vectorization and one-more hidden-group- action assumptions. As an application, we describe a distributed private lookup service whose encrypted database remains valid across repeated share renewals and committee migrations.

↑