arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

依赖感知的 ML-KEM-768 在启发式失败规模下的 ROM/CBD 正确性界

Dependency-Aware ROM/CBD Correctness Bounds for ML-KEM-768 at the Heuristic Failure Scale

Aurélie Duriez, Christophe Tommasini

arXiv 2609.09983首次发表:更新:

发表机构

netHsys SARL; Tommasini Conseil(netHsys有限责任公司; Tommasini咨询公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文在显式 ROM/CBD 抽象下,为 ML-KEM-768 证明了依赖保持的诚实解封装失败上界,达到启发式失败规模,认证指数为 164.81 比特。

AI 中文摘要

我们在一个显式的随机函数/中心二项分布(ROM/CBD)抽象中,证明了 ML-KEM-768 的诚实解封装失败上界。域分离的公开矩阵流被建模为独立的均匀环元素,秘密/噪声多项式被建模为独立的 CBD2 原语;这不是关于 FIPS 203 的固定 SHAKE 实例化的信息论陈述。最近的正式评估将 ML-KEM 的启发式解封装失败规模的严格证明确定为开放问题;在我们研究的显式 ROM/CBD 抽象内,我们获得了该规模下的依赖保持的认证上界。该分析保留了由公开矩阵和两个密文压缩项引起的依赖关系。其终端链包含三个部分:一个用于联合 c_u/c_v 残差的精确图耦合全理想参考;一个真理想双变量傅里叶传输,其稀有 |T|>=3 分支通过穷举三因子反集中重放闭合;以及精确的比特特定 FIPS 解码事件,之后仅跟随 256 坐标并集界。一个形式化的部分傅里叶引理使谱到全变差的步骤显式化。约简的有理证书满足 Pr[K' != K] <= P_* <= 2^-164.81,其中 -log2(P_*) = 164.810716201343121...。164.81 阈值是精确但数值上紧的:认证指数仅超过它约 0.0007162 比特,且 164.82 未被认证。该结果是针对独立于公开和秘密随机性固定的任意消息的上界,在诚实加密和解封装下成立。它不是精确的 DFR,不是固定 SHAKE 等价定理,不是新的 IND-CCA 归约,也不是自适应 delta 正确性结果。

英文摘要

We certify an honest-decapsulation failure upper bound for ML-KEM-768 in an explicit random-function/centered-binomial (ROM/CBD) abstraction. Domain-separated public-matrix streams are modeled as independent uniform ring elements and secret/noise polynomials as independent CBD2 primitives; this is not an information-theoretic statement about the fixed SHAKE instantiation of FIPS 203. Recent formal assessments identify rigorous justification of ML-KEM's heuristic decapsulation-failure scale as an open problem; within the explicit ROM/CBD abstraction studied here, we obtain a dependency-preserving certified upper bound at that scale. The analysis preserves dependencies induced by the public matrix and by both ciphertext-compression terms. Its terminal chain has three components: an exact graph-coupled full-ideal reference for the joint c_u/c_v residual; a proper-ideal bivariate Fourier transport whose rare |T|>=3 branch is closed by an exhaustive three-factor anti-concentration replay; and exact bit-specific FIPS decoding events followed only by a 256-coordinate union bound. A formal partial-Fourier lemma makes the spectral-to-total-variation step explicit. The reduced rational certificate satisfies Pr[K' != K] <= P_* <= 2^-164.81, with -log2(P_*) = 164.810716201343121.... The 164.81 threshold is exact but numerically tight: the certified exponent exceeds it by only about 0.0007162 bit, and 164.82 is not certified. The result is an upper bound for an arbitrary message fixed independently of the public and secret randomness, under honest encryption and decapsulation. It is not an exact DFR, not a fixed-SHAKE equivalence theorem, not a new IND-CCA reduction, and not an adaptive delta-correctness result.

Comments34 pages, 0 figures. Includes a deterministic verification capsule and an exact rational terminal certificate; result is in an explicit fixed-message ROM/CBD abstraction and is not an exact fixed-SHAKE DFR

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑