发表机构
South East Technological University(东南科技大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出基于 CRT 分解的 CSIDH Σ-协议,实现零知识证明,具有完美完备性和 2-特殊可靠性,在 QROM 下直线提取,并验证了安全性与效率,但当前参数下安全性受限。
AI 中文摘要
我们为 CSIDH 群作用构造了一个零知识证明系统,该系统利用了理想类群的 CRT 结构,该结构在群结构精确已知时可用,例如 CSIDH-512。我们证明了完美完备性、完美特殊诚实验证者零知识性以及 2-特殊可靠性,其中从两个接受性转录中恢复秘密仅需每个 CRT 分量进行一次减法和一次模逆运算;提取器中不涉及重绕循环、格归约或启发式采样。由于每一轮恰好有两个响应,Unruh 变换在量子随机预言机模型(QROM)中产生具有直线提取的非交互式证明,消除了乘法分叉引理损失。我们在 CSIDH-512 类群上实例化了该方案,通过机器在精确的 258 位模数(10^4 个随机实例,全部通过)上验证了代数层,并报告了指数模型中的协议级模拟:蒙特卡洛可靠性率在 95% 置信水平下与所证明的 2^{-t} 界限匹配,序列化签名大小与公式偏差在 1.6% 以内,仪器化动作计数,以及一个缩放的中期相遇攻击,其测量成本遵循预测的 √q 定律。我们进一步证明了两个界限性结果:CRT 分解不能扩大每轮挑战空间,并且发布 CRT 跳跃曲线将经典密钥恢复成本从约 2^{128.6} 降低到约 2^{67.3} 次群作用评估。因此,该构造在今天是正确且结构完整的,但仅在类数具有大素因子的未来参数上定量安全。我们与 CSI-FiSh、CSI-Otter 和 Tanuki 进行了比较;基于此知识证明的紧致盲签名留待未来工作。
英文摘要
We construct a zero-knowledge proof of knowledge for the CSIDH group action that exploits the Chinese Remainder Theorem (CRT) structure of the ideal class group, available whenever the group structure is known exactly, as for CSIDH-512. We prove perfect completeness, perfect special honest-verifier zero-knowledge, and 2-special soundness, in which the secret is recovered from two accepting transcripts by one subtraction and one modular inversion per CRT component; no rewinding loop, lattice reduction, or heuristic sampling appears in the extractor. Because each round admits exactly two responses, Unruh's transform yields a non-interactive proof with straight-line extraction in the quantum random oracle model (QROM), removing the multiplicative forking-lemma loss. We instantiate the scheme on the CSIDH-512 class group, verify the algebraic layer by machine over the exact 258-bit modulus ($10^4$ random instances, all passing), and report protocol-level simulations in the exponent model: Monte Carlo soundness rates matching the proven $2^{-t}$ bound within 95\% confidence at every tested $t$, serialized signature sizes within 1.6\% of the formulas, instrumented action counts, and a scaled meet-in-the-middle attack whose measured cost follows the predicted $\sqrt{q}$ law. We further prove two delimiting results: CRT decomposition cannot enlarge the per-round challenge space, and publishing the CRT hop curves lowers classical key-recovery cost from about $2^{128.6}$ to about $2^{67.3}$ group action evaluations. The construction is therefore correct and structurally complete today, but quantitatively secure only on future parameters whose class number has large prime factors. We compare against CSI-FiSh, CSI-Otter, and Tanuki; a tightly secure blind signature from this proof of knowledge is left to future work.