arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

碰撞检测在生日阈值下是实例 $\widetilde{O}$ 最优的

Collision Detection is Instance $\widetilde{O}$ptimal Under the Birthday Threshold

Omri Ben-Eliezer, Tomer Grossman, Václav Rozhoň, Jakub Tětek

arXiv 2609.37342首次发表:更新:

发表机构

Technion – Israel Institute of Technology; Weizmann Institute; Charles University(以色列理工学院; 魏茨曼科学研究所; 查理大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文证明在碰撞检测中,当碰撞查找所需查询次数远小于生日界限时,存在一个几乎实例最优的算法,其查询开销与结构感知算法相比仅有 $O(\log n)$ 的紧乘法因子,从而排除了密码设计中植入结构性后门的可能性。

AI 中文摘要

关于哈希函数的结构性知识能否帮助加速(黑盒)检测其中的碰撞?鉴于抗碰撞哈希函数的重要性,这个问题对密码学理论至关重要,本文从实例最优性的角度来探讨,这是超越最坏情况算法分析的一种终极概念,近年来获得了广泛关注。实例最优性要求一个单一算法,在每一个输入上,其性能都几乎与“知道该特定输入结构”的最佳正确算法相当。这里我们通过算法对哈希函数 $f\colon [n]\to [n]$ 的查询次数来衡量算法,并称一个算法“知道输入的结构”,如果除了对 $f$ 的查询访问外,它还能免费访问 $f$ 的一个无标记副本 $\pi^{-1}\circ f\circ\pi$,其中 $\pi$ 是 $[n]$ 上的未知置换。我们证明了在从密码学角度看最有趣的场景中,即对于找到碰撞所需的查询次数显著少于 $\sqrt{n}$ 的函数,存在一个(几乎)实例最优的碰撞检测算法。具体而言,我们证明存在一个单一算法 $A$,对于任何输入 $f$,如果某个结构感知算法期望用 $q\leq O(\sqrt{n/\log n})$ 次查询就能找到碰撞,那么 $A$ 最多用 $O(q\log n)$ 次查询就能找到碰撞。$O(\log n)$ 的乘法开销是紧的,匹配了 Ben-Eliezer、Grossman 和 Naor [ICALP'25] 的下界,部分解决了他们的主要开放问题。我们的结果尤其意味着,密码设计者不可能为碰撞寻找植入纯粹的结构性后门(对于这种无标记的结构概念):无论设计者的秘密知识能找到什么碰撞,公众都能以 $O(\log n)$ 的乘法开销找到。

英文摘要

Can structural knowledge about a hash function help accelerate the (black box) detection of collisions in it? This question is fundamental to cryptography theory given the importance of collision-resistant hash functions, and in this paper we tackle it from the angle of instance optimality, an ultimate notion of beyond worst case algorithm analysis that has gained significant traction in recent years. Instance optimality asks for a single algorithm that, on every input, performs nearly as well as the best correct algorithm that ``knows the structure'' of that specific input. Here we measure algorithms by the number of queries they make to the hash function $f\colon [n]\to [n]$, and we say that an algorithm ``knows the structure'' of the input if, in addition to query access to $f$, it has free access to an unlabeled copy $π^{-1}\circ f\circπ$ of $f$, for an unknown permutation $π$ on $[n]$. We prove the existence of an (almost) instance-optimal algorithm for collision detection in the regime most interesting from a cryptographic perspective: among functions where finding a collision takes significantly less than $\sqrt{n}$ queries. Specifically, we prove the existence of a single algorithm $A$ that, for any input $f$ in which a structure-aware algorithm can find a collision using $q\leq O(\sqrt{n/\log n})$ queries in expectation, $A$ can find a collision in at most $O(q\log n)$ queries. The $O(\log n)$ multiplicative overhead is tight, matching a lower bound of Ben-Eliezer, Grossman, and Naor [ICALP'25], and partially resolving their main open question. Our result implies, in particular, that it is impossible for a cryptographic designer to plant purely structural backdoors for collision finding (for this unlabeled notion of structure): whatever collisions the designer's secret knowledge finds, the public can find with a multiplicative overhead of $O(\log n)$.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑