arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

量子提取的自然障碍:关于(O)EKE与Masny-Rindal OT的后量子(不)安全性

Natural Barriers to Quantum Extraction: On the Post-Quantum (In)security of (O)EKE and Masny-Rindal OT

James Bartusek, Jake Januzelli

arXiv 2609.39844首次发表:更新:

AI 中文总结

本研究证明(O)EKE协议和Masny-Rindal OT编译器即使使用后量子KEM,在量子对抗模型下也不具备UC安全性,并提出了一个优势紧致的单向到隐藏引理。

AI 中文摘要

加密密钥交换(EKE)由Bellovin和Merritt(IEEE S&P 1992)提出,Masny-Rindal OT由Masny和Rindal(ACM CCS 2019)提出,它们是高效的方法,仅依赖理想化的对称密钥原语,即可将几乎任何KEM编译成高级密码协议,即口令认证密钥交换(PAKE)和不经意传输(OT)。由于(1)其简洁性,(2)其即插即用特性,允许灵活选择KEM,以及(3)已有的UC安全性证明(在经典对抗模型下),它们已成为实际可实现的PAKE和OT的主要候选方案。鉴于上述第(2)点,这些编译器为高效的后量子PAKE和OT提供了有吸引力的候选方案,尤其是考虑到最近后量子KEM标准化工作的进展。这引发了这些编译器的(UC)安全性是否能迁移到量子对抗模型的问题。在本工作中,我们证明其不能。具体而言,我们证明一般族的(O)EKE协议以及Masny-Rindal OT,即使以后量子KEM实例化,也并非对量子多项式时间对手是UC安全的。为确立UC不安全性,我们设计了一种对抗策略,该策略可证明地挫败模拟器提取其输入(在PAKE中为口令,在OT中为接收者的选择比特)的任何尝试。为补充这些负面结果,我们证明这两种编译器均能实现某些基于博弈的安全概念。在此过程中,我们建立了一个新颖的“优势紧致”的单向到隐藏引理,该引理可能具有独立的研究价值。

英文摘要

Encrypted key exchange (EKE), introduced by Bellovin and Merritt (IEEE S\&P 1992), and Masny-Rindal OT, introduced by Masny and Rindal (ACM CCS 2019), are highly-efficient methods for compiling essentially any KEM into advanced cryptographic protocols, namely password-authenticated key exchange (PAKE) and oblivious transfer (OT), by relying only on idealized symmetric-key primitives. They have become leading candidates for practically-implementable PAKE and OT due to (1) their simplicity, (2) their plug-and-play nature, allowing for flexibility in the choice of KEM, and (3) existing proofs of UC-security (in the classical adversarial model). Due to point (2) above, these compilers yield attractive candidates for efficient \emph{post-quantum} PAKE and OT, especially given the recent post-quantum KEM standardization efforts. This motivates the question of whether the (UC-)security of these compilers translates to the quantum adversarial model. In this work, we show that it does not. In particular, we prove that a general family of (O)EKE protocols, as well as Masny-Rindal OT, are \emph{not} UC-secure against quantum polynomial-time adversaries, even when instantiated with a post-quantum KEM. To establish UC-insecurity, we devise an adversarial strategy that provably thwarts any attempt by the simulator to extract its input (the password in the case of PAKE, and the receiver's choice bit in the case of OT). To complement these negative results, we establish that both compilers yield certain notions of \emph{game-based} security. Along the way, we establish a novel ``advantage-tight'' one-way to hiding lemma that may be of independent interest.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑