arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于小指数哈希的简单极强有损函数

Simple Extremely Lossy Functions from Small-Exponent Hashing

Damiano Abram, Agni Datta, Archisman Dutta, Lawrence Roy

arXiv 2610.07351首次发表:更新:

发表机构

The University of Edinburgh; Aarhus University; IBM Zurich Research(爱丁堡大学; 奥胡斯大学; 苏黎世IBM研究实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出极强有损陷门哈希(ELTDH),一步构造出比现有极强有损函数更简单高效的方案,基于小指数离散对数的指数安全性与DCR的多项式安全性,使ELFs的假设基础更多样化。

AI 中文摘要

极强有损函数(ELFs)是一种标准模型原语,它捕获了随机预言机的许多有用性质(Zhandry,Crypto 2016)。尽管存在许多具有额外性质的ELFs变体,但每个构造(除混淆外)本质上都遵循相同的模板,即从仅对固定规模对手安全的ELFs序列进行自举,并且每个构造都仅基于DDH(或k-Lin)的指数级困难性,这是一种仅在椭圆曲线上才合理的假设。我们引入并构造了极强有损陷门哈希(ELTDH),这是一种更强的概念,蕴含了所有已知的ELFs变体。我们的构造一步到位地实现了ELTDH,无需从仅对固定规模对手安全的方案进行自举,这使得它比现有的ELFs更简单且更高效。我们假设小指数离散对数的指数级安全性,以及判定性合数剩余类(DCR)的多项式级安全性。指数级安全性仅要求秘密指数的规模,而非群的规模,因此该假设对模N^2乘法(以及许多其他密码学群)是合理的,尽管存在来自索引演算的亚指数时间离散对数攻击。我们的结果使ELFs所基于的假设多样化,同时提供了更简单的构造。

英文摘要

Extremely Lossy Functions (ELFs) are a standard model primitive that captures many useful properties of random oracles (Zhandry, Crypto 2016). While there are many variations of ELFs with additional properties, every construction (excluding obfuscation) has followed essentially the same template of bootstrapping from a sequence of ELFs secure only against fixed-size adversaries, and every construction was based on only the exponential hardness of DDH (or $k$-Lin), an assumption that is only reasonable over elliptic curves. We introduce and construct Extremely Lossy Trapdoor Hashing (ELTDH), a stronger notion that implies all known variations of ELFs. Our construction achieves ELTDH in one go, without bootstrapping from schemes secure for only fixed-size adversaries, which makes it simpler and more efficient than existing ELFs. We assume exponential security of the small-exponent discrete logarithm, together with polynomial security of decisional composite residuosity (DCR). Exponential security is only required in the size of the secret exponent, not the size of the group, so the assumption plausibly holds for multiplication modulo $N^2$ (and for many other cryptographic groups), despite the subexponential-time discrete logarithm attacks from index calculus. Our results diversify the assumptions underlying ELFs, while also giving a simpler construction.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑