arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.10010cs.CR

定义目的受限的秘密

Defining Purpose-Limited Secrets

Bhumika Mittal, Aalok Thakkar

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出将目的作为密码学秘密的属性,定义限制、调解和问责三种制度,通过统一规范比较功能签名、约束PRF等原语,并以支付令牌为例展示多制度应用。

中文摘要 AI 辅助

密码学秘密是为特定目的而签发,但授予的通常是更大的能力:用于计算聚合的解密密钥可以读取每条记录,用于支付一张发票的令牌可以清空账户。已部署的系统在策略中声明目的,但仅强制执行能力。我们将目的作为秘密的一个属性。机制看到的是操作,而非原因,因此方案强制执行一个可允许操作集 $A(P)$,用以代表声明的预期用途 $I$;$I$ 是否捕捉人类目的是一种建模义务,标志着策略接管之处。针对同一 $I$,我们定义了三种制度:在限制(confinement)下,超出预期用途的操作不可行;在调解(mediation)下,可信组件拒绝该操作;在问责(accountability)下,超出规定界限的使用是可能的,但归属于持有者。限制游戏(针对不可预测性和不可区分性)与功能签名不可伪造性和约束PRF伪随机性的密钥查询形式一致,并对应于其可行性边界内的模拟安全功能加密;针对 $I$ 陈述时,它们还登记了一个允许过多操作的谓词。支付令牌在一个秘密上使用所有三种制度:它在一个商家支付一笔有上限的费用,可以收窄但不能放宽,由商家检查,如果使用两次则识别提款账户。衰减不可伪造性在无随机预言机下归约为不可伪造签名和抗碰撞哈希;可追溯性和不可诬陷性在随机预言机模型下基于离散对数和不可伪造签名成立。我们不声称新原语、新困难假设或通用组合定理;该框架是一种通用规范,用于陈述和比较此类原语。

英文摘要

A cryptographic secret is issued for a purpose but grants a capability, and the capability is usually larger: a decryption key meant for computing aggregates can read every record, and a token meant to pay one invoice can drain the account. Deployed systems state the purpose in policy and enforce only the capability. We make the purpose a property of the secret. A mechanism sees operations, not reasons, so a scheme enforces an admissible set $A(P)$ of operations that stands in for a declared intended use $I$; whether $I$ captures the human purpose is a modeling obligation that marks where policy takes over. Against the same $I$ we define three regimes: under confinement an operation outside the intended use is infeasible, under mediation a trusted component refuses it, and under accountability use beyond a stated bound is possible but attributed to the holder. The confinement games, for unpredictability and indistinguishability, coincide with the key-query forms of functional-signature unforgeability and constrained-PRF pseudorandomness and correspond to simulation-secure functional encryption within its feasibility boundary; stated against $I$, they also register a predicate that permits too much. A payment token uses all three regimes on one secret: it pays one capped charge at one merchant, can be narrowed but not widened, is checked by the merchant, and identifies the withdrawing account if spent twice. Attenuation unforgeability reduces to unforgeable signatures and a collision-resistant hash without random oracles; traceability and non-frameability hold under discrete log and unforgeable signatures in the random-oracle model. We claim no new primitive, hardness assumption, or general composition theorem; the framework is a common specification against which such primitives are stated and compared.

发表机构

  • Georgia Institute of Technology(佐治亚理工学院)
  • Ashoka University(阿育王大学)

机构由 AI 辅助整理,请以论文原文为准。

↑