Security of NewHope Under Partial Key Exposure

Security of NewHope Under Partial Key Exposure
复制标题

部分密钥暴露下 NewHope 的安全性

DOI:
10.1007/978-3-030-58748-2_6
复制
发表时间:
2020
期刊:
Association for Women in Mathematics series
影响因子:
--
通讯作者:
Shahverdi, Aria
Shahverdi, Aria
中科院分区:
--
文献类型:
--
作者:
Dachman-Soled, Dana;Gong, Huijing;Kulkarni, Mukul;Shahverdi, Aria

文献摘要

参考文献

相似文献

最近,Bolboceanu等人的工作(Asiacrypt '19)和Dachman Soled等人的工作(Mathcrypt '19)已经研究了一种泄漏模型,该模型假设RLWE密码系统中秘密密钥的NTT坐标的一部分泄漏(或者等效地,故意将NTT坐标的一部分设置为0来采样秘密)。这可以被视为部分密钥暴露问题,因为出于效率目的,RLWE密码系统中的秘密密钥通常存储在其NTT表示中。我们通过分析纽霍普密钥交换方案在部分密钥暴露为各方秘密的NTT坐标的1 scin 8分数的情况下的安全性来扩展这项研究。我们采用Dachman Soled等人(Mathcrypt '19)的工作中引入的决策Leaky-RLWE(Leaky-DRLWE)假设的形式主义,该假设假定在秘密的NTT坐标的足够小的部分上给出泄漏,输出的剩余坐标保持与均匀不可区分。我们注意到,Dachman Soled等人的工作中的假设。(Mathcrypt '19)严格弱于Bolboceanu等人的工作中的相应假设。(Asiacrypt '19),这要求整个输出保持一致。我们表明,假设泄漏DRLWE是很难为1 scin 8-分数泄漏,共享keyv(然后使用随机oracle散列)是计算上无法区分的随机变量与平均最小熵237,条件的转录和泄漏,而没有泄漏的最小熵为256。注意,在该泄漏模型中泄漏了2 × 1738比特的信息,因此在共享的256比特密钥中保留任何熵的事实是重要的。
Recently, the work of Bolboceanu et al. (Asiacrypt ’19) and the work of Dachman Soled et al. (Mathcrypt ’19) have studied a leakage model that assumes leakage of some fraction of the NTT coordinates of the secret key in RLWE cryptosystems (or equivalently, intentionally sampling secrets with some fraction of NTT coordinates set to 0). This can be viewed as a partial key exposure problem, since for efficiency purposes, secret keys in RLWE cryptosystems are typically stored in their NTT representation. We extend this study by analyzing the security of the NewHope key exchange scheme under partial key exposure of 1∕8-fraction of the NTT coordinates of the parties’ secrets. We adopt the formalism of the decision Leaky-RLWE (Leaky-DRLWE) assumption introduced in the work of Dachman Soled et al. (Mathcrypt ’19), which posits that given leakage on a sufficiently small fraction of NTT coordinates of the secret, the remaining coordinates of the output remain indistinguishable from uniform. We note that the assumption in the work of Dachman Soled et al. (Mathcrypt ’19) is strictly weaker than the corresponding assumption in the work of Bolboceanu et al. (Asiacrypt ’19), which requires that the entire output remain indistinguishable from uniform. We show that, assuming that Leaky-DRLWE is hard for 1∕8-fraction of leakage, the shared keyv(which is then hashed using a random oracle) is computationally indistinguishable from a random variable with average min-entropy 237, conditioned on the transcript and leakage, whereas without leakage the min-entropy is 256. Note that 2 ⋅ 1738 number of bits of information are leaked in this leakage model, and so the fact that any entropy remains in the shared 256-bit key is non-trivial.
应用于体积问题的样条符号
DOI: --
发表时间: 1979
期刊:
影响因子: --
作者:
D. L. Barrow;Philip W. Smith
通讯作者: Philip W. Smith