All-But-Many Lossy Trapdoor Functions

All-But-Many Lossy Trapdoor Functions
复制标题

DOI:
10.1007/978-3-642-29011-4_14
复制
发表时间:
2012-04
期刊:
--
影响因子:
--
通讯作者:
D. Hofheinz
D. Hofheinz
中科院分区:
其他
文献类型:
--
作者:
D. Hofheinz

文献摘要

被引文献

相似文献

提出了一种有耗陷门函数的推广。也就是说,几乎所有的有损陷门函数(ABM-LTF)是用标签参数化的LTF。每个标签可以是单射的或有损的,这导致可逆或有损函数。ABM-LTF的有趣特性是,它可以通过一个特殊的陷门生成任意数量的有损标签,而没有这个陷门则不可能生成有损标签。我们的定义和构造可以被看作是除了一个LTF(由于Peikert和沃茨)和除了NLTF(由于Hemenway等人)的一般化。然而,为了实现ABM-LTF(以及因此不受任何多项式约束的多个有损标签),我们必须采用一些新技巧。具体地说,我们给出了两个结构,使用“伪装”的变种的沃茨,分别。Boneh-Boyen签名方案,使生成的有损标签很难没有陷门。简而言之,有损标记只是对应于有效签名。同时,标签被伪装(即,适当地盲化)以保持有损标签与单射标签不可区分。ABM-LTF在存在多项式数量的对抗性挑战的设置中是有用的(例如,挑战密文)。具体来说,在Hemenway等人的工作基础上,我们表明,ABM-LTF可以用来实现选择性开放的安全选择密文攻击。因此,我们的ABM-LTF结构之一产生了第一个SO-CCA安全加密方案与紧凑的密文(组元素),其效率不依赖于挑战的数量。我们的第二ABM-LTF建设产生一个IND-CCA(实际上是SO-CCA)安全加密方案,其安全性降低是独立的挑战和解密查询的数量。
We put forward a generalization of lossy trapdoor functions (LTFs). Namely, all-but-many lossy trapdoor functions (ABM-LTFs) are LTFs that are parametrized with tags. Each tag can either be injective or lossy, which leads to an invertible or a lossy function. The interesting property of ABM-LTFs is that it is possible to generate an arbitrary number of lossy tags by means of a special trapdoor, while it is not feasible to produce lossy tags without this trapdoor.Our definition and construction can be seen as generalizations of all-but-one LTFs (due to Peikert and Waters) and all-but-NLTFs (due to Hemenway et al.). However, to achieve ABM-LTFs (and thus a number of lossy tags which is not bounded by any polynomial), we have to employ some new tricks. Concretely, we give two constructions that use “disguised” variants of the Waters, resp. Boneh-Boyen signature schemes to make the generation of lossy tags hard without trapdoor. In a nutshell, lossy tags simply correspond to valid signatures. At the same time, tags are disguised (i.e., suitably blinded) to keep lossy tags indistinguishable from injective tags.ABM-LTFs are useful in settings in which there are a polynomial number of adversarial challenges (e.g., challenge ciphertexts). Specifically, building on work by Hemenway et al., we show that ABM-LTFs can be used to achieve selective opening security against chosen-ciphertext attacks. One of our ABM-LTF constructions thus yields the first SO-CCA secure encryption scheme with compact ciphertexts (group elements) whose efficiency does not depend on the number of challenges. Our second ABM-LTF construction yields an IND-CCA (and in fact SO-CCA) secure encryption scheme whose security reduction is independent of the number of challenges and decryption queries.