Adversary-Dependent Lossy Trapdoor Function from Hardness of Factoring Semi-smooth RSA Subgroup Moduli

Adversary-Dependent Lossy Trapdoor Function from Hardness of Factoring Semi-smooth RSA Subgroup Moduli
复制标题

DOI:
10.1007/978-3-662-53008-5_1
复制
发表时间:
2016-08
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Takashi Yamakawa;Shota Yamada;Goichiro Hanaoka;N. Kunihiro
Takashi Yamakawa;Shota Yamada;Goichiro Hanaoka;N. Kunihiro
中科院分区:
其他
文献类型:
--
作者:
Takashi Yamakawa;Shota Yamada;Goichiro Hanaoka;N. Kunihiro

文献摘要

相似文献

由Peikert和沃茨(STOC'08)提出的有耗陷门函数(LTDFs)在密码学中具有许多应用。它们是基于各种假设构建的,其中包括二次剩余(QR)和决策复合剩余(DCR)假设,这是基于因子分解的决策假设。然而,没有已知的基于因子分解假设或其他因子分解相关搜索假设的LTDF构造。在本文中,我们首先定义了一个概念adversary-dependent有损陷门函数(ad-LTDFs),它是LTDFs的一个较弱的变体。基于Groth(TCC'05)提出的半光滑RSA子群(SS)模的特殊形式的RSA模的分解困难性,构造了一个ad-LTDF。此外,我们表明,广告LTDFs可以取代LTDFs在许多应用中。特别是,我们获得了第一个基于因子分解的确定性加密方案,满足Boldyreva等人定义的安全概念。(NIPPTO '08),而不依赖于决策假设。除了直接应用ad-LTDFs之外,基于因子分解假设w.r.t. SS模量
Lossy trapdoor functions (LTDFs), proposed by Peikert and Waters (STOC’08), are known to have a number of applications in cryptography. They have been constructed based on various assumptions, which include the quadratic residuosity (QR) and decisional composite residuosity (DCR) assumptions, which are factoring-baseddecisionassumptions. However, there is no known construction of an LTDF based on the factoring assumption or other factoring-related search assumptions. In this paper, we first define a notion ofadversary-dependent lossy trapdoor functions(ad-LTDFs) that is a weaker variant of LTDFs. Then we construct an ad-LTDF based on the hardness of factorizing RSA moduli of a special form called semi-smooth RSA subgroup (SS) moduli proposed by Groth (TCC’05). Moreover, we show that ad-LTDFs can replace LTDFs in many applications. Especially, we obtain the first factoring-based deterministic encryption scheme that satisfies the security notion defined by Boldyreva et al. (CRYPTO’08) without relying on a decision assumption. Besides direct applications of ad-LTDFs, by a similar technique, we construct a chosen ciphertext secure public key encryption scheme whose ciphertext overhead is the shortest among existing schemes based on the factoring assumption w.r.t. SS moduli.