Counterexamples to New Circular Security Assumptions Underlying iO

Counterexamples to New Circular Security Assumptions Underlying iO
复制标题

DOI:
10.1007/978-3-030-84245-1_23
复制
发表时间:
2021
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Samuel B. Hopkins;Aayush Jain;Huijia Lin
Samuel B. Hopkins;Aayush Jain;Huijia Lin
中科院分区:
其他
文献类型:
--
作者:
Samuel B. Hopkins;Aayush Jain;Huijia Lin

文献摘要

相似文献

我们研究了几个加强经典的循环安全假设,这些假设最近被引入了四个新的基于格的不可混淆性结构:布拉克尔斯基-德特灵-加尔格-马拉沃尔塔(Eurocrypt 2020),同性恋通行证(STOC 2021),布拉克尔斯基-德特灵-加尔格-马拉沃尔塔(Eprint 2020)和Wee-Wichs(Eprint 2020)。Gay-Pass提出的Gentry-Sahai-沃茨全同态加密方案和Wee-Wichs提出的同态伪随机LWE样本猜想。我们的工作表明,经典的循环安全的那种基础的unleveled全同态加密从加强版本的基础最近的iO constructions之间的分离,表明他们是不是(尚未)在同一foundations.Our反例利用灵活性,选择特定的实现电路,这是明确允许的Gay-Pass假设和未指定的Wee-Wichs假设。他们的不可否认的混淆方案仍然没有被打破。我们的工作表明,这些假设至少需要改进。特别是,通用泄漏弹性循环安全假设是微妙的,其安全性对所涉及的泄漏的具体结构是敏感的。
We study several strengthening of classical circular security assumptions which were recently introduced in four new lattice-based constructions of indistinguishability obfuscation: Brakerski-Döttling-Garg-Malavolta (Eurocrypt 2020), Gay-Pass (STOC 2021), Brakerski-Döttling-Garg-Malavolta (Eprint 2020) and Wee-Wichs (Eprint 2020).We provide explicit counterexamples to the 2-circular shielded randomness leakageassumption w.r.t. the Gentry-Sahai-Waters fully homomorphic encryption scheme proposed by Gay-Pass, and thehomomorphic pseudorandom LWE samplesconjecture proposed by Wee-Wichs. Our work suggests a separation between classical circular security of the kind underlying un-levelled fully-homomorphic encryption from the strengthened versions underlying recent iO constructions, showing that they are not (yet) on the same footing.Our counterexamples exploit the flexibility to choose specific implementations of circuits, which is explicitly allowed in the Gay-Pass assumption and unspecified in the Wee-Wichs assumption. Their indistinguishabilty obfuscation schemes are still unbroken. Our work shows that the assumptions, at least, need refinement. In particular, generic leakage-resilient circular security assumptions are delicate, and their security is sensitive to the specific structure of the leakages involved.