Practical Implementation of Lattice-Based Program Obfuscators for Point Functions

Practical Implementation of Lattice-Based Program Obfuscators for Point Functions
复制标题

DOI:
10.1109/hpcs.2017.115
复制
发表时间:
2017-07
期刊:
2017 International Conference on High Performance Computing & Simulation (HPCS)
影响因子:
--
通讯作者:
L. Bahler;G. D. Crescenzo;Y. Polyakov;Kurt Rohloff;David Cousins
L. Bahler;G. D. Crescenzo;Y. Polyakov;Kurt Rohloff;David Cousins
中科院分区:
其他
文献类型:
--
作者:
L. Bahler;G. D. Crescenzo;Y. Polyakov;Kurt Rohloff;David Cousins

文献摘要

被引文献

相似文献

基于格的密码学最近产生了几个时间有效的密码系统,这些密码系统在量子计算机不知道更容易解决的假设下是可证明安全的。一个有趣的研究方向是提高其存储复杂性,因为目前的解决方案在这方面还远远不够实用。在本文中,我们证明了基于格理论的点函数的程序混淆器是时间有效的,存储有效的,并且在基于格的密码学中通常研究的假设的研究修改下可证明是安全的(即,LWE和LWR假设)。点函数混淆器最近被证明是在密码学中常用的硬度假设下可证明的程序混淆器的第一个例子。点函数可以看作是如果输入值等于程序中存储的秘密值则返回1,否则返回0的函数。由于我们的设计和编码优化,值得注意的实现结果是:(a)基于修改的LWR假设的点函数混淆器,运行时间为0.01 s,存储小于100 B,以及(B)基于修改的LWE假设的点函数混淆器,运行时间为0.2 s,存储小于35 KB,两者都使用商品计算资源。
Lattice-based cryptography has recently produced several time-efficient cryptosystems that are provably secure under assumptions that are not known to be more easily solvable by quantum computers. An interesting research direction is improving their storage complexity, as current solutions are far from practical with respect to this metric. In this paper we show that program obfuscators for point functions based on lattice theory which are time-efficient, storage-efficient, and provably secure under studied modifications of assumptions commonly studied in lattice-based cryptography (i.e., LWE and LWR assumptions). Point function obfuscators have recently been shown to be the first examples of program obfuscators provable under hardness assumptions commonly used in cryptography. Point functions can be seen as functions that return 1 if the input value is equal to a secret value stored in the program, and 0 otherwise. Notable implementation results due to our design and coding optimizations are: (a) a point function obfuscator based on a modified LWR assumption with running time 0.01s and storage less than 100B, and (b) a point function obfuscator based on modified LWE assumption with running time 0.2s and storage less than 35KB, both using commodity computing resources.