One Sample Ring-LWE with Rounding and its Application to Key Exchange
One Sample Ring-LWE with Rounding and its Application to Key Exchange
复制标题
一种带舍入环的样本环LWE及其在密钥交换中的应用
DOI:
10.1007/978-3-030-21568-2_16
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Yuntao Wang
中科院分区:
文献类型:
--
作者:
Jintai Ding;Xinwei Gao;Tsuyoshi Takagi;Yuntao Wang
In this paper, we introduce a new provably secure ephemeral-only RLWE+Rounding-based key exchange protocol and a proper approach to more accurately estimate the security level of the RLWE problem with only one sample. Since our scheme is an ephemeral-only key exchange, it generates only one RLWE sample from protocol execution. We carefully analyze how to estimate the practical security of the RLWE problem with only one sample, which we call the ONE-sample RLWE problem. Our approach is different from existing approaches that are based on estimation with multiple RLWE samples. Though our analysis is based on some recently developed techniques in Darmstadt, our type of practical security estimate was never done before and it produces security estimates substantial different from the estimates before based on multiple RLWE samples. We show that the new design improves the security and reduce the communication cost of the protocol simultaneously by using one RLWE+Rounding sample technique. We also present two parameter choices ensuringkey exchange failure probability which cover security of AES-128/192/256 with concrete security analysis and implementation. We believe that our construction is secure, simple, efficient and elegant with wide application prospects.