Nonmalleable Digital Lockers and Robust Fuzzy Extractors in the Plain Model

Nonmalleable Digital Lockers and Robust Fuzzy Extractors in the Plain Model
复制标题

DOI:
10.1007/978-3-031-22972-5_13
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Daniel Apon;Chloé Cachet;Benjamin Fuller;Peter Hall;Feng-Hao Liu
Daniel Apon;Chloé Cachet;Benjamin Fuller;Peter Hall;Feng-Hao Liu
中科院分区:
其他
文献类型:
--
作者:
Daniel Apon;Chloé Cachet;Benjamin Fuller;Peter Hall;Feng-Hao Liu

文献摘要

相似文献

我们在 1)不可延展的数字储物柜(Canetti 和 Varia,TCC 2009)和 2)稳健的模糊提取器(Boyen 等人,Eurocrypt 2005)的简单模型中给出了第一个构造,它们保护熵低于其长度 1/2 的源。以前,我们只知道这两种原语的构造是假设随机预言或公共参考字符串 (CRS)。在此过程中,我们定义了一种新的原语,称为不可延展点函数与关联数据的混淆。相关数据是公开的,但不会被篡改。我们使用相同的范例将其扩展到数字储物柜。我们的构造通过将 CRS 放入相关数据并使用适当的非交互式零知识证明来实现输出点的不可延展性。可以防止输入点对低次多项式的篡改以及对输出点和相关数据的任何篡改。我们的构造实现了虚拟黑匣子安全性。然后,这些构造用于创建强大的模糊提取器,可以支持简单模型中的低熵源。通过使用综合症安全草图的几何结构(Dodis 等人,SIAM 计算杂志 2008),对手的篡改函数始终可以表示为低次多项式;因此,由构造的不可延展的物体提供的保护就足够了。
We give the first constructions in the plain model of 1) nonmalleable digital lockers (Canetti and Varia, TCC 2009) and 2) robust fuzzy extractors (Boyen et al., Eurocrypt 2005) that secure sources with entropy below 1/2 of their length. Constructions were previously only known for both primitives assuming random oracles or a common reference string (CRS).Along the way, we define a new primitive called a nonmalleable point function obfuscation with associated data. The associated data is public but protected from all tampering. We use the same paradigm to then extend this to digital lockers. Our constructions achieve nonmalleability over the output point by placing a CRS into the associated data and using an appropriate non-interactive zero-knowledge proof. Tampering is protected against the input point over low-degree polynomials and over any tampering to the output point and associated data. Our constructions achieve virtual black box security.These constructions are then used to create robust fuzzy extractors that can support low-entropy sources in the plain model. By using the geometric structure of a syndrome secure sketch (Dodis et al., SIAM Journal on Computing 2008), the adversary’s tampering function can always be expressed as a low-degree polynomial; thus, the protection provided by the constructed nonmalleable objects suffices.