Randomized Half-Ideal Cipher on Groups with applications to UC (a)PAKE

Randomized Half-Ideal Cipher on Groups with applications to UC (a)PAKE
复制标题

DOI:
10.1007/978-3-031-30589-4_5
复制
发表时间:
2023
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Bruno Freitas Dos Santos;Yanqi Gu;Stanislaw Jarecki
Bruno Freitas Dos Santos;Yanqi Gu;Stanislaw Jarecki
中科院分区:
其他
文献类型:
--
作者:
Bruno Freitas Dos Santos;Yanqi Gu;Stanislaw Jarecki

文献摘要

相似文献

理想密码(Ideal Cipher,IC)是一种密码,其中每个密钥定义域上的随机排列。群上的理想密码有许多吸引人的应用,例如,用于密码验证密钥交换(PAKE)或非对称PAKE(aPAKE)的加密密钥交换(EKE)协议[,]。然而,用于组域上的IC的已知构造都具有缺点,包括来自定时信息的密钥泄漏,如果IC是8轮Feistel,则需要4次散列到组上的操作,以及将域限制为组的一半或使用可变时间编码[,]如果IC是通过从群到位串的(准)双射实现的,我们提出了一种IC松弛,称为(随机)半理想密码(HIC),我们表明,HIC的一个组可以实现修改的2轮Feistel(m2F),在1个哈希到组操作的成本,击败现有的IC结构的通用性和计算成本。HIC通过让部分密文是非随机的来削弱IC属性,但是我们通过表明EKE和aPAKE分别实现UC PAKE和UC aPAKE,即使它们使用HIC而不是IC,也可以将其用作IC的直接替代品。m2F构造也可以用作IC域扩展,因为m2F从RO不可微散列ontoD和IC on位字符串构造域D上的HIC,用于安全参数。这种扩展器的一个应用是使用用HIC和匿名的基于格的KEM实例化的EKE的模块化的基于格的UC PAKE。
An Ideal Cipher (IC) is a cipher where each key defines a random permutation on the domain. Ideal Cipher on a group has many attractive applications, e.g., theEncrypted Key Exchange(EKE) protocol for Password Authenticated Key Exchange (PAKE) , or asymmetric PAKE (aPAKE) [, ]. However, known constructions for IC on a group domain all have drawbacks, including key leakage from timing information , requiring 4 hash-onto-group operations if IC is an 8-round Feistel , and limiting the domain to half the group or using variable-time encoding [, ] if IC is implemented via (quasi-) bijections from groups to bitstrings .We propose an IC relaxation called a(Randomized) Half-Ideal Cipher(HIC), and we show that HIC on a group can be realized by amodified 2-round Feistel(m2F), at a cost of 1 hash-onto-group operation, which beats existing IC constructions in versatility and computational cost. HIC weakens IC properties by letting part of the ciphertext be non-random, but we exemplify that it can be used as a drop-in replacement for IC by showing that EKE and aPAKE of realize respectively UC PAKE and UC aPAKE even if they use HIC instead of IC. The m2F construction can also serve as IC domain extension, because m2F constructs HIC on domainDfrom an RO-indifferentiable hash ontoDand an IC on-bit strings, fora security parameter. One application of such extender is a modular lattice-based UC PAKE using EKE instantiated with HIC and anonymous lattice-based KEM.