Improved Bound on the Local Leakage-resilience of Shamir’s Secret Sharing

Improved Bound on the Local Leakage-resilience of Shamir’s Secret Sharing
复制标题

DOI:
10.1109/isit50566.2022.9834695
复制
发表时间:
2022-06
期刊:
2022 IEEE International Symposium on Information Theory (ISIT)
影响因子:
--
通讯作者:
H. K. Maji;Hai H. Nguyen;Anat Paskin-Cherniavsky;Mingyuan Wang
H. K. Maji;Hai H. Nguyen;Anat Paskin-Cherniavsky;Mingyuan Wang
中科院分区:
其他
文献类型:
--
作者:
H. K. Maji;Hai H. Nguyen;Anat Paskin-Cherniavsky;Mingyuan Wang

文献摘要

被引文献

相似文献

侧渠攻击反复假设加密系统是黑匣子。 2018)激发了对秘密共享方案的当地泄漏弹性的研究Benhamouda等人(2018年加密货币)在安全计算中进行了秘密份额。 Benhamouda等人以前具有小部分重建阈值的弹性。 0.907次,Shamir的秘密共享方案足以抵抗每个秘密份额的局部泄漏。 2021)分别将此阈值分别降低到K/N⩾0.8675和K/N⩾0.85。这篇论文对这一研究贡献了这一贡献,并证明了K/N⩾ 0.78是足够的。我们的技术分析通过傅立叶分析进行,并准确估算此分析中产生的指数总和。
Side-channel attacks have repeatedly falsified the assumption that cryptosystems are black boxes. Leakage-resilient cryptography studies the robustness of cryptographic constructions when an unforeseen revelation of information occurs. In this context, recently, Benhamouda, Degwekar, Ishai, and Rabin (CRYPTO–2018) motivated the study of the local leakage resilience of secret-sharing schemes against an adversary who obtains independent leakage from each secret share.Motivated by applications in secure computation, Benhamouda et al. (CRYPTO–2018) initiated the study of the local leakage resilience of Shamir’s secret-sharing scheme, an essential primitive for nearly all threshold cryptography. The objective is to achieve local leakage resilience with as small a fractional reconstruction threshold as possible. Previously, Benhamouda et al. showed that the reconstruction threshold k being at least 0.907 times the number of parties n is sufficient for Shamir’s secretsharing scheme to be resilient against arbitrary single-bit local leakage from each secret share. After that, Maji et al. (CRYPTO–2021) and Benhamouda et al. (Journal of Cryptology–2021) independently lowered this threshold to k/n ⩾ 0.8675 and k/n ⩾0.85, respectively.This paper contributes to this line of research and proves that k/n ⩾ 0.78 is sufficient. Next, motivated by applications in GMW-style leakage-resilient secure computation, our work extends this bound to a more general adversary who corrupts some parties (obtaining their entire secret shares) and obtains leakage from the remaining honest parties’ secret shares.Our technical analysis proceeds by Fourier analysis and accurately estimates an exponential sum arising in this analysis.