A Fast and Simple Partially Oblivious PRF, with Applications

A Fast and Simple Partially Oblivious PRF, with Applications
复制标题

DOI:
10.1007/978-3-031-07085-3_23
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Nirvan Tyagi;S. Celi;Thomas Ristenpart;N. Sullivan;Stefano Tessaro;Christopher A. Wood
Nirvan Tyagi;S. Celi;Thomas Ristenpart;N. Sullivan;Stefano Tessaro;Christopher A. Wood
中科院分区:
其他
文献类型:
--
作者:
Nirvan Tyagi;S. Celi;Thomas Ristenpart;N. Sullivan;Stefano Tessaro;Christopher A. Wood

文献摘要

相似文献

我们构建了不依赖于双线性对的部分无关伪随机函数(POPRF)的第一个构造。我们的构建可以看作是将Jarecki, Kiayias和Krawczyk的2HashDH PRF元素与Dodis-Yampolskiy PRF相结合。通过简化到一个新的多间隙强Diffie-Hellman反演假设,分析了POPRF在随机oracle模型中的安全性。最重要的技术挑战是建立对新假设的信心,这需要新的证明技术,使我们能够证明它的硬度是由代数群模型中的q- dl假设隐含的。我们的新结构与当前标准跟踪的OPRF 2HashDH协议一样快,但提供了在各种应用程序中有用的新程度的灵活性。我们展示了如何使用poprf来防止针对隐私通行证的令牌囤积攻击,降低OPAQUE密码身份验证密钥交换协议中的密钥管理复杂性,并确保密码泄露警报服务的更强安全性。
We build the first construction of a partially oblivious pseudorandom function (POPRF) that does not rely on bilinear pairings. Our construction can be viewed as combining elements of the 2HashDH OPRF of Jarecki, Kiayias, and Krawczyk with the Dodis-Yampolskiy PRF. We analyze our POPRF’s security in the random oracle model via reduction to a new one-more gap strong Diffie-Hellman inversion assumption. The most significant technical challenge is establishing confidence in the new assumption, which requires new proof techniques that enable us to show that its hardness is implied by theq-DL assumption in the algebraic group model.Our new construction is as fast as the current, standards-track OPRF 2HashDH protocol, yet provides a new degree of flexibility useful in a variety of applications. We show how POPRFs can be used to prevent token hoarding attacks against Privacy Pass, reduce key management complexity in the OPAQUE password authenticated key exchange protocol, and ensure stronger security for password breach alerting services.