Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only Indifferentiability

Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only Indifferentiability
复制标题

DOI:
10.1007/978-3-030-45724-2_1
复制
发表时间:
2020-03
期刊:
Advances in Cryptology – EUROCRYPT 2020
影响因子:
--
通讯作者:
M. Bellare;Hannah Davis;Felix Günther
M. Bellare;Hannah Davis;Felix Günther
中科院分区:
其他
文献类型:
--
作者:
M. Bellare;Hannah Davis;Felix Günther

文献摘要

相似文献

随机预言机模型中的方案假设访问多个随机预言机(RO)是方便和常见的,将从单个RO构建它们的任务(我们称之为预言机克隆)留给实现。本文的第一部分是对KEM提交给NIST后量子密码标准化过程的Oracle克隆的案例研究。我们给一些提交的关键恢复攻击所产生的错误,在Oracle克隆,并找到其他提交使用Oracle克隆方法的有效性不明确。基于此,本文第二部分对甲骨文克隆进行了理论探讨。我们给出了一个定义,什么是“甲骨文克隆方法”,这意味着这样一个方法的“工作”,在一个框架中,我们称之为只读不可微性,经典不可微性的一个简单的变体,产生的安全性不仅用于单阶段的游戏,但也在多阶段的。我们形式化的域分离,并指定和研究了许多Oracle克隆方法,包括常见的域分离的,给出了一些一般性的结果来证明(证明只读不可微)某些类的方法。我们不仅能够验证许多未中断的NIST PQC KEM中使用的Oracle克隆方法,而且还能够指定和验证可能有用的Oracle克隆方法。
It is convenient and common for schemes in the random oracle model to assume access to multiple random oracles (ROs), leaving to implementations the task—we call it oracle cloning—of constructing them from a single RO. The first part of the paper is a case study of oracle cloning in KEM submissions to the NIST Post-Quantum Cryptography standardization process. We give key-recovery attacks on some submissions arising from mistakes in oracle cloning, and find other submissions using oracle cloning methods whose validity is unclear. Motivated by this, the second part of the paper gives a theoretical treatment of oracle cloning. We give a definition of what is an “oracle cloning method” and what it means for such a method to “work,” in a framework we call read-only indifferentiability, a simple variant of classical indifferentiability that yields security not only for usage in single-stage games but also in multi-stage ones. We formalize domain separation, and specify and study many oracle cloning methods, including common domain-separating ones, giving some general results to justify (prove read-only indifferentiability of) certain classes of methods. We are not only able to validate the oracle cloning methods used in many of the unbroken NIST PQC KEMs, but also able to specify and validate oracle cloning methods that may be useful beyond that.