Same Point Composable and Nonmalleable Obfuscated Point Functions

Same Point Composable and Nonmalleable Obfuscated Point Functions
复制标题

DOI:
10.1007/978-3-030-57878-7_7
复制
发表时间:
2020-10
期刊:
--
影响因子:
--
通讯作者:
Peter Fenteany;Benjamin Fuller
Peter Fenteany;Benjamin Fuller
中科院分区:
其他
文献类型:
--
作者:
Peter Fenteany;Benjamin Fuller

文献摘要

被引文献

相似文献

点混淆程序是一种混淆程序,它指示用户是否输入了以前存储的密码。数字储物柜更强大:如果用户输入之前存储的密码,就会输出密钥。实数或随机变换允许一个人从一个可组合的点混乱器(Canetti和Daldouk,Eurocrypt 2008)建立一个数字储物柜。理想情况下,这两个对象都是不可延展的,可以检测对手的篡改。Komargoski和Yogev(Eurocrypt,2018)在普通随机串(CRS)模型中添加了非交互的零知识知识证明,从而增加了不可延展性。我们证明了他们的证明中的一个引理是错误的,使得他们的构造的安全性不清楚。Bartusek,Ma和Zhandry(Crypto,2019)使用了类似的技术,并引入了另一个不可延展点函数;如果同一点被混淆两次,他们的混乱器是不安全的。因此,没有可组合和不可延展点函数来实例化实数或随机结构。我们的主要贡献是一个不可延展点混乱器,它可以与相同的点组合任意多项式次数(必须提前知道)。安全性依赖于Bartusek、Ma和Zhandry中使用的假设。作为第二个贡献,我们引入了密钥编码步骤来检测对密钥的篡改。这一步结合了不可延展性代码和种子相关的电容器。冷凝器的种子必须是公共的,并且不能被篡改,因此这可以在CRS模型中实现。密码分发可能取决于冷凝器的种子,只要它是有效的可采样的。这种构造是点混淆中的黑盒,对于可以表示为低次多项式的函数,保证了密码的不可延展性。密钥不可延展性继承自不可延展性代码阻止的函数类。
A point obfuscator is an obfuscated program that indicates if a user enters a previously stored password. A digital locker is stronger: outputting a key if a user enters a previously stored password. The real-or-random transform allows one to build a digital locker from a composable point obfuscator (Canetti and Dakdouk, Eurocrypt 2008).Ideally, both objects would be nonmalleable, detecting adversarial tampering. Appending a non-interactive zero knowledge proof of knowledge adds nonmalleability in the common random string (CRS) model.Komargodski and Yogev (Eurocrypt, 2018) built a nonmalleable point obfuscator without a CRS. We show a lemma in their proof is false, leaving security of their construction unclear. Bartusek, Ma, and Zhandry (Crypto, 2019) used similar techniques and introduced another nonmalleable point function; their obfuscator is not secure if the same point is obfuscated twice. Thus, there was no composable and nonmalleable point function to instantiate the real-or-random construction.Our primary contribution is a nonmalleable point obfuscator that can be composed any polynomial number of times with the same point (which must be known ahead of time). Security relies on the assumption used in Bartusek, Ma, and Zhandry. This construction enables a digital locker that is nonmalleable with respect to the input password.As a secondary contribution, we introduce a key encoding step to detect tampering on the key. This step combines nonmalleable codes and seed-dependent condensers. The seed for the condenser must be public and not tampered, so this can be achieved in the CRS model. The password distribution may depend on the condenser’s seed as long as it is efficiently sampleable. This construction is black box in the underlying point obfuscation.Nonmalleability for the password is ensured for functions that can be represented as low degree polynomials. Key nonmalleability is inherited from the class of functions prevented by the nonmalleable code.