Leakage Resilience from Program Obfuscation

Leakage Resilience from Program Obfuscation
复制标题

DOI:
10.1007/s00145-018-9286-z
复制
发表时间:
2019-07
影响因子:
3
通讯作者:
Dana Dachman-Soled;S. Dov Gordon;Feng-Hao Liu;Adam O'Neill;Hong-Sheng Zhou
Dana Dachman-Soled;S. Dov Gordon;Feng-Hao Liu;Adam O'Neill;Hong-Sheng Zhou
中科院分区:
计算机科学4区
文献类型:
--
作者:
Dana Dachman-Soled;S. Dov Gordon;Feng-Hao Liu;Adam O'Neill;Hong-Sheng Zhou

文献摘要

被引文献

相似文献

关于泄漏弹性密码学的文献包含提供不同安全级别的各种泄漏模型。在有界泄漏模型(Akavia等人- TCC 2009),假设在该方案的整个生命周期中,攻击者可能在秘密密钥上泄漏的比特数有一个固定的上限。或者,在连续泄漏模型中(Brakerski等人- FOCS 2010,Dodis等人- FOCS 2010),加密方案的生命周期被划分为“时间段”,在这些时间段之间更新方案的秘密密钥。此外,在其攻击中,对手可以在每个时间段内获得当前密钥的一定数量的泄漏。在连续泄漏模型中,一个具有挑战性的问题一直是提供安全againstleakage对密钥更新,即泄漏,这是一个功能,不仅是当前的秘密密钥,但也用于更新it. We的随机性提出了一个模块化的方法来克服这个问题的基础上程序混淆。也就是说,我们提出了一个编译器,该编译器将任何公钥加密或签名方案转换为连续泄漏弹性的轻微加强,我们称之为连续泄漏弹性,以在密钥更新时泄漏,假设可恢复性混淆(Barak et al.美国专利商标局,2001年,Garg等人,FOCS 2013)。在更强的混淆形式下,我们编译的方案所容忍的泄漏率基本上与起始方案一样好。我们的编译器是通过在密钥更新的泄漏问题和所谓的发送者可否认加密之间建立联系而得到的(Canetti et al.最近由Sahai和沃茨基于不可解释性混淆(STOC 2014)构建的。在有界泄漏模型下,基于Sahai和沃茨的公钥加密方案(STOC 2014),给出了一种从程序混淆中构造抗泄漏公钥加密的方法.特别是,我们实现了泄漏弹性公钥加密容忍泄漏的任何Lfromandone-way函数的Lbits。我们以此为基础,实现泄漏弹性公钥加密与最佳泄漏率基于更强形式的混淆和抗碰撞哈希函数。这样的泄漏率是不知道的,是可以实现的,在一个通用的方式,仅基于公共密钥加密。然后,我们开发其他技术来构建公钥加密,是(连续)持续泄漏弹性适当的假设下,我们认为是独立的利益。
The literature on leakage-resilient cryptography contains various leakage models that provide different levels of security. In the bounded leakage model (Akavia et al.—TCC 2009), it is assumed that there is a fixed upper boundLon the number of bits the attacker may leak on the secret key in the entire lifetime of the scheme. Alternatively, in the continual leakage model (Brakerski et al.—FOCS 2010, Dodis et al.—FOCS 2010), the lifetime of a cryptographic scheme is divided into “time periods” between which the scheme’s secret key is updated. Furthermore, in its attack the adversary is allowed to obtain some bounded amount of leakage on the current secret key during each time period. In the continual leakage model, a challenging problem has been to provide security againstleakage on key updates, that is, leakage that is a function of not only the current secret key but also the randomness used to update it. We propose a modular approach to overcome this problem based on program obfuscation. Namely, we present a compiler that transforms any public key encryption or signature scheme that achieves a slight strengthening of continual leakage resilience, which we callconsecutivecontinual leakage resilience, to one that is continual leakage resilient with leakage on key updates, assumingindistinguishability obfuscation(Barak et al.—CRYPTO 2001, Garg et al.—FOCS 2013). Under stronger forms of obfuscation, the leakage rate tolerated by our compiled scheme is essentially as good as that of the starting scheme. Our compiler is derived by making a connection between the problems of leakage on key updates and so-called sender-deniable encryption (Canetti et al.—CRYPTO 1997), which was recently constructed based on indistinguishability obfuscation by Sahai and Waters (STOC 2014). In the bounded leakage model, we give an approach to constructing leakage-resilient public key encryption from program obfuscation based on the public key encryption scheme of Sahai and Waters (STOC 2014). In particular, we achieve leakage-resilient public key encryption toleratingLbits of leakage for anyLfromand one-way functions. We build on this to achieve leakage-resilient public key encryption with optimal leakage rate ofbased on stronger forms of obfuscation and collision-resistant hash functions. Such a leakage rate is not known to be achievable in a generic way based on public key encryption alone. We then develop additional techniques to construct public key encryption that is (consecutive) continual leakage resilient under appropriate assumptions, which we believe is of independent interest.