Concurrent Secure Computation with Optimal Query Complexity

Concurrent Secure Computation with Optimal Query Complexity
复制标题

DOI:
10.1007/978-3-662-48000-7_3
复制
发表时间:
2015-08
期刊:
--
影响因子:
--
通讯作者:
R. Canetti;Vipul Goyal;Abhishek Jain
R. Canetti;Vipul Goyal;Abhishek Jain
中科院分区:
其他
文献类型:
--
作者:
R. Canetti;Vipul Goyal;Abhishek Jain

文献摘要

被引文献

相似文献

多重理想查询(MIQ)模型[Goyal,Jain和Ostrovsky,Crypto'10]为并发安全计算提供了一个宽松的安全概念,其中允许模拟器在每个会话中多次查询理想函数(而不是标准定义中的一次)。该模型提供了一个定量的措施,在并发自组合下的安全退化,其中退化是衡量的理想查询的数量。然而,到目前为止,所有已知的MIQ-secure协议只保证在整个执行过程中每个会话的查询数量的overallaveragebound,从而允许对手可能完全妥协其选择的一些会话。此外,[Goyal and Jain,Eurocrypt'13]排除了模拟器每个会话只进行与对手无关的恒定数量的理想查询的协议。我们展示了第一个具有最坏情况每个会话保证的MIQ-secure协议。具体来说,我们展示了一个协议,用于匹配[GJ 13]界限的任何功能:模拟器在每个会话中只进行常数数量的理想查询。常数依赖于对手,但独立的安全parameter.As我们的主要结果的直接推论,我们得到了第一个密码认证密钥交换(PAKE)协议的完全并发,多个密码设置在标准模型中没有设置的假设。
The multiple ideal query (MIQ) model [Goyal, Jain, and Ostrovsky, Crypto’10] offers a relaxed notion of security for concurrent secure computation, where the simulator is allowed to query the ideal functionalitymultiple times per session(as opposed to just once in the standard definition). The model provides a quantitative measure for the degradation in security under concurrent self-composition, where the degradation is measured by the number of ideal queries. However, to date, all known MIQ-secure protocols guarantee only an overallaveragebound on the number of queries per session throughout the execution, thus allowing the adversary to potentially fully compromise some sessions of its choice. Furthermore, [Goyal and Jain, Eurocrypt’13] rule out protocols where the simulator makes only an adversary-independent constant number of ideal queries per session.We show the first MIQ-secure protocol with worst-case per-session guarantee. Specifically, we show a protocol for any functionality that matches the [GJ13] bound: The simulator makes only aconstantnumber of ideal queries ineverysession. The constant depends on the adversary but is independent of the security parameter.As an immediate corollary of our main result, we obtain the first password authenticated key exchange (PAKE) protocol for the fully concurrent, multiple password setting in the standard model with no set-up assumptions.