UC-Commitment Schemes with Phase-Adaptive Security from Trapdoor Functions

UC-Commitment Schemes with Phase-Adaptive Security from Trapdoor Functions
复制标题

具有来自 Trapdoor 功能的阶段自适应安全性的 UC 承诺方案

DOI:
--
复制
发表时间:
2019
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
P. Mateus
P. Mateus
中科院分区:
--
文献类型:
--
作者:
P. Branco;Manuel Goulão;P. Mateus

文献摘要

被引文献

相似文献

我们提出了一个在Canetti的全局随机Oracle模型中完美隐藏UC-Commitment方案的通用框架。(CCS 14)。我们构造的主要组成部分是一个称为采样范围陷阱门函数的新颖原语,也就是说,当给定其上域和相应的陷阱门的均匀选择元素时,有不可忽略的概率找到预像。为了展示框架的多功能性,我们给出了基于分解、基于代码和基于网格的硬度假设的具体实例。我们的构造产生了第一个基于格的UCCommitment方案(不是通过通用转换构建的,例如通过遗忘传输),并实现了我们所谓的相位自适应安全性,这是我们引入的一种比静态安全性更强的新型安全概念。实现UC-Commitment方案的自适应安全性是非常重要的,通常是以效率为代价的。相位自适应安全性介于自适应安全性和静态安全性之间,可能具有独立的兴趣。在此模型中,攻击者可以在协议的开始阶段或在协议的提交和打开阶段之间破坏,但不会在执行期间破坏。这个新模型的动机是这样一个事实:在实践中,各方更有可能在协议的各个阶段之间(相对较长的一段时间可能会过去)被破坏,而不是在执行期间。
We propose a generic framework for perfectly hiding UC-Commitment schemes in the Global Random Oracle model of Canetti el at. (CCS 14). The main building block of our construction is a novel primitive called Sampleable-Range Trapdoor Function, that is, a trapdoor function for which there is a non-negligible probability of finding preimages when given a uniformly chosen element of its codomain and the corresponding trapdoor. To show the versatility of the framework, we give concrete instantiations based on factoring, code-based, and lattice-based hardness assumptions. Our construction yields the first lattice-based UCCommitment scheme (not constructed via generic transformations, such as via Oblivious Transfer), and achieves what we call phase-adaptive security, a novel security notion we introduce which is stronger than static security. Achieving adaptive security for UC-Commitment schemes is non-trivial and, usually, comes at the price of efficiency. Phase-adaptive security stands between adaptive and static security, and may be of independent interest. In this model, adversaries can corrupt at the beginning or between the commitment and opening phases of the protocol, but not during their execution. This new model is motivated by the fact that, in practice, it is more likely that parties are corrupted between phases of the protocol (where a relatively long period may elapse) than during their execution.