Traceable PRFs: Full Collusion Resistance and Active Security

Traceable PRFs: Full Collusion Resistance and Active Security
复制标题

DOI:
10.1007/978-3-030-97121-2_16
复制
发表时间:
2021
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Sarasij Maitra;David J. Wu
Sarasij Maitra;David J. Wu
中科院分区:
其他
文献类型:
--
作者:
Sarasij Maitra;David J. Wu

文献摘要

相似文献

可追踪密码学的主要目标是防止密码功能的未经授权的重新分发。这样的方案提供了一种嵌入身份(即,"标记")在密码对象内(例如,加密方案中的解密密钥、签名方案中的签名密钥)。反过来,跟踪保证,确保任何“海盗设备”,成功地复制了底层的功能,可以成功地跟踪到一组用于建立设备的身份。在这项工作中,我们研究了可跟踪的伪随机函数(PRFs)。由于PRF是对称密码学的主力,可追踪的PRF对于增强具有强可追踪安全保证的对称密码原语是有用的。然而,可追踪的PRF的现有构造要么依赖于强概念,如不可混淆性混淆,要么满足弱安全保证,如单密钥安全性(即,在这项工作中,我们展示了如何使用指纹编码将单密钥可追踪的PRF升级为完全抗共谋可追踪的PRF,其中安全性与对手拥有多少密钥无关。我们还引入了一个更强的安全性概念,其中跟踪安全性甚至适用于具有Oracle访问跟踪算法的活动对手。结合已知的单密钥可追踪的PRF的构造,我们从标准格假设中获得了第一个完全抗共谋可追踪的PRF。我们的可追踪的PRF直接意味着新的基于格的秘密密钥叛徒跟踪计划,CCA安全的跟踪安全持有对主动的对手,可以访问跟踪预言。
The main goal of traceable cryptography is to protect against unauthorized redistribution of cryptographic functionalities. Such schemes provide a way to embed identities (i.e., a “mark”) within cryptographic objects (e.g., decryption keys in an encryption scheme, signing keys in a signature scheme). In turn, the tracing guarantee ensures that any “pirate device” that successfully replicates the underlying functionality can be successfully traced to the set of identities used to build the device.In this work, we study traceable pseudorandom functions (PRFs). As PRFs are the workhorses of symmetric cryptography, traceable PRFs are useful for augmenting symmetric cryptographic primitives with strong traceable security guarantees. However, existing constructions of traceable PRFs either rely on strong notions like indistinguishability obfuscation or satisfy weak security guarantees like single-key security (i.e., tracing only works against adversaries that possess asinglemarked key).In this work, we show how to use fingerprinting codes to upgrade a single-key traceable PRF into afully collusion resistanttraceable PRF, where security holds regardless of how many keys the adversary possesses. We additionally introduce a stronger notion of security where tracing security holds even againstactive adversariesthat have oracle access to the tracing algorithm. In conjunction with known constructions of single-key traceable PRFs, we obtain the first fully collusion resistant traceable PRF from standard lattice assumptions. Our traceable PRFs directly imply new lattice-based secret-key traitor tracing schemes that are CCA-secure and where tracing security holds against active adversaries that have access to the tracing oracle.