An Algebraic Framework for Pseudorandom Functions and Applications - - PowerPoint PPT Presentation
An Algebraic Framework for Pseudorandom Functions and Applications - - PowerPoint PPT Presentation
An Algebraic Framework for Pseudorandom Functions and Applications to Related-Key Security Michel Abdalla, Fabrice Benhamouda, Alain Passelgue Pseudorandom functions [GGM86] - efficiently computable function : -
Pseudorandom functions
- efficiently computable function ๐บ: ๐ฟ ร ๐ธ โ ๐
- indistinguishable from a random function ๐: ๐ธ โ ๐
๐บ
๐ โ ๐ฟ ๐ฆ ๐บ(๐, ๐ฆ)
๐
๐ฆ ๐(๐ฆ)
โ๐
[GGM86]
1/22
Number-theoretic PRF
๐๐: โค๐
๐ ร 0,1 ๐ โ ๐ฟ
DDH-based (Naor-Reingold) PRF
[NR97]
๐ , ๐ฆ ๐ ๐=1
๐
๐๐
๐ฆ๐
โฆ
2/22
๐๐: โค๐
๐ ร 0,1 ๐ โ ๐ฟ
DDH-based (Naor-Reingold) PRF
Number-theoretic PRF
๐ , ๐ฆ ๐=1
๐
๐๐
๐ฆ๐
โฆ
[NR97]
2/22
๐๐: โค๐
๐ ร 0,1 ๐ โ ๐ฟ
DDH-based (Naor-Reingold) PRF
Number-theoretic PRF
๐ , ๐ฆ ๐
๐ฆ(
๐) with ๐
๐ฆ ๐ 1, โฆ , ๐ ๐ = ๐=1 ๐
๐
๐ ๐ฆ๐
โฆ
[NR97]
2/22
๐๐: โค๐
๐ ร 0,1 ๐ โ ๐ฟ
DDH-based (Naor-Reingold) PRF
Number-theoretic PRF
๐ , ๐ฆ ๐
๐ฆ(
๐) with ๐
๐ฆ ๐ 1, โฆ , ๐ ๐ = ๐=1 ๐
๐
๐ ๐ฆ๐
โฆ fact 1: ๐
๐ฆ ๐ฆโ 0,1 ๐ linearly independent ๐-variate polynomials
fact 2:
- ther constructions with the same form (๐ถ๐๐, ๐๐, โฆ )
[NR97]
2/22
Main question
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ ๐
๐ฆ ๐ฆโ๐ธ linearly independent ๐-variate polynomials over โค๐
?
3/22
Main question
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ ๐
๐ฆ ๐ฆโ๐ธ linearly independent ๐-variate polynomials over โค๐
(standard assumption?)
?
3/22
Outline
- motivation for such an equivalence and proof
- applications to (RKA) PRF
- new algebraic framework for related-key security
4/22
Motivation 1
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials
5/22
Motivation 1
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials
toy example: ๐๐: ๐, ๐ฆ โ โค๐
๐ ร 0,1 ๐ โฆ ๐=1 ๐
๐๐
๐ฆ๐ โ ๐ฟ is a PRF
proof: { ๐=1
๐
๐
๐ ๐ฆ๐
๐ฆ โ 0,1 ๐ are linearly independent
5/22
Def: ฮฆ-RKA-PRF
- ฮฆ โ ๐บ๐ฃ๐(๐ฟ, ๐ฟ) a class of functions
- efficiently computable function ๐บ: ๐ฟ ร ๐ธ โ ๐
- indistinguishable from a random function ๐: ๐ฟ ร ๐ธ โ ๐
๐บ
๐ โ ๐ฟ ๐, ๐ฆ ๐บ(๐ ๐ , ๐ฆ)
๐
๐, ๐ฆ ๐(๐ ๐ , ๐ฆ)
โ๐
[BK03] ๐ โ ๐ฟ
Motivation 2
6/22
Def: ฮฆ-RKA-PRF
- ฮฆ โ ๐บ๐ฃ๐(๐ฟ, ๐ฟ) a class of functions
- efficiently computable function ๐บ: ๐ฟ ร ๐ธ โ ๐
- indistinguishable from a random function ๐: ๐ฟ ร ๐ธ โ ๐
๐บ
๐ โ ๐ฟ ๐, ๐ฆ ๐บ(๐ ๐ , ๐ฆ)
๐
๐, ๐ฆ ๐(๐ ๐ , ๐ฆ)
โ๐
[BK03] ๐ โ ๐ฟ
[BK03]: impossibility results for certain classes
Motivation 2
6/22
Def: ฮฆ-RKA-PRF
- ฮฆ โ ๐บ๐ฃ๐(๐ฟ, ๐ฟ) a class of functions
- efficiently computable function ๐บ: ๐ฟ ร ๐ธ โ ๐
- indistinguishable from a random function ๐: ๐ฟ ร ๐ธ โ ๐
๐บ
๐ โ ๐ฟ ๐, ๐ฆ ๐บ(๐ ๐ , ๐ฆ)
๐
๐, ๐ฆ ๐(๐ ๐ , ๐ฆ)
โ๐
[BK03] ๐ โ ๐ฟ
[BK03]: impossibility results for certain classes goal: ฮฆ-RKA-security for largest possible classes
Motivation 2
6/22
๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ฮฆ โ โค๐ ๐
1, โฆ , ๐ ๐ contains only ๐-variate polynomials
7/22
๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ฮฆ โ โค๐ ๐
1, โฆ , ๐ ๐ contains only ๐-variate polynomials
then ๐บ ๐ ๐ , ๐ฆ = ๐
๐ฆ ๐
๐ = ๐
๐ฆ โ ๐
๐
7/22
๐บ
๐ โ โค๐
๐
๐, ๐ฆ ๐
๐ฆ โ ๐
๐
๐
๐, ๐ฆ $
โ๐
๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ฮฆ โ โค๐ ๐
1, โฆ , ๐ ๐ contains only ๐-variate polynomials
then ๐บ ๐ ๐ , ๐ฆ = ๐
๐ฆ ๐
๐ = ๐
๐ฆ โ ๐
๐
๐ โ โค๐
๐
7/22
๐บ
๐ โ โค๐
๐
๐, ๐ฆ ๐
๐ฆ โ ๐
๐
๐
๐, ๐ฆ $
โ๐
๐
๐ฆ โ ๐ ๐ฆโ๐ธ ๐โฮฆ
- lin. ind. ๐-variate polynomials
๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ฮฆ โ โค๐ ๐
1, โฆ , ๐ ๐ contains only ๐-variate polynomials
then ๐บ ๐ ๐ , ๐ฆ = ๐
๐ฆ ๐
๐ = ๐
๐ฆ โ ๐
๐
๐ โ โค๐
๐
7/22
Summary of our (RKA) PRF results
๐พ ๐๐ โฆ ๐๐ + ๐๐ ๐๐ โฆ ๐๐ โ ๐๐ ๐๐ โฆ ๐ธ(๐๐) ๐๐ โฆ ๐๐(๐) ๐๐ โฆ ๐ธ(๐๐(๐)) [BC10] ๐๐โ (exp. time) ๐๐โ, ๐๐
? ? ?
[ABPP14] ๐๐โ ๐๐โ ๐๐โ
? ?
this paper ๐๐, ๐๐โ, ๐๐, ๐๐๐๐, โฆ ๐๐, ๐๐โ, ๐๐, ๐๐๐๐, โฆ ๐๐, ๐๐โ, ๐๐, ๐๐๐๐, โฆ ๐๐๐๐๐, ๐ถ๐๐ ๐๐๐๐๐
PRFs: simple proofs for ๐๐, ๐ถ๐๐, ๐๐, ๐๐๐๐ and their extensions
8/22
๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials over โค๐
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐
?
9/22
๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials over โค๐
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐
?
10/22
assume ๐
๐ฆ0 = ๐1๐ ๐ฆ1 + โฆ + ๐๐๐ ๐ฆ๐
๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials over โค๐
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐
?
10/22
assume ๐
๐ฆ0 = ๐1๐ ๐ฆ1 + โฆ + ๐๐๐ ๐ฆ๐
๐บ
๐ โ โค๐
๐
๐ฆ0, ๐ฆ1, โฆ , ๐ฆ๐ [๐
๐ฆ0(
๐)], โฆ , [๐
๐ฆ๐(
๐)]
๐
๐ฆ0, ๐ฆ1, โฆ , ๐ฆ๐ ๐ ๐ฆ0 , โฆ , ๐(๐ฆ๐)
โ๐
๐ ๐ฆ0 โ ๐ ๐ฆ1 ๐1 โ โฆ โ ๐ ๐ฆ๐
๐๐
๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials over โค๐
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ = ๐
๐ฆ1
๐
๐1 โ โฆ โ ๐ ๐ฆ๐
๐
๐๐
๐
๐ฆ0(
๐) = ๐1๐
๐ฆ1
๐ + โฆ + ๐๐๐
๐ฆ๐
๐
10/22
๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials over โค๐
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐
?
11/22
Real ๐ [๐( ๐)] Rand ๐
where the polynomials queried are lin. ind.
๐ โ โค๐
๐
๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials over โค๐
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐
$
?
11/22
Real ๐ [๐( ๐)] Rand ๐ $
โ๐
thm: linearly independent polynomial (lip) security where the polynomials queried are lin. ind.
๐ โ โค๐
๐
standard assumption
๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials over โค๐
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐
11/22
This talk
Real ๐ [๐( ๐)] Rand ๐ $
โ๐
thm: linearly independent polynomial (lip) security where the polynomials queried are
- lin. ind. + multilinear
๐ โ โค๐
๐
DDH
12/22
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
13/22
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1]
13/22
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1] [๐1] [1]
13/22
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1] [1] ๐2 [๐1] [๐1] ๐1๐2 [1]
13/22
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐1] [๐1] ๐1๐2 [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1]
13/22
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐1] [๐1] ๐1๐2 [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1]
13/22
๐
1๐3
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐1] [๐1] ๐1๐2 [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1]
13/22
๐
1๐3
๐ฆ1 = 1
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐1] [๐1] ๐1๐2 [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1]
13/22
๐
1๐3
๐ฆ1 = 1 ๐ฆ2 = 0
simple case:
- ๐ = 3
- only monomials queried: ๐ โ {๐
1 ๐ฆ1๐ 2 ๐ฆ2๐ 3 ๐ฆ3 | ๐ฆ โ 0,1 3}
๏ computation of ๐ ๐ as a path through a binary tree
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐1] [๐1] ๐1๐2 [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1]
13/22
๐
1๐3
๐ฆ1 = 1 ๐ฆ2 = 0 ๐ฆ3 = 1
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐1] [๐1] ๐1๐2 [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1]
13/22
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐ฝ] [๐ฝ] ๐ฝ๐2 [๐ฝ] [๐ฝ๐3] [๐ฝ๐2] [๐ฝ๐2๐3] [1]
13/22
[1] [1] ๐2 [1] [๐3] [๐2] [๐2๐3] [๐ฝ] [๐ฝ] ๐ฝ๐2 [๐ฝ] [๐ฝ๐3] [๐ฝ๐2] [๐ฝ๐2๐3] [1]
13/22
DDH assumption: 1 , ๐ , ๐ , ๐๐ โ๐ 1 , ๐ฝ , ๐พ , ๐ฟ
[1] ๐พ [1] [๐3] [๐พ] [๐พ๐3] [๐ฝ] ๐ฟ [๐ฝ] [๐ฝ๐3] [๐ฟ] [๐ฟ๐3] [1] [๐ฝ] [1]
DDH assumption: 1 , ๐ , ๐ , ๐๐ โ๐ 1 , ๐ฝ , ๐พ , ๐ฟ
13/22
[1] ๐พ [1] [๐] [๐พ] [๐] [๐ฝ] ๐ฟ [๐ฝ] [๐] [๐ฟ] [๐] [1] [๐ฝ] [1]
DDH assumption: 1 , ๐ , ๐ , ๐๐ โ๐ 1 , ๐ฝ , ๐พ , ๐ฟ
13/22
[1] [๐3] [๐2] [๐2๐3] [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1] [๐ฟ] [๐พ] [๐] [๐ฝ] [๐] [๐] [๐]
โ๐
DDH
general case: use these monomials to simulate any (multilinear) polynomial e.g.: ๐1 + 1 ๐2 + 1 ๐3 + 1 = ๐ฆโ 0,1 ๐ ๐1
๐ฆ1๐2 ๐ฆ2๐3 ๐ฆ3
= 1 + ๐1 + ๐2 + ๐3 + ๐1๐2 + ๐1๐3 + ๐2๐3 + ๐1๐2๐3
โ๐
1 + ๐ฝ + ๐พ + ๐ฟ + ๐ + ๐ + ๐ + ๐
DDH
14/22
[1] [๐3] [๐2] [๐2๐3] [๐1] [๐1๐3] [๐1๐2] [๐1๐2๐3] [1] [๐ฟ] [๐พ] [๐] [๐ฝ] [๐] [๐] [๐]
โ๐
DDH
general case: use these monomials to simulate any (multilinear) polynomial e.g.: ๐1 + 1 ๐2 + 1 ๐3 + 1 = ๐ฆโ 0,1 ๐ ๐1
๐ฆ1๐2 ๐ฆ2๐3 ๐ฆ3
= 1 + ๐1 + ๐2 + ๐3 + ๐1๐2 + ๐1๐3 + ๐2๐3 + ๐1๐2๐3
โ๐
1 + ๐ฝ + ๐พ + ๐ฟ + ๐ + ๐ + ๐ + ๐
DDH
no linear relation between polynomials ๐
1, โฆ , ๐ ๐
๏ ๐
1
๐ , โฆ , ๐
๐
๐ โ๐ $1, โฆ , $๐ problem: reduction time = ๐(2๐) (# of monomials) ๏subexponential hardness of DDH required in the paper: proof under standard DDH idea: lazy simulation
14/22
Real ๐ [๐( ๐)] Rand ๐ $
โ๐
where the polynomials queried are lin. ind. + multilinear (+ subexponential hardness of DDH)
๐ โ โค๐
๐
DDH
15/22
Real ๐ [๐( ๐ต)] Rand ๐ $
โ๐
where the polynomials queried are lin. ind. (+ natural assumptions for ๐ โฅ 2) polynomial-time proof
๐ต โ (โค๐
๐ร๐)
๐
Main result
MDDH
15/22
Applications
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials
16/22
Applications
PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ๐
๐ฆ ๐ฆโ๐ธ lin. ind. ๐-variate polynomials
ฮฆ โ โค๐ ๐
1, โฆ , ๐ ๐
ฮฆ-RKA-PRF ๐บ: ๐, ๐ฆ โ โค๐
๐ ร ๐ธ โฆ ๐ ๐ฆ
๐ โ ๐ฟ ๐
๐ฆ โ ๐ ๐ฆโ๐ธ ๐โฮฆ
- lin. ind. ๐-variate polynomials
16/22
condition: ๐
๐ฆ โ ๐ ๐ฆโ๐ธ ๐โฮฆ
- lin. ind. ๐-variate polynomials
this is a very strong condition!
17/22
condition: ๐
๐ฆ โ ๐ ๐ฆโ๐ธ ๐โฮฆ
- lin. ind. ๐-variate polynomials
this is a very strong condition! counter-example: ฮฆ = ฮฆ+, ๐๐ ๐ = ๐1 + ๐1, โฆ , ๐๐ + ๐๐ ๐๐: ๐, ๐ฆ โ โค๐
๐ ร 0,1 ๐ โฆ [ ๐=1 ๐
๐๐
๐ฆ๐]
17/22
condition: ๐
๐ฆ โ ๐ ๐ฆโ๐ธ ๐โฮฆ
- lin. ind. ๐-variate polynomials
this is a very strong condition! counter-example: ฮฆ = ฮฆ+, ๐๐ ๐ = ๐1 + ๐1, โฆ , ๐๐ + ๐๐ ๐๐: ๐, ๐ฆ โ โค๐
๐ ร 0,1 ๐ โฆ [ ๐=1 ๐
๐๐
๐ฆ๐]
attack against ๐๐ with 3 queries: ๐๐ ๐, 01 โฆ 0 = [๐2] ๐๐ ๐, 11 โฆ 0 = [๐1๐2] ๐๐ ๐(1,0,โฆ,0)( ๐), 110 โฆ 0 = ๐1 + 1 ๐2 = ๐1๐2 โ [๐2]
17/22
this case was addressed in [BC10] idea: it is secure if the adversary is unique-input solution: force the adversary to be unique-input
18/22
this case was addressed in [BC10] idea: it is secure if the adversary is unique-input solution: force the adversary to be unique-input intuition: construct a PRF ๐ป from ๐บ as ๐ฏ ๐, ๐ = ๐ฎ ๐, ๐ฐ ๐, ๐ where ๐ผ is a collision-resistant hash function โ if ๐ or ๐ฆ change, then so does ๐ผ( ๐, ๐ฆ)
18/22
Our new framework
instead of: ๐ป ๐, ๐ฆ = ๐บ ๐, ๐ผ ๐, ๐ฆ we use: ๐ป ๐, ๐ฆ = ๐บ ๐, ๐ผ ๐๐ , โฆ , [๐๐], ๐ฆ ๏ reduction to the lip security notion!
19/22
Proof idea
simulate:
- ๐1 , โฆ , [๐๐] by querying polynomials ๐
1, โฆ , ๐ ๐
- ๐ป
๐, ๐ฆ by querying ๐๐ผ ๐1 ,โฆ,[๐๐],๐ฆ ๐ป ๐, ๐ฆ = ๐๐ผ ๐ ,๐ฆ ๐ ๏ ๐ป ๐, ๐ฆ โ๐ $ ๐
1, โฆ , ๐ ๐ and polynomials ๐โ โ ๐ lin. ind. (for distinct โ)
20/22
Conclusion
- completely algebraic framework
- unifies most of the existing number-theoretic (RKA-)PRFs
- simplifies proofs of (related-key) security
- new constructions and security results
21/22
Real ๐ [๐( ๐ต)] Rand ๐ $
โ๐
๐ต โ (โค๐
๐ร๐)
๐
MDDH ๐พ ๐๐ โฆ ๐๐ + ๐๐ ๐๐ โฆ ๐๐ โ ๐๐ ๐๐ โฆ ๐ธ(๐๐) ๐๐ โฆ ๐๐(๐) ๐๐ โฆ ๐ธ(๐๐(๐)) [BC10] ๐๐โ (exp. time) ๐๐โ, ๐๐
? ? ?
[ABPP14] ๐๐โ ๐๐โ ๐๐โ
? ?
this paper ๐๐, ๐๐โ, ๐๐, ๐๐๐๐, โฆ ๐๐, ๐๐โ, ๐๐, ๐๐๐๐, โฆ ๐๐, ๐๐โ, ๐๐, ๐๐๐๐, โฆ ๐๐๐๐๐, ๐ถ๐๐ ๐๐๐๐๐
Thank you! Questions?
22/22