An Algebraic Framework for Pseudorandom Functions and Applications - - PowerPoint PPT Presentation

โ–ถ
an algebraic framework for
SMART_READER_LITE
LIVE PREVIEW

An Algebraic Framework for Pseudorandom Functions and Applications - - PowerPoint PPT Presentation

An Algebraic Framework for Pseudorandom Functions and Applications to Related-Key Security Michel Abdalla, Fabrice Benhamouda, Alain Passelgue Pseudorandom functions [GGM86] - efficiently computable function : -


slide-1
SLIDE 1

Michel Abdalla, Fabrice Benhamouda, Alain Passelรจgue

An Algebraic Framework for Pseudorandom Functions and Applications to Related-Key Security

slide-2
SLIDE 2

Pseudorandom functions

  • efficiently computable function ๐บ: ๐ฟ ร— ๐ธ โ†’ ๐‘†
  • indistinguishable from a random function ๐‘”: ๐ธ โ†’ ๐‘†

๐บ

๐‘ โˆˆ ๐ฟ ๐‘ฆ ๐บ(๐‘, ๐‘ฆ)

๐‘”

๐‘ฆ ๐‘”(๐‘ฆ)

โ‰ˆ๐‘‘

[GGM86]

1/22

slide-3
SLIDE 3

Number-theoretic PRF

๐‘‚๐‘†: โ„ค๐‘ž

๐‘œ ร— 0,1 ๐‘œ โ†’ ๐”ฟ

DDH-based (Naor-Reingold) PRF

[NR97]

๐‘ , ๐‘ฆ ๐‘• ๐‘—=1

๐‘œ

๐‘๐‘—

๐‘ฆ๐‘—

โ†ฆ

2/22

slide-4
SLIDE 4

๐‘‚๐‘†: โ„ค๐‘ž

๐‘œ ร— 0,1 ๐‘œ โ†’ ๐”ฟ

DDH-based (Naor-Reingold) PRF

Number-theoretic PRF

๐‘ , ๐‘ฆ ๐‘—=1

๐‘œ

๐‘๐‘—

๐‘ฆ๐‘—

โ†ฆ

[NR97]

2/22

slide-5
SLIDE 5

๐‘‚๐‘†: โ„ค๐‘ž

๐‘œ ร— 0,1 ๐‘œ โ†’ ๐”ฟ

DDH-based (Naor-Reingold) PRF

Number-theoretic PRF

๐‘ , ๐‘ฆ ๐‘„

๐‘ฆ(

๐‘) with ๐‘„

๐‘ฆ ๐‘ˆ 1, โ€ฆ , ๐‘ˆ ๐‘œ = ๐‘—=1 ๐‘œ

๐‘ˆ

๐‘— ๐‘ฆ๐‘—

โ†ฆ

[NR97]

2/22

slide-6
SLIDE 6

๐‘‚๐‘†: โ„ค๐‘ž

๐‘œ ร— 0,1 ๐‘œ โ†’ ๐”ฟ

DDH-based (Naor-Reingold) PRF

Number-theoretic PRF

๐‘ , ๐‘ฆ ๐‘„

๐‘ฆ(

๐‘) with ๐‘„

๐‘ฆ ๐‘ˆ 1, โ€ฆ , ๐‘ˆ ๐‘œ = ๐‘—=1 ๐‘œ

๐‘ˆ

๐‘— ๐‘ฆ๐‘—

โ†ฆ fact 1: ๐‘„

๐‘ฆ ๐‘ฆโˆˆ 0,1 ๐‘œ linearly independent ๐‘œ-variate polynomials

fact 2:

  • ther constructions with the same form (๐ถ๐‘๐‘†, ๐‘€๐‘‹, โ€ฆ )

[NR97]

2/22

slide-7
SLIDE 7

Main question

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ ๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ linearly independent ๐‘œ-variate polynomials over โ„ค๐‘ž

?

3/22

slide-8
SLIDE 8

Main question

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ ๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ linearly independent ๐‘œ-variate polynomials over โ„ค๐‘ž

(standard assumption?)

?

3/22

slide-9
SLIDE 9

Outline

  • motivation for such an equivalence and proof
  • applications to (RKA) PRF
  • new algebraic framework for related-key security

4/22

slide-10
SLIDE 10

Motivation 1

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials

5/22

slide-11
SLIDE 11

Motivation 1

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials

toy example: ๐‘‚๐‘†: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— 0,1 ๐‘œ โ†ฆ ๐‘—=1 ๐‘œ

๐‘๐‘—

๐‘ฆ๐‘— โˆˆ ๐”ฟ is a PRF

proof: { ๐‘—=1

๐‘œ

๐‘ˆ

๐‘— ๐‘ฆ๐‘—

๐‘ฆ โˆˆ 0,1 ๐‘œ are linearly independent

5/22

slide-12
SLIDE 12

Def: ฮฆ-RKA-PRF

  • ฮฆ โІ ๐บ๐‘ฃ๐‘œ(๐ฟ, ๐ฟ) a class of functions
  • efficiently computable function ๐บ: ๐ฟ ร— ๐ธ โ†’ ๐‘†
  • indistinguishable from a random function ๐‘”: ๐ฟ ร— ๐ธ โ†’ ๐‘†

๐บ

๐‘ โˆˆ ๐ฟ ๐”, ๐‘ฆ ๐บ(๐” ๐’ƒ , ๐‘ฆ)

๐‘”

๐”, ๐‘ฆ ๐‘”(๐” ๐’ƒ , ๐‘ฆ)

โ‰ˆ๐‘‘

[BK03] ๐‘ โˆˆ ๐ฟ

Motivation 2

6/22

slide-13
SLIDE 13

Def: ฮฆ-RKA-PRF

  • ฮฆ โІ ๐บ๐‘ฃ๐‘œ(๐ฟ, ๐ฟ) a class of functions
  • efficiently computable function ๐บ: ๐ฟ ร— ๐ธ โ†’ ๐‘†
  • indistinguishable from a random function ๐‘”: ๐ฟ ร— ๐ธ โ†’ ๐‘†

๐บ

๐‘ โˆˆ ๐ฟ ๐”, ๐‘ฆ ๐บ(๐” ๐’ƒ , ๐‘ฆ)

๐‘”

๐”, ๐‘ฆ ๐‘”(๐” ๐’ƒ , ๐‘ฆ)

โ‰ˆ๐‘‘

[BK03] ๐‘ โˆˆ ๐ฟ

[BK03]: impossibility results for certain classes

Motivation 2

6/22

slide-14
SLIDE 14

Def: ฮฆ-RKA-PRF

  • ฮฆ โІ ๐บ๐‘ฃ๐‘œ(๐ฟ, ๐ฟ) a class of functions
  • efficiently computable function ๐บ: ๐ฟ ร— ๐ธ โ†’ ๐‘†
  • indistinguishable from a random function ๐‘”: ๐ฟ ร— ๐ธ โ†’ ๐‘†

๐บ

๐‘ โˆˆ ๐ฟ ๐”, ๐‘ฆ ๐บ(๐” ๐’ƒ , ๐‘ฆ)

๐‘”

๐”, ๐‘ฆ ๐‘”(๐” ๐’ƒ , ๐‘ฆ)

โ‰ˆ๐‘‘

[BK03] ๐‘ โˆˆ ๐ฟ

[BK03]: impossibility results for certain classes goal: ฮฆ-RKA-security for largest possible classes

Motivation 2

6/22

slide-15
SLIDE 15

๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ฮฆ โІ โ„ค๐‘ž ๐‘ˆ

1, โ€ฆ , ๐‘ˆ ๐‘œ contains only ๐‘œ-variate polynomials

7/22

slide-16
SLIDE 16

๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ฮฆ โІ โ„ค๐‘ž ๐‘ˆ

1, โ€ฆ , ๐‘ˆ ๐‘œ contains only ๐‘œ-variate polynomials

then ๐บ ๐œš ๐‘ , ๐‘ฆ = ๐‘„

๐‘ฆ ๐œš

๐‘ = ๐‘„

๐‘ฆ โˆ˜ ๐œš

๐‘

7/22

slide-17
SLIDE 17

๐บ

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

๐œš, ๐‘ฆ ๐‘„

๐‘ฆ โˆ˜ ๐œš

๐‘

๐‘”

๐œš, ๐‘ฆ $

โ‰ˆ๐‘‘

๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ฮฆ โІ โ„ค๐‘ž ๐‘ˆ

1, โ€ฆ , ๐‘ˆ ๐‘œ contains only ๐‘œ-variate polynomials

then ๐บ ๐œš ๐‘ , ๐‘ฆ = ๐‘„

๐‘ฆ ๐œš

๐‘ = ๐‘„

๐‘ฆ โˆ˜ ๐œš

๐‘

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

7/22

slide-18
SLIDE 18

๐บ

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

๐œš, ๐‘ฆ ๐‘„

๐‘ฆ โˆ˜ ๐œš

๐‘

๐‘”

๐œš, ๐‘ฆ $

โ‰ˆ๐‘‘

๐‘„

๐‘ฆ โˆ˜ ๐œš ๐‘ฆโˆˆ๐ธ ๐œšโˆˆฮฆ

  • lin. ind. ๐‘œ-variate polynomials

๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ฮฆ โІ โ„ค๐‘ž ๐‘ˆ

1, โ€ฆ , ๐‘ˆ ๐‘œ contains only ๐‘œ-variate polynomials

then ๐บ ๐œš ๐‘ , ๐‘ฆ = ๐‘„

๐‘ฆ ๐œš

๐‘ = ๐‘„

๐‘ฆ โˆ˜ ๐œš

๐‘

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

7/22

slide-19
SLIDE 19

Summary of our (RKA) PRF results

๐šพ ๐’ƒ๐’‹ โ†ฆ ๐’ƒ๐’‹ + ๐’„๐’‹ ๐’ƒ๐’‹ โ†ฆ ๐’ƒ๐’‹ โˆ— ๐’„๐’‹ ๐’ƒ๐’‹ โ†ฆ ๐‘ธ(๐’ƒ๐’‹) ๐’ƒ๐’‹ โ†ฆ ๐’ƒ๐‰(๐’‹) ๐’ƒ๐’‹ โ†ฆ ๐‘ธ(๐’ƒ๐‰(๐’‹)) [BC10] ๐‘‚๐‘†โˆ— (exp. time) ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹

? ? ?

[ABPP14] ๐‘‚๐‘†โˆ— ๐‘‚๐‘†โˆ— ๐‘‚๐‘†โˆ—

? ?

this paper ๐‘‚๐‘†, ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹, ๐‘™๐‘€๐‘—๐‘œ, โ€ฆ ๐‘‚๐‘†, ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹, ๐‘™๐‘€๐‘—๐‘œ, โ€ฆ ๐‘‚๐‘†, ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹, ๐‘™๐‘€๐‘—๐‘œ, โ€ฆ ๐‘‚๐‘†๐‘š๐‘—๐‘œ, ๐ถ๐‘๐‘† ๐‘‚๐‘†๐‘š๐‘—๐‘œ

PRFs: simple proofs for ๐‘‚๐‘†, ๐ถ๐‘๐‘†, ๐‘€๐‘‹, ๐‘™๐‘€๐‘—๐‘œ and their extensions

8/22

slide-20
SLIDE 20

๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials over โ„ค๐‘ž

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘

?

9/22

slide-21
SLIDE 21

๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials over โ„ค๐‘ž

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘

?

10/22

slide-22
SLIDE 22

assume ๐‘„

๐‘ฆ0 = ๐œ‡1๐‘„ ๐‘ฆ1 + โ€ฆ + ๐œ‡๐‘Ÿ๐‘„ ๐‘ฆ๐‘Ÿ

๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials over โ„ค๐‘ž

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘

?

10/22

slide-23
SLIDE 23

assume ๐‘„

๐‘ฆ0 = ๐œ‡1๐‘„ ๐‘ฆ1 + โ€ฆ + ๐œ‡๐‘Ÿ๐‘„ ๐‘ฆ๐‘Ÿ

๐บ

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

๐‘ฆ0, ๐‘ฆ1, โ€ฆ , ๐‘ฆ๐‘Ÿ [๐‘„

๐‘ฆ0(

๐‘)], โ€ฆ , [๐‘„

๐‘ฆ๐‘Ÿ(

๐‘)]

๐‘”

๐‘ฆ0, ๐‘ฆ1, โ€ฆ , ๐‘ฆ๐‘Ÿ ๐‘” ๐‘ฆ0 , โ€ฆ , ๐‘”(๐‘ฆ๐‘Ÿ)

โ‰‰๐‘‘

๐‘” ๐‘ฆ0 โ‰  ๐‘” ๐‘ฆ1 ๐œ‡1 โ‹… โ€ฆ โ‹… ๐‘” ๐‘ฆ๐‘Ÿ

๐œ‡๐‘Ÿ

๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials over โ„ค๐‘ž

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ = ๐‘„

๐‘ฆ1

๐‘

๐œ‡1 โ‹… โ€ฆ โ‹… ๐‘„ ๐‘ฆ๐‘Ÿ

๐‘

๐œ‡๐‘Ÿ

๐‘„

๐‘ฆ0(

๐‘) = ๐œ‡1๐‘„

๐‘ฆ1

๐‘ + โ€ฆ + ๐œ‡๐‘Ÿ๐‘„

๐‘ฆ๐‘Ÿ

๐‘

10/22

slide-24
SLIDE 24

๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials over โ„ค๐‘ž

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘

?

11/22

slide-25
SLIDE 25

Real ๐‘„ [๐‘„( ๐‘)] Rand ๐‘„

where the polynomials queried are lin. ind.

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials over โ„ค๐‘ž

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘

$

?

11/22

slide-26
SLIDE 26

Real ๐‘„ [๐‘„( ๐‘)] Rand ๐‘„ $

โ‰ˆ๐‘‘

thm: linearly independent polynomial (lip) security where the polynomials queried are lin. ind.

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

standard assumption

๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials over โ„ค๐‘ž

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘

11/22

slide-27
SLIDE 27

This talk

Real ๐‘„ [๐‘„( ๐‘)] Rand ๐‘„ $

โ‰ˆ๐‘‘

thm: linearly independent polynomial (lip) security where the polynomials queried are

  • lin. ind. + multilinear

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

DDH

12/22

slide-28
SLIDE 28

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

13/22

slide-29
SLIDE 29

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1]

13/22

slide-30
SLIDE 30

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1] [๐‘1] [1]

13/22

slide-31
SLIDE 31

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1] [1] ๐‘2 [๐‘1] [๐‘1] ๐‘1๐‘2 [1]

13/22

slide-32
SLIDE 32

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1] ๐‘1๐‘2 [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1]

13/22

slide-33
SLIDE 33

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1] ๐‘1๐‘2 [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1]

13/22

๐‘ˆ

1๐‘ˆ3

slide-34
SLIDE 34

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1] ๐‘1๐‘2 [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1]

13/22

๐‘ˆ

1๐‘ˆ3

๐‘ฆ1 = 1

slide-35
SLIDE 35

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1] ๐‘1๐‘2 [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1]

13/22

๐‘ˆ

1๐‘ˆ3

๐‘ฆ1 = 1 ๐‘ฆ2 = 0

slide-36
SLIDE 36

simple case:

  • ๐‘œ = 3
  • only monomials queried: ๐‘„ โˆˆ {๐‘ˆ

1 ๐‘ฆ1๐‘ˆ 2 ๐‘ฆ2๐‘ˆ 3 ๐‘ฆ3 | ๐‘ฆ โˆˆ 0,1 3}

๏ƒž computation of ๐‘„ ๐‘ as a path through a binary tree

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1] ๐‘1๐‘2 [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1]

13/22

๐‘ˆ

1๐‘ˆ3

๐‘ฆ1 = 1 ๐‘ฆ2 = 0 ๐‘ฆ3 = 1

slide-37
SLIDE 37

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1] ๐‘1๐‘2 [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1]

13/22

slide-38
SLIDE 38

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐›ฝ] [๐›ฝ] ๐›ฝ๐‘2 [๐›ฝ] [๐›ฝ๐‘3] [๐›ฝ๐‘2] [๐›ฝ๐‘2๐‘3] [1]

13/22

slide-39
SLIDE 39

[1] [1] ๐‘2 [1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐›ฝ] [๐›ฝ] ๐›ฝ๐‘2 [๐›ฝ] [๐›ฝ๐‘3] [๐›ฝ๐‘2] [๐›ฝ๐‘2๐‘3] [1]

13/22

DDH assumption: 1 , ๐‘ , ๐‘ , ๐‘๐‘ โ‰ˆ๐‘‘ 1 , ๐›ฝ , ๐›พ , ๐›ฟ

slide-40
SLIDE 40

[1] ๐›พ [1] [๐‘3] [๐›พ] [๐›พ๐‘3] [๐›ฝ] ๐›ฟ [๐›ฝ] [๐›ฝ๐‘3] [๐›ฟ] [๐›ฟ๐‘3] [1] [๐›ฝ] [1]

DDH assumption: 1 , ๐‘ , ๐‘ , ๐‘๐‘ โ‰ˆ๐‘‘ 1 , ๐›ฝ , ๐›พ , ๐›ฟ

13/22

slide-41
SLIDE 41

[1] ๐›พ [1] [๐œ€] [๐›พ] [๐œ—] [๐›ฝ] ๐›ฟ [๐›ฝ] [๐œ‚] [๐›ฟ] [๐œƒ] [1] [๐›ฝ] [1]

DDH assumption: 1 , ๐‘ , ๐‘ , ๐‘๐‘ โ‰ˆ๐‘‘ 1 , ๐›ฝ , ๐›พ , ๐›ฟ

13/22

slide-42
SLIDE 42

[1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1] [๐›ฟ] [๐›พ] [๐œ—] [๐›ฝ] [๐œ‚] [๐œ€] [๐œƒ]

โ‰ˆ๐‘‘

DDH

general case: use these monomials to simulate any (multilinear) polynomial e.g.: ๐‘1 + 1 ๐‘2 + 1 ๐‘3 + 1 = ๐‘ฆโˆˆ 0,1 ๐‘œ ๐‘1

๐‘ฆ1๐‘2 ๐‘ฆ2๐‘3 ๐‘ฆ3

= 1 + ๐‘1 + ๐‘2 + ๐‘3 + ๐‘1๐‘2 + ๐‘1๐‘3 + ๐‘2๐‘3 + ๐‘1๐‘2๐‘3

โ‰ˆ๐‘‘

1 + ๐›ฝ + ๐›พ + ๐›ฟ + ๐œ€ + ๐œ‚ + ๐œ— + ๐œƒ

DDH

14/22

slide-43
SLIDE 43

[1] [๐‘3] [๐‘2] [๐‘2๐‘3] [๐‘1] [๐‘1๐‘3] [๐‘1๐‘2] [๐‘1๐‘2๐‘3] [1] [๐›ฟ] [๐›พ] [๐œ—] [๐›ฝ] [๐œ‚] [๐œ€] [๐œƒ]

โ‰ˆ๐‘‘

DDH

general case: use these monomials to simulate any (multilinear) polynomial e.g.: ๐‘1 + 1 ๐‘2 + 1 ๐‘3 + 1 = ๐‘ฆโˆˆ 0,1 ๐‘œ ๐‘1

๐‘ฆ1๐‘2 ๐‘ฆ2๐‘3 ๐‘ฆ3

= 1 + ๐‘1 + ๐‘2 + ๐‘3 + ๐‘1๐‘2 + ๐‘1๐‘3 + ๐‘2๐‘3 + ๐‘1๐‘2๐‘3

โ‰ˆ๐‘‘

1 + ๐›ฝ + ๐›พ + ๐›ฟ + ๐œ€ + ๐œ‚ + ๐œ— + ๐œƒ

DDH

no linear relation between polynomials ๐‘„

1, โ€ฆ , ๐‘„ ๐‘Ÿ

๏ƒž ๐‘„

1

๐‘ , โ€ฆ , ๐‘„

๐‘Ÿ

๐‘ โ‰ˆ๐‘‘ $1, โ€ฆ , $๐‘Ÿ problem: reduction time = ๐‘ƒ(2๐‘œ) (# of monomials) ๏ƒžsubexponential hardness of DDH required in the paper: proof under standard DDH idea: lazy simulation

14/22

slide-44
SLIDE 44

Real ๐‘„ [๐‘„( ๐‘)] Rand ๐‘„ $

โ‰ˆ๐‘‘

where the polynomials queried are lin. ind. + multilinear (+ subexponential hardness of DDH)

๐‘ โˆˆ โ„ค๐‘ž

๐‘œ

DDH

15/22

slide-45
SLIDE 45

Real ๐‘„ [๐‘„( ๐ต)] Rand ๐‘„ $

โ‰ˆ๐‘‘

where the polynomials queried are lin. ind. (+ natural assumptions for ๐‘™ โ‰ฅ 2) polynomial-time proof

๐ต โˆˆ (โ„ค๐‘ž

๐‘™ร—๐‘™)

๐‘œ

Main result

MDDH

15/22

slide-46
SLIDE 46

Applications

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials

16/22

slide-47
SLIDE 47

Applications

PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ๐‘„

๐‘ฆ ๐‘ฆโˆˆ๐ธ lin. ind. ๐‘œ-variate polynomials

ฮฆ โІ โ„ค๐‘ž ๐‘ˆ

1, โ€ฆ , ๐‘ˆ ๐‘œ

ฮฆ-RKA-PRF ๐บ: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— ๐ธ โ†ฆ ๐‘„ ๐‘ฆ

๐‘ โˆˆ ๐”ฟ ๐‘„

๐‘ฆ โˆ˜ ๐œš ๐‘ฆโˆˆ๐ธ ๐œšโˆˆฮฆ

  • lin. ind. ๐‘œ-variate polynomials

16/22

slide-48
SLIDE 48

condition: ๐‘„

๐‘ฆ โˆ˜ ๐œš ๐‘ฆโˆˆ๐ธ ๐œšโˆˆฮฆ

  • lin. ind. ๐‘œ-variate polynomials

this is a very strong condition!

17/22

slide-49
SLIDE 49

condition: ๐‘„

๐‘ฆ โˆ˜ ๐œš ๐‘ฆโˆˆ๐ธ ๐œšโˆˆฮฆ

  • lin. ind. ๐‘œ-variate polynomials

this is a very strong condition! counter-example: ฮฆ = ฮฆ+, ๐œš๐‘ ๐‘ = ๐‘1 + ๐‘1, โ€ฆ , ๐‘๐‘œ + ๐‘๐‘œ ๐‘‚๐‘†: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— 0,1 ๐‘œ โ†ฆ [ ๐‘—=1 ๐‘œ

๐‘๐‘—

๐‘ฆ๐‘—]

17/22

slide-50
SLIDE 50

condition: ๐‘„

๐‘ฆ โˆ˜ ๐œš ๐‘ฆโˆˆ๐ธ ๐œšโˆˆฮฆ

  • lin. ind. ๐‘œ-variate polynomials

this is a very strong condition! counter-example: ฮฆ = ฮฆ+, ๐œš๐‘ ๐‘ = ๐‘1 + ๐‘1, โ€ฆ , ๐‘๐‘œ + ๐‘๐‘œ ๐‘‚๐‘†: ๐‘, ๐‘ฆ โˆˆ โ„ค๐‘ž

๐‘œ ร— 0,1 ๐‘œ โ†ฆ [ ๐‘—=1 ๐‘œ

๐‘๐‘—

๐‘ฆ๐‘—]

attack against ๐‘‚๐‘† with 3 queries: ๐‘‚๐‘† ๐‘, 01 โ€ฆ 0 = [๐‘2] ๐‘‚๐‘† ๐‘, 11 โ€ฆ 0 = [๐‘1๐‘2] ๐‘‚๐‘† ๐œš(1,0,โ€ฆ,0)( ๐‘), 110 โ€ฆ 0 = ๐‘1 + 1 ๐‘2 = ๐‘1๐‘2 โ‹… [๐‘2]

17/22

slide-51
SLIDE 51

this case was addressed in [BC10] idea: it is secure if the adversary is unique-input solution: force the adversary to be unique-input

18/22

slide-52
SLIDE 52

this case was addressed in [BC10] idea: it is secure if the adversary is unique-input solution: force the adversary to be unique-input intuition: construct a PRF ๐ป from ๐บ as ๐‘ฏ ๐’ƒ, ๐’š = ๐‘ฎ ๐’ƒ, ๐‘ฐ ๐’ƒ, ๐’š where ๐ผ is a collision-resistant hash function โ‡’ if ๐‘ or ๐‘ฆ change, then so does ๐ผ( ๐‘, ๐‘ฆ)

18/22

slide-53
SLIDE 53

Our new framework

instead of: ๐ป ๐‘, ๐‘ฆ = ๐บ ๐‘, ๐ผ ๐’ƒ, ๐‘ฆ we use: ๐ป ๐‘, ๐‘ฆ = ๐บ ๐‘, ๐ผ ๐’ƒ๐Ÿ , โ€ฆ , [๐’ƒ๐’], ๐‘ฆ ๏ƒž reduction to the lip security notion!

19/22

slide-54
SLIDE 54

Proof idea

simulate:

  • ๐‘1 , โ€ฆ , [๐‘๐‘œ] by querying polynomials ๐‘ˆ

1, โ€ฆ , ๐‘ˆ ๐‘œ

  • ๐ป

๐‘, ๐‘ฆ by querying ๐‘„๐ผ ๐‘1 ,โ€ฆ,[๐‘๐‘œ],๐‘ฆ ๐ป ๐‘, ๐‘ฆ = ๐‘„๐ผ ๐‘ ,๐‘ฆ ๐‘ ๏ƒž ๐ป ๐‘, ๐‘ฆ โ‰ˆ๐‘‘ $ ๐‘ˆ

1, โ€ฆ , ๐‘ˆ ๐‘œ and polynomials ๐‘„โ„Ž โˆ˜ ๐œš lin. ind. (for distinct โ„Ž)

20/22

slide-55
SLIDE 55

Conclusion

  • completely algebraic framework
  • unifies most of the existing number-theoretic (RKA-)PRFs
  • simplifies proofs of (related-key) security
  • new constructions and security results

21/22

slide-56
SLIDE 56

Real ๐‘„ [๐‘„( ๐ต)] Rand ๐‘„ $

โ‰ˆ๐‘‘

๐ต โˆˆ (โ„ค๐‘ž

๐‘™ร—๐‘™)

๐‘œ

MDDH ๐šพ ๐’ƒ๐’‹ โ†ฆ ๐’ƒ๐’‹ + ๐’„๐’‹ ๐’ƒ๐’‹ โ†ฆ ๐’ƒ๐’‹ โˆ— ๐’„๐’‹ ๐’ƒ๐’‹ โ†ฆ ๐‘ธ(๐’ƒ๐’‹) ๐’ƒ๐’‹ โ†ฆ ๐’ƒ๐‰(๐’‹) ๐’ƒ๐’‹ โ†ฆ ๐‘ธ(๐’ƒ๐‰(๐’‹)) [BC10] ๐‘‚๐‘†โˆ— (exp. time) ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹

? ? ?

[ABPP14] ๐‘‚๐‘†โˆ— ๐‘‚๐‘†โˆ— ๐‘‚๐‘†โˆ—

? ?

this paper ๐‘‚๐‘†, ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹, ๐‘™๐‘€๐‘—๐‘œ, โ€ฆ ๐‘‚๐‘†, ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹, ๐‘™๐‘€๐‘—๐‘œ, โ€ฆ ๐‘‚๐‘†, ๐‘‚๐‘†โˆ—, ๐‘€๐‘‹, ๐‘™๐‘€๐‘—๐‘œ, โ€ฆ ๐‘‚๐‘†๐‘š๐‘—๐‘œ, ๐ถ๐‘๐‘† ๐‘‚๐‘†๐‘š๐‘—๐‘œ

Thank you! Questions?

22/22