论文标题

优雅地失败:解密失败和富士基 - 奥卡本转变

Failing gracefully: Decryption failures and the Fujisaki-Okamoto transform

论文作者

Hövelmanns, Kathrin, Hülsing, Andreas, Majenz, Christian

论文摘要

为了减少富士克 - 奥卡摩托转换的已知安全性,通过减少解决了解密失败的解决,从而解决了私钥,从而找到了不自然的任务,即找到失败的明文,从而导致Grover搜索范围。此外,它们需要无效的密文的隐式拒绝机制,以实现QROM中限制的合理安全性。我们提出了这些缺陷的减少:我们介绍了两个与发现解密失败有关的安全游戏,其中一个捕获了使用公共密钥来查找解密失败的计算上的艰巨任务,以及一个捕获统计上艰难的任务,以搜索随机甲骨文以搜索密钥独立的失败,例如,例如,例如,大随机性。结果,我们在QROM中的安全界限比以前的QROM相对于通用的随机搜索攻击而更紧:攻击者只能部分计算搜索谓词,即对于所述密钥无关的失败。此外,我们的整个还原作用于转换的显式拒绝变体,并在其所有已知降低中都显着改善。除了是转换的更自然变体外,显式拒绝机制的安全性也与隐式拒绝变体的侧渠道攻击弹性有关。在此过程中,我们证明了一些技术结果,这些技术结果表征了QROM中可能具有独立感兴趣的QROM中的某些搜索任务。

In known security reductions for the Fujisaki-Okamoto transformation, decryption failures are handled via a reduction solving the rather unnatural task of finding failing plaintexts given the private key, resulting in a Grover search bound. Moreover, they require an implicit rejection mechanism for invalid ciphertexts to achieve a reasonable security bound in the QROM. We present a reduction that has neither of these deficiencies: We introduce two security games related to finding decryption failures, one capturing the computationally hard task of using the public key to find a decryption failure, and one capturing the statistically hard task of searching the random oracle for key-independent failures like, e.g., large randomness. As a result, our security bounds in the QROM are tighter than previous ones with respect to the generic random oracle search attacks: The attacker can only partially compute the search predicate, namely for said key-independent failures. In addition, our entire reduction works for the explicit-reject variant of the transformation and improves significantly over all of its known reductions. Besides being the more natural variant of the transformation, security of the explicit reject mechanism is also relevant for side channel attack resilience of the implicit-rejection variant. Along the way, we prove several technical results characterizing preimage extraction and certain search tasks in the QROM that might be of independent interest.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源