On the Memory-Tightness of Hashed ElGamal
Ashrujit Ghoshal, Stefano Tessaro
Abstract
We study the memory-tightness of security reductions in public-key cryptography, focusing in particular on Hashed ElGamal. We prove that any straightline (i.e., without rewinding) black-box reduction needs memory which grows linearly with the number of queries of the adversary it has access to, as long as this reduction treats the underlying group generically. This makes progress towards proving a conjecture by Auerbach et al. (CRYPTO 2017), and is also the first lower bound on memory-tightness for a concrete cryptographic scheme (as opposed to generalized reductions across security notions). Our proof relies on compression arguments in the generic group model.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a6950df8-b834-4a02-a625-cd4730db03ceCited by top-tier papers2
- The Memory-Tightness of Authenticated EncryptionAshrujit Ghoshal, Joseph Jaeger, Stefano TessaroCRYPTO 2020 · 9 citations
- On Time-Space Tradeoffs for Bounded-Length Collisions in Merkle-Damgård HashingAshrujit Ghoshal, Ilan KomargodskiCRYPTO 2022 · 8 citations
Related papers
- Hiding in Plain Sight: Memory-Tight Proofs via Randomness ProgrammingAshrujit Ghoshal, Riddhi Ghosal, Joseph Jaeger, Stefano TessaroEUROCRYPT 2022 · 5 citations
- The Power of Undirected Rewindings for Adaptive SecurityDennis Hofheinz, Julia Kastner, Karen KleinCRYPTO 2023 · 4 citations
- Signatures with Memory-Tight Security in the Quantum Random Oracle ModelKeita XagawaEUROCRYPT 2024 · 3 citations
- Memory-Sample Lower Bounds for LWEMingqi Lu, Junzhao YangCRYPTO 2024 · 1 citation
- Everybody's a Target: Scalability in Public-Key EncryptionBenedikt Auerbach, Federico Giacon, Eike KiltzEUROCRYPT 2020 · 10 citations
