Fine-Grained Non-interactive Key Exchange, Revisited
Balthazar Bauer, Geoffroy Couteau, Elahe Sadeghi
摘要
We revisit the construction of multiparty non-interactive key-exchange protocols with fine-grained security, which was recently studied in (Afshar et al., Eurocrypt 2023). Their work introduced a 4party non-interactive key exchange with quadratic hardness, and proved it secure in Shoup's generic group model. This positive result was complemented with a proof that n-party non-interactive key exchange with superquadratic security cannot exist in Maurer's generic group model, for any n ≥ 3. Because Shoup's model is stronger than Maurer's model, this leaves a gap between the positive and the negative result, and their work left as an open question the goal of closing this gap, and of obtaining fine-grained non-interactive key exchange without relying on idealized models. In this work, we make significant progress on both questions. We obtain two main results:
-A 4-party non-interactive key exchange protocol with quadratic security gap, assuming the existence of exponentially secure injective pseudorandom generators, and the subexponential hardness of the computational Diffie-Hellman assumption. In addition, our scheme is conceptually simpler, and can be generalized to other settings (with more parties or from other assumptions). -Assuming the existence of non-uniformly secure injective pseudorandom generators with exponential hardness, we further show that our protocol is secure in Maurer's model, albeit with a smaller hardness gap (up to N 1.6 ), making progress on filling the gap between the positive and the negative result of (Afshar et al., Eurocrypt 2023). Somewhat intriguingly, proving the security of our scheme in Maurer's idealized model turns out to be significantly harder than proving its security in the standard model.
Informally, in the generic group model, the parties and the adversary have oracle access to the group operations. In Maurer's model, the group elements are represented as values in an array (stored in the oracle) and the parties cannot see them, but can test the equality between elements using oracle queries. In Shoup's model, a representation of the group elements computed through oracle queries via a random injective mapping is given to the parties (letting them in particular test locally the equality between group elements). Together, these result demonstrate that in contrast with the standard setting of security against 4 For example, a primitive with a quadratic gap between the runtime of the honest parties and that of the best-possible adversary could be realistically usable: running 2 40 operations requires a moderate amount of time on a standard computers, while (2 40 ) 2 = 2 80 remains out of reach of anyone but state-level organizations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Non-Interactive Zero-Knowledge Proofs with Fine-Grained SecurityYuyu Wang, Jiaxin PanEUROCRYPT 2022 · 被引用 11 次
- On Building Fine-Grained One-Way Functions from Strong Average-Case HardnessChris Brzuska, Geoffroy CouteauEUROCRYPT 2022 · 被引用 9 次
- Fine-Grained Non-interactive Key-Exchange: Constructions and Lower BoundsAbtin Afshar, Geoffroy Couteau, Mohammad Mahmoody, Elahe SadeghiEUROCRYPT 2023 · 被引用 6 次
- Beating Brute Force for Compression ProblemsShuichi Hirahara, Rahul Ilango, R. Ryan WilliamsSTOC 2024 · 被引用 3 次
相关 Paper
- Fine-Grained Non-interactive Key-Exchange Without Idealized AssumptionsYuyu Wang, Chuanjie Su, Jiaxin PanCRYPTO 2024 · 被引用 1 次
- To Label, or Not To Label (in Generic Groups)Mark ZhandryCRYPTO 2022 · 被引用 50 次
- List Oblivious Transfer and Applications to Round-Optimal Black-Box Multiparty Coin TossingMichele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Hendrik WaldnerCRYPTO 2023 · 被引用 4 次
- On the Round Complexity of Black-Box Secure MPCYuval Ishai, Dakshita Khurana, Amit Sahai, Akshayaram SrinivasanCRYPTO 2021 · 被引用 18 次
- Generic-Group Barriers for Function-Hiding and Multi-input Functional EncryptionMohammad Hajiabadi, Roman Langrehr, Mingyuan WangCRYPTO 2026
