Lune

CRYPTO2024顶会

Cryptanalysis of Lattice-Based Sequentiality Assumptions and Proofs of Sequential Work

Chris Peikert, Yi Tang

2024年份
6被引次数
1顶会引用

摘要

This work completely breaks the sequentiality assumption (and broad generalizations thereof) underlying the candidate lattice-based proof of sequential work (PoSW) recently proposed by Lai and Malavolta at CRYPTO 2023. In addition, it breaks an essentially identical variant of the PoSW, which differs from the original in only an arbitrary choice that is immaterial to the design and security proof (under the falsified assumption). This suggests that whatever security the original PoSW may have is fragile, and further motivates the search for a construction based on a sound lattice-based assumption.

Specifically, for sequentiality parameter TT and SIS parameters n,q,m=nlog⁡qn,q,m = n \log q, the attack on the sequentiality assumption finds a solution of quasipolynomial norm m⌈log⁡T⌉m^{\lceil \log T \rceil} (or norm O(m)⌈log⁡T⌉O(\sqrt{m})^{\lceil \log T \rceil} with high probability) in only logarithmic O~n,q(log⁡T)\tilde{O}_{n,q}(\log T) depth; this strongly falsifies the assumption that finding such a solution requires depth linear in TT. (The O~\tilde{O} notation hides polylogarithmic factors in the variables appearing in its subscript.) Alternatively, the attack finds a solution of polynomial norm m1/εm^{1/\varepsilon} in depth O~n,q(Tε)\tilde{O}_{n,q}(T^{\varepsilon}), for any constant ε>0\varepsilon > 0. Similarly, the attack on the (slightly modified) PoSW constructs a valid proof in polylogarithmic O~n,q(log⁡2T)\tilde{O}_{n,q}(\log^2 T) depth, thus strongly falsifying the expectation that doing so requires linear sequential work.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖