Lune

EUROCRYPT2024顶会

Leakage-Tolerant Circuits

Yuval Ishai, Yifan Song

2024年份
5被引次数
1顶会引用

摘要

A leakage-resilient circuit for f:{0,1}n→{0,1}mf:\{0,1\}^n\to\{0,1\}^m is a randomized Boolean circuit CC mapping a randomized encoding of an input xx to an encoding of y=f(x)y=f(x), such that applying any leakage function L∈LL\in \cal L to the wires of CC reveals essentially nothing about xx. A leakage-tolerant circuit achieves the stronger guarantee that even when xx and yy are not protected by any encoding, the output of LL can be simulated by applying some L′∈LL'\in \cal L to xx and yy alone. Thus, CC is as secure as an ideal hardware implementation of ff with respect to leakage from L\cal L.

Leakage-resilient circuits were constructed for low-complexity classes L\cal L, including (length-tt output) AC0\mathcal{AC}0 functions, parities, and functions with bounded communication complexity. In contrast, leakage-tolerant circuits were only known for the simple case of probing leakage, where LL outputs the values of tt wires in CC.

We initiate a systematic study of leakage-tolerant circuits for natural classes L\cal L of global leakage functions, obtaining the following main results.

Leakage-tolerant circuits for depth-1 leakage.\textbf{Leakage-tolerant circuits for depth-1 leakage.} Every circuit CfC_f for ff can be efficiently compiled into an L\cal L-tolerant circuit CC for ff, where L\cal L includes all leakage functions LL that output either tt parities or tt disjunctions (alternatively, conjunctions) of any number of wires or their negations. In the case of parities, our simulator runs in 2O(t)2^{O(t)} time. We provide partial evidence that this may be inherent.

Application to stateful leakage-resilient circuits.\textbf{Application to stateful leakage-resilient circuits.} We present a general transformation from (stateless) leakage-tolerant circuits to stateful leakage-resilient circuits. Using this transformation, we obtain the first constructions of stateful tt-leakage-resilient circuits that tolerate a continuous parity/disjunction/conjunction leakage in which the circuit size grows sub-quadratically with tt. Interestingly, here we can obtain poly(t)\mathtt{poly}(t)-time simulation even in the case of parities.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖