Practical Graphs for Optimal Side-Channel Resistant Memory-Hard Functions
Joël Alwen, Jeremiah Blocki, Benjamin Harsha
摘要
A memory-hard function (MHF) f n with parameter n can be computed in sequential time and space n. Simultaneously, a high amortized parallel area-time complexity (aAT) is incurred per evaluation. In practice, MHFs are used to limit the rate at which an adversary (using a custom computational device) can evaluate a security sensitive function that still occasionally needs to be evaluated by honest users (using an off-the-shelf general purpose device). The most prevalent examples of such sensitive functions are Key Derivation Functions (KDFs) and password hashing algorithms where rate limits help mitigate off-line dictionary attacks. As the honest users' inputs to these functions are often (low-entropy) passwords special attention is given to a class of side-channel resistant MHFs called iMHFs.
Essentially all iMHFs can be viewed as some mode of operation (making n calls to some round function) given by a directed acyclic graph (DAG) with very low indegree. Recently, a combinatorial property of a DAG has been identified (called "depth-robustness") which results in good provable security for an iMHF based on that DAG. Depth-robust DAGs have also proven useful in other cryptographic applications. Unfortunately, up till now, all known very depth-robust DAGs are impractically complicated and little is known about their exact (i.e. non-asymptotic) depth-robustness both in theory and in practice.
In this work we build and analyze (both formally and empirically) several exceedingly simple and efficient to navigate practical DAGs for use in iMHFs and other applications. For each DAG we:
• Prove that their depth-robustness is asymptotically maximal.
• Prove bounds of at least 3 orders of magnitude better on their exact depth-robustness compared to known bounds for other practical iMHF.
• Implement and empirically evaluate their depth-robustness and aAT against a variety of state-of-the art (and several
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- On the Economics of Offline Password CrackingJeremiah Blocki, Benjamin Harsha, Samson ZhouS&P 2018 · 被引用 79 次
- PIEs: Public Incompressible Encodings for Decentralized StorageEthan Cecchetti, Ben Fisch, Ian Miers, Ari JuelsCCS 2019 · 被引用 18 次
- Bandwidth-Hard Functions: Reductions and Lower BoundsJeremiah Blocki, Ling Ren, Samson ZhouCCS 2018 · 被引用 17 次
- Sustained Space and Cumulative Complexity Trade-Offs for Data-Dependent Memory-Hard FunctionsJeremiah Blocki, Blake HolmanCRYPTO 2022 · 被引用 5 次
- Data-Dependent Memory-Hard Functions: Sustained Space and Cumulative Complexity Trade-Offs in the Parallel Random Oracle ModelJeremiah Blocki, Blake HolmanCRYPTO 2026
相关 Paper
- Trapdoor Memory-Hard FunctionsBenedikt Auerbach, Christoph U. Günther, Krzysztof PietrzakEUROCRYPT 2024 · 被引用 5 次
- The Impact of Reversibility on Parallel PebblingJeremiah Blocki, Blake Holman, Seunghoon LeeEUROCRYPT 2025 · 被引用 1 次
- The exact complexity of pseudorandom functions and the black-box natural proof barrier for bootstrapping results in computational complexityZhiyuan Fan, Jiatu Li, Tianqi YangSTOC 2022 · 被引用 4 次
- Egalitarian ComputingAlex Biryukov, Dmitry KhovratovichUSENIX Security 2016 · 被引用 26 次
- Threshold Password-Hardened Encryption ServicesJulian Brost, Christoph Egger, Russell W. F. Lai, Fritz Schmid 等CCS 2020 · 被引用 24 次
