[論文レビュー] Equivalence of the Random Oracle Model and the Ideal Cipher Model, Revisited
本稿は、ランダムオракルモデルとアイドル・シファー・モデルの間の同値性を再検討し、以前は逆転可能ランダム置換から無差別性であると主張されていた6ラウンドFeistel構造が、具体的な区別攻撃によって失敗することを示している。これを解決するために、著者らは14ラウンドFeistel構造が無差別性を達成することを証明し、各ラウンドに固有の役割を割り当てることで短い構造に見られる脆弱性を回避する、新しい証明戦略を用いる。
We consider the cryptographic problem of constructing an invertible random permutation from a public random function (i.e., which can be accessed by the adversary). This goal is formalized by the notion of indifferentiability of Maurer et al. (TCC 2004). This is the natural extension to the public setting of the well-studied problem of building random permutations from random functions, which was first solved by Luby and Rackoff (Siam J. Comput., '88) using the so-called Feistel construction. The most important implication of such a construction is the equivalence of the random oracle model (Bellare and Rogaway, CCS '93) and the ideal cipher model, which is typically used in the analysis of several constructions in symmetric cryptography. Coron et al. (CRYPTO 2008) gave a rather involved proof that the six-round Feistel construction with independent random round functions is indifferentiable from an invertible random permutation. Also, it is known that fewer than six rounds do not suffice for indifferentiability. The first contribution (and starting point) of our paper is a concrete distinguishing attack which shows that the indifferentiability proof of Coron et al. is not correct. In addition, we provide supporting evidence that an indifferentiability proof for the six-round Feistel construction may be very hard to find. To overcome this gap, our main contribution is a proof that the Feistel construction with eigthteen rounds is indifferentiable from an invertible random permutation. The approach of our proof relies on assigning to each of the rounds in the construction a unique and specific role needed in the proof. This avoids many of the problems that appear in the six-round case.
研究の動機と目的
- ランダムオラクルとアイドル・シファー・モデルの文脈において、6ラウンドFeistel構造が逆転可能ランダム置換から無差別性であると主張する正当性を検証すること。
- Coronら(CRYPTO 2008)の以前の証明で用いられたシミュレータに対する、具体的な区別攻撃を同定および実証すること。
- アイドル・シファー・モデル下でのFeistel構造に対して、正しいかつ強固な無差別性証明を確立することにより、ランダムオラクルとアイドル・シファー・モデルの間の同値性を回復すること。
- 短い構造で見られる病理的現象を回避するために、Feistel構造の各ラウンドに特定で固有の役割を割り当てる、新しい証明技法を開発すること。
提案手法
- 6ラウンドFeistel構造におけるシミュレータの挙動の不整合性を突く区別攻撃を導入し、シミュレータがアイドル・シファーを完全に模倣できないことを示す。
- 各ラウンドが証明構造内で一意な役割を果たすように設計された14ラウンドFeistel構造を安全な代替手段として提案する。
- 3段階のシミュレーションフレームワークを採用する:(1) 置換をランダム関数に置き換え、(2) Feistel構造を導入し、(3) シミュレータを削除してアイドル・モデルと比較する。
- 確率的解析を用いて、シミュレーション中に発生する「悪い事象」(例えば、一貫性のないクエリや衝突)の確率を抑え、それが無視できる程度であることを示す。
- シミュレータのランダム性とテーブル上の一様分布との間のマッピングを適用し、統計的距離が $ \frac{4 \cdot 10^{19} \cdot q^{10}}{2^n} $ で有界であることを証明する。
- チェーン長およびクエリ集合に関する補題を活用し、潜在的な衝突数を抑え、シミュレータの挙動がアイドルな原 primitive から統計的に区別不能であることを保証する。
実験結果
リサーチクエスチョン
- RQ16ラウンドFeistel構造は、アイドル・シファー・モデル下で、逆転可能ランダム置換から本当に無差別性を満たすのか?
- RQ2Coronらの以前の証明で用いられたシミュレータに対して、区別攻撃を構築できるか?
- RQ3Feistel構造が逆転可能ランダム置換から無差別性を達成するための最小ラウンド数は何か?
- RQ4各ラウンドに固有の役割を割り当てることで、従来の手法の欠陥を回避できる新しい証明技法を考案できるか?
主な発見
- 6ラウンドFeistel構造におけるシミュレータに対して、具体的な区別攻撃が実証され、Coronらの以前の証明が無効であることが判明した。
- 14ラウンドFeistel構造が逆転可能ランダム置換から無差別性であることが証明され、ランダムオラクルとアイドル・シファー・モデルの間の同値性の正しい基盤が確立された。
- シミュレータの出力とアイドル・モデルとの間の統計的距離が $ \frac{8 \cdot 10^{19} \cdot q^{10}}{2^n} $ で有界であることが示され、$ n $ が十分に大きい場合には無視できる。
- 良い入力に対して、シミュレータの挙動はアイドル・シファーと統計的に区別不能であり、失敗確率(悪い事象)が $ \frac{4 \cdot 10^{19} \cdot q^{10}}{2^n} $ で有界であることが証明された。
- 各ラウンドに固有の役割を割り当てる手法により、特に6ラウンド構造に見られる衝突および一貫性の問題が防止された。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。