[論文レビュー] Non-Malleable Extractors and Codes, with their Many Tampered Extensions
本稿では、最小エントロピー $k \geq \log^2 n$ および $k \geq n - n^{\Omega(1)}$ のそれぞれについて、最適なパラメータを達成する、複数回の改ざん攻撃に耐性を持つ非マネージャブル抽出器および符号の明示的構成を提示する。改ざん下での出力独立性を保証するための新規技術を導入し、最初の効率的なプレイメージサンプリングを可能にするとともに、高い改ざん耐性と定数レート誤りを有する非マネージャブル符号を構築する。
Randomness extractors and error correcting codes are fundamental objects in computer science. Recently, there have been several natural generalizations of these objects, in the context and study of tamper resilient cryptography. These are seeded non-malleable extractors, introduced in [DW09]; seedless non-malleable extractors, introduced in [CG14b]; and non-malleable codes, introduced in [DPW10]. However, explicit constructions of non-malleable extractors appear to be hard, and the known constructions are far behind their non-tampered counterparts. In this paper we make progress towards solving the above problems. Our contributions are as follows. (1) We construct an explicit seeded non-malleable extractor for min-entropy $k \geq \log^2 n$. This dramatically improves all previous results and gives a simpler 2-round privacy amplification protocol with optimal entropy loss, matching the best known result in [Li15b]. (2) We construct the first explicit non-malleable two-source extractor for min-entropy $k \geq n-n^{Ω(1)}$, with output size $n^{Ω(1)}$ and error $2^{-n^{Ω(1)}}$. (3) We initiate the study of two natural generalizations of seedless non-malleable extractors and non-malleable codes, where the sources or the codeword may be tampered many times. We construct the first explicit non-malleable two-source extractor with tampering degree $t$ up to $n^{Ω(1)}$, which works for min-entropy $k \geq n-n^{Ω(1)}$, with output size $n^{Ω(1)}$ and error $2^{-n^{Ω(1)}}$. We show that we can efficiently sample uniformly from any pre-image. By the connection in [CG14b], we also obtain the first explicit non-malleable codes with tampering degree $t$ up to $n^{Ω(1)}$, relative rate $n^{Ω(1)}/n$, and error $2^{-n^{Ω(1)}}$.
研究の動機と目的
- 特に2ソースおよびシードレス設定において、非マネージャブル抽出器の明示的構成の不足に対処する。
- 既存の非マネージャブル符号が単一の改ざんにしか耐えられないという制限を克服し、複数回の改ざんに耐性を持つようにする。
- 改ざん耐性の先行研究を拡張し、多数の改ざん状況下での非マネージャブル抽出器および符号の統一的フレームワークを構築する。
- 新規抽出器を用いて、プライバシー強化プロトコルにおける最適なエントロピー損失および誤差バウンドを達成する。
- 非マネージャブル秘密分散などの暗号的応用にとって不可欠な、非マネージャブル抽出器のプレイメージを効率的にサンプリング可能にする。
提案手法
- 最小エントロピー $k \geq \log^2 n$ のための、抽出器とエラー訂正符号の性質の新しい組み合わせを用いた、シード付き非マネージャブル抽出器の構築。
- 代数的幾何学と有限体上のランダムネス抽出を活用し、最小エントロピー $k \geq n - n^{\Omega(1)}$ の2ソース抽出器を設計。
- 最大 $n^{\Omega(1)}$ の改ざん度 $t$ を持つ改ざん度の概念を導入し、単一改ざんモデルを複数の攻撃的改ざんに一般化する。
- リード・ソロモングコードとその部分行列の性質を用いて改ざん行動をモデル化し、ランクに基づく部分空間的議論により出力の独立性を保証する。
- ランク・ノルティー定理を適用し、改ざん入力下でのプレイメージが固定サイズの部分空間上に存在することを示し、均一なサンプリングを可能にする。
- 任意の出力のプレイメージを、サンプラーの入力に依存しない形で一様にサンプリングする効率的な手順 $\textnormal{Samp}_{nm}$ を構築する。
実験結果
リサーチクエスチョン
- RQ1最小エントロピー $k \geq \log^2 n$ の明示的シード付き非マネージャブル抽出器を、最適なエントロピー損失で構築可能か?
- RQ2ほぼ完全な最小エントロピーを持つソースに対して、非マネージャブル2ソース抽出器を構築可能か、かつ誤差が超指数的か?
- RQ3非マネージャブル抽出器および符号を、1回ではなく複数回の改ざんに耐性を持たせるように一般化可能か?
- RQ4非マネージャブル抽出器および符号が安全かつ効率的であるための最大の改ざん度 $t$ は何か?
- RQ5攻撃的改ざん下でも、非マネージャブル抽出器の出力のプレイメージを効率的にサンプリング可能か?
主な発見
- 最小エントロピー $k \geq \log^2 n$ の明示的シード付き非マネージャブル抽出器が構築され、最適なエントロピー損失を達成し、最適パラメータの2ラウンドプライバシー強化プロトコルを可能にする。
- 最小エントロピー $k \geq n - n^{\Omega(1)}$ のための、最初の明示的非マネージャブル2ソース抽出器が構築され、出力サイズは $n^{\Omega(1)}$、誤差は $2^{-n^{\Omega(1)}}$ である。
- 改ざん度 $t$ が $n^{\Omega(1)}$ まで可能な非マネージャブル2ソース抽出器が構築され、単一改ざんの場合と同等の誤差および出力サイズを維持する。
- 本稿では、非マネージャブル抽出器の任意の出力のプレイメージから均一にサンプリングする効率的な手続きを提供する。これは暗号的応用にとって重要な要件である。
- [CG14b] における関係性を活用し、改ざん度 $t \leq n^{\Omega(1)}$、相対レート $n^{\Omega(1)}/n$、誤差 $2^{-n^{\Omega(1)}}$ を有する、最初の明示的非マネージャブル符号が構築される。
- 非マネージャブル抽出器の任意の出力のプレイメージのサイズは、サンプリング手順の入力に依存せず、均一性と正しさを保証する。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。