Skip to main content
QUICK REVIEW

[논문 리뷰] Equivalence of the Random Oracle Model and the Ideal Cipher Model, Revisited

Thomas Holenstein, Robin Künzler|arXiv (Cornell University)|2010. 11. 04.
Cryptography and Data Security참고 문헌 3인용 수 4
한 줄 요약

이 논문은 랜덤 오ракulum 모델과 이상적 키 기반 모델 간의 등가성에 대해 재검토하며, 이전에 비가역적 랜덤 순열에서의 무차별성으로 주장된 6라운드 페이스텔 구조가 구체적인 구분 공격으로 인해 실패함을 보여준다. 이를 해결하기 위해 저자들은 새로운 증명 전략을 사용하여 14라운드 페이스텔 구조가 무차별성을 달성함을 증명한다. 이 전략은 각 라운드에 고유한 역할을 부여하여 짧은 구조에서 발생하는 취약성을 방지한다.

ABSTRACT

We consider the cryptographic problem of constructing an invertible random permutation from a public random function (i.e., which can be accessed by the adversary). This goal is formalized by the notion of indifferentiability of Maurer et al. (TCC 2004). This is the natural extension to the public setting of the well-studied problem of building random permutations from random functions, which was first solved by Luby and Rackoff (Siam J. Comput., '88) using the so-called Feistel construction. The most important implication of such a construction is the equivalence of the random oracle model (Bellare and Rogaway, CCS '93) and the ideal cipher model, which is typically used in the analysis of several constructions in symmetric cryptography. Coron et al. (CRYPTO 2008) gave a rather involved proof that the six-round Feistel construction with independent random round functions is indifferentiable from an invertible random permutation. Also, it is known that fewer than six rounds do not suffice for indifferentiability. The first contribution (and starting point) of our paper is a concrete distinguishing attack which shows that the indifferentiability proof of Coron et al. is not correct. In addition, we provide supporting evidence that an indifferentiability proof for the six-round Feistel construction may be very hard to find. To overcome this gap, our main contribution is a proof that the Feistel construction with eigthteen rounds is indifferentiable from an invertible random permutation. The approach of our proof relies on assigning to each of the rounds in the construction a unique and specific role needed in the proof. This avoids many of the problems that appear in the six-round case.

연구 동기 및 목표

  • 랜덤 오라큘럼 모델과 이상적 키 기반 모델의 맥락에서, 6라운드 페이스텔 구조가 비가역적 랜덤 순열에서 무차별성을 갖는다는 주장의 타당성을 조사한다.
  • 코로나 등이 (CRYPTO 2008)에서 제시한 이전 증명에서 사용된 시뮬레이터에 대한 구체적인 구분 공격을 식별하고 이를 입증한다.
  • 이상적 키 기반 모델 하에서 페이스텔 구조의 정확하고 강력한 무차별성 증명을 수립함으로써, 랜덤 오라큘럼 모델과 이상적 키 기반 모델 간의 등가성을 복원한다.
  • 각 라운드에 특정하고 고유한 역할을 할당하여 짧은 구조에서 나타나는 병리적 문제를 방지하는 새로운 증명 기법을 개발한다.

제안 방법

  • 6라운드 페이스텔 구조에서 시뮬레이터의 행동에 나타나는 일관성 없는 점을 악용하는 구분 공격을 도입하여, 시뮬레이터가 이상적 키 기반 모델을 완벽하게 모방할 수 없음을 보여준다.
  • 충격적인 충돌 및 일관성 문제를 방지하기 위해 각 라운드에 고유한 역할을 할당한 14라운드 페이스텔 구조를 안전한 대안으로 제안한다.
  • 세 단계의 시뮬레이션 프레임워크를 활용한다: (1) 순열을 랜덤 함수로 교체, (2) 페이스텔 구조 도입, (3) 시뮬레이터 제거 후 이상 모델과 비교.
  • 확률적 분석을 통해 시뮬레이션 중 '나쁜 사건'(예: 일관성 없는 쿼리 또는 충돌)이 발생할 확률을 유한하게 제한하며, 이는 무시할 수 있을 정도로 낮음을 보여준다.
  • 시뮬레이터의 난수와 표의 균일 분포 사이의 매핑을 적용하여 통계적 거리가 $ \frac{4 \cdot 10^{19} \cdot q^{10}}{2^n} $ 이하로 제한됨을 증명한다.
  • 체인 길이 및 쿼리 집합에 관한 보조정리를 활용하여 잠재적 충돌 수를 제한하고, 시뮬레이터의 행동이 이상적 원천과 통계적으로 구분 불가능하게 유지됨을 보장한다.

실험 결과

연구 질문

  • RQ16라운드 페이스텔 구조는 이상적 키 기반 모델 하에서 비가역적 랜덤 순열에서 진정으로 무차별성인가?
  • RQ2코로나 등의 이전 증명에서 사용된 시뮬레이터에 대해 구분 공격를 구성할 수 있는가?
  • RQ3비가역적 랜덤 순열에서 무차별성을 달성하기 위해 필요한 최소 라운드 수는 얼마인가?
  • RQ4각 라운드에 고유한 역할를 할당함으로써 이전 접근법의 결함을 피할 수 있는 새로운 증명 기법을 개발할 수 있는가?

주요 결과

  • 코로나 등의 이전 증명을 무너뜨리는 6라운드 페이스텔 구조의 시뮬레이터에 대한 구체적인 구분 공격이 입증되었다.
  • 14라운드 페이스텔 구조가 비가역적 랜덤 순열에서 무차별성임을 증명하여, 랜덤 오라큘럼 모델과 이상적 키 기반 모델 간의 등가성에 대한 올바른 기초를 확립하였다.
  • 시뮬레이터의 출력과 이상 모델 간의 통계적 거리는 $ \frac{8 \cdot 10^{19} \cdot q^{10}}{2^n} $ 이하로 제한되며, 이는 큰 $ n $ 에서는 무시할 수 있다.
  • 좋은 입력에 대해 시뮬레이터의 행동은 이상 키 기반 모델과 통계적으로 구분 불가능하며, 실패 확률(나쁜 사건)은 $ \frac{4 \cdot 10^{19} \cdot q^{10}}{2^n} $ 이하로 제한된다.
  • 각 라운드에 고유한 역할를 할당하는 방법은 특히 6라운드 변형에서 악영향을 미치는 충돌 및 일관성 문제를 방지한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.