[论文解读] Low Ambiguity in Strong, Total, Associative, One-Way Functions
本文研究了强、完全、结合性单向函数(AOWFs)的模糊性,证明了若标准无模糊单向函数存在,则可构造出 O(n)-对一的此类 AOWFs —— 提供了一个合理的模糊性上界。此外,本文确立了 n^O(1)-对一 AOWFs 存在当且仅当 P ≠ FewP,并表明在 Σ*×Σ*→Σ* 上不存在 O(1)-对一的完全结合函数。
Rabi and Sherman present a cryptographic paradigm based on associative, one-way functions that are strong (i.e., hard to invert even if one of their arguments is given) and total. Hemaspaandra and Rothe proved that such powerful one-way functions exist exactly if (standard) one-way functions exist, thus showing that the associative one-way function approach is as plausible as previous approaches. In the present paper, we study the degree of ambiguity of one-way functions. Rabiand Sherman showed that no associative one-way function (over a universe having at least two elements) can be unambiguous (i.e., one-to-one). Nonetheless, we prove that if standard, unambiguous, one-way functions exist, then there exist strong, total, associative, one-way functions that are $\mathcal{O}(n)$-to-one. This puts a reasonable upper bound on the ambiguity.
研究动机与目标
- 在密码学假设下,确定强、完全、结合性单向函数(AOWFs)的最小可能模糊性(即原像大小)。
- 弥合已知模糊性上界与代数结构及复杂性理论所施加的固有下界之间的差距。
- 阐明具有有界模糊性的 AOWFs 的存在性与 FewP 和 P 等复杂性类之间的关系。
- 研究在字符串上完全、结合、递归函数的结构性限制,特别是关于常数对一映射的限制。
提出的方法
- 针对任意无界、非减、递归的 g: ℕ → ℕ,通过递归编码与基于多重集的复合,构造出 g(n)-对一、完全、结合、交换、递归的函数族。
- 基于函数输出增长速率与原像计数之间的矛盾论证,证明在 Σ*×Σ*→Σ* 上不存在 O(1)-对一的完全结合函数。
- 利用结合复合输出长度的对数增长界,推导出模糊性的下界,表明其不能为 o(g(n))-对一,其中 g 为特定快速增长函数。
- 利用复杂性理论约化:通过从无模糊单向函数构造,证明 n^O(1)-对一 AOWFs 的存在性等价于 P ≠ FewP。
- 采用多重集像集计数与基数论证(‖σ⁻¹(s)‖),分析不同字符串长度下原像集及其大小。
- 使用递归函数 f(n) = ⌈2 log n⌉^{l^{⌈log n⌉}} 定义一个增长阈值 g(n),其为 f 的反函数,并证明模糊性不能为 o(g(n))-对一。
实验结果
研究问题
- RQ1能否构造出模糊性较低的强、完全、结合性单向函数,其模糊性的最紧上界是什么?
- RQ2是否存在对 n^O(1)-对一强、完全、结合性单向函数存在的复杂性理论刻画?
- RQ3是否存在 Σ*×Σ*→Σ* 上的 O(1)-对一完全、结合、递归函数?若否,原因是什么?
- RQ4对于输出长度在输入长度上多项式有界的完全、结合函数,其最小可能模糊性是多少?
- RQ5在自然假设下,强、完全 AOWFs 的模糊性能否被一个比任何多项式增长更快的函数从下方有界?
主要发现
- 若标准无模糊单向函数存在,则存在强、完全、结合性单向函数,其为 O(n)-对一,为模糊性提供了合理的上界。
- n^O(1)-对一强、完全、结合性单向函数的存在性等价于 P ≠ FewP。
- 在 Σ*×Σ*→Σ* 上,不存在 O(1)-对一的完全、结合、递归函数,确立了根本的结构性限制。
- 对任意无界、非减、完全、递归函数 g: ℕ → ℕ,存在 g(n)-对一、完全、结合、交换、递归函数,其定义在 Σ*×Σ*→Σ* 上。
- 对任意完全、结合函数 σ: Σ*×Σ*→Σ*,若其输出多项式有界,则其模糊性不能为 o(g(n))-对一,其中 g 为 f(n) = ⌈2 log n⌉^{l^{⌈log n⌉}} 的反函数(l > 1)。
- 模糊性的下界为超多项式,且增长快于任何多项式,表明在自然约束下,强、完全 AOWFs 无法具有次多项式模糊性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。