<p>In the case of standard LWE samples <InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(({\textbf {A}},{\textbf {b = sA + e}})\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mo stretchy="false">(</mo> <mi mathvariant="bold">A</mi> <mo>,</mo> <mrow> <mi mathvariant="bold">b</mi> <mo>=</mo> <mi mathvariant="bold">sA</mi> <mo>+</mo> <mi mathvariant="bold">e</mi> </mrow> <mo stretchy="false">)</mo> </mrow> </math></EquationSource> </InlineEquation>, <InlineEquation ID="IEq2"> <EquationSource Format="TEX">\({\textbf {A}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="bold">A</mi> </math></EquationSource> </InlineEquation> is typically uniformly over <InlineEquation ID="IEq3"> <EquationSource Format="TEX">\(\mathbb {Z}_q^{n \times m}\)</EquationSource> <EquationSource Format="MATHML"><math> <msubsup> <mi mathvariant="double-struck">Z</mi> <mi>q</mi> <mrow> <mi>n</mi> <mo>×</mo> <mi>m</mi> </mrow> </msubsup> </math></EquationSource> </InlineEquation>. Under the <InlineEquation ID="IEq4"> <EquationSource Format="TEX">\(\textsf {DLWE}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">DLWE</mi> </math></EquationSource> </InlineEquation> assumption, the conditional distribution of <InlineEquation ID="IEq5"> <EquationSource Format="TEX">\({\textbf {s}}|({\textbf {A}}, {\textbf {b}})\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="bold">s</mi> <mo stretchy="false">|</mo> <mo stretchy="false">(</mo> <mi mathvariant="bold">A</mi> <mo>,</mo> <mi mathvariant="bold">b</mi> <mo stretchy="false">)</mo> </mrow> </math></EquationSource> </InlineEquation> and <InlineEquation ID="IEq6"> <EquationSource Format="TEX">\({\textbf {s}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="bold">s</mi> </math></EquationSource> </InlineEquation> is expected to be consistent. However, in the case where an adversary chooses <InlineEquation ID="IEq7"> <EquationSource Format="TEX">\({\textbf {A}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="bold">A</mi> </math></EquationSource> </InlineEquation> adaptively, the disparity between the two entities may be larger. In this work, our primary focus is on the quantification of the Average Conditional Min-Entropy <InlineEquation ID="IEq8"> <EquationSource Format="TEX">\(\tilde{H}_\infty ({\textbf {s}}|{\textbf {sA + e}})\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <msub> <mover accent="true"> <mi>H</mi> <mo stretchy="false">~</mo> </mover> <mi>∞</mi> </msub> <mrow> <mo stretchy="false">(</mo> <mi mathvariant="bold">s</mi> <mo stretchy="false">|</mo> <mrow> <mi mathvariant="bold">sA</mi> <mo>+</mo> <mi mathvariant="bold">e</mi> </mrow> <mo stretchy="false">)</mo> </mrow> </mrow> </math></EquationSource> </InlineEquation> of <InlineEquation ID="IEq9"> <EquationSource Format="TEX">\({\textbf {s}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="bold">s</mi> </math></EquationSource> </InlineEquation>, where <InlineEquation ID="IEq10"> <EquationSource Format="TEX">\({\textbf {A}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="bold">A</mi> </math></EquationSource> </InlineEquation> is chosen by the adversary. Brakerski and Döttling answered the question in one case: they proved that when <InlineEquation ID="IEq11"> <EquationSource Format="TEX">\({\textbf {s}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="bold">s</mi> </math></EquationSource> </InlineEquation> is uniformly chosen from <InlineEquation ID="IEq12"> <EquationSource Format="TEX">\(\mathbb {Z}_q^n\)</EquationSource> <EquationSource Format="MATHML"><math> <msubsup> <mi mathvariant="double-struck">Z</mi> <mi>q</mi> <mi>n</mi> </msubsup> </math></EquationSource> </InlineEquation>, it holds that <InlineEquation ID="IEq13"> <EquationSource Format="TEX">\(\tilde{H}_\infty ({\textbf {s}}|{\textbf {sA + e}}) \varpropto \rho _\sigma (\varLambda _q({\textbf {A}}))\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <msub> <mover accent="true"> <mi>H</mi> <mo stretchy="false">~</mo> </mover> <mi>∞</mi> </msub> <mrow> <mo stretchy="false">(</mo> <mi mathvariant="bold">s</mi> <mo stretchy="false">|</mo> <mrow> <mi mathvariant="bold">sA</mi> <mo>+</mo> <mi mathvariant="bold">e</mi> </mrow> <mo stretchy="false">)</mo> </mrow> <mo>∝</mo> <msub> <mi>ρ</mi> <mi>σ</mi> </msub> <mrow> <mo stretchy="false">(</mo> <msub> <mi>Λ</mi> <mi>q</mi> </msub> <mrow> <mo stretchy="false">(</mo> <mi mathvariant="bold">A</mi> <mo stretchy="false">)</mo> </mrow> <mo stretchy="false">)</mo> </mrow> </mrow> </math></EquationSource> </InlineEquation>. We prove that for any <InlineEquation ID="IEq14"> <EquationSource Format="TEX">\(d \le q\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>d</mi> <mo>≤</mo> <mi>q</mi> </mrow> </math></EquationSource> </InlineEquation>, when <InlineEquation ID="IEq15"> <EquationSource Format="TEX">\({\textbf {s}}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="bold">s</mi> </math></EquationSource> </InlineEquation> is uniformly chosen from <InlineEquation ID="IEq16"> <EquationSource Format="TEX">\(\mathbb {Z}_d^n\)</EquationSource> <EquationSource Format="MATHML"><math> <msubsup> <mi mathvariant="double-struck">Z</mi> <mi>d</mi> <mi>n</mi> </msubsup> </math></EquationSource> </InlineEquation> or is sampled from a discrete Gaussian distribution, there are also similar results. As an application of the above results, we improved the multi-key fully homomorphic encryption and answered the question raised at the end of their work positively: we have GSW-type ciphertext rather than Dual-GSW, and the improved scheme has shorter keys and ciphertexts.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Lattice-based, LWE-leakage model for Gaussian and uniform secret and its application in decentralization

  • Xiaokang Dai,
  • Jingwei Chen,
  • Wenyuan Wu,
  • Yong Feng

摘要

In the case of standard LWE samples \(({\textbf {A}},{\textbf {b = sA + e}})\) ( A , b = sA + e ) , \({\textbf {A}}\) A is typically uniformly over \(\mathbb {Z}_q^{n \times m}\) Z q n × m . Under the \(\textsf {DLWE}\) DLWE assumption, the conditional distribution of \({\textbf {s}}|({\textbf {A}}, {\textbf {b}})\) s | ( A , b ) and \({\textbf {s}}\) s is expected to be consistent. However, in the case where an adversary chooses \({\textbf {A}}\) A adaptively, the disparity between the two entities may be larger. In this work, our primary focus is on the quantification of the Average Conditional Min-Entropy \(\tilde{H}_\infty ({\textbf {s}}|{\textbf {sA + e}})\) H ~ ( s | sA + e ) of \({\textbf {s}}\) s , where \({\textbf {A}}\) A is chosen by the adversary. Brakerski and Döttling answered the question in one case: they proved that when \({\textbf {s}}\) s is uniformly chosen from \(\mathbb {Z}_q^n\) Z q n , it holds that \(\tilde{H}_\infty ({\textbf {s}}|{\textbf {sA + e}}) \varpropto \rho _\sigma (\varLambda _q({\textbf {A}}))\) H ~ ( s | sA + e ) ρ σ ( Λ q ( A ) ) . We prove that for any \(d \le q\) d q , when \({\textbf {s}}\) s is uniformly chosen from \(\mathbb {Z}_d^n\) Z d n or is sampled from a discrete Gaussian distribution, there are also similar results. As an application of the above results, we improved the multi-key fully homomorphic encryption and answered the question raised at the end of their work positively: we have GSW-type ciphertext rather than Dual-GSW, and the improved scheme has shorter keys and ciphertexts.