Random Oracle Reducibility

نویسندگان

  • Paul Baecher
  • Marc Fischlin
چکیده

We discuss a reduction notion relating the random oracles in two cryptographic schemes A and B. Basically, the random oracle of scheme B reduces to the one of scheme A if any hash function instantiation of the random oracle (possibly still oracle based) which makes A secure also makes B secure. In a sense, instantiating the random oracle in scheme B is thus not more demanding than the one for scheme A. If, in addition, the standard cryptographic assumptions for scheme B are implied by the ones for scheme A, we can conclude that scheme B actually relies on weaker assumptions. Technically, such a conclusion cannot be made given only individual proofs in the random oracle model for each scheme. The notion of random oracle reducibility immediately allows to transfer an uninstantiability result from an uninstantiable scheme B to a scheme A to which the random oracle reduces. We are nonetheless mainly interested in the other direction as a mean to establish hierarchically ordered random-oracle based schemes in terms of security assumptions. As a positive example, we consider the twin Diffie-Hellman (DH) encryption scheme of Cash et al. (Journal of Cryptology, 2009), which has been shown to be secure under the DH assumption in the random oracle scheme. It thus appears to improve over the related hashed ElGamal encryption scheme which relies on the random oracle model and the strong DH assumption where the adversary also gets access to a decisional DH oracle. As explained above, we complement this belief by showing that the random oracle in the twin DH scheme actually reduces to the one of the hashed ElGamal encryption scheme. We finally discuss further random oracle reductions between common signature schemes like GQ, PSS, and FDH.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Randomness notions and partial relativization

We study weak 2 randomness, weak randomness relative to ∅′ and Schnorr randomness relative to ∅′. One major theme is characterizing the oracles A such that ML[A] ⊆ C, where C is a randomness notion and ML[A] denotes the Martin-Löf random reals relative to A. We discuss the connections with LR-reducibility and also study the reducibility associated with weak 2randomness.

متن کامل

Coherence , Random - Self - Reducibility , and Self

We study three types of self-reducibility that are motivated by the theory of program veriication. A set A is random-self-reducible if one can determine whether an input x is in A by making random queries to an A-oracle. The distribution of each query may depend only on the length of x. A set B is self-correctable over a distribution D if one can convert a program that is correct on most of the...

متن کامل

Enumeration Reducibility, Nondeterministic Computations and Relative Computability of Partial Functions

In a computation using auxiliary informational inputs one can think of the external resource making itself available in different ways. One way is via an oracle as in Turing reducibility, where information is supplied on demand without any time delay. Alternatively the Scott graph model for lambda calculus suggests a situation where new information, only some of it immediately related to the cu...

متن کامل

On truth-table reducibility to SAT and the difference hierarchy over NP

We show that polynomial time truth-table reducibility via Boolean circuits to SAT is the same as log space truth-table reducibility via Boolean formulas to SAT and the same as log space Turing reducibility to SAT. In addition, we prove that a constant number of rounds of parallel queries to SAT is equivalent to one round of parallel queries. Finally, we show that the infinite difference hierarc...

متن کامل

On Truth-Table Reducibility to SAT

We show that polynomial time truth-table reducibility via Boolean circuits to SAT is the same as logspace truth-table reducibility via Boolean formulas to SAT and the same as logspace Turing reducibility to SAT. In addition, we prove that a constant number of rounds of parallel queries to SAT is equivalent to one round of parallel queries. We give an oracle relative to which ∆p2 is not equal to...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011