Algebraic (trapdoor) one-way functions: Constructions and applications

被引:0
|
作者
Catalano, Dario [1 ]
Fiore, Dario [2 ]
Gennaro, Rosario [3 ]
Vamvourellis, Konstantinos [3 ]
机构
[1] Dipartimento di Matematica e Informatica, Università di Catania, Italy
[2] IMDEA Software Institute, Madrid, Spain
[3] City College of New York, United States
基金
美国国家科学基金会;
关键词
Authentication - Network security - Public key cryptography - Group theory;
D O I
暂无
中图分类号
学科分类号
摘要
In this paper we introduce the notion of Algebraic (Trapdoor) One Way Functions, which, roughly speaking, captures and formalizes many of the properties of number-theoretic one-way functions. Informally, a (trapdoor) one way function F:X→Y is said to be algebraic if X and Y are (finite) abelian cyclic groups, the function is homomorphic i.e. F(x) F(y)=F(xy), and is ring-homomorphic, meaning that it is possible to compute linear operations in the exponent over some ring (which may be different from Zp where p is the order of the underlying group X) without knowing the bases. Moreover, algebraic OWFs must be flexibly one-way in the sense that given y=F(x), it must be infeasible to compute (x', d) such that F(x')=yd (for d≠0). Interestingly, algebraic one way functions can be constructed from a variety of standard number theoretic assumptions, such as RSA, Factoring and CDH over bilinear groups.As a second contribution of this paper, we show several applications where algebraic (trapdoor) OWFs turn out to be useful. In particular:. •Publicly Verifiable Secure Outsourcing of Polynomials: We present efficient solutions which work for rings of arbitrary size and characteristic. When instantiating our protocol with the RSA/Factoring based algebraic OWFs we obtain the first solution which supports small field size, is efficient and does not require bilinear maps to obtain public verifiability.•Linearly-Homomorphic Signatures: We give a direct construction of FDH-like linearly homomorphic signatures from algebraic (trapdoor) one way permutations. Our constructions support messages and homomorphic operations over arbitrary rings and in particular even small fields such as F2. While it was already known how to realize linearly homomorphic signatures over small fields (Boneh-Freeman, Eurocrypt 2011), from lattices in the random oracle model, ours are the first schemes achieving this in a very efficient way from Factoring/RSA.•Batch execution of Sigma protocols: We construct a simple and efficient Sigma protocol for any algebraic OWP and show a batch version of it, i.e. a protocol where many statements can be proven at a cost (slightly superior) of the cost of a single execution of the original protocol. Given our RSA/Factoring instantiations of algebraic OWP, this yields, to the best of our knowledge, the first batch verifiable Sigma protocol for groups of unknown order. © 2015 Elsevier B.V.
引用
收藏
页码:143 / 165
相关论文
共 50 条
  • [31] On complete one-way functions
    Kozhevnikov, A. A.
    Nikolenko, S. I.
    PROBLEMS OF INFORMATION TRANSMISSION, 2009, 45 (02) : 168 - 183
  • [32] Pseudorandom Generators from Regular One-Way Functions: New Constructions with Improved Parameters
    Yu, Yu
    Li, Xiangxue
    Weng, Jian
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2013, PT II, 2013, 8270 : 261 - 279
  • [33] Pseudorandom generators from regular one-way functions: New constructions with improved parameters
    Yu, Yu
    Li, Xiangxue
    Weng, Jian
    THEORETICAL COMPUTER SCIENCE, 2015, 569 : 58 - 69
  • [34] Efficient universal padding techniques for multiplicative trapdoor one-way permutation
    Komano, Y
    Ohta, K
    ADVANCES IN CRYPTOLOGY-CRYPTO 2003, PROCEEDINGS, 2003, 2729 : 366 - 382
  • [35] Non-adaptive Universal One-Way Hash Functions from Arbitrary One-Way Functions
    Mao, Xinyu
    Mazor, Noam
    Zhang, Jiapeng
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2023, PT IV, 2023, 14007 : 502 - 531
  • [36] SYMMETRY OF INFORMATION AND ONE-WAY FUNCTIONS
    LONGPRE, L
    MOCAS, S
    LECTURE NOTES IN COMPUTER SCIENCE, 1991, 557 : 308 - 315
  • [37] ONE-WAY FUNCTIONS AND THE ISOMORPHISM CONJECTURE
    GANESAN, K
    THEORETICAL COMPUTER SCIENCE, 1994, 129 (02) : 309 - 321
  • [38] SYMMETRY OF INFORMATION AND ONE-WAY FUNCTIONS
    LONGPRE, L
    MOCAS, S
    INFORMATION PROCESSING LETTERS, 1993, 46 (02) : 95 - 100
  • [39] Kolmogorov One-Way Functions Revisited
    Casal, Filipe
    Rasga, Joao
    Souto, Andre
    CRYPTOGRAPHY, 2018, 2 (02) : 1 - 12
  • [40] On hardness amplification of one-way functions
    Lin, H
    Trevisan, L
    Wee, H
    THEORY OF CRYPTOGRAPHY, PROCEEDINGS, 2005, 3378 : 34 - 49