
We study certified everlasting security for functional encryption (FE) and other advanced cryptographic primitives. Informally, certified everlasting security provides a quantum deletion guarantee: a receiver who holds a quantum cryptographic object (e.g., a ciphertext) can produce a deletion certificate attesting that the object has been deleted, so that any information encoded in it (e.g., the plaintext) is irrecoverable. If the certificate verifies, then security holds even if the receiver later becomes computationally unbounded. Since many primitives are impossible (or are widely believed to be impossible) to realize with information-theoretic security even with quantum communication, certified everlasting security offers an appealing, inherently quantum compromise. In this work, we formalize certified everlasting secure variants of FE, compute-and-compare obfuscation, predicate encryption (PE), secret-key encryption (SKE), public-key encryption (PKE), receiver non-committing encryption (RNCE), and garbled circuits. We then give the following constructions:
The Fiat-Shamir transform is one of the most widely applied methods for secure signature construction. Fiat-Shamir starts with an interactive zero-knowledge identification protocol and transforms this via a hash function into a non-interactive signature. The protocol’s zero-knowledge property ensures that a signature does not leak information on its secret key s , which is achieved by blinding s⃗ via proper randomness y . Most prominent Fiat-Shamir examples are EC-DSA signatures and the new post-quantum standard ML-DSA (aka Dilithium). In practice, EC-DSA signatures have experienced fatal attacks via leakage of a few bits of the randomness y per signature. Similar attacks now emerge for lattice-based signatures, such as ML-DSA. We build on, improve and generalize the pioneering leakage attack on ML-DSA by Liu, Zhou, Sun, Wang, Zhang, and Ming. Using a transformation to Integer LWE (ILWE), their attack can recover a 256-dimensional subkey of ML-DSA-44 from leakage in a single bit of y per signature, in any bit position j ≥ 6 . However, the number of required signatures grows exponentially as 4^j . In this work, we show that not all leaky signatures carry information about the secret subkey. We introduce the notion of informative signature relations. This notion allows us to define a preprocessing step, called filter-and-shift that leads to ILWE instances that require a smaller sample amount. Unlike the standard ILWE transformation, filter-and-shift exploits the smallness of secret keys, and therefore might be of independent cryptanalytic interest. In comparison to Liu et al., for j=6 we require only a quarter of the signatures and reduce the exponential growth to 2^j . In addition, we show that the secret subkey can be recovered even with a leak bit corrupted by a large amount of noise, in theory up to the maximum of 50% . Experimentally, we still recover the secret with 43% noise, where we need 170 times as many signatures as in the noise-free setting. The attack applies more generally to all Fiat-Shamir-type lattice-based signatures. For a signature scheme based on module LWE over an ℓ -dimensional module, the attack uses a 1-bit leak per signature to efficiently recover a 1/ℓ -fraction of the secret key. In the ring LWE setting, which can be seen as module LWE with ℓ = 1 , the attack recovers the whole key.
We present two general compilers that endow a wide range of cryptographic primitives—including public-key encryption, attribute-based encryption, and (quantum) fully homomorphic encryption—with the publicly verifiable deletion property. Our compilers are based solely on minimal cryptographic assumptions: They require only one-way functions, one-way state generators, or, more generally, hard quantum planted problems for , all of which are implied by the existence of one-way functions. By relying on these minimal assumptions, our compilers enable the addition of the publicly verifiable deletion property to the aforementioned primitives without introducing any additional assumptions. In contrast, prior approaches, such as the one by Bartusek, Khurana, and Poremba [13], rely on stronger assumptions, including injective trapdoor one-way functions or pseudorandom group actions. From a technical standpoint, our work builds upon the compiler for privately verifiable deletion introduced by Bartusek and Khurana [11] and enhances it to achieve public verifiability. This is accomplished by incorporating one-time digital signatures—either directly or via indirect mechanisms.
Abstract The Fiat–Shamir transformation is a general principle to turn any public-coin interactive proof into non-interactive one (with security then typically analyzed in the random oracle model). While initially used for 3-round protocols, many recent constructions use it for multi-round protocols. However, in general the soundness error of the Fiat–Shamir transformed protocol degrades exponentially in the number of rounds. On the positive side, it was shown that for the special class of $$(k_1,\dots ,k_\mu )$$ ( k 1 , ⋯ , k μ ) -special-sound $$\varSigma $$ Σ -protocols, which is a natural multi-round generalization of the well-known class of special-sound protocols, the loss is actually only linear in the number of random oracle queries, and independent of the number of rounds, which is optimal. A natural next question is whether this positive result extends to the Fiat–Shamir transformation of so-called $$(\varGamma _1,\dots ,\varGamma _\mu )$$ ( Γ 1 , ⋯ , Γ μ ) -special-sound protocols. This notion was recently defined and analyzed in the interactive case; it captures a larger class of protocols, namely where the special-soundness property is characterized by a general access structure, rather than a threshold. We show in this work that this is indeed the case. Concretely, we show that the Fiat–Shamir transformation of any $$(\varGamma _1, \ldots , \varGamma _\mu )$$ ( Γ 1 , … , Γ μ ) -special-sound interactive proof is knowledge sound under the same condition on $$\varGamma _1,\dots ,\varGamma _\mu $$ Γ 1 , ⋯ , Γ μ for which the original interactive proof is knowledge sound. Furthermore, also here the loss is linear in the number of random oracle queries and independent of the number of rounds. In light of the above, one might suspect that our argument follows as a straightforward combination of the above mentioned prior works. However, this is not the case. The approach used for $$(k_1,\dots ,k_\mu )$$ ( k 1 , ⋯ , k μ ) -special-sound protocols, which is based on an extractor that samples without replacement, does not (seem to) generalize; on the other hand, the other approach, which uses an extractor based on sampling with replacement, comes with an additional loss that would blow up in the recursive multi-round analysis. Thus, new techniques are necessary to handle the above complications.
The Fiat-Shamir transformation is a general principle to turn any public-coin interactive proof into non-interactive one (with security then typically analyzed in the random oracle model). While initially used for 3-round protocols, many recent constructions use it for multi-round protocols. However, in general the soundness error of the Fiat-Shamir transformed protocol degrades exponentially in the number of rounds. On the positive side, it was shown that for the special class of (k1,& ctdot;,k mu)-special-sound Sigma-protocols, which is a natural multi-round generalization of the well-known class of special-sound protocols, the loss is actually only linear in the number of random oracle queries, and independent of the number of rounds, which is optimal. A natural next question is whether this positive result extends to the Fiat-Shamir transformation of so-called (Gamma 1,& ctdot;,Gamma mu)-special-sound protocols. This notion was recently defined and analyzed in the interactive case; it captures a larger class of protocols, namely where the special-soundness property is characterized by a general access structure, rather than a threshold. We show in this work that this is indeed the case. Concretely, we show that the Fiat-Shamir transformation of any (Gamma 1,& mldr;,Gamma mu)-special-sound interactive proof is knowledge sound under the same condition on Gamma 1,& ctdot;,Gamma mu for which the original interactive proof is knowledge sound. Furthermore, also here the loss is linear in the number of random oracle queries and independent of the number of rounds. In light of the above, one might suspect that our argument follows as a straightforward combination of the above mentioned prior works. However, this is not the case. The approach used for (k1,& ctdot;,k mu)-special-sound protocols, which is based on an extractor that samples without replacement, does not (seem to) generalize; on the other hand, the other approach, which uses an extractor based on sampling with replacement, comes with an additional loss that would blow up in the recursive multi-round analysis. Thus, new techniques are necessary to handle the above complications.
Elliptic Curve Hidden Number Problem (EC-HNP) was first introduced by Boneh, Halevi and Howgrave-Graham at Asiacrypt 2001. To rigorously assess the bit security of the Diffie–Hellman key exchange with elliptic curves (ECDH), the Diffie–Hellman variant of EC-HNP, regarded as an elliptic curve analogy of the Hidden Number Problem (HNP), was presented at PKC 2017. This variant can also be used for practical cryptanalysis of ECDH key exchange in the situation of side-channel attacks. In this paper, we revisit the Coppersmith method for solving the involved modular multivariate polynomials in the Diffie–Hellman variant of EC-HNP and demonstrate that, for a given sufficiently large prime p, and a fixed elliptic curve over the prime field 𝔽_p , if there is an oracle that outputs the δ/log _2 p -fraction of the most (least) significant bits of the x-coordinate of the ECDH key, where δ is the number of output bits that satisfies 0<δ/log _2 p<1 and δ/log _2 p is close to 0, then one can give a heuristic algorithm to compute all the bits within polynomial time in log _2 p . The known fraction δ/log _2 p in our result can be any constant between (0, 1). Therefore, it is much better than some constant fractions of 5/6, 1/2 in previous works [33, 36]. Due to the heuristics involved in the Coppersmith method, we do not get the ECDH bit security on a fixed curve. However, we experimentally verify the effectiveness of the heuristics on NIST curves for small dimension lattices.
In recent years, progress in practical applications of multi-party computation (MPC), fully homomorphic encryption (FHE), and zero-knowledge proofs (ZKP) motivates people to explore symmetric-key cryptographic algorithms, as well as corresponding cryptanalysis techniques (such as differential cryptanalysis, linear cryptanalysis), over finite Abelian groups or prime fields 𝔽_p for large p. In this paper, we establish the links between linear cryptanalysis and differential cryptanalysis over general finite Abelian groups. As the first application, we revisit linear cryptanalysis and give general results of linear approximations over arbitrary finite Abelian groups. More precisely, we consider the linearity, which is the maximal non-trivial linear approximation, to characterize the resistance of a function against linear cryptanalysis. This thereby generalizes the work of Pott in 2004 and completes the generalization of Sidelnikov–Chabaud–Vaudenay’s bound from 𝔽_2^n to finite Abelian groups. As the second application, we give an exact expression for the correlation of differential-linear approximations over arbitrary finite Abelian groups ( 𝔽_p^n ) under the sole assumption that the two parts of the cipher are independent of each other. In particular, we completely generalize the differential-linear cryptanalysis from 𝔽_2^n to arbitrary finite Abelian groups ( 𝔽_p^n ).
Most existing work on secure multi-party computation (MPC) ignores a key idiosyncrasy of modern communication networks, that there are a limited number of communication paths between any two nodes, many of which might even be corrupted. The problem becomes particularly acute in the information-theoretic setting, where the lack of trusted setups (and the cryptographic primitives they enable) makes communication over sparse networks more challenging. The work by Garay and Ostrovsky [EUROCRYPT’08] on almost-everywhere MPC (AE-MPC), introduced “best-possible security” properties for MPC over such incomplete networks, where necessarily some of the honest parties may be excluded from the computation. In this work, we provide a universally composable definition of almost-everywhere security, which allows us to automatically and accurately capture the guarantees of AE-MPC (as well as AE-communication, the analogous “best-possible security” version of secure communication) in the Universal Composability (UC) framework of Canetti. Our results offer the first simulation-based treatment of this important but under-investigated problem, along with the first simulation-based proof of AE-MPC. To achieve that goal, we state and prove a general composition theorem, which makes precise the level or “quality” of AE-security that is obtained when a protocol’s hybrids are replaced with almost-everywhere components.
We propose two generic constructions of public-key encryption (PKE) with tight simulation-based selective-opening security against chosen-ciphertext attacks (SIM-SO-CCA) in the random oracle model. Our constructions can be instantiated with a small constant number of elements in the ciphertext, ignoring smaller contributions from symmetric-key encryption. That is, they have compact ciphertexts. Furthermore, three of our instantiations have compact public keys as well. Known (almost) tightly SIM-SO-CCA secure PKE schemes are due to the work of Lyu et al. (PKC 2018) and Libert et al. (Crypto 2017). They have either linear-size ciphertexts or linear-size public keys. Moreover, they only achieve almost tightness, namely with security loss depending on the security parameter. In contrast with them, our schemes are the first ones achieving both tight SIM-SO-CCA security and compactness. More precisely, our two generic constructions are:
It is shown how bounds on exponential sums derived from modern algebraic geometry, and ℓ -adic cohomology specifically, can be used to upper bound the absolute correlations of linear approximations for cryptographic constructions of low algebraic degree. This is illustrated by applying results of Deligne, Denef and Loeser, and Rojas-León, to obtain correlation bounds for a generalization of the Butterfly construction, three-round Feistel ciphers, and a generalization of the Flystel construction. For each of these constructions, bounds obtained using other methods are significantly weaker. In the case of the Flystel construction, our bounds resolve a conjecture by the designers. Correlation bounds of this type are relevant for the development of security arguments against linear cryptanalysis, especially in the weak-key setting or for primitives that do not involve a key. Since the methods used in this paper are applicable to constructions defined over arbitrary finite fields, the results are also relevant for arithmetization-oriented primitives such as Anemoi, which uses S-boxes based on the Flystel construction.
We study combinatorial properties of plateaued functions F :𝔽_p^n →𝔽_p^m . All quadratic functions, bent functions and most known APN functions are plateaued, so many cryptographic primitives rely on plateaued functions as building blocks. The main focus of our study is the interplay of the Walsh transform and linearity of a plateaued function, its differential properties, and their value distributions, i.e., the sizes of image and preimage sets. In particular, we study the special case of “almost balanced” plateaued functions, which only have two nonzero preimage set sizes, generalising, for instance, all monomial functions. We achieve several direct connections and (non)existence conditions for these functions, showing in particular that plateaued d-to-1 functions (and thus plateaued monomials) only exist for a very select choice of d, and we derive for all these functions their linearity as well as bounds on their differential uniformity. We also specifically study the Walsh transform of plateaued APN functions and their relation to their value distribution.
We provide two improvements to Regev’s quantum factoring algorithm (arXiv:2308.06572), addressing its space efficiency and its noise-tolerance. Our first contribution is to improve the quantum space efficiency of Regev’s algorithm while keeping the circuit size the same. Our main result constructs a quantum factoring circuit using O(n log n) qubits and O(n^3/2log n) gates. We achieve the best of Shor and Regev (upto a logarithmic factor in the space complexity): on the one hand, Regev’s circuit requires O(n^3/2) qubits and O(n^3/2log n) gates, while Shor’s circuit requires O(n^2 log n) gates but only O(n) qubits. As with Regev, to factor an n-bit integer N, we run our circuit independently ≈√(n) times and apply Regev’s classical postprocessing procedure. Our optimization is achieved by implementing efficient and reversible exponentiation with Fibonacci numbers in the exponent, rather than the usual powers of 2, adapting work by Kaliski (arXiv:1711.02491) from the classical reversible setting to the quantum setting. This technique also allows us to perform quantum modular exponentiation that is efficient in both space and size without requiring significant precomputation, a result that may be useful for other quantum algorithms. A key ingredient of our exponentiation implementation is an efficient circuit for a function resembling in-place quantum-quantum modular multiplication. This implementation works with only black-box access to any quantum circuit for out-of-place modular multiplication, which we believe is yet another result of potentially broader interest. Our second contribution is to show that Regev’s classical postprocessing procedure can be modified to tolerate a constant fraction of the quantum circuit runs being corrupted by errors. In contrast, Regev’s analysis of his classical postprocessing procedure requires all ≈√(n) runs to be successful. In a nutshell, we achieve this using lattice reduction techniques to detect and filter out corrupt samples.
In an Instance-Hiding Interactive Proof (IHIP) [BFS90], an efficient verifier with a private input x interacts with an unbounded prover to determine whether x is contained in a language ℒ . In addition to completeness and soundness, the instance-hiding property requires that the prover should not learn anything about x in the course of the interaction. Such proof systems capture natural privacy properties, and may be seen as a generalization of the influential concept of Randomized Encodings [IK00, AIK04, AIKPC15], and as a counterpart to Zero-Knowledge proofs [GMR89]. We investigate the properties and power of such instance-hiding proofs, and show the following:
Robust (fuzzy) extractors are very useful for, e.g., authenticated key exchange from a shared weak secret and remote biometric authentication against active adversaries. They enable two parties to extract the same uniform randomness with a “helper” string. More importantly, they have an authentication mechanism built in that tampering of the “helper” string will be detected. Unfortunately, as shown by Dodis and Wichs, in the information-theoretic setting, a robust extractor for an (n, k)-source requires k>n/2 , which is in sharp contrast with randomness extractors which only require k=ω (log n) . Existing works either rely on random oracles or introduce CRS and work only for CRS-independent sources (even in the computational setting). In this work, we give a systematic study about robust (fuzzy) extractors for general CRS dependent sources. We show in the information-theoretic setting, the same entropy lower bound holds even in the CRS model; we then show we can have robust extractors in the computational setting for general CRS-dependent source that is only with minimal entropy. We further extend our construction to robust fuzzy extractors. Along the way, we propose a new primitive called κ -MAC, which is unforgeable with a weak key and hides all partial information about the key (both against auxiliary input); it may be of independent interests.
We study certified everlasting secure functional encryption (FE) and many other cryptographic primitives in this work. Certified everlasting security roughly means the following. A receiver possessing a quantum cryptographic object can issue a certificate showing that the receiver has deleted the cryptographic object and information included in the object was lost. If the certificate is valid, the security is guaranteed even if the receiver becomes computationally unbounded after the deletion. Many cryptographic primitives are known to be impossible (or unlikely) to have information-theoretical security even in the quantum world. Hence, certified everlasting security is a nice compromise (intrinsic to quantum). In this work, we define certified everlasting secure versions of FE, compute-and-compare obfuscation, predicate encryption (PE), secret-key encryption (SKE), public-key encryption (PKE), receiver non-committing encryption (RNCE), and garbled circuits. We also present the following constructions: - Adaptively certified everlasting secure collusion-resistant public-key FE for all polynomial-size circuits from indistinguishability obfuscation and one-way functions. - Adaptively certified everlasting secure bounded collusion-resistant public-key FE for NC1 circuits from standard PKE. - Certified everlasting secure compute-and-compare obfuscation from standard fully homomorphic encryption and standard compute-and-compare obfuscation - Adaptively (resp., selectively) certified everlasting secure PE from standard adaptively (resp., selectively) secure attribute-based encryption and certified everlasting secure compute-and-compare obfuscation. - Certified everlasting secure SKE and PKE from standard SKE and PKE, respectively. - Certified everlasting secure RNCE from standard PKE. - Certified everlasting secure garbled circuits from standard SKE.
Distributed Zero-Knowledge (dZK) proofs, recently introduced by Boneh et al. (CRYPTO‘19), allow a prover 𝒫 to prove NP statements on an input x which is distributed between k verifiers 𝒱_1,… ,𝒱_k , where each 𝒱_i holds only a piece of x. As in standard ZK proofs, dZK proofs guarantee Completeness when all parties are honest; Soundness against a malicious prover colluding with t verifiers; and Zero Knowledge against a subset of t malicious verifiers, in the sense that they learn nothing about the NP witness and the input pieces of the honest verifiers. Unfortunately, dZK proofs provide no correctness guarantee for an honest prover against a subset of maliciously corrupted verifiers. In particular, such verifiers might be able to “frame” the prover, causing honest verifiers to reject a true claim. This is a significant limitation, since such scenarios arise naturally in dZK applications, e.g., for proving honest behavior, and such attacks are indeed possible in existing dZKs (Boneh et al., CRYPTO‘19). We put forth and study the notion of strong completeness for dZKs, guaranteeing that true claims are accepted even when t verifiers are maliciously corrupted. We then design strongly-complete dZK proofs using the “MPC-in-the-head” paradigm of Ishai et al. (STOC‘07), providing a novel analysis that exploits the unique properties of the distributed setting. To demonstrate the usefulness of strong completeness, we present several applications in which it is instrumental in obtaining security. First, we construct a certifiable version of Verifiable Secret Sharing (VSS), which is a VSS in which the dealer additionally proves that the shared secret satisfies a given NP relation. Our construction withstands a constant fraction of corruptions, whereas a previous construction of Ishai et al. (TCC‘14) required k=( t) . We also design a reusable version of certifiable VSS that we introduce, in which the dealer can prove an unlimited number of predicates on the same shared secret. Finally, we extend a compiler of Boneh et al. (CRYPTO‘19), who used dZKs to transform a class of “natural” semi-honest protocols in the honest-majority setting into maliciously secure ones with abort. Our compiler uses strongly-complete dZKs to obtain identifiable abort.
This technical paper explores two solutions for arithmetization of computational integrity statements in STARKs, namely the algebraic intermediate representation, AIR, and its preprocessed variant, PAIR. The work then focuses on their soundness implications for Reed–Solomon proximity testing. It proceeds by presenting a comparative study of these methods, providing their theoretical foundations and deriving the degree bounds for low-degree proximity testing. The study shows that using PAIR increases the degree bound for Reed–Solomon proximity testing, which affects its soundness and complexity. However, the possibility of reducing the degree bound with multiple selector columns is also explored, namely by following an approach based on the decomposition of the selector values. Focusing on performance optimization, the work proceeds by qualitatively comparing computational demands of the components of both arithmetization methods, particularly their impact on the low-degree extensions. The paper concludes that, while PAIR might simplify constraint enforcement, it can be easily translated to AIR, and system testing with benchmarks is necessary to determine the application-specific superiority of either method. This work should provide insight into the strengths and limitations of each method, helping researchers and practitioners in the field of STARKs make informed design choices.
An important classification of permutations over F2m, suitable for constructing Maiorana-McFarland bent functions on F2mxF2m with the unique M-subspace of maximal dimension, was recently considered in Pasalic et al (IEEE Trans Inf Theory 70:4464-4477, 2024). More precisely, two properties called (P1) and (P2) were introduced and a generic method of constructing permutations having the property (P1) was presented, whereas no such results were provided related to the (P2) property. In this article, we provide a deeper insight on these properties, their mutual relationship, and specify some explicit classes of permutations having these properties. Such permutations are then employed to generate a large variety of bent functions outside the completed Maiorana-McFarland class M#. We also introduce l-optimal bent functions as bent functions with the lowest possible linearity index; such functions can be considered as opposite to Maiorana-McFarland bent functions. We give explicit constructions of l-optimal bent functions within the D0 class, which in turn can be employed in certain secondary constructions of bent functions (Zhang et al in Inf Comput 297:105149, 2024) for providing even more classes of bent functions that are provably outside M#. Moreover, we demonstrate that a certain subclass of D0 has an additional property of having only 5-valued spectra decompositions, similarly to the only result in this direction concerning monomial bent functions (Canteaut and Charpin in IEEE Trans Inf Theory 498:2004-2019, 2003). Finally, we generalize the so-called swapping variables method introduced in Pasalic et al. (IEEE Trans Inf Theory 70:4464-4477, 2024) which then allows us to specify much larger families of bent functions outside M# compared to Pasalic et al (IEEE Trans Inf Theory 70:4464-4477, 2024). In this way, we give a better explanation of the origin of bent functions in dimension eight, since the vast majority of them is outside M#, as indicated in Langevin and Leander (Designs Codes Cryptogr 59:193-205, 2011).
Fully homomorphic encryption (FHE) enables secure data processing without compromising data access. However, its computational cost and slower execution compared to plaintext operations present significant challenges. The increasing interest in FHE-based secure computation underscores the need to accelerate homomorphic computations. Existing research predominantly focuses on reducing the multiplicative depth (MD) of FHE circuits, as a lower MD enhances the execution efficiency of each homomorphic operation. However, this often comes at the expense of increased multiplicative complexity (MC), leading to more homomorphic multiplications - a computationally intensive task. Currently, there is a lack of approaches that effectively balance the trade-off between MD reduction and MC increase, potentially resulting in sub-optimal outcomes. This paper addresses this critical gap with three main contributions: (a) an exact synthesis paradigm for generating optimal FHE circuit implementations, (b) a heuristic circuit optimization algorithm, named MC-aware MD minimization, that leverages the exact synthesis paradigm to optimize FHE circuits efficiently, and (c) an FHE circuit optimization flow that integrates MC-aware MD minimization with existing MD reduction techniques. Experimental results demonstrate a 21.32% average reduction in homomorphic computation time and highlight significantly improved efficiency in circuit optimization.