This paper introduces a bearingless motor topology with a magnet-free rotor that provides a higher rotor torque density and wider magnetic air gap compared to previously published topologies. The stray flux is minimized by using a stator with only eight teeth in temple configuration that contain permanent magnets. The motor performance is analyzed based on experimental prototypes, that were designed using 3D FEM simulations, for even and odd rotor pole pair numbers of six and nine, respectively. Control schemes that compensate parasitic radial forces to achieve stable magnetic levitation of the rotors are presented. The implemented prototypes reached a rotational speed of 2000 rpm and a maximum torque of 8 Nm.
This paper uses a variant of the notion of inaccessible entropy (Haitner, Reingold, Vadhan and Wee, STOC 2009), to give an alternative construction and proof for the fundamental result, first proved by Rompel (STOC 1990), that Universal One-Way Hash Functions (UOWHFs) can be based on any one-way functions. We observe that a small tweak of any one-way function f is already a weak form of a UOWHF: consider the function F (x,i) that returns the i-bit-long prefix of f (x). If F were a UOWHF then given a random x and i it would be hard to come up with x' not equal x such that F (x, i) = F (x', i) . While this may not be the case, we show (rather easily) that it is hard to sample x' with almost full entropy among all the possible such values of x'. The rest of our construction simply amplifies and exploits this basic property. Combined with other recent work, the construction of three fundamental cryptographic primitives (Pseudorandom Generators, Statistically Hiding Commitments and UOWHFs) out of one-way functions is now to a large extent unified. In particular, all three constructions rely on and manipulate computational notions of entropy in similar ways. Pseudorandom Generators rely on the well-established notion of pseudoentropy, whereas Statistically Hiding Commitments and UOWHFs rely on the newer notion of inaccessible entropy. In an additional result we reprove the seminal result of Impagliazzo and Levin (FOCS 1989): a reduction from "uniform distribution" average-case complexity problems to ones with arbitrary (polynomial-time samplable) distributions. We do that using techniques similar to those we use to construct UOWHFs from one-way functions, where the source of this similarity is the use of a notion similar to inaccessible entropy. This draws an interesting connection between two seemingly separate lines of research: average-case complexity and universal one-way hash-functions.
Recent years have Shown a development of electrical drive systems toward high rotational speeds to increase the power density. Applications such as optical systems benefit from rotational speeds at which conventional ball bearings suffer from high losses, excessive wear, and decreased reliability. In such cases, magnetic bearings offer an interesting alternative. This work presents a universally applicable design procedure for miniature bearingless slice motors intended for rotational speeds of several hundred thousand revolutions per minute. Design trade-offs are illustrated and facilitate the selection of Pareto-optimal implementations. An exemplary motor prototype for rotational speeds of up to 760 000 rpm with a rotor diameter of 4 mm and a suitable inverter featuring an FPGA-based controller are demonstrated briefly.
This paper presents a bearingless synchronous reluctance slice motor, which contains no permanent magnets. The rotor with four iron poles and flux barriers is levitated and rotated through a stator winding system with six coils wired as two three-phase systems. After applying a constant rotor oriented magnetization current, the system can be controlled just like a bearingless permanent magnet synchronous slice motor, including the passive stabilization of axial and tilting movements. In a first step, the motor geometry is being optimized and the performance characteristics of the designed motor are examined. The motor is then compared to two other designs, which contain permanent magnets either in the rotor or the stator. The comparison includes torque generation, radial force generation, passive axial and tilting stiffnesses and wide air gap suitability. The introduced topology outperforms the others for ultra high process or ambient temperatures and rotor disposable applications with a short exchange interval.
Private simultaneous message (PSM) protocols were introduced by Feige, Kilian, and Naor (STOC ’94) as a minimal non-interactive model for information theoretic three-party secure computation. While it is known that every function $$f:\{0,1\}^k\times \{0,1\}^k \rightarrow \{0,1\}$$ admits a PSM protocol with exponential communication of $$2^{k/2}$$ (Beimel et al., TCC ’14), the best known (non-explicit) lower-bound is $$3k-O(1)$$ bits. To prove this lower-bound, FKN identified a set of simple requirements, showed that any function that satisfies these requirements is subject to the $$3k-O(1)$$ lower-bound, and proved that a random function is likely to satisfy the requirements. We revisit the FKN lower-bound and prove the following results: (Counterexample) We construct a function that satisfies the FKN requirements but has a PSM protocol with communication of $$2k+O(1)$$ bits, revealing a gap in the FKN proof. (PSM lower-bounds) We show that by imposing additional requirements, the FKN argument can be fixed leading to a $$3k-O(\log k)$$ lower-bound for a random function. We also get a similar lower-bound for a function that can be computed by a polynomial-size circuit (or even polynomial-time Turing machine under standard complexity-theoretic assumptions). This yields the first non-trivial lower-bound for an explicit Boolean function partially resolving an open problem of Data, Prabhakaran, and Prabhakaran (Crypto ’14, IEEE Information Theory ’16). We further extend these results to the setting of imperfect PSM protocols which may have small correctness or privacy error. (CDS lower-bounds) We show that the original FKN argument applies (as is) to some weak form of PSM protocols which are strongly related to the setting of Conditional Disclosure of Secrets (CDS). This connection yields a simple combinatorial criterion for establishing linear $$\varOmega (k)$$-bit CDS lower-bounds. As a corollary, we settle the complexity of the inner-product predicate resolving an open problem of Gay, Kerenidis, and Wee (Crypto ’15).
Product Space Models of Correlation: Between Noise Stability and Additive Combinatorics, Discrete Analysis 2018:20, 63 pp. Szemerédi's theorem states that for every positive integer $\ell$ and every $\mu>0$ there exists $N$ such that every subset of $\{1,2,\dots,N\}$ of density at least $\mu$ contains an arithmetic progression of length $\ell$. It is not hard to prove that this is equivalent to the statement that if $N$ is sufficiently large, then every function $f:\mathbb Z_N\to[0,1]$ (where $\mathbb Z_N$ is the cyclic group of order $N$) with average value at least $\mu$ satisfies an inequality of the form $$\mathbb E_{x,d}f(x)f(x+d)\dots f(x+(\ell-1)d)\geq \delta$$ where $\delta$ is a positive constant that depends only on $\mu$ and $\ell$. We can express this as a statement about a product of random variables, as follows. Let $x$ and $d$ be chosen uniformly at random and for each $1\leq i\leq\ell$ let $X^{(i)}$ be the random variable that takes the value $x+(i-1)d$. Then for every function $f:\mathbb Z_N$ that takes values in $[0,1]$, if $\mathbb E[f(X^{(i)})]\geq\mu$ for each $i$, then we also have that $\mathbb E f(X^{(1)})\dots f(X^{(\ell)})\geq\delta$. A sequence of random variables with this property is called _same-set hitting_. Note that the random variables $X^{(i)}$ here are not independent, but they are individually uniformly distributed. In particular, they are identically distributed. The equivalent form of Szemerédi's theorem given above can be stated and proved for other Abelian groups. A particularly well-known case is when the group is $\mathbb F_p^n$ for some fixed prime $p\geq\ell$. Here we can say more about the corresponding random variables $X^{(i)}$. Now they take values in $\mathbb F_p^n$, and if for each coordinate $j$ we form the vector $\underline{X}_j=(X^{(1)}_j,\dots,X^{(\ell)}_j)$, we find that the vectors $\underline{X}_j$ are independent and identically distributed. Indeed, each one is a random (possibly degenerate) arithmetic progression in the group $\mathbb F_p$. The purpose of this paper is to consider this situation in general, and in particular to try to understand which systems of random variables $X^{(1)},\dots,X^{(\ell)}$ satisfying the above conditions are same-set hitting. A related concept, which also comes up in additive combinatorics, is that of being _set hitting_. This is the natural off-diagonal strengthening of being same-set hitting. That is, the random variables are set hitting if whenever $f_1,\dots,f_\ell$ are functions taking values in $[0,1]$ and $\mathbb Ef_i(X^{(i)})\geq\mu$ for each $i$, we have that $\mathbb Ef_1(X^{(1)})\dots f_\ell(X^{(\ell)})\geq\delta$, where once again $\delta$ depends only on $\mu$ and $\ell$. To see that this is a considerably stronger property, one need only look at the case of random arithmetic progressions $(X^{(1)},X^{(2)},X^{(3)})$ of length 3 in $\mathbb F_3^n$. If we let $f_1=f_2(x)=1$ if $x_1=0$ and $0$ otherwise, and $f_3(x)=1$ if $x_1=1$ and $0$ otherwise, then each $\mathbb E f_i(X^{(i)})$ is equal to 1/3, but the product $f_1(X^{(1)})f_2(X^{(2)})f_3(X^{(3)})$ is identically zero. It turns out to be useful in the theory of noise stability to characterize set hitting distributions, and this has been done. But it is harder to characterize same-set hitting distributions. One of the main results of the paper is a characterization in the case $\ell=2$. This is already an interesting case: for example, a consequence of their results is the non-obvious fact that for all $\mu>0$ there exists $\delta>0$ such that if $A$ is a dense subset of $\mathbb F_3^n$ and $(x,y)\in\mathbb F_3^n$ is chosen randomly from all pairs with the property that $y_j-x_j\in\{0,1\}$ for every coordinate $j$, then with probability at least $\delta$ both $x$ and $y$ belong to $A$. For $\ell>2$, sufficient conditions are obtained. The paper uses techniques from both additive combinatorics and the theory of noise sensitivity, combining the two fields in a new and interesting way. It also contains several interesting open problems.
This paper introduces a bearingless motor topology with a magnet free rotor, which enables higher rotor torque densities and wider air gap compared to previously published topologies. Flux density in the air gap and therefore torque capability is maximized by a stator in temple configuration, which provides large winding space. The low number of eight stator and six rotor teeth keeps stray flux low, which enables wider air gap ratios at the same time. A challenge of having a low teeth number are large angle dependent force and torque nonlinearities, which are compensated in the control algorithm. A 3D FEM optimized prototype was constructed and put into operation. Measurements of the running system are presented to confirm the feasibility of the introduced topology.
We study a special kind of bounds (so called forbidden subgraph bounds, cf. Feige, Verbitsky '02) for parallel repetition of multi-prover games. First, we show that forbidden subgraph upper bounds for $r \ge 3$ provers imply the same bounds for the density Hales-Jewett theorem for alphabet of size $r$. As a consequence, this yields a new family of games with slow decrease in the parallel repetition value. Second, we introduce a new technique for proving exponential forbidden subgraph upper bounds and explore its power and limitations. In particular, we obtain exponential upper bounds for two-prover games with question graphs of treewidth at most two and show that our method cannot give exponential bounds for all two-prover graphs.
We propose a method to automatically derive hardware structures that perform a fixed linear permutation on streaming data. Linear permutations are permutations that map linearly the bit representation of the elements addresses. This set contains many of the most important permutations in media processing, communication, and other applications and includes perfect shuffles, stride permutations, and the bit reversal. Streaming means that the data to be permuted arrive as a sequence of chunks over several cycles. We solve this problem by mathematically decomposing a given permutation into a sequence of three permutations that are either temporal or spatial. The former are implemented as banks of RAM, the latter as switching networks. We prove optimality of our solution in terms of the number of switches in these networks.
We study generalisations of a simple, combinatorial proof of a Chernoff bound similar to the one by Impagliazzo and Kabanets (RANDOM, 2010). In particular, we prove a randomized version of the hitting property of expander random walks and apply it to obtain a concentration bound for expander random walks which is essentially optimal for small deviations and a large number of steps. At the same time, we present a simpler proof that still yields a "right" bound settling a question asked by Impagliazzo and Kabanets. Next, we obtain a simple upper tail bound for polynomials with input variables in $[0, 1]$ which are not necessarily independent, but obey a certain condition inspired by Impagliazzo and Kabanets. The resulting bound is used by Holenstein and Sinha (FOCS, 2012) in the proof of a lower bound for the number of calls in a black-box construction of a pseudorandom generator from a one-way function. We then show that the same technique yields the upper tail bound for the number of copies of a fixed graph in an Erd\H{o}s-R\'enyi random graph, matching the one given by Janson, Oleszkiewicz and Ruci\'nski (Israel J. Math, 2002).
An integral quadratic form is a homogeneous polynomial of uniform degree~2 in several variables e.g., an $n$-ary integral quadratic form in variables $x_1,\cdots, x_n$ looks like $\sum_{1 \leq i, j \leq n}a_{ij}x_ix_j$, where $a_{ij}=a_{ji} \in \mathbb{Z}$. We present a $\text{poly}(n,k, \log p, \log t)$ randomize algorithm that given a quadratic form $\mathtt{Q}^n$ and an integer $t$, samples a uniform solution of $\mathtt{Q}(x_1,\cdots,x_n)\equiv t \bmod{p^k}$.
This paper provides the first provably secure construction of an invertible random permutation (and of an ideal cipher) from a public random function that can be evaluated by all parties in the system, including the adversary. The associated security goal was formalized via the notion of indifferentiability by Maurer et al. (TCC 2004). The problem is the natural extension of that of building (invertible) random permutations from (private) random functions, first solved by Luby and Rackoff (SIAM J Comput 17(2):373–386, 1988) via the four-round Feistel construction. As our main result, we prove that the Feistel construction with fourteen rounds is indifferentiable from an invertible random permutation. We also provide a new lower bound showing that five rounds are not sufficient to achieve indifferentiability. A major corollary of our result is the equivalence (in a well-defined sense) of the random oracle model and the ideal cipher model.
We would like to stress that the ETH Disciplinary Code applies to this special assignment as it constitutes part of your final grade. The only exception we make to the Code is that we encourage you to verbally discuss the tasks with your colleagues. It is strictly prohibited to share any (hand)written or electronic (partial) solutions with any of your colleagues. We are obligated to inform the Rector of any violations of the Code.
(b) For this part (and also then Part (c)) of the exercise, it is crucial to make use of the special (increasing) order of the keys in which the nodes are inserted into the treap. The fact that the key of every current node i is strictly larger than all keys already in the treap implies that temporarily |at the start of its insertion| it must always end up as the right-most leaf of the current treap. This means that after the necessary rotations for its insertion are completed, our node must end up somewhere on the right spine of the treap. Furthermore, all rotations that will ever be performed in the whole process are
We study the result by Bogdanov and Trevisan (FOCS, 2003), who show that under reasonable assumptions, there is no non-adaptive reduction that bases the average-case hardness of an NP-problem on the worst-case complexity of an NP-complete problem. We replace the hiding and the heavy samples protocol in [BT03] by employing the histogram verification protocol of Haitner, Mahmoody and Xiao (CCC, 2010), which proves to be very useful in this context. Once the histogram is verified, our hiding protocol is directly public-coin, whereas the intuition behind the original protocol inherently relies on private coins.
We give an AM protocol that allows the verifier to sample elements x from a probability distribution P, which is held by the prover. If the prover is honest, the verifier outputs (x, P(x)) with probability close to P(x).In case the prover is dishonest, one may hope for the following guarantee: if the verifier outputs (x, p), then the probability that the verifier outputs x is close to p. Simple examples show that this cannot be achieved. Instead, we show that the following weaker condition holds (in a well defined sense) on average: If (x, p) is output, then p is an upper bound on the probability that x is output.Our protocol yields a new transformation to turn interactive proofs where the verifier uses private random coins into proofs with public coins. The verifier has better running time compared to the well-known Goldwasser-Sipser transformation (STOC, 1986). For constant-round protocols, we only lose an arbitrarily small constant in soundness and completeness, while our public-coin verifier calls the private-coin verifier only once.
An $n$-ary integral quadratic form is a formal expression $Q(x_1,...,x_n)=\sum_{1\leq i,j\leq n}a_{ij}x_ix_j$ in $n$-variables $x_1,...,x_n$, where $a_{ij}=a_{ji} \in \mathbb{Z}$. We present a poly$(n,k, \log p, \log t)$ randomized algorithm that given a quadratic form $Q(x_1,...,x_n)$, a prime $p$, a positive integer $k$ and an integer $t$, samples a uniform solution of $Q(x_1,...,x_n)\equiv t \bmod{p^k}$.
Let p be a prime and k, t be positive integers. Given a quadratic equation Q(x1,x2,...,xn)=t mod p^k in n-variables; we present a polynomial time Las-Vegas algorithm that samples a uniformly random solution of the quadratic equation.
General rules for solving exercises This is a theory course, which means: if an exercise does not explicitly say \you do not need to prove your answer" or \justify intuitively", then a formal proof is always required. All exercises and their solutions, no matter whether they are graded or regular/optional ones, are part of the material relevant for the two exams. Some of the exercises are marked as "in-class", which means that we do not expect you to solve them before the exercise session. Instead, your teaching assistant will solve them with you in class. You are highly encouraged to solve all other exercises (those not marked as "in-class") on your own and to hand in a writeup of your solutions no later than the due date. If you choose to do so, please write the name of your teaching assistant on the front sheet.
Given a non-empty genus in $n$ dimensions with determinant $d$, we give a randomized algorithm that outputs a quadratic form from this genus. The time complexity of the algorithm is poly$(n,\log d)$; assuming Generalized Riemann Hypothesis (GRH).
Liad Blumrosen合作论文数hebrew university3
Martin Hirt合作论文数Institute of Theoretical Computer Science2