On the Lossiness of the Rabin Trapdoor Function
نویسنده
چکیده
Lossy trapdoor functions, introduced by Peikert and Waters (STOC ’08), are functions that can be generated in two indistinguishable ways: either the function is injective, and there is a trapdoor to invert it, or the function is lossy, meaning that the size of its range is strictly smaller than the size of its domain. Kakvi and Kiltz (EUROCRYPT 2012) proved that the Full Domain Hash signature scheme based on a lossy trapdoor function has a tight security reduction from the lossiness of the trapdoor function. Since Kiltz, O’Neill, and Smith (CRYPTO 2010) showed that the RSA trapdoor function is lossy under the Φ-Hiding assumption of Cachin, Micali, and Stadler (EUROCRYPT ’99), this implies that the RSA Full Domain Hash signature scheme has a tight security reduction from the Φ-Hiding assumption (for public exponents e < N1/4). In this work, we consider the Rabin trapdoor function, i.e. modular squaring over ZN . We show that when adequately restricting its domain (either to the set QRN of quadratic residues, or to (JN )+, the set of positive integers 1 ≤ x ≤ (N − 1)/2 with Jacobi symbol +1) the Rabin trapdoor function is lossy, the injective mode corresponding to Blum integers N = pq with p, q ≡ 3 mod 4, and the lossy mode corresponding to what we call pseudo-Blum integers N = pq with p, q ≡ 1 mod 4. This lossiness result holds under a natural extension of the ΦHiding assumption to the case e = 2 that we call the 2-Φ/4-Hiding assumption. We then use this result to prove that deterministic variants of Rabin-Williams Full Domain Hash signatures have a tight reduction from the 2-Φ/4-Hiding assumption. We also show that these schemes are unlikely to have a tight reduction from the factorization problem by extending a previous “meta-reduction” result by Coron (EUROCRYPT 2002), later corrected by Kakvi and Kiltz (EUROCRYPT 2012). These two results therefore answer one of the main questions left open by Bernstein (EUROCRYPT 2008) in his work on Rabin-Williams signatures.
منابع مشابه
Simplified OAEP for the RSA and Rabin Functions
Optimal Asymmetric Encryption Padding (OAEP) is a technique for converting the RSA trapdoor permutation into a chosen ciphertext secure system in the random oracle model. OAEP padding can be viewed as two rounds of a Feistel network. We show that for the Rabin and RSA trapdoor functions a much simpler padding scheme is sufficient for chosen ciphertext security in the random oracle model. We sho...
متن کاملA New Rabin-type Trapdoor Permutation Equivalent to Factoring and Its Applications
Public key cryptography has been invented to overcome some key management problems in open networks. Although nearly all aspects of public key cryptography rely on the existence of trapdoor one-way functions, only a very few candidates of this primitive have been observed yet. In this paper, we introduce a new trapdoor one-way permutation based on the hardness of factoring integers of pq-type. ...
متن کاملChosen-Ciphertext Security from Slightly Lossy Trapdoor Functions
Lossy Trapdoor Functions (LTDFs), introduced by Peikert and Waters (STOC 2008) have been useful for building many cryptographic primitives. In particular, by using an LTDF that loses a (1 − 1/ω(log n)) fraction of all its input bits, it is possible to achieve CCA security using the LTDF as a black-box. Unfortunately, not all candidate LTDFs achieve such a high level of lossiness. In this paper ...
متن کاملRegularity of Lossy RSA on Subdomains and Its Applications
We build on an approach of Kiltz et al. (CRYPTO ’10) and bring new techniques to bear on the study of how “lossiness” of the RSA trapdoor permutation under the Φ-Hiding Assumption (ΦA) can be used to understand the security of classical RSA-based cryptographic systems. In particular, we show that, under ΦA, several questions or conjectures about the security of such systems can be reduced to bo...
متن کاملAn Experimental Investigation into the Arching Effect in Fine Sand
In the current paper results of a well instrumented experimental procedure for studying the arching effect in loose and dense sand are presented. The apparatus comprises concentric circular trapdoors with different diameters that can yield downward while stresses and deformations are recorded simultaneously. As the trapdoor starts to yield, the whole soil mass deforms elastically. However, afte...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2013 شماره
صفحات -
تاریخ انتشار 2013