Theoretical Aspects of Post-Quantum Cryptography

Published  . 0 views
↓ Download
Theoretical Aspects of Post-Quantum Cryptography
1 / 1
Theoretical Aspects of Post-Quantum Cryptography - slide 1 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 2 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 3 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 4 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 5 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 6 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 7 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 8 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 9 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 10 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 11 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 12 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 13 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 14 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 15 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 16 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 17 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 18 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 19 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 20 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 21 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 22 of 23 Theoretical Aspects of Post-Quantum Cryptography - slide 23 of 23
Description: Theoretical Aspects of Post-Quantum Cryptography III Postquantum Crypto Minischool Kai-Min Chung Fujisaki-Okamoto (FO) Transformation IND-CPA PKE IND-CCA KEM FO transformation OW-CCA PKE Key Encapsulation Mechanism(KEM) Alice Bob Public

Related Topics

Download Presentation

"Theoretical Aspects of Post-Quantum Cryptography" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Theoretical Aspects of
Post-Quantum Cryptography III

Postquantum Crypto Minischool

Kai-Min Chung<br>
slide2. Fujisaki-Okamoto (FO) Transformation IND-CPA PKE IND-CCA KEM FO transformation OW-CCA PKE<br>
slide3. Key Encapsulation Mechanism(KEM) Alice Bob Public Channel Eve Can I get K? K K<br>
slide4. 2022/7/15 4 IND-CCA KEM game Ch RO H<br>
slide5. U Transformation<br>
slide6. 2022/7/15 6 Easy Hard But easy with sk<br>
slide7. 2022/7/15 7<br>
slide8. Reduction OW-CCA secure PKE ๐šท<br>
slide9. Ch R OW-CCA game<br>
slide10. 2022/7/15 10 IND-CCA KEM game Ch RO H<br>
slide11. OW-CCA PKE game IND-CCA KEM game Ch R Take care of Decaps oracle? IND to OW? Take care of RO? Lazy sampling Lazy sampling ?<br>
slide12. Real Decaps Simulated Decapsโ€™ The only difference<br>
slide13. OW-CCA PKE game IND-CCA KEM game Ch R IND to OW? ????????????? ? Lazy sampling<br>
slide14. OW-CCA PKE game IND-CCA KEM game Ch R ????????????? HIT! Observation: This query directly breaks OW-CPA PKE!!! ๐ŸŽŠ ๐Ÿ˜ˆ ๐ŸŽ‰ m<br>
slide15. OW-CCA PKE game IND-CCA KEM game Ch R Doesnโ€™t matter This is what we mainly want. We will soon know why this is useful.<br>
slide16. 2022/7/15 16<br>
slide17. NIST PQC Standardization PKE/KEMs
CRYSTALS-KYBER

Digital Signatures
CRYSTALS-Dilithium

FALCON

SPHINCS+ 17<br>
slide18. NIST PQC Fourth Round Candidate (KEMs) BIKE

Classic McEliece

HQC

SIKE 18<br>
slide19. Variants of FO transformation Fujisaki and Okamoto (1999) proposed an transformation directly from OW-CPA PKE to IND-CCA PKE (under classical ROM)
Hofheinz et al (2017) gives a modular proof to FO-transformation, and introduced plenty different variant of transformation from OW-CPA PKE to IND-CCA KEM
They also achieved security under QROM
There is also tons of other constructions along the history 2022/7/15 19 Our proof today is in fact extracted from this work.<br>
slide20. Quantum Random Oracle Model 2022/7/15 20<br>
slide21. 2022/7/15 21 Quantum Random Oracle Model<br>
slide22. Heuristically assume that a ROM secure scheme is also QROM secure
This is in fact quite widely used
Find other approach to analyze statements proved under classical ROM
Targhi and Unruh (2015) proved (a variant of) Fujisaki-Okamoto transformation is secure in QROM.
Don et el. (2019) proved that Fiat-Shamir transformation is secure in QROM.
This is still an very active area! 2022/7/15 22 Approaches to achieve QROM security<br>
slide23. TAMC course: https://hackmd.io/@csie-tamc/SJTFrm3RF 2022/7/15 23 Thank you!<br>