Theoretical Aspects of Post-Quantum Cryptography
Description: Theoretical Aspects of Post-Quantum Cryptography III Postquantum Crypto Minischool Kai-Min Chung Fujisaki-Okamoto (FO) Transformation IND-CPA PKE IND-CCA KEM FO transformation OW-CCA PKE Key Encapsulation Mechanism(KEM) Alice Bob Public
Related Topics
Download Presentation
"Theoretical Aspects of Post-Quantum Cryptography" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Theoretical Aspects of
Post-Quantum Cryptography III
Postquantum Crypto Minischool
Kai-Min Chung<br>
slide2. Fujisaki-Okamoto (FO) Transformation IND-CPA PKE IND-CCA KEM FO transformation OW-CCA PKE<br>
slide3. Key Encapsulation Mechanism(KEM) Alice Bob Public Channel Eve Can I get K? K K<br>
slide4. 2022/7/15 4 IND-CCA KEM game Ch RO H<br>
slide5. U Transformation<br>
slide6. 2022/7/15 6 Easy Hard But easy with sk<br>
slide7. 2022/7/15 7<br>
slide8. Reduction OW-CCA secure PKE ๐ท<br>
slide9. Ch R OW-CCA game<br>
slide10. 2022/7/15 10 IND-CCA KEM game Ch RO H<br>
slide11. OW-CCA PKE game IND-CCA KEM game Ch R Take care of Decaps oracle? IND to OW? Take care of RO? Lazy sampling Lazy sampling ?<br>
slide12. Real Decaps Simulated Decapsโ The only difference<br>
slide13. OW-CCA PKE game IND-CCA KEM game Ch R IND to OW? ????????????? ? Lazy sampling<br>
slide14. OW-CCA PKE game IND-CCA KEM game Ch R ????????????? HIT! Observation: This query directly breaks OW-CPA PKE!!! ๐ ๐ ๐ m<br>
slide15. OW-CCA PKE game IND-CCA KEM game Ch R Doesnโt matter This is what we mainly want. We will soon know why this is useful.<br>
slide16. 2022/7/15 16<br>
slide17. NIST PQC Standardization PKE/KEMs
CRYSTALS-KYBER
Digital Signatures
CRYSTALS-Dilithium
FALCON
SPHINCS+ 17<br>
slide18. NIST PQC Fourth Round Candidate (KEMs) BIKE
Classic McEliece
HQC
SIKE 18<br>
slide19. Variants of FO transformation Fujisaki and Okamoto (1999) proposed an transformation directly from OW-CPA PKE to IND-CCA PKE (under classical ROM)
Hofheinz et al (2017) gives a modular proof to FO-transformation, and introduced plenty different variant of transformation from OW-CPA PKE to IND-CCA KEM
They also achieved security under QROM
There is also tons of other constructions along the history 2022/7/15 19 Our proof today is in fact extracted from this work.<br>
slide20. Quantum Random Oracle Model 2022/7/15 20<br>
slide21. 2022/7/15 21 Quantum Random Oracle Model<br>
slide22. Heuristically assume that a ROM secure scheme is also QROM secure
This is in fact quite widely used
Find other approach to analyze statements proved under classical ROM
Targhi and Unruh (2015) proved (a variant of) Fujisaki-Okamoto transformation is secure in QROM.
Don et el. (2019) proved that Fiat-Shamir transformation is secure in QROM.
This is still an very active area! 2022/7/15 22 Approaches to achieve QROM security<br>
slide23. TAMC course: https://hackmd.io/@csie-tamc/SJTFrm3RF 2022/7/15 23 Thank you!<br>
Post-Quantum Cryptography III
Postquantum Crypto Minischool
Kai-Min Chung<br>
slide2. Fujisaki-Okamoto (FO) Transformation IND-CPA PKE IND-CCA KEM FO transformation OW-CCA PKE<br>
slide3. Key Encapsulation Mechanism(KEM) Alice Bob Public Channel Eve Can I get K? K K<br>
slide4. 2022/7/15 4 IND-CCA KEM game Ch RO H<br>
slide5. U Transformation<br>
slide6. 2022/7/15 6 Easy Hard But easy with sk<br>
slide7. 2022/7/15 7<br>
slide8. Reduction OW-CCA secure PKE ๐ท<br>
slide9. Ch R OW-CCA game<br>
slide10. 2022/7/15 10 IND-CCA KEM game Ch RO H<br>
slide11. OW-CCA PKE game IND-CCA KEM game Ch R Take care of Decaps oracle? IND to OW? Take care of RO? Lazy sampling Lazy sampling ?<br>
slide12. Real Decaps Simulated Decapsโ The only difference<br>
slide13. OW-CCA PKE game IND-CCA KEM game Ch R IND to OW? ????????????? ? Lazy sampling<br>
slide14. OW-CCA PKE game IND-CCA KEM game Ch R ????????????? HIT! Observation: This query directly breaks OW-CPA PKE!!! ๐ ๐ ๐ m<br>
slide15. OW-CCA PKE game IND-CCA KEM game Ch R Doesnโt matter This is what we mainly want. We will soon know why this is useful.<br>
slide16. 2022/7/15 16<br>
slide17. NIST PQC Standardization PKE/KEMs
CRYSTALS-KYBER
Digital Signatures
CRYSTALS-Dilithium
FALCON
SPHINCS+ 17<br>
slide18. NIST PQC Fourth Round Candidate (KEMs) BIKE
Classic McEliece
HQC
SIKE 18<br>
slide19. Variants of FO transformation Fujisaki and Okamoto (1999) proposed an transformation directly from OW-CPA PKE to IND-CCA PKE (under classical ROM)
Hofheinz et al (2017) gives a modular proof to FO-transformation, and introduced plenty different variant of transformation from OW-CPA PKE to IND-CCA KEM
They also achieved security under QROM
There is also tons of other constructions along the history 2022/7/15 19 Our proof today is in fact extracted from this work.<br>
slide20. Quantum Random Oracle Model 2022/7/15 20<br>
slide21. 2022/7/15 21 Quantum Random Oracle Model<br>
slide22. Heuristically assume that a ROM secure scheme is also QROM secure
This is in fact quite widely used
Find other approach to analyze statements proved under classical ROM
Targhi and Unruh (2015) proved (a variant of) Fujisaki-Okamoto transformation is secure in QROM.
Don et el. (2019) proved that Fiat-Shamir transformation is secure in QROM.
This is still an very active area! 2022/7/15 22 Approaches to achieve QROM security<br>
slide23. TAMC course: https://hackmd.io/@csie-tamc/SJTFrm3RF 2022/7/15 23 Thank you!<br>