Quantum Oblivious LWE Sampling and Insecurity of Standard Model Lattice-Based SNARKs

被引:0
|
作者
Debris-Alazard, Thomas [1 ,2 ]
Fallahpour, Pouria [3 ,4 ]
Stehle, Damien [3 ,4 ,5 ]
机构
[1] INRIA, Palaiseau, France
[2] Ecole Polytech, Lab LIX, Palaiseau, France
[3] ENS Lyon, Lyon, France
[4] U Lyon, UCBL, ENS Lyon, LIP,CNRS,Inria, Lyon, France
[5] Cryptolab Inc, Lyon, France
关键词
learning with errors; oblivious sampling; quantum algorithms; succint non-interactive arguments of knowledge;
D O I
10.1145/3618260.3649766
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Learning With Errors (LWE) problem asks to find s from an input of the form (A, b = As+e) epsilon (Z/qZ)(m x n) x (Z/qZ)(m), for a vector e that has small-magnitude entries. In this work, we do not focus on solving LWE but on the task of sampling instances. As these are extremely sparse in their range, it may seem plausible that the only way to proceed is to first create s and e and then set b = As+e. In particular, such an instance sampler knows the solution. This raises the question whether it is possible to obliviously sample (A, As+e), namely, without knowing the underlying s. A variant of the assumption that oblivious LWE sampling is hard has been used in a series of works to analyze the security of candidate constructions of Succinct Non-interactive Arguments of Knowledge (SNARKs). As the assumption is related to LWE, these SNARKs have been conjectured to be secure in the presence of quantum adversaries. Our main result is a quantum polynomial-time algorithm that samples well-distributed LWE instances while provably not knowing the solution, under the assumption that LWE is hard. Moreover, the approach works for a vast range of LWE parametrizations, including those used in the above-mentioned SNARKs. This invalidates the assumptions used in their security analyses, although it does not yield attacks against the constructions themselves.
引用
收藏
页码:423 / 434
页数:12
相关论文
共 50 条
  • [21] Lattice-based certificateless public-key encryption in the standard model
    Sepahi, Reza
    Steinfeld, Ron
    Pieprzyk, Josef
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2014, 13 (04) : 315 - 333
  • [22] Lattice-Based Completely Non-malleable PKE in the Standard Model
    Sepahi, Reza
    Steinfeld, Ron
    Pieprzyk, Josef
    INFORMATION SECURITY AND PRIVACY, 2011, 6812 : 407 - 411
  • [23] Oblivious Transfer via Lossy Encryption from Lattice-Based Cryptography
    Li, Zengpeng
    Xiang, Can
    Wang, Chengyu
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2018,
  • [24] Lattice-based hierarchical identity-based broadcast encryption scheme in the standard model
    Tang Yongli
    Wang Mingming
    Ye Qing
    Qin Panke
    Zhao Zongqu
    The Journal of China Universities of Posts and Telecommunications, 2019, (04) : 70 - 79
  • [25] A Lattice-Based Identity-Based Proxy Blind Signature Scheme in the Standard Model
    Zhang, Lili
    Ma, Yanqin
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2014, 2014
  • [26] Lattice-based hierarchical identity-based broadcast encryption scheme in the standard model
    Tang Yongli
    Wang Mingming
    Ye Qing
    Qin Panke
    Zhao Zongqu
    The Journal of China Universities of Posts and Telecommunications, 2019, 26 (04) : 70 - 79
  • [27] Lattice-Based IBE with Equality Test Supporting Flexible Authorization in the Standard Model
    Nguyen, Giang Linh Duc
    Susilo, Willy
    Dung Hoang Duong
    Huy Quoc Le
    Guo, Fuchun
    PROGRESS IN CRYPTOLOGY - INDOCRYPT 2020, 2020, 12578 : 624 - 643
  • [28] Improved lattice-based CCA2-secure PKE in the standard model
    Zhang, Jiang
    Yu, Yu
    Fan, Shuqin
    Zhang, Zhenfeng
    SCIENCE CHINA-INFORMATION SCIENCES, 2020, 63 (08)
  • [29] Lattice-based hierarchical identity-based broadcast encryption scheme in the standard model
    Yongli T.
    Mingming W.
    Qing Y.
    Panke Q.
    Zongqu Z.
    Journal of China Universities of Posts and Telecommunications, 2019, 26 (04): : 70 - 79
  • [30] Improved lattice-based CCA2-secure PKE in the standard model
    Jiang Zhang
    Yu Yu
    Shuqin Fan
    Zhenfeng Zhang
    Science China Information Sciences, 2020, 63