Extracting Randomness from Extractor-Dependent Sources

被引:9
|
作者
Dodis, Yevgeniy [1 ]
Vaikuntanathan, Vinod [2 ]
Wichs, Daniel [3 ,4 ]
机构
[1] NYU, New York, NY USA
[2] MIT, Cambridge, MA 02139 USA
[3] Northeastern Univ, Boston, MA 02115 USA
[4] NTT Res Inc, East Palo Altos, CA 94303 USA
基金
美国国家科学基金会;
关键词
D O I
10.1007/978-3-030-45721-1_12
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We revisit the well-studied problem of extracting nearly uniform randomness from an arbitrary source of sufficient min-entropy. Strong seeded extractors solve this problem by relying on a public random seed, which is unknown to the source. Here, we consider a setting where the seed is reused over time and the source may depend on prior calls to the extractor with the same seed. Can we still extract nearly uniform randomness? In more detail, we assume the seed is chosen randomly, but the source can make arbitrary oracle queries to the extractor with the given seed before outputting a sample. We require that the sample has entropy and differs from any of the previously queried values. The extracted output should look uniform even to a distinguisher that gets the seed. We consider two variants of the problem, depending on whether the source only outputs the sample, or whether it can also output some correlated public auxiliary information that preserves the sample's entropy. Our results are: Without Auxiliary Information: We show that every pseudo-random function (PRF) with a sufficiently high security level is a good extractor in this setting, even if the distinguisher is computationally unbounded. We further show that the source necessarily needs to be computationally bounded and that such extractors imply one-way functions. With Auxiliary Information: We construct secure extractors in this setting, as long as both the source and the distinguisher are computationally bounded. We give several constructions based on different intermediate primitives, yielding instantiations based on the DDH, DLIN, LWE or DCR assumptions. On the negative side, we show that one cannot prove security against computationally unbounded distinguishers in this setting under any standard assumption via a black-box reduction. Furthermore, even when restricting to computationally bounded distinguishers, we show that there exist PRFs that are insecure as extractors in this setting and that a large class of constructions cannot be proven secure via a black-box reduction from standard assumptions.
引用
收藏
页码:313 / 342
页数:30
相关论文
共 50 条
  • [21] Extracting randomness: How and why a survey
    Nisan, N
    ELEVENTH ANNUAL IEEE CONFERENCE ON COMPUTATIONAL COMPLEXITY, PROCEEDINGS, 1996, : 44 - 58
  • [22] Extracting classical randomness in a quantum world
    Renner, Renato
    2008 IEEE INFORMATION THEORY WORKSHOP, 2008, : 360 - 363
  • [23] Extracting randomness within a subset is hard
    Kjos-Hanssen, Bjorn
    Liu, Lu
    EUROPEAN JOURNAL OF MATHEMATICS, 2020, 6 (04) : 1438 - 1451
  • [24] Extracting randomness via repeated condensing
    Reingold, O
    Shaltiel, R
    Wigderson, A
    SIAM JOURNAL ON COMPUTING, 2006, 35 (05) : 1185 - 1209
  • [25] Extracting energy from multiple sources
    Donaldson, Laurie
    MATERIALS TODAY, 2017, 20 (04) : 164 - 165
  • [26] How to Extract Useful Randomness from Unreliable Sources
    Aggarwal, Divesh
    Obremski, Maciej
    Ribeiro, Joao
    Siniscalchi, Luisa
    Visconti, Ivan
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2020, PT I, 2020, 12105 : 343 - 372
  • [27] Certified Randomness from Untrusted Sources and Uncharacterized Measurements
    Lin, Xing
    Wang, Rong
    Wang, Shuang
    Yin, Zhen-Qiang
    Chen, Wei
    Guo, Guang-Can
    Han, Zheng-Fu
    PHYSICAL REVIEW LETTERS, 2022, 129 (05)
  • [28] Improved randomness extraction from two independent sources
    Dodis, Y
    Elbaz, A
    Oliveira, R
    Raz, R
    APPROXIMATION, RANDOMIZATION, AND COMBINATORIAL OPTIMIZATION: ALGORITHMS AND TECHNIQUES, PROCEEDINGS, 2004, 3122 : 334 - 344
  • [29] Common Randomness Generation from Sources with Countable Alphabet
    Labidi, Wafa
    Ezzine, Rami
    Deppe, Christian
    Wiese, Moritz
    Boche, Holger
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 2425 - 2430
  • [30] Pure Randomness Extracted from Two Poor Sources
    Monroe, Don
    COMMUNICATIONS OF THE ACM, 2017, 60 (01) : 13 - 15