nizks with an untrusted crs security in the face of
play

NIZKs with an untrusted CRS: Security in the face of parameter - PowerPoint PPT Presentation

NIZKs with an untrusted CRS: Security in the face of parameter subversion Mihir Bellare Alessandra Scafuro Georg Fuchsbauer Asiacrypt 2016 Motivation 2013 compromised security not covered by standard model here: parameter


  1. NIZKs with an untrusted CRS: Security in the face of parameter subversion Mihir Bellare Alessandra Scafuro Georg Fuchsbauer Asiacrypt 2016

  2. Motivation • 2013 • compromised security not covered by standard model • here: parameter subversion

  3. Motivation • 2013 • compromised security not covered by standard model • here: parameter subversion • example: Dual EC RNG – “trusted” parameters P, Q – int’l standard; NSA paid RSA $10 million – knowledge of log Q P ⇒ predictable [ShuFer07] ⇒ break TLS [CFN + 14]

  4. Motivation • 2013 • compromised security not covered by standard model • here: parameter subversion • goal: subversion resistance • this work: NIZK, relies on common reference string ( ) • example: zk-SNARK parameters ) [BCG + 14] for Zerocash (

  5. Related work NIZK • 2-move ZK protocols [BLV03, Pass03, BP04, BCPR14] • NIZK in bare PK model [Wee07] • CRS via multiparty computation [KKZZ14, BSCG + 15] • UC w/ adv. CRS [CPs07], multiple CRSs [GO07, GGJS11]

  6. Related work NIZK • 2-move ZK protocols [BLV03, Pass03, BP04, BCPR14] • NIZK in bare PK model [Wee07] • CRS via multiparty computation [KKZZ14, BSCG + 15] • UC w/ adv. CRS [CPs07], multiple CRSs [GO07, GGJS11] Subversion • Algorithm-substitution attacks [BPR14, AMV15] • Kleptography [YY96, YY97], cliptography [RTYZ16] • Backdoored blockciphers [RP97, PG97, Pat99]

  7. Non-interactive proofs • let L ∈ NP crs • prove x ∈ L π � / × Prover: x, w Verifier: x

  8. Non-interactive proofs crs π Soundness: π � ⇒ x ∈ L Prover: x, w Verifier: x

  9. Non-interactive proofs crs π Witness-indistinguishability: π [ w ] ≈ c π [ w ′ ] Prover: x, w Verifier: x

  10. Non-interactive proofs crs π Zero-knowledge: crs ′ π ′ Prover: x, w Verifier: x × Simulator: x, w

  11. Non-interactive proofs crs π ≈ s Zero-knowledge: crs ′ π ′ Prover: x, w Verifier: x × Simulator: x, w

  12. Subversion-resistant NI proofs crs π Subversion Soundness: π � ⇒ x ∈ L Prover: x, w Verifier: x

  13. Subversion-resistant NI proofs crs π Subversion WI: π [ w ] ≈ c π [ w ′ ] Prover: x, w Verifier: x

  14. Non-interactive proofs crs π ≈ s Zero-knowledge: crs ′ π ′ Prover: x, w Verifier: x × Simulator: x, w

  15. Subversion-resistant NI proofs crs $ π ≈ s Subversion ZK: crs ′ , $ ′ π ′ Prover: x, w Verifier: x × Simulator: x, w

  16. Subversion-resistant NI proofs crs $ π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , π ′ Prover: x, w Verifier: x × Simulator: x, w

  17. Our results S-SND S-ZK ✲ S-WI ❄ ❄ ❄ SND ZK ✲ WI

  18. Our results S-SND S-ZK ✲ S-WI ❄ ❄ ❄ SND ZK ✲ WI

  19. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI

  20. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI � — • ε � Prover: x, w Verifier: x

  21. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI � — • w w witness for x ? Prover: x, w Verifier: x

  22. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI ? ? ? • • •

  23. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • (if L is non-trivial) crs x, π Breaking S-SND: π � ∧ x / ∈ L

  24. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • (if L is non-trivial) crs ′ x, π ′ Breaking S-SND: π � ∧ x / ∈ L

  25. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • ? • • • •

  26. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • � DLin • • • • Non-interactive Zaps [GOS06] • NI WI proofs • without CRS No CRS ⇒ subversion-resistant

  27. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • � DLin • • • • ? • • • • •

  28. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • � DLin • • • • ? • • • • • • implies 2-move ZK (verifier chooses CRS) ⇒ only achieved under extractability assumpt’s [BCPR14] • construction under new knowledge of exponent assumption

  29. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ ,

  30. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , KEA : ∀ → ( g s , h s ) ( g, h ) →

  31. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , KEA : ∀ → ( g s , h s ) ( g, h ) → ∃ → → s

  32. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , idea: KEA : ∀ → ( g s , h s ) ( g, h ) → crs ∃ trapdoor → → s

  33. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , idea: KEA : ∀ → ( g s , h s ) ( g, h ) → crs ∃ trapdoor → → s Zap! Prove: x ∈ L ∨ “I know s ”

  34. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , idea: KEA : ∀ → ( g s , h s ) ( g, h ) → crs ∃ trapdoor → → s who chooses h ? Prove: x ∈ L ∨ “I know s ”

  35. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , ∀ → ( g s , h s , h = g η ) DH-KEA : ∃ → → s OR → η Prove: x ∈ L ∨ “I know s or η ”

  36. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , crs = ( g s , h s , h = g η ) prove knowledge how? Prove: x ∈ L ∨ “I know s or η ”

  37. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , crs = ( g s , h s , h = g η ) Enc ( pk, s ) prove knowledge how? Prove: x ∈ L ∨ “I know s or η ”

  38. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , ? crs = ( g s , h s , h = g η ) Enc ( pk, s ) pk prove knowledge how? Prove: x ∈ L ∨ “I know s or η ”

  39. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , crs = ( g s , h s , h = g η ) Enc ( pk, s ) pk prove knowledge how? Prove: x ∈ L ∨ “I know s or η ”

  40. Achieving SND + S-ZK π ∀ ∃ ∀ : � � � � ≈ c crs , $ , crs ′ , $ ′ , crs = ( g s , h s , h = g η ) Enc ( pk, s ) pk prove knowledge how? + KEA-proof of sk Prove: x ∈ L ∨ “I know s or η ”

  41. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • � DLin • • • • � DH-KEA • • • • •

  42. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • � DLin • • • • � DH-KEA • • • • • � NIZK • • • •

  43. Our results Standard Subversion-resistant Possible? Assumpt’s: SND ZK WI S-SND S-ZK S-WI × • • � DLin • • • • � DH-KEA • • • • • � NIZK • • • • QUESTIONS? THANK YOU!

Recommend


More recommend