Uploaded by TheIACR on Oct 9, 2011
Sanjam Garg, Abhishek Jain, and Amit Sahai
UCLA
Abstract. In this paper, we initiate a study of zero knowledge proof systems in the presence of side-channel attacks. Specifically, we consider a setting where a cheating verifier is allowed to obtain arbitrary bounded leakage on the entire state (including the witness and the random coins) of the prover during the entire protocol execution. We formalize a meaningful definition of leakage-resilient zero knowledge (LR-ZK) proof system, that intuitively guarantees that the protocol does not yield anything beyond the validity of the statement and the leakage obtained by the verifier.
We give a construction of LR-ZK interactive proof system based on standard general assumptions. To the best of our knowledge, this is the first instance of a cryptographic interactive protocol where the adversary is allowed to perform leakage attacks during the protocol execution on the entire state of honest party (in contrast, prior work only considered leakage prior to the protocol execution, or very limited leakage during the protocol execution). Next, we give an LR-NIZK proof system based on standard number-theoretic assumptions.
Finally, we demonstrate the usefulness of our notions by giving two concrete applications:
We initiate a new line of research to relax the assumption on the "tamper-proofness" of hardware tokens used in the design of various cryptographic protocols. In particular, we give a construction of a universally composable multiparty computation protocol in the leaky token model (where an adversary in possession of a token is allowed to obtain arbitrary bounded leakage on the entire state of the token) based on standard general assumptions.
Next, we give simple, generic constructions of fully leakage-resilient signatures in the bounded leakage model as well as the continual leakage model. Unlike the recent constructions of such schemes, we also obtain security in the "noisy leakage" model.
-
1 likes, 1 dislikes
40 videos

Crypto 2011
20:36
Cryptography with Tamperable and Leaky Memory (Crypto 2011)by TheIACR176 views
21:17
Secure Computation on the Web: Computing without Simultaneous Interaction (Crypto 2011)by TheIACR129 views
16:56
1/p-Secure Multiparty Computation without Honest Majority and the Best of Both Worlds (Crypto 2011)by TheIACR99 views
21:07
The IPS Compiler: Optimizations, Variants and Concrete Efficiency (Crypto 2011)by TheIACR53 views
1:24:46
Sigma Protocols and Zero Knowledgeby barilanuniversity358 views
19:45
Perfectly-Secure Multiplication for any t < n/3 (Crypto 2011)by TheIACR161 views
19:16
Automatic Search of Attacks on Round-Reduced AES and Applications (Crypto 2011)by TheIACR71 views
22:10
Leftover Hash Lemma, Revisited (Crypto 2011)by TheIACR297 views
23:42
Computer-Aided Security Proofs for the Working Cryptographer (Crypto 2011)by TheIACR157 views
20:55
Verifiable Delegation of Computation over Large Datasets (Crypto 2011)by TheIACR60 views
17:52
The PHOTON Family of Lightweight Hash Functions (Crypto 2011)by TheIACR119 views
18:48
Generic Side-Channel Distinguishers: Improvements and Limitations (Crypto 2011)by TheIACR130 views
6:06
Unplugged: The show. Part 8: Cryptographic protocolsby csunplugged2,604 views
0:51
John Clippinger "Zero knowledge proofs" enable us to share without revealing too muchby IdeasProject268 views
56:57
Illegitimi Non Carborundum (IACR Distinguished Lecture by Ron Rivest)by TheIACR535 views
23:51
Position-Based Quantum Cryptography: Impossibility and Constructionsby TheIACR159 views
20:37
Optimal Verification of Operations on Dynamic Sets (Crypto 2011)by TheIACR119 views
11:09
Information Security: Principles and Practice, Chapter 9, part 9by JeremyBoob00254 views
22:42
Bi-Deniable Public-Key Encryptionby TheIACR58 views
19:52
Time-Lock Puzzles in the Random Oracle Modelby TheIACR116 views
- Loading more suggestions...
Link to this comment:
All Comments (0)