收稿日期: 2010-06-14
修回日期: 2010-09-03
网络出版日期: 2011-11-15
基金资助
河北省自然科学基金(F2009000927)资助
Simple proof of bit security for NTRU
Received date: 2010-06-14
Revised date: 2010-09-03
Online published: 2011-11-15
赵永斌 , 范通让 . NTRU比特安全性的简单证明[J]. 中国科学院大学学报, 2011 , 28(6) : 832 -836 . DOI: 10.7523/j.issn.2095-6134.2011.6.019
Based on the malleability, the bit security for NTRU is proved in a simplified decision model. In the model, the oracle can obtain the goal plain text through a sequence of queries if the oracle can output the parity of summation of coefficients in the goal plain text. Compared to the work of Mats, the model is simple and consistent with the decryption process of NTRU. Finally, the relationship between bit security and indistinguishability of encryption scheme is analyzed and the result shows that the formal definition of strong security is of great practicability.
Key words: public key cryptography; bit security; NTRU; malleability; oracle
[1] Schnorr C P, Bell Laboratories. Security of almost ALL discrete log bits . Electronic Colloq on Comp Compl, Univ of Trier, 1998, TR98-033: 1-13.
[2] Hastad J, Naslund M. The security of all RSA and discrete log bits
[J]. Journal of the ACM, 2004, 51(2): 187-230.
[3] Consortium for Efficient Embedded Security, Effcient Embedded Security Standard #1, Version 2. http://www.ceesstandards.org.
[4] Naslund M, Shparlinski I E, Whyte W. On the bit security of NTRUEncrypt. http://www.ntru.com.
[5] Hoffstein J, Pipher J, Silverman J H. NTRU: a ring-based public key cryptosystem //Buhler P. ANTS-III, LNCS 1423. Berlin: Springer-Verlag, 1998: 267-288.
[6] Mao W B. Modern cryptography: theory and practice
[M]. London: Prentice Hall PTR, 2004.
[7] Goldwasser S, Micali S. Probabilistic encryption
[J]. Journal of Computer and System Science, 1984, 28(2): 270-299.
/
| 〈 |
|
〉 |