Adaptive Oblivious Transfer with Access Control from Lattice Assumptions
Texte intégral
Outline
Documents relatifs
Because of this problem, in both Issuer-Free OTAC protocols, any malicious receiver can obtain any message from the sender, regardless of the access control policy associated with
In the case of the classical sylvester relation, we know that the Tamari lattice can be seen either as a sub-lattice of the right weak order (by taking the subset of maximal
Using the closed sets lattice ( C I , ⊆) instead of the whole concept lattice ( C , ≤ C ) gives raise to a storage improvement, for example in case of large amount of objects.. A
In order to guarantee a security reduction of our construction of Section 4, we will have to guarantee that some encoding provided by the adversary is not “too noisy” and that it
2.5 about the security of the oblivious transfer schemes in the group-based setting can be transposed to the supersingular isogeny setting; in particular, we can differentiate
We introduce a “Coulombian renormalized energy” W which is a logarithmic type of interaction between points in the plane, computed by a “renormalization.” We prove various of
Once collecting enough such short difference vectors, we can recover the whole or the partial secret key by lattice reduction algorithms, which implies that the randomized version
In order to have all the elements needed to give a technical overview of our scheme, we start by describing three existing constructions: the group signa- ture scheme of [KY19], the