Succinct randomized encodings allow encoding the input x of a time-t uniform computation M(x) in sub-linear time o(t). The resulting encoding \(\tilde{x}\) allows recovering the result of the computation M(x), but hides any other information about x. These encodings have powerful applications, including time-lock puzzles, reducing communication in MPC, and bootstrapping advanced encryption schemes. Until not long ago, the only known constructions were based on indistinguishability obfuscation, and in particular were not based on standard post-quantum assumptions. In terms of efficiency, these constructions’ encoding time is \(\textrm{polylog}(t)\) , essentially the best one can hope for. Recently, a new construction was presented based on Circular Learning with Errors, an assumption similar to the one used in fully-homomorphic encryption schemes, and which is widely considered to be post-quantum resistant. However, the encoding efficiency significantly falls behind obfuscation-based scheme and is \(\approx \sqrt{t} \cdot s\) , where s is the space of the computation. We construct, under the same assumption, succinct randomized encodings with encoding time \(\approx t^{\varepsilon } \cdot s\) for arbitrarily small constant \(\varepsilon <1\) . Our construction is relatively simple, generic and relies on any laconic function evaluation scheme that satisfies a natural efficiency preservation property. Under sub-exponential assumptions, the encoding time can be further reduced to \(\approx \sqrt{s}\) , but at the account of a huge security loss. As a corollary, assuming also bounded-space languages that are worst-case hard-to-parallelize, we obtain time-lock puzzles with an arbitrary polynomial gap between encoding and decoding times.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Succinct Randomized Encodings from Laconic Function Evaluation, Faster and Simpler

  • Nir Bitansky,
  • Rachit Garg

摘要

Succinct randomized encodings allow encoding the input x of a time-t uniform computation M(x) in sub-linear time o(t). The resulting encoding \(\tilde{x}\) allows recovering the result of the computation M(x), but hides any other information about x. These encodings have powerful applications, including time-lock puzzles, reducing communication in MPC, and bootstrapping advanced encryption schemes. Until not long ago, the only known constructions were based on indistinguishability obfuscation, and in particular were not based on standard post-quantum assumptions. In terms of efficiency, these constructions’ encoding time is \(\textrm{polylog}(t)\) , essentially the best one can hope for. Recently, a new construction was presented based on Circular Learning with Errors, an assumption similar to the one used in fully-homomorphic encryption schemes, and which is widely considered to be post-quantum resistant. However, the encoding efficiency significantly falls behind obfuscation-based scheme and is \(\approx \sqrt{t} \cdot s\) , where s is the space of the computation. We construct, under the same assumption, succinct randomized encodings with encoding time \(\approx t^{\varepsilon } \cdot s\) for arbitrarily small constant \(\varepsilon <1\) . Our construction is relatively simple, generic and relies on any laconic function evaluation scheme that satisfies a natural efficiency preservation property. Under sub-exponential assumptions, the encoding time can be further reduced to \(\approx \sqrt{s}\) , but at the account of a huge security loss. As a corollary, assuming also bounded-space languages that are worst-case hard-to-parallelize, we obtain time-lock puzzles with an arbitrary polynomial gap between encoding and decoding times.