pCUBE.social
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Natanael@infosec.pub to Cryptography @ Infosec.pub@infosec.pubEnglish ·
edit-2
1 month ago

A Fiat–Shamir Transformation From Duplex Sponges

eprint.iacr.org

external-link
message-square
0
link
fedilink
1
external-link

A Fiat–Shamir Transformation From Duplex Sponges

eprint.iacr.org

Natanael@infosec.pub to Cryptography @ Infosec.pub@infosec.pubEnglish ·
edit-2
1 month ago
message-square
0
link
fedilink
We analyze a variant of the Fiat–Shamir transformation based on an ideal permutation. The transformation relies on the popular duplex sponge paradigm, and minimizes the number of calls to the permutation (given the information to absorb/squeeze). This closely models deployed variants of the Fiat–Shamir transformation, and our analysis provides concrete security bounds to guide security parameters in practice. Our results contribute to the ongoing community-wide effort to achieve rigorous, and ultimately formally verified, security proofs for deployed cryptographic proofs. Along the way, we find that indifferentiability (a property proven for many modes of operation, including the duplex sponge) is ill-suited for establishing the knowledge soundness and zero knowledge of a non-interactive argument. We additionally contribute spongefish, an open-source Rust library implementing our Fiat–Shamir transformation. The library is interoperable across multiple cryptographic frameworks, and works with any choice of permutation. The library comes equipped with Keccak and Poseidon permutations, as well as several "codecs" for re-mapping prover and verifier messages to the permutation's domain.

https://bsky.app/profile/tumbolia.bsky.social/post/3ltyahiem3s2u

We updated our paper on Fiat-Shamir!

We now take a closer look at the gap between what symmetric cryptography has focused on for over 10 years (indifferentiability) and what is actually needed for the soundness of ZKPs and SNARKs (something stronger!).

alert-triangle
You must log in or # to comment.

Cryptography @ Infosec.pub@infosec.pub

crypto@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !crypto@infosec.pub

Questions, answers, discussions, and literature on the theory and practice of cryptography

Rules (longer version here)

  • Stick to cryptography / infosec
  • Be a good netizen - be kind, act in good faith, maintain high quality, don’t mislead
  • Link directly to original sources
  • Don’t use us to cheat on challenges or tests!
  • Crypto review requests must show the algorithm
  • CTF / challenges and puzzles must use modern crypto
  • Avoid making duplicate posts
  • All use of AI / LLM and their prompts MUST be disclosed in your submissions and comments

##Related resources;

  • Reddit cryptography forums 1 & 2; /r/crypto /r/cryptography
  • Cryptology ePrint archive
  • Discussion site for ePrint papers
  • Libera Chat’s IRC:s #crypto - (IRC protocol URL)
  • Metzdowd cryptography mailing list
  • Randombit cryptography mailing list
  • StackExchange cryptography community
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 5 users / day
  • 5 users / week
  • 5 users / month
  • 5 users / 6 months
  • 0 local subscribers
  • 529 subscribers
  • 50 Posts
  • 0 Comments
  • Modlog
  • mods:
  • SqueamishOssifrage@infosec.pub
  • Trusted Third Party@infosec.pub
  • BE: 0.19.12
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org