The main feature of our constructions is that they offer a graceful degradation of security in situations where standard existential unforgeability is impossible. This property was recently put forward by Nielsen, Venturi, and Zottarel (PKC 2014) to deal with settings in which the secret key is much larger than the size of a signature. One remarkable such case is the so-called Bounded-Retrieval Model (BRM), where one intentionally inflates the size of the secret key while keeping constant the signature size and the computational complexity of the scheme.
Our main constructions have leakage rate $1-o(1)$, and are proven secure in the standard model. We additionally give a construction in the BRM, relying on a random oracle. All of our schemes are described in terms of generic building blocks, but also admit efficient instantiations under fairly standard number-theoretic assumptions. Finally, we explain how to extend some of our schemes to the setting of noisy leakage, where the only restriction on the leakage functions is that the output does not decrease the min-entropy of the secret key by too much.Category / Keywords: public-key cryptography / leakage resilient cryptography Original Publication (with major differences): ICALP 2015 Date: received 5 Nov 2014, last revised 26 Oct 2016 Contact author: faonio at di uniroma1 it Available format(s): PDF | BibTeX Citation Note: Fixed minor inconsistencies. Version: 20161026:214512 (All versions of this report) Short URL: ia.cr/2014/913 Discussion forum: Show discussion | Start new discussion