English

Improved Non-Malleable Extractors, Non-Malleable Codes and Independent Source Extractors

Computational Complexity 2016-08-02 v1 Cryptography and Security

Abstract

In this paper we give improved constructions of several central objects in the literature of randomness extraction and tamper-resilient cryptography. Our main results are: (1) An explicit seeded non-malleable extractor with error ϵ\epsilon and seed length d=O(logn)+O(log(1/ϵ)loglog(1/ϵ))d=O(\log n)+O(\log(1/\epsilon)\log \log (1/\epsilon)), that supports min-entropy k=Ω(d)k=\Omega(d) and outputs Ω(k)\Omega(k) bits. Combined with the protocol in \cite{DW09}, this gives a two round privacy amplification protocol with optimal entropy loss in the presence of an active adversary, for all security parameters up to Ω(k/logk)\Omega(k/\log k). (2) An explicit non-malleable two-source extractor for min-entropy k(1γ)nk \geq (1-\gamma)n, some constant γ>0\gamma>0, that outputs Ω(k)\Omega(k) bits with error 2Ω(n/logn)2^{-\Omega(n/\log n)}. Combined with the connection in \cite{CG14b} this gives a non-malleable code in the two-split-state model with relative rate Ω(1/logn)\Omega(1/\log n). This exponentially improves previous constructions, all of which only achieve rate nΩ(1)n^{-\Omega(1)}.\footnote{The work of Aggarwal et. al \cite{ADKO15} had a construction which "achieves" constant rate, but recently the author found an error in their proof.} (3)A two-source extractor for min-entropy O(lognloglogn)O(\log n \log \log n), which also implies a KK-Ramsey graph on NN vertices with K=(logN)O(logloglogN)K=(\log N)^{O(\log \log \log N)}. We also obtain a seeded non-malleable 99-source extractor with optimal seed length, which in turn gives a 1010-source extractor for min-entropy O(logn)O(\log n). Previously the best known extractor for such min-entropy requires O(loglogn)O(\log \log n) sources \cite{CohL16}. Independent of our work, Cohen \cite{Cohen16} obtained similar results to (1) and the two-source extractor, except the dependence on ϵ\epsilon is log(1/ϵ)(loglog(1/ϵ))O(1)\log(1/\epsilon)(\log \log (1/\epsilon))^{O(1)} and the two-source extractor requires min-entropy logn(loglogn)O(1)\log n (\log \log n)^{O(1)}.

Keywords

Cite

@article{arxiv.1608.00127,
  title  = {Improved Non-Malleable Extractors, Non-Malleable Codes and Independent Source Extractors},
  author = {Xin Li},
  journal= {arXiv preprint arXiv:1608.00127},
  year   = {2016}
}