Indistinguishability Obfuscation from Well-Founded Assumptions Aayush Jain* Huijia Lin† Amit Sahai‡ August 18, 2020 Abstract In this work, we show how to construct indistinguishability obfuscation from subexponential hardness of four well-founded assumptions. We prove: Theorem (Informal). Let τ (0, ), δ (0, 1),ǫ (0, 1) be arbitrary constants. As- ∈ ∞ ∈ ∈ sume sub-exponential security of the following assumptions, where λ is a security parameter, and the parameters ℓ,k,n below are large enough polynomials in λ: • the SXDH assumption on asymmetric bilinear groups of a prime order p = O(2λ), kǫ • the LWE assumption over Zp with subexponential modulus-to-noise ratio 2 , where k is the dimension of the LWE secret, • the LPN assumption over Zp with polynomially many LPN samples and error rate 1/ℓδ, where ℓ is the dimension of the LPN secret, • the existence of a Boolean PRG in NC0 with stretch n1+τ , Then, (subexponentially secure) indistinguishability obfuscation for all polynomial- size circuits exists. arXiv:2008.09317v1 [cs.CR] 21 Aug 2020 Further, assuming only polynomial security of the aforementioned assumptions, there exists collusion resistant public-key functional encryption for all polynomial- size circuits. *UCLA, Center for Encrypted Functionalities, and NTT Research. Email:
[email protected]. †UW. Email:
[email protected]. ‡UCLA, Center for Encrypted Functionalities. Email:
[email protected]. Contents 1 Introduction 1 1.1 AssumptionsinMoreDetail. ... 2 1.2 OurIdeasinaNutshell............................. .. 3 2 Preliminaries 4 3 Definition of Structured-Seed PRG 7 4 Construction of Structured Seed PRG 8 5 Bootstrapping to Indistinguishability Obfuscation 20 5.1 PerturbationResilientGenerators . ........ 23 6 Acknowledgements 26 7 References 27 A Partially Hiding Functional Encryption 36 B Recap of constant-depth functional encryption 37 1 Introduction In this work, we study the notion of indistinguishability obfuscation (i ) for general O polynomial-size circuits [BGI+01a, GKR08, GGH+13b].