campanelli2022f.pdf

Structure-Preserving Compilers from New Notions of Obfuscations

Matteo Campanelli¹, Danilo Francati², and Claudio Orlandi²

1 Protocol Labs, matteo@protocol.ai

1 Protocol Labs, matteo@protocol.ai matteo@protocol.ai

2 Aarhus University, dfrancati@cs.au.dk, orlandi@cs.au.dk

Abstract. The dream of software obfuscation is to take programs, as they are, and then compile them into obfuscated versions that hide their secret inner workings. In this work we investigate notions of obfuscations weaker than virtual black-box (VBB) but which still allow obfuscating cryptographic primitives preserving their original functionalities as much as possible. In particular we propose two new notions of obfuscations, which we call oracle-differing-input obfuscation (odiO) and oracle-indistinguishability obfuscation (oiO). In a nutshell, odiO is a natural strengthening of differing-input obfuscation (diO) and allows obfuscating programs for which it is hard to find a differing-input when given only oracle access to the programs. An oiO obfuscator allows to obfuscate programs that are hard to distinguish when treated as oracles. We then show applications of these notions, as well as positive and negative results around them.

A few highlights include:

– Our new notions are weaker than VBB and stronger than diO.

– As it is the case for VBB, we show that there exist programs that cannot be obfuscated with odiO or oiO.

– Our new notions allow to compile several flavours of secret key primitives (e.g., SKE, MAC, designated verifier NIZK) into their public key equivalent (e.g., PKE, signatures, publicly verifiable NIZK) while preserving one of the algorithms of the original scheme (function-preserving), or the structure of their outputs (format-preserving).


Table of Contents

1 Introduction ..... 1 1.1 Technical Overview ..... 3 1.2 Future Directions ..... 6 2 Related Work ..... 7 3 Preliminaries on Obfuscation ..... 8 4 Oracle-differing-input and oracle-indistinguishability Obfuscation ..... 9 5 Applications of odiO and oiO ..... 12 5.1 Function-Preserving PV-NIZK from DV-NIZK ..... 13 5.2 Function-Preserving Signatures from MACs ..... 14 5.3 Format-Preserving Signatures from MACs ..... 15 5.4 Format-Preserving PKE from IV-based SKE ..... 16 5.5 Function-Preserving PKE from SKE ..... 17 6 Impossibility Results ..... 17 6.1 Unobfuscatable odiO/oiO-samplers ..... 18 6.2 Unobfuscatable SKE ..... 20 A Further Preliminaries ..... 24 A.1 Notation ..... 24 A.2 Non-Interactive Argument systems ..... 24 A.3 One-way and (Puncturable) Pseudorandom Functions ..... 25 A.4 Message Authentication Codes ..... 26 A.5 Digital Signatures ..... 27 A.6 Symmetric Key Encryption ..... 27 A.7 Public Key Encryption ..... 29 B Supporting Proofs ..... 30 B.1 Proof of Theorem 4.6 ..... 30 B.2 Proof of Theorem 5.1 ..... 30 B.3 Proof of Theorem 5.2 ..... 31 B.4 Proof of Theorem 5.4 ..... 34 B.5 Proof of Theorem 5.5 ..... 35 B.6 Proof of Theorem 5.6 ..... 37 B.7 Proof of Theorem 5.7 ..... 40 B.8 Proof of Theorem 6.1 ..... 41 B.9 Proof of Theorem 6.3 ..... 44 B.10 Proof of Theorem 6.5 ..... 44


1 Introduction

Obfuscation and its (dream) applications. Obfuscation—the ability of running a program hiding its inner working—is a cryptographer’s dream. This is especially true of its most powerful instantiation, virtual black-box (VBB) obfuscation: anything a VBB-obfuscated program leaks can be simulated through + oracle access to the function it computes [BGI 12]. It follows that one important application of VBB is to transform secret key cryptographic primitives into their public key counterparts (an approach sometimes referred to as white-box cryptography). For example, the seminal work of Diffie and Hellman [DH76] already imagined compiling secret key encryption (SKE) into public key encryption (PKE) by letting the public key consist of the obfuscated encryption program Enc(k*, ·*). Note that this compiler has the advantage of preserving the format of the underlying ciphertext, as well as the function used to perform decryption.

$$ [ \mathrm {B G I} ^ {+} 1 2 ] $$

Transforming primitives, nicely. In this paper, we are interested in obfucators that allow structure preserving transformation of cryptographic primitives i.e., obfuscators that allow to compile cryptographic primitives while preserving parts of the original primitive. For instance, like in the Diffie and Hellman example, compile a SKE into a PKE in a function-preserving way (e.g., the decryption algorithm of the PKE is the same as the SKE), or at least in a format-preserving way (e.g., the PKE ciphertext is of the same format as the SKE one). We see this as an interesting design approach to transformation of primitives, worth of study of its own. Structure-preserving compilers—as we dub those preserving either function or format—are desirable because of: (i) reusability/retrocompatibility and (ii) efficiency. First, with function-preserving transformations we can reuse existing code, programs, libraries, constructions and their cryptanalysis. Cryptographic primitives deployed in hardware could reuse that same hardware for the transformed primitive, instead of having to be redesigned from scratch and possibly replaced in a production environment. Moreover, transformations that preserve the format of their output allow to reuse parsing-related software and to be retrocompatible with older standards (particularly important for legacy systems). Also, a structure-preserving transformation maintains some of the scheme’s original efficiency guarantees, either preserving the running time of the (possibly heavily optimized) original function or its communication complexity.

$$ [ \mathrm {B G I} ^ {+} 0 1, \mathrm {B G I} ^ {+} 1 2 ] $$

Can we obtain structure-preserving transformations from notions of obfuscation weaker than VBB*?*

Our results: new primitives, compilers, connections to prior notions. In this work we propose two new definitions of obfuscation, oracle-differing-input obfuscation (odiO) and oracle-indistinguishability obfuscation (oiO), and apply them to structure-preserving transformations for several classes of primitives.

$$ \mathrm{[B G I^{+}12,A B G^{+}13} $$


(1)

(2)

(5)

(3)

(4)

Fig. 1: The transformations (1)-(5) of this work: function-preserving on top row; format-preserving on bottom row. By odiO*/*oiO we denote an algorithm obtained through direct obfuscation of the one on the left; by ≡ one that is completely unchanged; by ∼ = one with minor changes but still able to take the same input; by (PPRF) we denote where we modify the algorithm through puncturable PRFs before obfuscation.

only oracle access to the programs. oiO then takes it a step further and allows to obfuscate any pair of programs that are indistinguishable when given as oracle.

In the paper we formally study the relationship between our new notions of obfuscation and the existing one. Note that: VBB > oiO > odiO > diO > iO

$$ V B>010>0110>10>10 $$

meaning that a VBB-obfuscator is also an oiO-obfuscator, and so on. Intuitively, the separation are strict. Again, focusing only on the first inequality: while a VBB-obfuscator cannot leak anything about the program that cannot be learned by the oracle version of the program, an oiO-obfuscator is allowed to leak any secret contained in its circuit, as long as these secrets do not allow to distinguish between the oracle programs. Focusing on oiO, odiO, diO, and iO, we have that all these notions provide the same flavor of security (i.e., two obfuscations are indistinguishable) but for different classes of circuits, each progressively contained into the other. For this reason, we have that oiO > odiO > diO > iO.

Note that odiO is stronger than diO. Since we do not have any candidate obfuscator for diO, we are then unable to provide any plausible candidate obfuscator for odiO and oiO (as for diO, one might use current candidates of iO obfuscator and “hope for the best”). Still, since oiO and odiO are weaker than VBB, it is plausibly easier to build oiO and odiO obfuscators than VBB ones (at least for specific classes of programs).

We then show that our new notions of obfuscation are enough for structure-preserving transformations of important cryptographic primitives. In particular we provide the following transformation (see also Figure1):

1.A function-preserving transformation from selectively sound succinct designated verifier non-interactive argument systems (dv-SNARG) into publicly verifiable ones (pv-SNARG) (Section5.1); The same transformation allows transforming non-interactive argument systems that satisfy straight-line knowledge soundness, i.e., it is possible to extract (through a trapdoor) a valid witness from verifying proofs 3 without interacting with the adversary;

2.A function-preserving transformation from strong existentially unforgeable MACs into digital signatures that remains strongly unforgeable only in the presence of adversaries that can ask signatures of arbitrary messages in a selective fashion (Section5.2);

3.A format-preserving transformation that leverages puncturable PRFs to convert selectively existentially unforgeable MACs into selectively existentially unforgeable digital signatures (Section5.3). In

3 As for straight-line knowledge soundness, we do not consider succinctness (i.e., we do not cover dv-SNARG/pv-SNARG) since, in order to have a straight-line extraction, the size of the proof is proportional to the size of the witness.


constrast to the previous (MACs to signatures) transformation, this is only format-preserving but achieves existential unforgeability under the standard notion of chosen message attacks (i.e., the adversary has adaptive oracle access to the signature algorithm);

4.A format-preserving transformation that leverages puncturable PRFs to convert IV-based selectively secure SKEs into selectively IND-CPA secure PKEs (Section5.4). Here, IV-based SKEs refer to encryption schemes of the form Enc(k*,m*; iv) = (iv*,c*) where iv is the initialization vector (i.e., randomness) used to encrypt a message m. Note that most SKE used in practice are IV-based e.g., those based on block ciphers mode operations such as AES-CBC-mode, AES-CTR-mode, and so on.

$$ \mathsf{E n c}(\mathsf{k},m;\mathsf{\dot{w}})=(\mathsf{\dot{w}},c) $$

5.A function-preserving transformation from any semantically secure and key indistinguishable SKE into a selective IND-CPA PKE (Section5.5). Here, the SKE’s key indistinguishability property must hold under chosen message randomness attacks, i.e., it is infeasible to determine under which key a target message has been encrypted even if the adversary has oracle access to Enc(k*, ·*; ·) that accepts adversarially chosen messages and randomnesses.

$$ \mathsf{E n c}(k,\cdot;\cdot) $$

We highlight that only the last transformation requires oiO (in order to use the key indistinguishability property of the SKE) whereas odiO is sufficient to achieve the other ones. Also, note that all the 4 transformations that use puncturable PRFs are (only) format-preserving.

Although both odiO and oiO are weaker than VBB, this does not tell us anything about the plausibility of these new notions of obfuscation (and their applications). As a last contribution, we investigate whether

$$ V B B ^ {\prime} s $$

$$ [ \mathrm {B G I} ^ {+} 0 1, \mathrm {B G I} ^ {+} 1 2 ] $$

$$ \mathrm{{[B G I^{+}01,,B G I^{+}12]} $$

1.1 Technical Overview

Oracle-Differing-Input Obfuscation (odiO). The notion of odiO is a variant of the notion of differinginput obfuscation, or diO. What is common with diO, for example, is that: (i) we are given a sampler S that outputs two circuits C₀ and C₁ and some auxiliary information α; (ii) the output of the sampler should satisfy some property P (we call such sampler “permissible”); (iii) if the sampler sastisfies property P then the obfuscated circuits Obf(C₀) and Obf(C₁) should look indistinguishable to a PPT adversary given also in input α. Also, in both diO and odiO, the property P corresponds to “no PPT D can find a differing input x for C₀ and C₁ (given in input α)”, that is an input x such that C₀(x) ̸= C₁(x). Where the two definitions diverge is that in diO algorithm D takes as input the actual representation (the code) of the two circuits, whereas in odiO D only has oracle access to the functions computed by C₀ and C₁.

$$ C_{0} $$

$$ C_{1} $$

$$ \mathsf{O b f}(C_{0}) $$

$$ \mathsf{O b f}(C_{1}) $$

$$ C_{0} $$

$$ C_{1} $$

$$ \alpha)^{?} $$

$$ x $$

$$ C_{0}(x)\neq C_{1}(x) $$

$$ C_{1} $$

$$ C_{0} $$

An example of sampler that is permissible for odiO but not diO is the following: consider two programs C₀ and C₁ where their only (high-entropy) differing input is encoded as a comment in their code. Given their code it is easy to find such input, but not with oracle access to them. We provide more examples when we discuss our transformations below.

$$ C_{0} $$

Public-key “forgery-based” transformations through odiO. We show that odiO is particularly suitable for transforming a general class of primitives—which we informally dub forgery-based—from their secret-key to their public-key version. By forgery-based we mean a primitive where the security is defined roughly as follows: “No adversary can produce (forge) a string passing a given test without knowledge of a certain secret (or if a certain condition does not hold)”. Straightforward examples of this type of primitives include message-authentication codes (MACs) and digital signature, but non-interactive proof systems and signatures of knowledge [CL06] also capture this intuition.

The properties of odiO are sufficient for compiling the forgery-based primitives (1)-(3) listed above. We now give the main intuitions behind our transformations and their security. Our goal is to transform

4 We will elaborate on this later, but intuitively this is because the obfuscated program will use the puncturable PRF to generate a fresh symmetric key for different input (e.g., messages, initialization vectors). Hence, on decryption/verification, the receiver needs to evaluate the same PRF in order to recompute the symmetric key used to decrypt/verify a particular ciphertext/signature.


a primitive allowing us to verify a string through knowledge of secret into one that can do the same 5 without such knowledge. Let us denote the first generic verification algorithm by Verify(sk*,...); we aim ′ to transform it into a public key equivalent Verify (pk,...). Our construction is straightforward: We define ′ pk as the odiO-obfuscation of Verify(sk,...), and the program Verify (pk,...*) simply runs the program encoded in pk.

$$ \mathsf{V e r i f y}(\mathsf{s k},\dots);^{5} $$

$$ \mathsf{u t}\operatorname{V e r i f y}^{\prime}(\mathsf{p k},\dots) $$

$$ \mathsf{V e r i f y}(\mathsf{s k},\dots) $$

$$ \mathsf{V e r i f y}^{\prime}(\mathsf{p k},\dots) $$

We now argue that the above is secure in a selective-security-flavored setting. In general, in such a setting, the adversary first claims some input (e.g., a message or an NP statement) for which it would like to forge a valid string (e.g., a signature or a proof). The rest of the intuition is better conveyed being specific. We thus focus on the setting of non-adaptive (selective) security in non-interactive proof systems where the verifier has the syntax Verify(vrs*,x,π*) and vrs is the (secret) verification key, x is a public statement (allegedly in a language L), π is the proof. In this security game, for any input ˆx ̸∈L, the adversary should not be able to forge a corresponding valid proof after seeing the public parameters (aka, common reference string or crs). We now show how to reduce the security of the publicly verifiable construction to that of the original (designated verifier) one applying odiO security. Recall that the security property of odiO must refer to a given sampler returning pairs of circuits. We require that our odiO obfuscator is secure against a sampler that returns (C₀,C₁) (we ignore the auxiliary input here) where:

$$ \mathsf{V e r i f y}(\mathsf{v r s},x,\pi) $$

$$ \mathcal{L}),,\pi $$

$$ \hat{x}\not\in\mathcal{L}. $$

$$ (C_{0},C_{1}) $$

$$ -\ C_{0}{\mathrm{t a k e sa si n p u t}}x{\mathrm{a n d}}\pi{\mathrm{a n dr e t u r n s~}}{mathsf\mathsf V{r i r i f}}y(\mathsf{v r s},x,\pi). $$

– C₁ behaves like C₀ except that it immediately returns 0 whenever x = ˆx.

$$ \ {\mathrm} $$

$$ x=\hat{x} $$

$$ C_{0} $$

The two circuits clearly satisfy the odiO permissibility notion since finding a differing input through oracle access to them would violate the original hypothesis of soundness (the only differing inputs are valid proofs for xˆ). Thus we can move to an hybrid where the crs is an obfuscation of C₁, and indistinguishability of the hybrids follows from the security of the odiO obfuscator. But now note that by construction of C₁, when crs = Obf(C₁), an adversary by definition cannot produce a valid for ˆx. Moreover, we obtain (for free) that our transformation preserves zero-knowledge since it is function-preserving and the Prove algorithm is not modified (see Remark5.3).

$$ C_{1} $$

$$ C_{1} $$

$$ \mathsf{c r s}=\mathsf{O b f}(C_{1}) $$

The blueprint for the construction and security proof above can be adapted (with the appropriate care) to the other forgery-settings (2)-(3) for which we propose transformations. For transformation (2)—which yields selectively-secure strongly unforgeable signatures—one technical challenge is that we need to simulate the queries to the signing oracle. Since these queries are selective we can embed them in one of the circuits we obfuscate during the hybrid arguments. Transformation (3) requires additional care since it yields a signature scheme secure against an adversary with adaptive queries to the signing oracle. To do so we slightly modify the signature algorithm and use a (puncturable) PRF to generate a fresh one-time symmetric-key used to sign a single message. The verification algorithm is similarly adapted and then obfuscated. Due to the use of the PRF, the transformation is not function-preserving but only format-preserving.

Compiling extractable argument systems. We are able to extend our result for argument schemes satisfying soundness to arguments that satisfy knowledge soundness. This is achieved by the exact same 6 function-preserving construction from odiO. We are able to compile an adaptively-secure straight-line extractable designated verifier argument into an adaptively-secure straight-line extractable publicly verifiable argument. Note that, when considering straight-line extractability, proofs are not succinct anymore; hence, in this case we cover dv-NIZK and pv-NIZK. In contrast to soundness—which achieves only selective security—here we are able to preserve adaptive security. Again, the transfomation is function-preserving and it does not alter the Prove algorithm. Hence, zero-knowledge is preserved (see also Remark5.3). To the best of our knowledge ours is the first work applying obfuscation in the context of extractability in proof schemes.

Using odiO for public-key encryption through puncturable PRFs. So far we discussed how odiO is particularly useful for forgery-flavored primitives. We observe, however, that we are able to prove security of another type of primitive, encryption. In Section5.4, we show how to compile IV-based

5 The rest of the input besides the key is irrelevant for this discussion.

6 Despite the construction is the same, the sampler required to prove knowledge soundness is different.


selectively secure SKEs (whose ciphertexts have the form Enc(k*,m*; iv) = (iv*,c*)) into selectively IND- CPA secure PKEs. Our obfuscated circuit (that will be our pk) uses two puncturable PRFs: The first to generate the initialization vector iv from the randomness given to the PKE’s Enc and, the second to 7 generate a one-time fresh symmetric-key (used to encrypt) from iv. The decryption algorithm has access to the key for the second PRF and takes as input the ciphertext (iv*,c*). It can then regenerate the key and thus decrypt. Note that this transformation is only format-preserving since we slightly modify both encryption and decryption algorithm to embed the evaluation of the PRF.

$$ \mathsf{E n c}(\mathsf{k},m;\mathsf{i v})=(\mathsf{i}\mathsf{v},c)\big) $$

$$ i_{1/7} $$

$$ (i v,c) $$

Oracle-Indistinguishability Obfuscation (oiO). The notion of oiO represents a natural strengthening of odiO. It has similar features to diO and odiO in that it requires samplers that output pairs of circuits satisfying some permissibility predicate P. While the permissibility predicate in diO and odiO requires hardness of finding a differing-input, in oiO we have a weaker permissibility predicate (which in turn makes oiO stronger than odiO): in oiO the sampler must output pairs of circuits such that an adversary (given also as input related auxiliary string α) cannot distinguish the circuits while having only oracle oracle access to them. An example of a sampler that is permissible for oiO but not odiO is the one where C₀ and C₁ are both PRFs but with different keys, since they differ on (almost) every input but their output distributions are indistinguishable.

$$ C_{0} $$

$$ C_{1} $$

Public-key “indistinguishability-based” transformations through oiO. While odiO is intuitively suitable for transforming forgery-based primitives, oiO has synergies with indistinguishability-based primitives, i.e. where “No adversary can distinguish between two distributions without knowledge of a certain secret”. Natural examples are encryption schemes where the distributions to distinguish are the encryption of different messages (e.g., IND-CPA security).

Through oiO we are able to prove the security of a more general transformation (compared to (4)) from SKEs to PKEs. Starting from a symmetric encryption algorithm Enc(k*, ·; ·), our aim is to transform it into something with the following syntax Enc(pk, ·; ·), where pk is a public key. Our transformation is identical to the one proposed by Diffie and Hellman [DH76]: We define pk as the oiO-obfuscation of Enc(k, ·*; ·) for some honestly chosen symmetric key k. To claim the IND-CPA security of the above transformation, we need to assume that the initial SKE is key indistinguishable under (adversarially) chosen message randomness attacks. The latter allows us to build a sampler that satisfies the permissibility predicate of oiO. In particular, the sampler returns (C₀,C₁) (again, we ignore the auxiliary input here) where:

$$ \mathsf{E n c}(\mathsf{p k},\cdot;\cdot) $$

$$ \mathsf{E n c}(k,\cdot,\cdot) $$

$$ \mathsf{E n c}(\mathsf{k},\cdot;\cdot) $$

$$ (C_{0},C_{1}) $$

– C₀ takes as input m and r and returns Enc(k*,m*; r).

$$ \ {\it-\ C_{0}} $$

$$ \mathsf{E n c}(\mathsf{k},m;r) $$

′ – C₁ is identical to the above except that it uses a different (honestly generated) symmetric key k.

$$ k^{\prime} $$

$$ \ {\mathrm} $$

Intuitively, the circuits satisfy the oiO permissibility notion since any adversary that is able to distinguish between oracles C₀ and C₁ would also violates the key indistinguishability security of the SKE. Now, since the obfuscations of these two circuits are indistinguishable, we can reduce the security of the PKE to the security of the original SKE. Consider the standard IND-CPA experiment of PKE where pk is set to the obfuscation of C₀ and the challenge ciphertext c is computed as c = pk(mb; r) = Enc(k*,m*b; r) for r randomly chosen. We can now do an hybrid where pk is set to the obfuscation of C₁ whereas the challenge ciphertext is still computed as c = Enc(k*,m*b; r) where k is the key hardcoded in C₀. Since the ciphertext c is computed using a key k that is not the obfuscated one (recall C₁ uses an independent ′ key k), we can now conclude the proof by doing a reduction to the semantic security of the original SKE. We highlight that this proof technique works only if we consider selective IND-CPA security. This is because the sampler needs to output an auxiliary input that is an honest encryption of mbunder the key k (hardcoded into C₀). This is fundamental to simulate the challenge ciphertext (of the selective IND-CPA experiment) and concludes the hybrid argument.

$$ C_{0} $$

$$ C_{1} $$

$$ c=p\ k k(m_{b};r)=n c\bigl(k,m_{b};r\bigr) $$

$$ C_{0} $$

$$ C_{1} $$

$$ c=\mathsf{E n c}(\mathsf{k},m_{b};r) $$

$$ C_{0} $$

$$ C_{1} $$

$$ \ {cal C C}_{0}) $$

$$ m_{b} $$

Why aren’t diO/iO sufficient for these transformations above? We observe that each of the compilation described above would not be feasible with either iO or diO. Intuitively, this is because we

7 If, instead of generating iv using the first PRF, we allow the circuit to take directly in input iv then the PKE (output by the transformation) is trivially broken. This is because (following the syntax of the IV-based SKE) iv is included into the ciphertext. Hence, an adversary can break the selective IND-CPA security of the compiled PKE by simply re-encrypting a message using the iv that is included into the challenge ciphertext.


would eventually need to reduce the security of our transformations (pv-SNARG, signature, PKE) to the security of the original secret-key primitive (dv-SNARG, MAC, SKE). However, in the latter experiment the secret-key sk (e.g., a vrs or a symmetric-key), that we need to obfuscate in order to conclude the reduction, is sampled and kept secret by the challenger. This makes iO and diO insufficient since we are not able to satisfy their permissibility notion during this reduction. For the case of iO, during the reduction, the only thing we could do is to to obfuscate different circuit C₁ that does not use the secretkey sk sampled by the challenger. However, this C₁ will have (with overwhelming probability) a different input/output behavior compared to C₀ (the original obfuscated circuit of the transformation that, in turn, contains sk).

$$ i0, $$

$$ C_{1} $$

$$ C_{1} $$

$$ C_{0} $$

A similar discussion applies to diO. For the sake of concreteness, consider transforming a dv-SNARG into a pv-SNARG by publishing an obfuscation of the circuit C₀ which implements the dv-SNARG verification algorithm using an hardcoded verification key vrs. During the reduction to the security of the underlying scheme we are not allowed to use the secret verification key vrs. Thus, during the reduction, we can only move to a hybrid where we obfuscate a circuit C₁ that does not use the vrs. But then we cannot argue that it is hard to find differing-inputs for C₀,C₁. In this specific case, the distinguisher could simply produce proofs π for true statements x and submit them to the circuits. While C₀ (using the vrs) returns 1, C₁ (without the vrs) is unable to verify the proof and cannot return a consistent output. Similar arguments apply to the other transformations.

$$ C_{0} $$

$$ C_{1} $$

$$ C_{0},C_{1} $$

$$ \pi $$

$$ C_{0} $$

$$ C_{1} $$

$$ \mathbf{o d i o//o i o} $$

$$ \mathrm{[B G I^{+}01,;B G I^{+}12]} $$

$$ \mathrm{B G I^{+}12}| $$

$$ \mathrm{[B G I^{+}01}, $$

$$ \mathrm{[B G I^{+}01,B G I^{+}12]} $$

$$ C_{s} $$

$$ \mathrm{[B G I^{+}12} $$

$$ [\mathrm{B G B^{+}12}] $$

1.2 Future Directions

Our work opens up several interesting future directions. How to generally formalize structure-preserving transformations? Can we characterize what type of games can be transformed (from “secret” to “public” key) through odiO? Several, but not all those we achieve, seem to have a “forgery” flavor to them (MAC, NIZKs, etc.). What are further connections between our proposed notions of obfuscation and VBB, iO + and diO? While the techniques in [BGI 12] seem to fail to show that some of our transformations are paradoxical, what are other techniques that could shed light on further limitations of odiO oiO? Can we leverage our techniques for going from secret-key to public-key variants of different cryptographic primitives than those we consider here, e.g., proofs of retrievability [SW13]?

$$ \mathrm{N I Z K s}. $$

$$ [mathrm B G G^{+}12] $$


2 Related Work

$$ \mathrm{B G K^{+}14}. $$

$$ [\mathrm{G G G^{+}13}] $$

$$ \mathrm{A J L}^{+}19 $$

$$ \mathrm{N C}^{0} $$

$$ \ {dot\}mathrm{i.e.} $$

Among weaker notions of obfuscation, we also include virtual gray-box obfuscation (VGB) [BC10, BCKP17]. This notion is close to that of VBB but models the simulator as semi-bounded, i.e., unbounded in running time but limited to a polynomial number of oracle queries. VGB is equivalent to another notion, strong iO (siO), where it holds that Obf(C₀) ≈cObf(C₁) whenever the pair (C₀,C₁) is sampled from a concentrated distribution D: For every input x, the probability that C₀(x) and C₁(x) do not return to common output majD(x) is negligible (where majD(·) is defined with respect to the concentrated distribution D taken into account). Observe that concentrated distributions are a generalization + of evasive functions [BBC 14]. Intuitively, siO is weaker than odiO (and oiO) since circuits (sampled from concentrated distributions) are oracle-diffing-input even against semi-bounded adversaries. Also, note that siO is not powerful enough to achieve structure-preserving transformations. Intuitively, because siO is able to obfuscate distributions of circuits that “pass” an information theoretical test. This is a obstacle when trying to implement our structure-preserving transformations since our objective is to compile/obfuscate primitives whose security follows from computational assumptions.

$$ \mathsf{O b f}(\mathcal{C_{{0}}})\approx_{c}\mathsf{O b f}(\mathcal{C}_{{1}}) $$

$$ (C_{0},C_{1}) $$

$$ C_{0}(x) $$

$$ x, $$

$$ C_{1}(x) $$

$$ m a j_{\mathbf{D}}(x) $$

$$ m a j_{\mathbf{D}}(\cdot) $$

$$ [\mathrm{B B C^{+}14}] $$

$$ \mathrm {s i O} $$


3 Preliminaries on Obfuscation

We assume the reader to be familiar with standard cryptographic notation and definitions. To make the paper self-contained, our notation and all the standard definitions used in the paper can be found in AppendixA.

Indistinguishability obfuscation and differing-input obfuscation. Let C = {Cλ}λ∈Nbe an en- ℓin semble of functionally equivalent circuits (of same size), i.e., ∀λ ∈ N*, ∀C₀,C₁ ∈ C*λ, ∀x ∈ {0,1}, + C₀(x) = C₁(x) and |C₀| = |C₁|. Indistinguishability obfuscation (iO) [BGI 01] guarantees that the obfuscation of any two functionally equivalent circuits C₀,C₁ ∈Cλare computationally indistinguishable.

$$ \mathcal{C}={\mathcal{C}{\lambda}}{\lambda\in\mathbb{N}} $$

$$ \forall\lambda\ \in\ \mathbb{N},\forall C_{0},C_{1}\ \in\ \acute{\mathcal{C}}{\lambda},\acute{\forall}x\ \in\ {0,1}^{\ell{\mathrm{}{i n}}} $$

$$ C_{0}(x)=C_{1}(x) $$

$$ |C_{0}|=|C_{1}| $$

$$ C_{0},C_{1}\in\mathcal{C}_{\lambda} $$

Definition 3.1. A sampler S for an ensemble of circuits C = {Cλ}λ∈Nis a PPT algorithm that, on input λ the security parameter 1*, it outputs two circuits C₀,C₁ ∈C*λsuch that |C₀| = |C₁| and (possibly) some auxiliary information α.

$$ \mathcal{C}={\mathcal{C}{\lambda}}{\lambda\in\mathbb{N}} $$

$$ 1^{\lambda}, $$

$$ C_{0},C_{1}\in\mathcal{C}_{\lambda} $$

$$ |C_{0}|=|C_{1}| $$

Definition 3.2. (diO-sampler) We say a sampler S (Definition3.1) is a diO*-sampler if for every PPT* adversary A we have

$$ \mathbb {P} \left[ C _ {0} (x) \neq C _ {1} (x) \mid \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow \mathrm {s} \mathsf {S} \left(1 ^ {\lambda}\right), x \leftarrow \mathrm {s} \mathsf {A} \left(1 ^ {\lambda}, C _ {0}, C _ {1}, \alpha\right) \right] \leq \operatorname {n e g l} (\lambda). $$

Definition 3.3(Differing-input obfuscation). Let S be an ensemble of diO*-samplers (Definition3.2).* S S For every S ∈S, let C = {Cλ}λ∈Nbe the ensemble of circuits output by S*. A PPT algorithm* Obf is a (S)-diO-obfuscator for the ensemble S if the following conditions are satisfied:

$$ {mathsf\mathsf S{}}\in{\mathcal{S}} $$

$$ \mathcal{C}^{\mathsf{S}}=\bar{{{\mathcal{C}{\lambda}^{\mathsf{S}}}}}{\lambda\in\mathbb{N}} $$

S ℓin ′ ′$λ Correctness. ∀S ∈S, ∀λ ∈ N, ∀C ∈Cλ, ∀x ∈{0,1}, we have C (x) = C(x) where C ← Obf(1*,C*). S λ Polynomial slowdown. There exists a polynomial p such that ∀S ∈S, ∀C ∈Cλ, we have |Obf(1,C)|≤ p(|C|).

$$ \forall\mathsf{S}\in\mathcal{S},:\forall\lambda\in\mathbb{N},:\forall C\in\mathcal{C}{\lambda}^{\mathsf{S}},:\forall x\in{0,1}^{\ell{i n}} $$

$$ C^{\prime}(x)=C(x) $$

$$ C^{\prime}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C) $$

$$ \forall\mathsf{S}\in\mathcal{S},\forall C\in\mathcal{C}_{\lambda}^{\mathsf{S}} $$

$$ |\mathsf{O b f}(1^{\lambda},C)|\leq $$

$$ p(|C|) $$

Indistinguishability. For every S ∈S, every PPT adversary D*, we have that*

$$ {mathsf\mathsf S{}}\in{\mathcal{S}} $$

$$ \left| \mathbb {P} \left[ \mathrm {D} \left(1 ^ {\lambda}, \mathrm {O b f} \left(1 ^ {\lambda}, C _ {0}\right), \alpha\right) = 1 \right] - \mathbb {P} \left[ \mathrm {D} \left(1 ^ {\lambda}, \mathrm {O b f} \left(1 ^ {\lambda}, C _ {1}\right), \alpha\right) = 1 \right] \right| \leq \operatorname {n e g l} (\lambda), $$

$λ where (C₀,C₁,α) ← S(1).

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {$} S \left(1 ^ {\lambda}\right). $$

The above definition is parametrized by an ensemble of diO-samplers since some negative results for diO are known [BSW16,GGHW17] (see next). Because of this, an universal (general) diO-obfuscator may not exists, i.e., a diO-obfuscator that obfuscates any diO-sampler.

Negative results. In the setting of Turing machines (not covered by this paper), Bellare et al. [BSW16] show that if sub-exponentially secure one-way functions exist then a sub-exponentially secure diOobfuscator Obf for any sampler for Turing machines does not exist (i.e., there exists a particular sampler that cannot be diO-obfuscated). We stress that the main impossibility result covers Turing machines but, as described by [BSW16], if SNARKs exist the negative result can be extended to diO for circuits. Garg et al. [GGHW17] show that under the conjecture that a special-purpose obfuscator exists (i.e., an obfuscator that does not follow from the existence of a diO-obfuscator) then a diO-obfuscator Obf for any sampler for circuits does not exist. We highlight that both [BSW16,GGHW17] show that only “some” diO-samplers cannot be obfuscated. Indeed, both works rely on samplers that output complex auxiliary information α (α is itself an obfuscation of contrived circuit/Turing machine). Hence, this does not rule out the possibility of obfuscating the same class of circuits/Turing machines under simpler auxiliary information.


$$ \mathrm{[B G I^{+}01]} $$

$$ \pi(C) $$

$$ [\mathrm{B G B}^{+}01] $$

Definition 3.4. (VBB-sampler) A VBB*-sampler* S for an ensemble of circuits C = {Cλ}λ∈Nis a PPT λ algorithm that, on input the security parameter 1*, it outputs a circuit C ∈ C*λand some auxiliary information α.

$$ \mathcal{C}={\mathcal{C}{\lambda}}{\lambda\in\mathbb{N}} $$

$$ 1^{\lambda} $$

$$ C\in\mathcal{C}_{\lambda} $$

Definition 3.5(Virtual black-box obfuscation). Let S be an ensemble of VBB*-samplers (Defini-* S S tion3.4). For every S ∈S, let C = {Cλ}λ∈Nbe the ensemble of circuits output by S*. A PPT algorithm* Obf is a (S)-VBB-obfuscator for the ensemble S if the following conditions are satisfied:

$$ \ .\ 4, $$

$$ {mathsf\mathsf S{}}\in{\mathcal{S}} $$

$$ \mathcal{C}^{\mathsf{S}}={\mathcal{C}{\lambda}^{\mathsf{S}}}{\lambda\in\mathbb{N}} $$

S ℓin ′ ′$λ Correctness. ∀S ∈S, ∀λ ∈ N, ∀C ∈Cλ, ∀x ∈{0,1}, we have C (x) = C(x) where C ← Obf(1*,C*). λ Polynomial slowdown. There exists a polynomial p such that ∀S ∈S, ∀C ∈Cλ, we have |Obf(1,C)|≤ p(|C|).

$$ \forall\mathsf{S}\in\mathcal{S},:\forall\lambda\in\mathbb{N},:\forall C\in\mathcal{C}{\lambda}^{\mathsf{S}},:\forall x\in{0,1}^{\ell{i n}} $$

$$ C^{\prime}(x)=C(x) $$

$$ C{{}}^\ {{\prime}}\leftarrow\ \ mathsf s s b f(1^{\lambda},C) $$

$$ \forall\mathsf{S}\in\mathcal{S},\forall\mathcal{C}\in\mathcal{C}_{\lambda} $$

$$ |\mathsf{O b f}(1^{\lambda},C)|\leq $$

$$ p(|C|) $$

Virtual black-box simulation. For every PPT adversary A*, there exists a PPT simulator* Sim such that for every S ∈S, we have h i

$$ {mathsf\mathsf S{}}\in{\mathcal{S}} $$

$$ \Big|\mathbb{P}\big[\mathsf{A}(1^{\lambda},\mathsf{O b f}(1^{\lambda},C),\alpha)=1\big]-\mathbb{P}\Big[\mathsf{S i m}^{C(\cdot)}(1^{\lambda},1^{|C|},\alpha)=1\Big]\Big|\leq\mathsf{n e g l}(\lambda), $$

$λ where (C,α) ← S(1).

$$ (C,\alpha)\leftarrow_{\mathfrak{S}}(1^{\lambda}) $$

Note that VBB is a much stronger flavor of obfuscation than diO and iO for two reasons. First, VBB defines the concept of ideal/oracle obfuscation, i.e., an obfuscated circuit behaves as an oracle. Second, VBB is a simulation-based definition (whereas both iO and diO are indistinguishability-based), i.e., any bit of leakage (that can be retrieved from the obfuscation of a circuit) can be simulated (except with negligible probability) having only oracle access to the unobfuscated circuit.

Impossibility results. VBB is a very interesting notion of obfuscation since it has several important applications (e.g., it permits to convert a SKE into PKE). However, VBB-obfuscation turned out to be im-

$$ \mathrm{[B C C^{+}14,B G I^{+}01,B G I^{+}12]} $$

$$ \mathrm{[B G I^{+}12} $$

4 Oracle-differing-input and oracle-indistinguishability Obfuscation

In this section, we propose two new notions of obfuscation, dubbed oracle-differing-input obfuscation and oracle-indistinguishability obfuscation (odiO and oiO in short). Both odiO and oiO are the result of two natural extensions of diO (resp. iO): they introduce the notion of oracle circuits (as in VBB) while keeping the indistinguishability property of diO (resp. iO). In a nutshell, odiO requires that the obfuscations of two circuits C₀,C₁ are computationally indistinguishable if the latter two are differing-input circuits when treated as oracles, i.e., an adversary cannot find an input x such that C₀(x) ̸= C₁(x) when given oracle access to both C₀ and C₁. On the other hand, oiO provides the same indistinguishability guarantee with respect to circuits C₀,C₁ that are computationally indistinguishable when treated as oracles.

$$ C_{0},C_{1} $$

$$ C_{0}(x)\neq C_{1}(x) $$

$$ C_{0} $$

$$ C_{1} $$

$$ C_{0},C_{1} $$

As usual, we define odiO and oiO with respect to an ensemble of samplers responsible of generating the circuits C₀,C₁ and (possibly) some auxiliary information α.

$$ C_{0},C_{1} $$

$$ \alpha. $$


Definition 4.1. (odiO- and oiO*-sampler) Let* type ∈{odiO,oiO}. We say a sampler S (Definition3.1) is an type*-sampler if for every PPT adversary* A we have

$$ \in{\mathsf{o d i O},\mathsf{o d O}} $$

If type = odiO:

$$ \mathbb {P} \left[ C _ {0} (x) \neq C _ {1} (x) \mid x \leftarrow^ {\mathrm {s}} \mathsf {A} ^ {C _ {0} (\cdot), C _ {1} (\cdot)} \left(1 ^ {\lambda}, 1 ^ {| C _ {0} |}, \alpha\right) \right] \leq \operatorname {n e g l} (\lambda), $$

If type = oiO:

$$ \Big|\mathbb{P}\Big[\mathsf{A}^{C_{0}(\cdot)}(1^{\lambda},1^{|C_{0}|},\alpha)=1\Big]-\mathbb{P}\Big[\mathsf{A}^{C_{1}(\cdot)}(1^{\lambda},1^{|C_{1}|},\alpha)=1\Big]\Big|\leq\mathsf{n e g l}(\lambda), $$

$λ 8 where (C₀,C₁,α) ← S(1).

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {$} S \left(1 ^ {\lambda}\right). ^ {8} $$

Definition 4.2(Oracle-differing-input and oracle-indistinguishability obfuscation). For type S S ∈{odiO,oiO}, let S be an ensemble of type*-samplers (Definition4.1). For every* S ∈S, let C = {Cλ}λ∈N be the ensemble of circuits output by S*. A PPT algorithm* Obf is a (S)-type-obfuscator for the ensemble S if the following conditions are satisfied:

$$ \in{\mathsf{o d i O},\mathsf{o i O}} $$

$$ 4.I) $$

$$ {mathsf\mathsf S{}}\in{\mathcal{S}} $$

$$ \mathcal{C}^{\mathsf{S}}={\mathcal{C}{\lambda}^{\mathsf{S}}}{\lambda\in\mathbb{N}} $$

S ℓin ′ ′$λ Correctness. ∀S ∈S, ∀λ ∈ N, ∀C ∈Cλ, ∀x ∈{0,1}, we have C (x) = C(x) where C ← Obf(1*,C*). S λ Polynomial slowdown. There exists a polynomial p such that ∀S ∈S, ∀C ∈Cλ, we have |Obf(1,C)|≤ p(|C|).

$$ \forall\mathsf{S}\in\mathcal{S},:\forall\lambda\in\mathbb{N},:\forall C\in\mathcal{C}{\lambda}^{\mathsf{S}},:\forall x\in{0,1}^{\ell{i n}} $$

$$ C^{\prime}(x)=C(x) $$

$$ C^{\prime}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C) $$

$$ \forall\mathsf{S}\in\mathcal{S},\forall C\in\dot{\mathcal{C}}_{\lambda}^{\mathsf{S}}. $$

$$ |\mathsf{O b f}(1^{\lambda},C)|\leq $$

$$ p(|C|) $$

Indistinguishability*. For every* S ∈S, every PPT adversary D*, we have that*

$$ {mathsf\mathsf S{}}\in{\mathcal{S}} $$

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {$} S \left(1 ^ {\lambda}\right). $$

$λ where (C₀,C₁,α) ← S(1).

Comparing diO-, odiO-, oiO-, and VBB-obfuscation. We now study the relations between diO, odiO, oiO, and VBB. In order to provide a meaningful comparison, we work in terms of best-possible universal obfuscators, i.e., we compare the classes of circuits/samplers that each flavor of obfuscation is able to handle. We start by defining the notion of best-possible universal type*-obfuscator* Obf (for type ∈{diO,odiO,oiO,VBB}) whose definition is tied with the (universal) set Stypecomposed of all the type-samplers that can be securely type-obfuscated (as defined in Definitions4.2to3.4).

$$ d i0-,i d0-i0. $$

$$ \in{\mathsf{d i0,d i0,0i0,B}} $$

$$ S_{\mathrm{t y p e}} $$

Definition 4.3(Best-possible universal type-obfuscator). Let type ∈{diO,odiO,oiO,VBB}. Con- sider the ensemble Stypecomposed of every type*-sampler* S (Definitions4.1,3.2and3.4) that can be securely type*-obfuscated (Definitions4.2,3.3and3.5), i.e.,*

$$ S_{\mathrm{t y p e}} $$

$$ 4.l,\ 3.\not $$

$$ 3.4) $$

$$ \mathcal {S} _ {\mathrm {t y p e}} = \left{\text {t y p e - s a m p l e r S |} \exists \mathrm {O b f} \textit {s. t. O b f i s a} ({S }) - \text {t y p e - o b f u s c a t o r} \right}. $$

A PPT algorithm Obf is a best-possible universal type-obfuscator if Obf is a (Stype)-type-obfuscator (Definitions4.2,3.3and3.5).

$$ a\ \left(\mathcal{S}_{\mathsf{t y p e}}\right) $$

Remark 4.4. There are two technical reasons behind the need of considering only best-possible universal obfuscators, while comparing diO, odiO, oiO, and VBB. First, for any notion of type-obfuscation, it is possible to find two contrived type-obfuscators Obf₀ and Obf₁ that result to be incomparable, even within the same flavor of obfuscation. As an example, we could have that Obf₀ (resp. Obf₁) is able to type- 9 obfuscate S₀ (resp. S₁) but not S₁ (resp. S₀) where S₀*,*S₁ are two type-samplers. The same argument holds between different notions. For example, if we consider diO and odiO, we could have that Obf₀ diO-obfuscates a diO-sampler S (that in turn, as we will see, is also a odiO-obfuscator) but Obf₁ does ′ ′ not odiO-obfuscate S. Also, we can have the symmetric case: there exist two obfuscators Obf0and Obf1 ′ ′ such that Obf1odiO-obfuscates S but Obf0does not diO-obfuscate S. Hence by changing the obfuscator we could reach any conclusions: (i) odiO and diO are incomparable, (ii) odiO implies diO, or (iii) diO implies odiO. This clearly does not allow for a meaningful comparison. Definition4.3naturally solves the above problem since a best-possible universal type-obfuscator uniquely represents the power of a particular notion of obfuscation, i.e., the set Stypeof samplers that can be securely type-obfuscated. This allows us to have a meaninful (and unique) formal comparison between diO, odiO, oiO, and VBB.

$$ {mathrm\ d d{0}}. $$

$$ \mathrm{O b f}_{0} $$

$$ \ mathrm O b b_{1} $$

$$ {sf S S}_{0} $$

$$ \mathrm{O b f}_{0} $$

$$ \ {sf S S}_{1}) $$

$$ \mathrm {S} _ {0}) $$

$$ {sf S S}_{1} $$

$$ \mathsf{S}{0},\mathsf{S}{1} $$

$$ \mathrm{O b f}_{1} $$

$$ \mathsf{O b f}_{0}^{\prime} $$

$$ \mathsf{O b f}_{0}^{\prime} $$

$$ \mathsf{O b f}_{1}^{\prime} $$

$$ \mathsf{O b f}_{1}^{\prime} $$

$$ S_{\mathrm{t y p e}} $$

8 Recall that |C₀| = |C₁| by definition of sampler (Definition3.1).

$$ |C_{0}|=|C_{1}| $$

9 For instance, we can have that Sbonly outputs circuits whose description starts with a bit b, and that Obfb rejects any circuit whose description starts with the bit 1 − b.

$$ S_{b} $$

$$ \ mathrm O b b_{b} $$

$$ 1-b. $$


Second, Definition4.3allows us to exclude from the comparison the known impossibility results

In the setting of best-possible universal obfuscation, odiO (resp. oiO) is stronger than diO since (i) any diO-sampler is also an odiO-sampler (resp. oiO-sampler) and (ii) both diO and odiO (resp. oiO) have the same indistinguishability-based security definition. The same argument applies to odiO and oiO, i.e., oiO is stronger than odiO.

Theorem 4.5(oiO ⇒ odiO ⇒ diO). For type ∈ {diO,odiO,oiO}, we have that SdiO⊆ SodiO⊆ SoiO where Stypeas defined in Definition4.3.

$$ \mathrm {t y p e} \in \left{\mathrm {d i O}, \mathrm {o d i O}, \mathrm {o i O} \right} $$

$$ \mathcal{S}{\mathsf{d i0}}\subseteq\mathcal{S}{\mathsf{o d i0}}\subseteq\mathcal{S}_{\mathsf{o i C}} $$

$$ S_{\mathrm{t y p e}} $$

$$ 4.3. $$

Proof.(Case odiO ⇒ diO*).* Consider a diO-sampler S ∈SdiO. By definition, we have that for every PPT adversary A, that takes as input (C₀,C₁,α) (output by S), it is infeasible for A to find a differing-input x such that C₀(x) ̸= C₁(x) (Definition3.2). As a consequence, it is also hard for A to find such a differinginput x when A has only oracle access to C₀ and C₁. Hence, S is also an odiO-sampler (Definition4.1*).* Moreover, by definition of SdiO, ObfdiOis a ({S})-diO-obfuscator. Since the indistinguishability property of odiO is identical to that of diO, it follows that ObfdiOis also a ({S})-odiO-obfuscator. As a consequence, we conclude that S ∈SodiO.

$$ \mathsf{S}\in\mathcal{S}_{\mathsf{d i}0} $$

$$ (C_{0},C_{1},\alpha) $$

$$ C_{0}(x)\neq C_{1}(x) $$

$$ C_{0} $$

$$ C_{1} $$

$$ \mathcal{S}{\sf{d i O}},,{\sf{O b f}}{\sf{d i O}} $$

$$ \mathsf{S}\in\mathcal{S}_{\mathsf{o d i0}} $$

$$ \mathsf{O b f_{d i O}} $$

(Case oiO ⇒ odiO*).* For S ∈SodiO, we have that for every PPT adversary A, that takes as input α, it is infeasible to find differing-input x if A has only oracle access to C₀ and C₁ (where (C₀,C₁,α) output by S). As a consequence, these circuits (except with negligible probability) are identical when treated as oracles. Hence, S is also an oiO-sampler. Moreover, both odiO and oiO have the same indistinguishability property. This implies that ObfodiOis also a ({S})-oiO-obfuscator and, in turn, this implies that S ∈SoiO. ⊓⊔

$$ \mathsf{S}\in\mathcal{S}_{\mathsf{o d i}0} $$

$$ \alpha, $$

$$ C_{0} $$

$$ C_{1} $$

$$ (left mathcal C{{0}},mathcal C{{1}},\alpha) $$

$$ \ {mathsf o b f}_{\tt o d i O0} $$

$$ \mathsf{S}\in\mathcal{S}_{\mathsf{o}\mathsf{i}0} $$

About (best-possible universal) odiO-, oiO-, and VBB-obfuscation, we have that VBB is stronger than odiO (resp. oiO) for two main reasons:

  1. VBB leverages a simulation-based definition: any bit of information that can be leaked from an obfuscated circuit C can be simulated by only having oracle access to C. On the other hand, odiO (resp. oiO) provides a much weaker security guarantee: the obfuscation of two circuits C₀,C₁ (output by an odiO-sampler (resp. oiO-sampler)) are computationally indistinguishable. This implies that a odiO-obfuscator (resp. oiO-obfuscator) could leak significant information about the circuit, as long as the leaked information does not help in distinguishing (except with negligible probability) between the obfuscations of C₀ and C₁.

$$ C_{0},C_{1} $$

$$ C_{0} $$

$$ C_{1} $$

2.Both VBB and odiO (resp. oiO) incorporate the notion of oracle circuits in their definitions. However, oracles are used to define two different concepts. VBB uses oracle circuits to define the amount of information a VBB-obfuscator may leak. Since oracles leak no information (except their input-output behavior), this implies that a VBB-obfuscator does not leak any information, except with negligible probability.

Conversely, odiO and oiO leverage the notion of oracle circuits to characterize the class of circuits (or samplers) that an odiO-/oiO-obfuscator can handle. The definition of security (i.e., the indistinguishability property of Definition4.2) is independent from the oracles. Both odiO and oiO “only” guarantee that the information leaked by the obfuscation of two circuits are the same. This does not imply that the odiO-/oiO-obfuscated circuits must “behave” as oracles (as required by VBB (Definition3.5)).

The relation between VBB*,*oiO, and odiO is formalized by the following theorem, whose proof appears in AppendixB.1.

Theorem 4.6(VBB ⇒ oiO and VBB ⇒ odiO). Let S be a sampler (Definition3.1). For b ∈{0,1}, λ ∗ λ let Sbbe a sampler such that (Cb,α) = Sb(1; r) where r ∈ {0,1}, and (C₀,C₁,α) = S(1; r). If S₀*,*S₁ ∈SVBBthen S ∈Stypewhere SVBBand Stypeare defined in Definition4.3.

$$ \mathsf{V B B}\Rightarrow\mathsf{o d i O}) $$

$$ S_{b} $$

$$ b\in{0,1} $$

$$ \big(C_{b},\alpha\big),=,\mathsf{S}_{b}\ 1^{\lambda};r\big) $$

$$ r\ \in\ {0,1}^{*} $$

$$ (\mathcal{C}{0},\mathcal{C}{1},\alpha),=,\S(1^{\lambda};r) $$

$$ \mathsf{S}{0},\mathsf{S}{1}\in\mathcal{S}_{\mathsf{V B B}} $$

$$ \mathsf{S}\in\mathcal{S}_{\mathsf{t y p e}} $$

$$ S_{\mathrm{t y p e}} $$

$$ 4.3. $$

By leveraging a similar argument to that used to prove Theorem4.5, we can demonstrate that any negative result for diO extends to odiO. This because any diO-sampler S is also an odiO-sampler and,


10 since diO and odiO leverage the same indistinguishability-based definition, if S ̸∈SdiOthen S ̸∈SodiO. The same applies between odiO and oiO, and between oiO and VBB (with respect to samplers as defined in Theorem4.6).

$$ \mathsf{S}\not\in\mathcal{S}_{\mathsf{o d i}0} $$

$$ \mathsf{S}\not\in\mathcal{S}_{\mathsf{d i}0} $$

$$ {\dot{\mathrm{i}}}0, $$

Corollary 4.7. For type ∈{diO,odiO,oiO,VBB}, let Stypebe an ensemble of type*-samplers as defined* in Definition4.3. The following conditions holds:

$$ \in \left{\mathrm {d i O}, \mathrm {o d i O}, \mathrm {o i O}, \mathrm {V B B} \right} $$

$$ S_{\mathrm{t y p e}} $$

1.For every diO*-sampler* S such that S ̸∈SdiOthen S ̸∈SodiO.

$$ \mathsf{S}\not\in\mathcal{S}_{\mathsf{d i00}} $$

$$ \mathsf{S}\not\in\mathcal{S}_{\mathsf{o d i0}} $$

2.For every odiO*-sampler* S such that S ̸∈SodiOthen S ̸∈SoiO.

$$ \mathsf{S}\notin\mathcal{S}_{\mathsf{o d i0}} $$

λ 3.For every oiO*-sampler* S and every pair of VBB*-samplers* (S₀*,S₁) such that (Cb,α*) = Sb(1; r) where ∗ λ r ∈ {0,1}, (C₀,C₁,α)=S(1; r) and b ∈ {0,1} (as defined in Theorem4.6), if S ̸∈ SoiOthen S₀ ̸∈SVBBor S₁ ̸∈SVBB.

$$ \mathsf{S}\not\in\mathcal{S}_{\mathsf{o}\mathsf{i}0} $$

$$ (\mathsf{S}{0},\mathsf{S}{1}) $$

$$ C{{\ ({\cal C}{b},\alpha)}}={\ {\sf S}{b}}(1^{\lambda};r)right) $$

$$ r\in{0,1}^{*},,(\mathcal{C}{0},\mathcal{C}{1},\alpha)=\S(1^{\lambda};r) $$

$$ 4.6) $$

$$ b\in\left{0,1\right} $$

$$ :\mathsf{S}\notin\mathcal{S}_{\mathsf{o}\mathsf{i}0} $$

$$ \mathsf{S}{0}\not\in\mathcal{S}{\mathsf{V B l}} $$

$$ {\mathsf{S}}_{1}\not\in{\mathcal{S}} $$

Lastly, odiO (resp. oiO) does not imply VBB, i.e., both odiO and oiO are strictly weaker than VBB. + This follows by leveraging two observations. First, Barak et al. [BGI 01, Lemma 3.5, Corollary 3.8] have demonstrated that there (unconditionally) exists a distribution of circuits that cannot be VBBobfuscated (see also Section6.1). This, in turn, implies that there exists a VBB-sampler S₀ ̸∈SVBB, i.e., + S₀ outputs (C, ⊥) where C comes from the distribution of [BGI 01, Lemma 3.5]. Second, we have that any sampler S₁, that outputs (C₀,C₁, ⊥) such that C₀ = C₁, is an odiO-sampler (resp. oiO-sampler) 11 that can be easily odiO-obfuscated (resp. oiO-obfuscated). By combining these two observations, we $λ conclude that if S₁ outputs (C₀,C₁, ⊥) where C₀ = C₁ and (C₀, ⊥) ← S₀(1), it follows that neither C₀ nor C₁ (sampled by S₀) can be VBB-obfuscated but S₁ can be odiO-obfuscated (resp. oiO-obfuscated). While this counterexample might be trivial at first sight, it indeed captures the fact that an odiO-/oiOobfuscator is allowed to reveal any information which is common to the two circuits, as long as this information does not allow to win the respective distinguishing game between the oracles.

$$ \mathrm{[B G I^{+}01} $$

$$ S_{0} $$

$$ \mathsf{S}{0}\not\in\mathcal{S}{\mathsf{V B B}} $$

$$ (C,\bot) $$

$$ C $$

$$ \mathrm{B G I^{+}01} $$

$$ {_{1}} $$

$$ \ {mathcal C C}{0}={\mathcal C}{1} $$

$$ (C_{0},C_{1},\bot) $$

$$ S_{1} $$

$$ C_{0} $$

$$ (C_{0},C_{1},\bot) $$

$$ C_{0}=C_{1} $$

$$ (C_{0},\bot)\leftarrow\ !mathsf S S_{0}(1^{\lambda}) $$

$$ C_{1} $$

$$ S_{1} $$

$$ \mathsf{S}_{0}) $$

Theorem 4.8(odiO ̸⇒ VBB and oiO ̸⇒ VBB). Let S₀ be a VBB*-sampler (Definition3.4). Consider* λ the odiO*-sampler (resp.* oiO*-sampler)* S₁ defined as (C₀,C₁,α) = S₁(1; r) where C₀ = C₁ and (C₀,α) = λ ∗ S₀(1; r) for r ∈{0,1}. For type ∈{odiO,oiO}, there exists a VBB*-sampler* S₀ such that S₀ ̸∈SVBBand S₁ ∈Stypewhere SVBBand Stypeas defined in Definition4.3.

$$ \ {sf o i i}\not\to{\sf V B B}) $$

$$ S_{0} $$

$$ {mathrm S S}_{1} $$

$$ (left mathcal C{{0}},mathcal\ C{{1}}{1},\alpha)=\mathsf{S}{1}(1^{\lambda};r) $$

$$ C_{0}=C_{1} $$

$$ \mathrm {S} _ {0} \left(1 ^ {\lambda}; r\right) $$

$$ (C_{0},\alpha)= $$

$$ r\in{0,1}^{*} $$

$$ \mathtt{a}\in{\mathtt{o d i O},\mathtt{o i O}} $$

$$ S_{0} $$

$$ \mathsf{S}{0}\not\in\mathcal{S}{\mathsf{V B B}} $$

$$ \mathsf{S}{1}\in\mathcal{S}{\mathsf{t y p e}} $$

$$ S_{\mathsf{V B B}} $$

$$ S_{\mathrm{t y p e}} $$

$$ 4.3 $$

5 Applications of odiO and oiO

In this section, we show that odiO and oiO are able to compile several symmetric key primitives into their corresponding public key versions and designated verifier non-interactive argument systems into their public verifiable version. These transformations achieve (and use) different flavors of security whose definitions can be found in AppendixA. In more details, we demonstrate the following transformations:

Function-Preserving PV-NIZK from DV-NIZK: odiO is able to compile any designated verifier non-interactive argument system (that satisfies either selective soundness or straight-line knowledge soundness) into its public verifiable version (Section5.1).

Function-Preserving Signatures from MACs: odiO is able to compile any (q)-sEUF-sel-CMA MAC into a (q)-sEUF-sel-CMA signature scheme (Section5.2).

$$ (q)\mathrm{-s E U F-s e l-_C M M}M A C $$

Format-Preserving Signatures from MACs: odiO is able to compile EUF MAC into a sel-EUF- CMA digital signature scheme, using puncturable PRF (Section5.3).

Format-Preserving PKE from IV-based SKE: odiO is able to compile semantically secure IV-based SKE (i.e., SKE whose encryption algorithm has the following sintax Enc(k*,m*; iv) = (iv*,c*)) into a sel-IND-CPA PKE, using puncturable PRF (Section5.4).

$$ \mathsf{E n c}(\mathsf{k},m;\mathsf{\dot{w}})=\big(\mathsf{\dot{w}},c\big), $$

Function-Preserving PKE from SKE: oiO is able to compile any semantically and sel-IND-CPRAkey secure SKE into a sel-IND-CPA PKE (Section5.5).

Note that transformations that use the puncturable PRFs are only format-preserving whereas the others are fully function-preserving.


$C_{\mathrm{vrs}}^{\mathrm{Verify}}(x,\pi)$ S_{x}(1^{\lambda};r)
return b=Verify*(\mathrm{vrs},x,\pi) (crs,vrs)=Setup*\left(1^{\lambda};r\right)
$C_{\mathrm{vrs},x^{*}}^{\mathrm{Verify}}(x,\pi)$ Set C_{0}=C_{\mathrm{vrs}}^{\mathrm{Verify}},C_{1}=C_{\mathrm{vrs},x}^{\mathrm{Verify}},\alpha=\mathrm{crs}$
If x=x^{*},return 0 return(C_{0},C_{1},\alpha)
return b=Verify*(\mathrm{vrs},x,\pi) S_{\mathrm{Ext}^{*}}(1^{\lambda};r)
$C_{\mathrm{vrs,td},r}^{\mathrm{Verify}}(x,\pi)$ Let r=(r_{0},r_{1})
$\omega=\mathrm{Ext}_{1}^{*} \left(1^{\lambda},\mathrm{td},x,\pi ;r\right)$ (crs,vrs,td)=Ext_{0}^{*} \left(1^{\lambda},\mathcal{R};r_{0}\right)$
If Verify*(\mathrm{vrs},x,\pi)=1 and(x,\omega)\in\mathcal{R},return 1 Set C_{0}=C_{\mathrm{vrs}}^{\mathrm{Verify}},C_{1}=C_{\mathrm{vrs,td},r_{1}}^{\mathrm{Verify}},\alpha=\mathrm{crs}$
return 0 return(C_{0},C_{1},\alpha)

$$ C_{\mathsf{v r s}}^{\mathsf{V e r i f y}}(x,\pi) $$

$$ \mathsf{S}_{x}(1^{\lambda};r) $$

$$ (\mathsf{c r s},\mathsf{v r s})=\mathsf{S e t u p}^{*}(1^{\lambda};r) $$

$$ b=\mathsf{V e r i f y}^{*}(\mathsf{v r s},x,\pi) $$

$$ C_{\mathsf{v r s},x^{*}}^{\mathsf{V e r i f y}}(x,\pi) $$

$$ \mathcal{C}{0}=\mathcal{C}{\mathsf{v r s}}^{\mathsf{V e r i f y}},\mathcal{C}{1}=\mathcal{C}{\mathsf{v r s},x}^{\mathsf{V e r i f y}},\alpha=\mathsf{c r S} $$

$$ (C_{0},C_{1},\alpha) $$

$$ x\mathbf{} $$

$$ b=\mathsf{V e r i f y}^{*}(\mathsf{v r s},x,\pi) $$

$$ \mathsf{S}_{\mathsf{E x t}^{*}}(1^{\lambda};r) $$

$$ \boldsymbol{r}=(r_{0},r_{1}) $$

$$ \ \big(\mathsf{c r s},\mathsf{v r s},\mathsf{t d}\big)=\mathsf{E x t}{0}^{*}\big(1^{\lambda},\mathcal{R};r{0}\big) $$

$$ \mathbf{f};\mathsf{V e r i f y}^{*}(\mathsf{v r s},x,\pi)=1 $$

$$ C_{\mathsf{v r s,t d},r}^{\mathsf{V e r i f y}}(x,\pi) $$

$$ \mathcal{C}{0}=\mathcal{C}{\mathsf{v r s}}^{\mathsf{V e r i f y}},\mathcal{C}{1}=\mathcal{C}{\mathsf{v r s},\mathsf{t d},r_{1}}^{\mathsf{V e r f f y}},\alpha=\mathsf{c r S} $$

$$ \omega={\sf E x t}_{1}^{*}(1^{\lambda},{\sf t d},x,\pi;r) $$

$$ \ x,\omega,\in\mathcal{R}. $$

$$ (C_{0},C_{1},\alpha) $$

Verify Verify Verify Verify Verify Verify Fig. 2: The circuits C, C ∗, C, and the samplers Sx,SExt∗. C and C ∗ (resp. C and vrs vrs,x vrs,td,r vrs vrs,x vrs Verify Verify Verify Verify Verify C) are padded to match the size γ = max*{|C*vrs|, |Cvrs,x∗ |} (resp. γ = max*{|C*vrs|, |C |}). vrs,td,r vrs*,td,r*

$$ C_{\mathsf{v r s}}^{\mathsf{V e r i f y}},C_{\mathsf{v r s},x^{*}}^{\mathsf{V e r i f y}},C_{\mathsf{v r s},\mathsf{t d},r}^{\mathsf{V e r i f y}}. $$

$$ \mathsf{S}{x}\mathbf,{mathsf mathsf S}{\mathsf{E x t}^{*}}.;C_{\mathsf{v r s}}^{\mathsf{V e r i f y}} $$

$$ C_{\mathsf{v r s},x^{*}}^{\mathsf{V e r i f y}};(\mathrm{r e s p.};C_{\mathsf{v r s}}^{\mathsf{V e r i f y}} $$

$$ C_{\mathsf{v r s,t d},r}^{\mathsf{V e r i f y}}) $$

$$ \gamma=\mathsf{m a x}{|C_{\mathsf{v r s}}^{\mathsf{V e r i f y}}|,|C_{\mathsf{v r s},x^{*}}^{\mathsf{V e r i f y}}|} $$

$$ \gamma=\mathsf{m a x}\big{|C_{\mathsf{v r s}}^{\mathsf{V e r i f y}}|,|C_{\mathsf{v r s,\mathsf{t d},r}}^{\mathsf{V e r i f y}}|}\big) $$

5.1 From designated verifier to public verifiable non-interactive argument systems

∗ ∗ ∗ ∗ Construction 1 Let Π = (Setup*,Prove,Verify) and Obf be a DV non-interactive argument system ∗ for a relation R and an obfuscator, respectively. We compile Π into a PV non-interactive argument system Π = (Setup,Prove,*Verify) for the same relation R as follows:

$$ \ Pi^{}=({\sf S e t u p}^{},{\sf P r o u e}^{},{\sf V e i i f}^{}) $$

$$ I^{*} $$

λ λ Setup(1*, R*): On input the security parameter 1 and a relation R, the setup algorithm computes ∗ ∗ ∗ λ ∗e eλ Verify (crs*,vrs) ←$ Setup (1, R*) and outputs crs = crs and vrs = C where C ←$ Obf(1*,C* ∗) and vrs Verify Cvrsis depicted in Figure2.

$$ (1^{\lambda},\mathcal{R}) $$

$$ 1^{\lambda} $$

$$ \left(\mathsf{c r S}^{},\mathsf{v r S}^{}\right)\leftarrow_{\mathfrak{s}}\mathsf{S e t u p}^{*}(1^{\lambda},\mathcal{R}) $$

$$ \ {mathsf c r r},=,{\mathsf{c r s}}^{*} $$

$$ =,{\widetilde C{C}} $$

$$ \widetilde {C} \leftarrow {} ^ {$} \mathrm {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {v r s} ^ {*}} ^ {\mathrm {V e r i f y}}\right) $$

$$ C _ {\mathrm {v r s}} ^ {\mathrm {V e r i f y}} $$

∗ Prove(crs*,x,ω*): On input the common reference string crs = crs*, a statement x, and a witness ω, the* ∗ ∗ prover algorithm outputs π ←$ Prove (crs*,x,ω*).

$$ (mathsf c r r,x,\omega) $$

$$ x, $$

$$ {\mathsf{c r s}}={\mathsf{c r s}}^{*} $$

Verify(vrs*,x,π*): On input the verification key vrs = Ce*, a statement x, and a proof π, the verification* algorithm returns b = Ce(x,π).

$$ k e y\ \mathsf{v r s}=\dot{C}} $$

$$ b=\tilde{C}(x,\pi) $$

Below we establish the following result whose proof appears in AppendixB.2.

∗ Theorem 5.1. Let Π and Obf as defined in Construction1. For every x ̸∈L, consider the sampler Sx depicted in Figure2.

$$ \ ^{*} $$

$$ x\not\in\mathcal{L}, $$

$$ {sf S}_{x} $$

∗ 1.If Π satisfies selective soundness (DefinitionA.2) then, for every x ̸∈ L, Sxis an odiO*-sampler* (Definition4.1), and

$$ \varPi^ {*} $$

$$ x;notnot\in;\ {mathcal L L},;\mathsf{S}_{x} $$

$$ 4.1) $$

2.if Obf is a ({Sx}x̸∈L)-odiO-obfuscator (Definition4.2) then the publicly verifiable non-interactive argument system Π of Construction1satisfies selective soundness (DefinitionsA.2andA.4).

$$ a \left(\left{\mathrm {S} _ {x} \right} _ {x \notin \mathcal {L}}\right) - \mathrm {o d i O} $$

$$ 4.2) $$

We extend the above result to the case of straight-line knowledge soundness. The proof appears in AppendixB.3.

$$ \ ^{*} $$

∗ Theorem 5.2. Let Π and Obf as defined in Construction1.

∗∗ 1.If Π satisfies straight-line knowledge soundness (DefinitionA.3) then the sampler SExtof Figure2 ∗ ∗ ∗ ∗ is an odiO*-sampler (Definition4.1) where* Ext = (Ext0*,*Ext1) is the PPT extractor of Π, and

$$ \varPi^ {*} $$

$$ \mathsf{S}_{\mathsf{E}\times\mathsf{t}^{*}} $$

$$ \mathsf{E x t}^{}=(\mathsf{E x t}_{0}^{},\mathsf{E x t}_{1}^{*}) $$

$$ 4.I) $$

$$ 2 $$

2.if Obf is a ({SExt∗})-odiO-obfuscator (Definition4.2) then the publicly verifiable non-interactive ar- gument system Π of Construction1satisfies straight-line knowledge soundness (DefinitionsA.3 andA.4).

$$ \ ^{*} $$

$$ a\left(\left{\mathsf{S}_{\mathsf{E x t}^{*}}\right}\right) $$

$$ 4.2) $$

$$ A.4) $$

10 Otherwise, if S ∈SodiO, there exists a ({S})-odiO-obfuscator that in turn is also a ({S})-diO-obfuscator.

$$ \mathsf{S}\in\mathcal{S}_{\mathsf{o d i0}} $$

11 Indeed, any PPT obfuscator Obf that satisfies correctness and polynomial slowdown is a ({S})-odiO-obfuscator (resp. ({S})-oiO-obfuscator), e.g., Obf is the identity function or Obf is an iO-obfuscator.


Remark 5.3(On zero-knowledge). Observe that Construction1preserves zero-knowledge if the under- ∗ lying designated verifier non-interactive argument system Π is zero-knowledge. This is straightforward and follows intuitively because Construction1only obfuscates vrs (that it is known by a malicious ver- ∗ ifier against zero-knowledge) and it does not alter Π ’s Prove. A proof sketch of the zero-knowledge property would be as follows. The simulator for the publicly verifiable case is the same as the one for the designated verifier case. Now assume there exists an adversary Apvdistinguishing simulated proofs from honest ones. We could then design adversary Advbreaking zero-knowledge of the original scheme. λ Verify This adversary can in fact internally run Apvpassing to it the obfuscation Obf(1*,C*vrs). It can do that because the designated-verifier zero-knowledge has access to vrs.

$$ \varPi^ {*} $$

$$ \varPi^ {*} \mathrm {s} $$

$$ \ _\mathrm{d v} $$

$$ \mathrm{A_{p v}} $$

$$ \mathrm{A_{p v}} $$

$$ \mathsf{O b f}(1^{\lambda},C_{\mathsf{v r s}}^{\mathsf{V e r i f y}}) $$

More on our transformations for arguments. To the best of our knowledge our work is the first to explicitly study how obfuscation can be used to transform designated verifiability into public verifia- 12 bility. One interesting feature of our transformation is that it fully preserves both the communication complexity and the prover complexity of the original designated-verifier scheme. Moreover, in certain cases it also preserves the asymptotic running time of the verifier. For example, if the verifier of the original dv-NIZK runs in asymptotic time O(polylog (|w|) poly(λ))—where w denotes the witness—so will 13 the verifier in the compiled publicly verifiable scheme. We believe these results can be of interest in at least two ways. First, they can leverage the efficiency (in terms of prover and proof size) of available designated-verifier schemes for which we cannot find a more efficient publicly verifiable counterpart. Second, they may provide a theoretical connection between designated and publicly verifiable SNARGs. For example, if both odiO and dv-SNARGs were known to be plausibly obtainable from assumption X, our transformation would show that pv-SNARGs can also be obtained from assumption X. To the best of our knowledge, not much is know on a separation between the two (see [CK21, Section 1.2] for a discussion).

We observe that constructions of non-adaptive zero-knowledge pv-SNARGs were already known through iO from the work in [SW14]. We now compare our results. First, we stress that our goals are different: our main priority is to obtain a pv-SNARG through a structure-preserving transformation from a weaker primitive (a dv-SNARG). The approach in [SW14] is not structure-preserving since their goal is to construct a zero-knowledge proof system “from scratch” through iO. Our constructions also differ with respect to some efficiency metrics. The verifier in [SW14] runs in O(poly (|x|,λ)) while ours can potentially have worse asymptotics; their proof size is always polynomial in the security parameter and independent of other parameters. On the other hand, their construction has large parameters—it includes an obfuscation of a program verifying the whole relation—while our transformation preserves the size of the public parameters in the original dv-SNARG, which may be small.

$$ O(\mathsf{p o l y}\left(|x|,\lambda\right)) $$

5.2 From (q)-sEUF-sel-CMA MACs to (q)-sEUF-sel-CMA digital signatures

∗ ∗ ∗ ∗ Construction 2 Let Π = (KGen*,Tag,Verify) and Obf be a MAC with message space M and an ∗ obfuscator, respectively. We compile Π into a digital signature scheme Π = (KGen,Sign,*Verify) with message space M as follows:

$$ \varPi^ {} = \left(\mathrm {K G e n} ^ {}, \mathrm {T a g} ^ {}, \mathrm {V e r i f y} ^ {}\right) $$

$$ I^{*} $$

λ q λ q KGen(1*,1): On input the security parameter 1, parameter* 1*, the key generation algorithm computes* ∗ ∗ λ qe∗eλ k ←$ KGen (1*,1) and outputs pk = C and sk = k where C ←$ Obf(1,C∗*) and C is kVerify kVerify depicted in Figure3.

$$ (1^{\lambda},1^{q}) $$

$$ 1^{\lambda} $$

$$ 1^{q}. $$

$$ \mathsf{k}^{}\leftarrow\ \ mathsf s mathsf K G\ \ !{1}^{}(1^{\lambda},1{}^{q}) $$

$$ {mathsf p p k}={\dot{C}} $$

$$ {mathfrak s k k},=,\mathsf{k}^{*} $$

$$ \widetilde {C} \leftarrow {} ^ {$} \mathrm {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {k} ^ {*}} ^ {\mathrm {V e r i f y}}\right) $$

$$ C_{k}^{\bar{\mathsf{V e r i f y}}} $$

∗ Sign(sk*,m*): On input the secret key sk = k and a message m ∈M, the randomized signing algorithm ∗ ∗ outputs σ ←$ Tag (k*,m*).

$$ \mathsf{s k}=\mathsf{k}^{*} $$

$$ m\in{\mathcal{M}} $$

$$ \sigma\leftarrow\ {sf s}\mathsf{T a g}^{}({\mathsf k}^{},m) $$

Verify(pk*,m,σ*): On input the public key pk = Ce*, a message m ∈M, and a signature σ, the verification* algorithm returns b = Ce(m,σ).

$$ \mathrm {p k} = \widetilde {C} $$

$$ (\mathsf{p k},m,\sigma) $$

$$ m\in{\mathcal{M}} $$

$$ b=C(m,\sigma) $$

$$ \sigma, $$

Below we establish the following result whose proof appears in AppendixB.4.

12 The work in [CK21] studies how much we can push succinct designated verifiability in proof schemes to obtain succinct and (somewhat) publicly verifiable schemes albeit both within a setting and through primitives very different from ours (e.g., requiring a committee sharing a secret).

13 This holds if the public input x is absent or of size polynomial in the security parameter (e.g., in the case of the opening of a Merkle tree with given root). In the more general case, the resulting verifier will run in time O(polylog (|w|) poly(λ) + poly(|x|)).


$$ \mathsf{S}_{\mathcal{Y}}(1^{\lambda};r) $$

$C_{k}^{\mathrm{Verify}}(m,\sigma)$ S_{\mathcal{Y}}(1^{\lambda};r)$
return $b=\mathrm{Verify}^{*}(\mathrm{k},m,\sigma)$ Let $r=(r_{0},\ldots,r_{q})$
$C_{\mathcal{X}}^{\mathrm{Verify}}(m,\sigma)$ Let $\mathcal{Y}={m_{1},\ldots,m_{q}}$
$C_{\mathcal{X}}^{\mathrm{Verify}}(m,\sigma)$ $\mathrm{k}=\mathrm{KGen}^{*}(1^{\lambda},1^{q};r_{0})$
If $(m,\sigma)\notin\mathcal{X}$, return 0 $\forall i\in[q],\sigma_{i}=\mathrm{Tag}^{*}(\mathrm{k},m_{i};r_{i})$
return 1 Set $\mathcal{X}={(m_{i},\sigma_{i})}_{i\in[q]}$
return 1 Set $C_{0}=C_{k}^{\mathrm{Verify}},C_{1}=C_{\mathcal{X}}^{\mathrm{Verify}},\alpha=(\sigma_{1},\ldots,\sigma_{q})$
return 1 return $(C_{0},C_{1},\alpha)$

$$ C_{\mathsf{k}}^{\mathsf{V e r i f y}}(m,\sigma) $$

$$ r=(r_{0},\ldots,r_{q}) $$

$$ b=\mathsf{V e r i f y}^{*}(\mathsf{k},m,\sigma) $$

$$ \mathcal{Y}=\left{m_{1},\ldots,m_{q}\right} $$

$$ \ {cal C C}_{\chi}^{\sf V e r i f y}(m,\sigma) $$

$$ \mathbf{I f};(m,\sigma)\not\in\mathcal{X},;\mathbf{r e t u r n};0 $$

$$ \forall i\in[q],;\sigma_{i}=\mathsf{T a g}^{*}\big(\mathsf{k},m_{i};r_{i}\big) $$

$$ {\sf{k}}={\sf{K G e n}}^{*}(1^{\lambda},1^{q};r_{0}) $$

$$ \mathcal{X}={\left(m_{i},\sigma_{i}\right)}_{i\in[q]} $$

$$ C_{0}{\ =\ }C_{\mathsf{k}}^{\mathsf{V e r i f y}},\mathit C_{1}{\ =\ }C_{\mathcal{X}}^{\mathsf{V e r i f y}},\alpha{\ =\ }(\sigma_{1},\ldots,\sigma_{q}) $$

$$ \left(C _ {0}, C _ {1}, \alpha\right) $$

Verify Verify Fig. 3: The circuits C, CX, and the sampler SY. C and CXare padded to match the size kVerify kVerify Verify γ = max*{|C |, |C*X|}. kVerify

$$ \mathsf{S}{\mathcal{Y}}.,C{\mathsf{k}}^{\mathsf{V e r i f y}} $$

$$ C_{\mathsf{k}}^{\mathsf{V e r i f y}},,C_{\mathcal{X}}^{\mathsf{V e r i f y}} $$

$$ C_{x}^{\mathsf{V e r i f y}} $$

$$ \gamma=\mathsf{m a x}{|C_{\mathsf{k}}^{\mathsf{V e r i f y}}|,|C_{\mathcal{X}}^{\mathsf{V e r i f y}}|} $$

$$ \mathcal{C}_{\mathfrak{s}}^{\mathsf{V e r i f y}}(m,\sigma) $$

$C_{s}^{\mathrm{Verify}}(m,\sigma)$ S_{m}(1^{\lambda};r)
k=KGen_{0}^{}(1^{\lambda};F_{1}^{}(s,m)) s=Gen_{1}^{*}(1^{\lambda};r)
return b=Verify_{0}^{*}(k,m,\sigma) s'=Punct_{1}^{*}(s,m)
$C_{s,m^{*}}^{\mathrm{Verify}}(m,\sigma)$ Set C_{0}=C_{s}^{\mathrm{Verify}},C_{1}=C_{s^{\prime},m}^{\mathrm{Verify}},\alpha=s^{\prime}$
If m=m^{*}, return 0 return(C_{0},C_{1},\alpha)
k=KGen_{0}^{}(1^{\lambda};F_{1}^{}(s,m))
return b=Verify_{0}^{*}(k,m,\sigma)

$$ \mathsf{S}_{m}(1^{\lambda};r) $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{1}^{}(\mathsf{s},m))\quad\quad\quad\mathsf{s}=\mathsf{G e n}_{1}^{}(1^{\lambda};r) $$

$$ b=\mathsf{V e r i f y}{0}^{*}(\mathsf{k},m,\sigma)\quad\mathsf{s}^{\prime}=\mathsf{P u n c t}{1}^{*}(\mathsf{s},m) $$

$$ \mathcal{C}{0}=\mathcal{C}{\mathfrak{s}}^{\mathsf{V e r i f y}},\mathcal{C}{1}=\mathcal{C}{\mathfrak{s}^{\prime},m}^{\mathsf{V e r i f y}},\alpha=\mathfrak{s}^{\prime} $$

$$ \mathcal{C}_{\mathfrak{s},m^{*}}^{\mathsf{V e r f y}}(m,\sigma) $$

$$ {\bf I f};m=m^{*},;{\bf r e t u r n};0 $$

$$ \left(C _ {0}, C _ {1}, \alpha\right) $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{1}^{*}(\mathsf{s},m)) $$

$$ {\mathrm{r e t u r n}};b={\mathsf{V e r i f y}}_{0}^{*}(\mathsf{k},m,\sigma) $$

Fig. 4: The circuits CsVerify, CsVerify,m∗, and the sampler Sm. CsVerifyand CsVerify,m∗ are padded to match the size γ = max*{|C*sVerify|, |CsVerify,m∗ |, |C′ ∗ ∗|} where C′ ∗ ∗is defined in AppendixB.5. sVerify,m,k sVerify,m,k

$$ \mathcal{C}{\mathfrak{s}}^{\mathsf{V e r i f y}},\mathcal{C}{\mathfrak{s},m^{*}}^{\mathsf{V e r i f y}} $$

$$ \mathsf{S}{m}.,\mathcal{C}{\mathsf{s}}^{\mathsf{V e r i f y}} $$

$$ C_{\mathsf{s},m^{*}}^{\mathsf{V e r i f y}} $$

$$ \gamma=\mathsf{m a x}{|C_{\mathbf{s}}^{\mathsf{V e r i f y}}|,|C_{\mathbf{s},m^{}}^{\mathsf{V e r i f y}}|,|C_{\mathbf{s}^{\prime},m^{},\mathbf{k}^{*}}^{\mathsf{V e r i f y}}|} $$

$$ C_{\mathsf{s}^{\prime},m^{},\mathsf{k}^{}}^{\mathsf{V e r i f y}} $$

∗ Theorem 5.4. Let Π and Obf as defined in Construction2. For every qinN*, every Y⊆M such that* |Y| = q, consider the sampler SYdepicted in Figure3.

$$ I^{*} $$

$$ \mathcal{Y}\subseteq\mathcal{M} $$

$$ |\mathcal{V}|=q, $$

$$ S y $$

∗ 1.If Π is (q)-sEUF-sel-CMA (DefinitionA.10) then for every Y ⊆M such that |Y| = q, SYis an odiO*-sampler (Definition4.1), and*

$$ I^{*} $$

$$ \ \mathcal\ Y\subseteq{\mathcal M} $$

$$ |\mathcal{Y}|=q,,\mathsf{S}_{\mathcal{Y}} $$

2.for every q ∈ N*, if* Obf is a ({SY}Y⊂M:|Y|=q)-odiO-obfuscator (Definition4.2) then the signature scheme Π of Construction2is (q)-sEUF-sel-CMA (DefinitionA.13).

$$ q\in\mathbb{N} $$

$$ a,({\S_{y}}_{\mathcal Y subset M:|\mathcal Y|=q})\to0010 $$

$$ 4.2) $$

$$ \sin(q)-s E F F-s e l-C M A $$

5.3 From EUF MACs to sel-EUF-CMA digital signatures using puncturable PRFs

∗ ∗ ∗ ∗ ∗ ∗ ∗ ∗ Construction 3 Let Π₀ = (KGen0,Tag0,Verify0), Π₁ = (Gen1, F1*,Punct1) and Obf be a MAC with ∗ ∗ message space M, a puncturable PRF, and an obfuscator, respectively. We combine Π₀ and Π₁ into a digital signature scheme Π = (KGen,Sign,*Verify) with message space M as follows:

$$ \varPi_ {0} ^ {} = \left(\mathrm {K G e n} _ {0} ^ {}, \mathrm {T a g} _ {0} ^ {}, \mathrm {V e r i f y} _ {0} ^ {}\right) $$

$$ \varPi_ {1} ^ {} = \left(\mathrm {G e n} _ {1} ^ {}, \mathrm {F} _ {1} ^ {}, \mathrm {P u n c t} _ {1} ^ {}\right) $$

$$ P R P, $$

$$ \ {cal Pi_{0}^{*}} $$

$$ \varPi_ {1} ^ {*} $$

$$ \mathit{\Pi}=(\mathsf{K G e n},\mathsf{S i g n},\mathsf{V e r i f y}) $$

λ λ ∗ λ KGen(1): On input the security parameter 1*, the key generation algorithm computes* s ←$ Gen (1) and 1 e e$λ outputs pk = C and sk = s where C ← Obf(1*,C*sVerify) and CsVerifyis depicted in Figure4.

$$ {mathsf{K G e n}(1^{\lambda})} $$

$$ 1^{\lambda} $$

$$ \mathsf{}mathsf s leftarrowleftarrow\mathsf{G e n}_{1}^{*}(1^{\lambda}) $$

$$ \widetilde {C} \leftarrow {} ^ {\mathrm {s}} \operatorname {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {s}} ^ {\mathrm {V e r i f y}}\right) $$

$$ C_{\mathrm{s}}^{\mathrm{V e r i f y}} $$

$$ \mathsf{S i g n(k,}m) $$

$$ {{\mathcal{}}{{\mathcal{4}}}}. $$

$$ =\mathrm{s} $$

Sign(sk*,m*): On input the secret key sk = s and a message m ∈M, the randomized signing algorithm ∗ λ ∗ outputs σ ←$ Tag (k*,m*) where k = KGen(1; F (s*,m*)). 1

$$ m\in{\mathcal{M}} $$

$$ \sigma\leftarrow\ {sf s}{\sf T a g}^{*}({\sf k},m) $$

Verify(pk*,m,σ*): On input the public key pk = Ce*, a message m ∈M, and a signature σ, the verification* algorithm returns b = Ce(m,σ).

$$ k\ {\ =\ }{\mathsf{K G n n}}(1^{\lambda};{\mathsf{F}}_{1}^{*}({\mathsf{s}},m)) $$

$$ (\mathsf{p k},m,\sigma) $$

$$ m\in{\mathcal{M}} $$

$$ {\mathfrak{p k}}=C. $$

$$ b=\tilde{C}(m,\sigma) $$

$$ \sigma, $$

Below we establish the following result whose proof appears in AppendixB.5.

∗ ∗ Theorem 5.5. Let Π₀, Π₁, and Obf as defined in Construction3. For every m ∈ M, consider the sampler Smdepicted in Figure4.

$$ \mathit{\Pi}{0}^{*},;\mathit{\Pi}{1}^{*} $$

$$ m\in{\mathcal{M}} $$

$$ S_{m} $$

$$ 4. $$


$C_{s_{1}, s_{2}}^{\mathrm{Enc}}(m,r)$ S_{m}(1^{\lambda};r)
iv=F_{1}^{*}(\mathrm{s}_{1}, r)$ Let $r=(r_{0}, r_{1}, r_{2})$
k=KGen_{0}^{}(1^{\lambda};\mathrm{F}_{2}^{}(\mathrm{s}_{2}, iv))$ $\mathrm{s}{1}=\mathrm{Gen}{1}^{}(1^{\lambda};r_{0}), \mathrm{s}{2}=\mathrm{Gen}{2}^{}(1^{\lambda};r_{1})$
return Enc_{0}^{*}(\mathrm{k}, m; iv)$ iv=F_{1}^{*}(\mathrm{s}{1}, r{2})
$C_{s_{1}, s_{2}, r^{*}}^{\mathrm{Enc}}(m,r)$ k=KGen_{0}^{}(1^{\lambda};\mathrm{F}_{2}^{}(\mathrm{s}_{2}, iv))$
If $r=r^{*}$, return 0 c=Enc_{0}^{*}(\mathrm{k}, m; iv)$
iv=F_{1}^{*}(\mathrm{s}_{1}, r)$ $\mathrm{s}{1}^{\prime}=\mathrm{Punct}{1}^{}(\mathrm{s}{1}, r{2}), \mathrm{s}{2}^{\prime}=\mathrm{Punct}{2}^{}(\mathrm{s}_{2}, iv)$
k=KGen_{0}^{}(1^{\lambda};\mathrm{F}_{2}^{}(\mathrm{s}_{2}, iv))$ Set $C_{0}=C_{s_{1}, s_{2}}^{\mathrm{Enc}}, C_{1}=C_{s_{1}^{\prime}, s_{2}^{\prime}, r_{2}}^{\mathrm{Enc}}, \alpha=c$
return Enc_{0}^{*}(\mathrm{k}, m; iv)$ return $(C_{0}, C_{1}, \alpha)$

$$ C_{\mathfrak{s}{1},\mathfrak{s}{2}}^{\sf E n c}(m,r) $$

$$ \mathsf{S}_{m}(1^{\lambda};r) $$

$$ \mathsf{i v}=\mathsf{F}{1}^{*}(\mathsf{s}{1},r) $$

$$ r(r_{0},r_{1},r_{2}) $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{2}^{}(\mathsf{s}_{2},\mathsf{i v}))\quad\mathrm{}{~\ {sf s}1=}\ \mathsf{G e n}{1}^{}(1^{\lambda};r_{0}),\mathrm{}{\ {\sf s}_2=}\mathsf{G e n}{2}^{*}(1^{\lambda};r{1}) $$

$$ \mathsf{i v}=\mathsf{F}{1}^{*}(\mathsf{s}{1},r_{2}) $$

$$ \mathrm {r e t u r n} \operatorname {E n c} _ {0} ^ {*} (\mathrm {k}, m; \mathrm {i v}) $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{2}^{*}(\mathsf{s}_{2},\mathsf{i v})) $$

$$ C_{\mathfrak{s_{1}},\mathfrak{s_{2}},r^{*}}^{\mathsf{E n c}}(m,r) $$

$$ c=\mathsf{E n c}_{0}^{*}(\mathsf{k},m;\mathsf{i v}) $$

$$ {\bf I f};r=r^{*},;{\bf r e t u r n};0 $$

$$ \mathsf{s}{1}^{\prime}=\mathsf{P u n c t}{1}^{}(\mathsf{s}{1},\mathsf{r}{2}),\ \mathsf{s}{2}^{\prime}=\mathsf{P u n c t}{2}^{}(\mathsf{s}_{2},\mathsf{i v}) $$

$$ \mathsf{i v}=\mathsf{F}{1}^{*}(\mathsf{s}{1},r) $$

$$ C{\ }!{\cal C}{0}=C{{\mathfrak{s}}{1},{\mathfrak{s}}{2}}^{\sf E n c},C_{1}=C_{{\mathfrak{s}}{1}^{\prime},{\mathfrak{s}}{2}^{\prime},{\mathfrak{r}}_{2}}^{\sf E n c},\alpha=c $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{2}^{*}(\mathsf{s}_{2},\mathsf{i}\mathsf{w})) $$

$$ \tt{r e t u r n};\ c_{0}^{*}(k\mathsf k,m;\dot{\mathsf{u}}) $$

$$ (C_{0},C_{1},\alpha) $$

Fig. 5: The circuits CsEnc,s, CsEnc,s,r∗ and the sampler Sm. CsEnc,sand CsEnc,s,r∗ (output by Sm) are padded 1 2 1 2 1 2 1 2 to match the size γ = max*{|CsEnc,s|, |C* ′ ′ ∗|, |C ′ ∗|} where *C ′ ∗*is output by the sampler eSmas 1 2 sEnc1,s2,r sEnc1,s2,r sEnc1,s2,r defined in AppendixB.6.

$$ C_{\mathsf{s_{1}},\mathsf{s_{2}}}^{\mathsf{E n c}},;C_{\mathsf{s_{1}},\mathsf{s_{2}},r^{*}}^{\mathsf{E n c}} $$

$$ \mathsf{S}{m}.;C{\mathsf{s}{1},\mathsf{s}{2}}^{\mathsf{E n c}} $$

$$ C _ {\mathrm {s} _ {1}, \mathrm {s} _ {2}, r ^ {*}} ^ {\mathrm {E n c}} $$

$$ {\sf{S}}_{m}) $$

$$ \gamma=\mathsf{m a x}{|C_{\mathsf{s}{1},\mathsf{s}{2}}^{\mathsf{E n c}}|,|C_{\mathsf{s}{1}^{\prime},\mathsf{s}{2}^{\prime},^{}}^{\mathsf{E n c}}|,|C_{\mathsf{s}{1}^{\prime},\mathsf{s}{2},\mathsf{r}^{}}^{\mathsf{E n c}}|} $$

$$ C_{\mathsf{s}{'}{1},\mathsf{s}{'}{2},r^{*}}^{\mathsf{E n c}} $$

$$ \widetilde {S} _ {m} $$

∗ ∗ 1.If Π₀ is EUF (DefinitionA.11) and Π₁ is secure (DefinitionA.8) then, for every m ∈M, Smis an odiO*-sampler (Definition4.1), and*

$$ \Pi_{0}^{*} $$

$$ A.11) $$

$$ I_{1}^{*} $$

$$ m\in\mathcal{M},,\mathsf{S}_{m} $$

2.if Obf is a ({Sm}m∈M)-odiO-obfuscator (Definition4.2) then the signature scheme Π of Construc- tion3is sel-EUF-CMA (DefinitionA.14).

$$ ({\mathsf{S}{m}}{m\in\mathcal{M}}) $$

5.4 From semantically secure IV-based SKEs to sel-IND-CPA PKEs using puncturable PRFs

Here, we compile IV-based SKEs into PKEs. IV-based SKEs (e.g., AES-CBC-mode) are symmetric key encryption schemes such that Enc outputs ciphertexts of the form Enc(k*,m*; iv) = (iv*,c*) where iv is the 14 initialization vector (i.e., randomness) used to encrypt the message.

$$ \mathsf{E n c}(\mathsf{k},m;\mathsf{\dot{w}})=(\mathsf{\dot{w}},c) $$

∗ ∗ ∗ ∗ ∗ ∗ ∗ ∗ ∗ ∗ ∗ ∗ Construction 4 Let Π₀ = (KGen0,Enc0,Dec0), Π₁ = (Gen1, F1,Punct1), Π₂ = (Gen2, F2,Punct2), and Obf be an IV*-based SKE with message space M, two puncturable PRFs, and an obfuscator, respectively.* ∗ ∗ ∗ We combine Π₀, Π₁, and Π₂ into a PKE scheme Π = (KGen*,Enc,*Dec) with message space M as follows:

$$ \varPi_ {0} ^ {} = \left(\mathrm {K G e n} _ {0} ^ {}, \mathrm {E n c} _ {0} ^ {}, \mathrm {D e c} _ {0} ^ {}\right), \varPi_ {1} ^ {} = \left(\mathrm {G e n} _ {1} ^ {}, \mathrm {F} _ {1} ^ {}, \mathrm {P u n c t} _ {1} ^ {}\right), \varPi_ {2} ^ {} = \left(\mathrm {G e n} _ {2} ^ {}, \mathrm {F} _ {2} ^ {}, \mathrm {P u n c t} _ {2} ^ {}\right) $$

$$ W e_{}, $$

$$ P R F s $$

$$ \mathit{\Pi}{0}^{*},;\mathit{\Pi}{1}^{*} $$

$$ \ {cal Pi_{{}2}^{*}} $$

λ λ ∗ λ KGen(1): On input the security parameter 1*, the key generation algorithm computes* s₁ ←$ Gen (1), 1 ∗ λe eλ s₂ ←$ Gen (1), and outputs pk = C and sk = s₂ where C ←$ Obf(1,C) and C is depicted 2 sEnc 1,s2 sEnc 1,s2 in Figure5.

$$ 1^{\lambda} $$

$$ \mathsf{s}{1}\leftarrow\ \mathsf{s e n}{1}^{*}(1^{\lambda}) $$

$$ \mathsf{s}{2}\leftarrow\mathsf{s e n}{2}^{*}(1^{\lambda}) $$

$$ {\mathfrak{p}}{\mathfrak{k}}=\widetilde{C\mathcal C} $$

$$ \mathsf{s k}=\mathsf{s}_{2} $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{\mathfrak{s}{1},\mathfrak{s}{2}}^{\mathsf{E n c}}) $$

$$ C_{\mathsf{s}{1},\mathsf{s}{2}}^{\mathsf{E n c}} $$

e∗ Enc(pk*,m*; r): On input the public key pk = C, a message m ∈ M, and randomness r ∈ {0,1}, the encryption algorithm outputs (iv*,c*) = Ce(m,r).

$$ \ (\mathsf{p k},m;r); $$

$$ \mathsf{p k}=\tilde{C} $$

$$ m\in{\mathcal{M}} $$

$$ r,\in,{0,1}^{*} $$

$$ (\mathsf{i}\mathsf{V},c)=C(m,r)} $$

$$ \mathsf{D e c}(\mathsf{s k},c) $$

Dec(sk*,c*): On input the secret key sk = s₂ and a ciphertext (iv*,c*), the deterministic decryption algorithm ∗ λ ∗ returns m = Dec(k*,(iv,c*)) where k = KGen0(1; F2(s₂*,iv)).*

$$ {\mathfrak{s k}}={\mathsf{s}}_{2} $$

$$ (\dot{\imath},\mathfrak{v},c) $$

$$ m=\mathsf{D e c}(\mathsf{k},(\mathsf{i}\mathsf{v},c)) $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{2}^{*}(\mathsf{s}_{2},\mathsf{i}\mathsf{w})) $$

Below we establish the following result whose proof appears in AppendixB.6.

∗ ∗ ∗ Theorem 5.6. Let Π₀, Π₁, Π₂, and Obf as defined in Construction4. For every m ∈M, consider the sampler Smdepicted in Figure5.

$$ S_{m} $$

$$ \mathit{\Pi}{0}^{*},,\mathit{\Pi}{1}^{},,\mathit{\Pi}_{2}^{} $$

$$ m\in{\mathcal{M}} $$

$$ 4. $$

∗ ∗ ∗ 1.If Π₀ is semantically secure (DefinitionA.18) and Π₁,Π₂ are secure (DefinitionA.8) then, for every m ∈M, Smis an odiO*-sampler (Definition4.1), and*

$$ \Pi_{0}^{*} $$

$$ \mathit{\Pi}{1}^{*},\mathit{\Pi}{2}^{*} $$

$$ \ \ m\ inin\mathcal{M},\ \mathsf{S}_{m} $$

2.if Obf is a ({Sm}m∈M)-odiO-obfuscator (Definition4.2) then the PKE scheme Π of Construction4 is sel-IND-CPA (DefinitionA.22).

$$ 4.1) $$

$$ i \left(\left{\mathsf {S} _ {m} \right} _ {m \in \mathcal {M}}\right) $$

$$ 4.2) $$

$$ 4 $$


$$ \mathsf{S}_{m}(1^{\lambda};r) $$

$$ C_{\mathsf{k}}^{\mathsf{E n c}}(m,r) $$

$C_{\mathrm{k}}^{\mathrm{Enc}}(m,r)$ $\mathrm{S}_{m}(1^{\lambda};r)$
return $c=\mathrm{Enc}^{*}(\mathrm{k},m;r)$ Let $r=(r_{0},r_{1},r_{2})$
return $c=\mathrm{Enc}^{*}(\mathrm{k},m;r)$ $\mathrm{k}{0}=\mathrm{KGen}^{*}(1^{\lambda};r{0}),\mathrm{k}{1}=\mathrm{KGen}^{*}(1^{\lambda};r{1})$
return $c=\mathrm{Enc}^{*}(\mathrm{k},m;r)$ $c=\mathrm{Enc}^{*}(\mathrm{k}{0},m;r{2})$
return $c=\mathrm{Enc}^{*}(\mathrm{k},m;r)$ Set $C_{0}=C_{\mathrm{k}{0}}^{\mathrm{Enc}},C{1}=C_{\mathrm{k}_{1}}^{\mathrm{Enc}},\alpha=c$
return $c=\mathrm{Enc}^{*}(\mathrm{k},m;r)$ return $(C_{0},C_{1},\alpha)$

$$ r=(r_{0},r_{1},r_{2}) $$

$$ c=\mathsf{E n c}^{*}(\mathsf{k},m;r) $$

$$ \mathrm {k} _ {0} = \mathrm {K G e n} ^ {} \left(1 ^ {\lambda}; r _ {0}\right), \mathrm {k} _ {1} = \mathrm {K G e n} ^ {} \left(1 ^ {\lambda}; r _ {1}\right) $$

$$ c={\sf E n c}^{*}(\ {sf k k}{0},m;r{2}) $$

$$ C_{0}=C_{\mathsf{k}{0}}^{\mathsf{E n c}},C{1}=C_{\mathsf{k}_{1}}^{\mathsf{E n c}},\alpha=c $$

$$ \left(C _ {0}, C _ {1}, \alpha\right) $$

Fig. 6: The circuit CkEncand the sampler Sm. CkEncand CkEnc(output by Sm) are padded to match the 0 1 size γ = max*{|C*kEnc|, |CkEnc|}) 0 1

$$ C_{\mathsf{k}}^{\mathsf{E n c}} $$

$$ \mathrm {S} _ {m}. C _ {\mathrm {k} _ {0}} ^ {\mathrm {E n c}} $$

$$ C_{\ {sf k k}_{1}}^{\sf E n c} $$

$$ \ _m $$

$$ \gamma=\mathsf{m a x}{|C_{\mathsf{k}{0}}^{\mathsf{E n c}}|,|C{\mathsf{k}_{1}}^{\mathsf{E n c}}|} $$

5.5 From semantically and sel-IND-CPRA-key SKEs to sel-IND-CPA PKEs

∗ ∗ ∗ ∗ Construction 5 Let Π = (KGen*,Enc,Dec) and Obf be a SKE with message space M and an ∗ obfuscator, respectively. We compile Π into a PKE scheme Π = (KGen,Enc,*Dec) with message space M as follows:

$$ {\mathit{\Pi}}^{},=,({\mathsf{K G e n}}^{},{\mathsf{E n c}}^{},{\mathsf{D e c}}^{}) $$

$$ I^{*} $$

$$ \varPi = (\mathrm {K G e n}, \mathrm {E n c}, \mathrm {D e c}) $$

λ λ ∗ ∗ λ KGen(1): On input the security parameter 1*, the key generation algorithm computes* k ←$ KGen (1) e∗e$λ and outputs pk = C and sk = k where C ← Obf(1*,C*kEnc∗) and CkEncis depicted in Figure6.

$$ 1^{\lambda} $$

$$ \left(1^{\lambda}\right) $$

$$ \mathsf{k}^{}\leftarrow_{\mathfrak{S}}\mathsf{K G e n}^{}(1^{\lambda}) $$

$$ {mathsf\mathsf p{k}}=\widetilde{C} $$

$$ ={\bf k}^{*} $$

$$ \widetilde {C} \leftarrow {} ^ {$} \operatorname {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {k} ^ {*}} ^ {\mathrm {E n c}}\right) $$

$$ C_{\mathsf{k}}^{\mathsf{E n c}} $$

e∗ Enc(pk*,m*; r): On input the public key pk = C, a message m ∈ M, and randomness r ∈ {0,1}, the encryption algorithm outputs c = Ce(m,r).

$$ \mathsf{E n c}(\mathsf{p k},m;r){:} $$

$$ :=\tilde{C}. $$

$$ m\in{\mathcal{M}} $$

$$ r,\in,{0,1}^{*} $$

$$ c=\ \ ddot C m m,r) $$

∗ Dec(sk*,c*): On input the secret key sk = k and a ciphertext c, the deterministic decryption algorithm ∗ ∗ returns m = Dec (k*,c*).

$$ {\sf{s k}}={\sf{k}}^{*} $$

$$ {,} $$

$$ m=\mathsf{D e c}^{}(\mathsf{k}^{},c) $$

Below we establish the following result whose proof appears in AppendixB.7.

∗ Theorem 5.7. Let Π and Obf as defined in Construction5. For every m ∈M, consider the sampler Smdepicted in Figure6.

$$ I^{*} $$

$$ S_{m} $$

$$ m\in{\mathcal{M}} $$

∗ 1.If Π is sel-IND-CPRA-key (DefinitionA.19) then, for every m ∈M, Smis an oiO*-sampler (Defi-* nition4.1), and

$$ H^{*} $$

$$ \ \ m\ inin\mathcal{M},\ \mathsf{S}_{m} $$

$$ 4.I1) $$

∗ 2.If Π is semantically secure (DefinitionA.16) and Obf is a ({Sm}m∈M)-oiO-obfuscator (Defini- tion4.2) then the PKE scheme Π of Construction5is sel-IND-CPA (DefinitionA.22).

$$ \varPi^ {*} $$

$$ a\ ({\mathsf{S}{m}}{m\in\mathcal{M}}) $$

$$ 4.2) $$

+ + 6 Extending the impossibility results of Barak et al. [BGI 01,BGI 12] to the setting of odiO and oiO

$$ [\mathrm{B G I^{+}01,,}\mathrm{B G I^{+}12}] $$

In Section4, we have demonstrated that both odiO and oiO are weaker than VBB and, despite this, these new notions are enough to implement several of the most important applications of VBB (Section5). At this point, the natural question is how weak odiO and oiO are, compared to VBB. In order to give an + answer to this question, we investigate whether the impossibility results for VBB (of Barak et al. [BGI 01, + BGI 12]) extend to either odiO or oiO (or both). Unfortunately, this turned out to be true: As we show in Section6.1, for type ∈{odiO,oiO}, there exist a type-sampler that cannot be type-obfuscated (unconditionally).

$$ \mathrm{B G I^{+}12])} $$

$$ \mathrm{[B G I^{+}01} $$

$$ \mathsf{t y p e}\in{\mathsf{o d i O},\mathsf{o i O}} $$

14 IV-based SKEs are related to nonce-based SKEs [Rog04]. The main difference is that in IV-based SKE the initialization vectors iv are random whereas in nonce-based SKE iv is replaced with a nonce that not necessarily needs to be randomly chosen (e.g., the nonce could be a counter).


$C_{k,a,b}^{0}(x,r)$ $C_{k,a}^{1}(i,r)$ $C_{k}^{2}(c_{1},c_{2},\odot,r)$
If $x=a$, return $b$ Let $a=a_{1}
return Enc0(k,0;r) return Enc0(k,ai;r) return Enc0(k,x;r)
$C_{k,a,b,y,e}^{3}(d_{1},\dots,d_{\lambda},r)$ $C_{s,(k,a,b,y,e)}^{*}(\ell,v,r)$
Let $b=b_{1} \dots
For $i\in[\lambda]$ do: $r^{\prime}=\mathrm{F}_{1}(\mathrm{s},(\ell,v,r))$
If Dec0(k,di)≠bi, If $\ell=0$, return $C_{k,a,b}^{0}(x,r^{\prime})$
return Enc0(k,0;r) If $\ell=1$, return $C_{k,a}^{1}(i,r^{\prime})$
return (k,a,y,e) If $\ell=2$, return $C_{k}^{2}(c_{1},c_{2},\odot r^{\prime})$
If $\ell=3$, return $C_{k,a,b,y,e}^{3}(d_{1},\dots,d_{\lambda},r^{\prime})$

$$ \mathsf{E n c}_{0}(\mathsf{k},0;r) $$

$$ C_{\mathsf{k},a,b,\mathsf{y},e}^{3}(d_{1},\ldots,d_{\lambda},r) $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*}(\ell,v,r) $$

$$ b=b_{1}||\dots||b_{\lambda} $$

$$ v = \left(x, i, c _ {1}, c _ {2}, \odot , d _ {1}, \dots , d _ {\lambda}\right) $$

$$ r^{\prime}=\mathsf{F}_{1}(\mathsf{s},(\ell,v,r)) $$

$$ \mathbf{I f};\mathsf{D e c}{0}(\mathsf{k},d{i})\neq b_{i}, $$

∗, 5λ+1 Fig. 7: The circuit C where (s, k*,a,b,y,e*) ∈{0,1} and ⊙ is the binary representation of a s (k,a,b,y,e) 2 × 2 table of an arbitrary binary operator (e.g., AND, OR, NOT).

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ ({\mathfrak{}},{\mathsf{k}},a,b,{\mathsf{y}},e)\in{0,1}^{5\lambda+1} $$

$$ 2\times2 $$

argument applies to our format- and function-preserving transformations, described in Construction4 and Construction5. In this case, we have a negative answer but only for the oiO-based function-preserving transformation (Construction5): We demonstrate that there exists a SKE Π that is semantically and sel-IND-CPRA-key secure that cannot be converted into a sel-IND-CPA PKE by simply obfuscating the SKE’s encryption algorithm together with a symmetric key, as done by our oiO-based Construction5. On the other hand, it remains unclear how we can prove a similar impossibility result for our odiO-based format-preserving transformation (Construction4) from SKEs to PKEs (through puncturable PRFs). See Section5.4and Remark6.6for more details.

$$ \mathrm{[B G I^{+}01} $$

$$ \mathrm{B G I^{+}12]} $$

6.1 Unobfuscatable odiO-samplers (resp. oiO-samplers) exist unconditionally

∗, 5λ+1 We build an ensemble of circuits C = {C} (indexed by (s*,* k*,a,b,y,e*) ∈ {0,1}) that (i) s (k,a,b,y,e) ∗, ∗, C leaks no information when treated as oracles, and (ii) the obfuscation of any C ∈C s (k,a,b,y,e) s (k,a,b,y,e) allows to extract the hardcoded values (k*,a,b,y,e*). We anticipate that the value e ∈{0,1} will allow us ∗, to prove that a circuit C cannot be odiO-obfuscated (resp. oiO-obfuscated) (see Section6.1). s (k,a,b,y,e) On the other hand, the value y is a key of a PRF that is fundamental to build a contrived semantically and sel-IND-CPRA-key secure SKE that cannot be obfuscated (as described in Construction5) into a sel-IND-CPA PKE (Section6.2). We build such an ensemble C (depicted in Figure7) by using a similar

$$ (\mathrm {s}, \mathrm {k}, a, b, \mathrm {y}, e) \in {0, 1 } ^ {5 \lambda + 1}) $$

$$ \mathcal {C} = \left{C _ {\mathrm {s}, (\mathrm {k}, a, b, \mathrm {y}, e)} ^ {*} \right} $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*}\in\mathcal{C} $$

$$ (\mathsf{k},a,b,\mathsf{y},e) $$

$$ e\in{0,1} $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ \mathrm{[B G I^{+}0]} $$

∗, In a nutshell, C (depicted in Figure7) is the composition of four circuits (Ck0,a,b,Ck1,a,Ck2, s (k,a,b,y,e) Ck3,a,b,y,e) and it is defined with respect to a SKE scheme Π₀ = (KGen₀*,Enc₀,Dec₀) and a PRF Π₁ = (Gen₁,*F₁) (required to generate “fresh” randomnesses). On input (ℓ,v,r) where v = (x,i,c₁,c₂, ⊙,d₁,..., ∗, dλ), C uses ℓ to select which circuit to execute: s (k,a,b,y,e)

$$ \ _{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ (C_{\mathsf{k},a,b}^{0},C_{\mathsf{k},a}^{1},C_{\mathsf{k}}^{2}. $$

$$ C_{\mathsf{k},a,b,y,e}^{3} $$

$$ {\mathit\Pi}{0}=({\sf K G e n}{0},{\sf E n c}{0},{\sf D e c}{0}) $$

$$ (\mathsf{G e n}{1},\mathsf{F}{1}) $$

$$ {\mathit Pi_{{1}}}= $$

$$ (\ell,v,r) $$

$$ v = \left(x, i, c _ {1}, c _ {2}, \odot , d _ {1}, \dots ,\right. $$

$$ d_{\lambda}),:C_{{\mathsf{s}},({\mathsf{k}},a,b,{\mathsf{y}},e)}^{*} $$

1.If ℓ = 0, Ck0,a,b(x, F₁(s*,* (ℓ,v,r))) is executed. This circuit presents a trigger input a. If x = a, Ck0,a,b(x, F₁(s*,* (ℓ,v,r))) returns b. Otherwise, it returns Enc₀(k*,0; F₁(s,* (ℓ,v,r))).

$$ \ell,=,0,,,\ {\mathcal C}{{\mathsf k},a.b}^{0}(x,{\mathsf F}{1}({\mathsf s},(\ell,v,r))) $$

$$ C_{\mathsf{k},a,b}^{0}(x,\mathsf{F}_{1}(\mathsf{s},(\ell,v,r))) $$

2.If ℓ = 1, Ck1,a(i, F₁(s*,* (ℓ,v,r))) is executed. This circuit simply outputs the encryption of the i-th bit of a, i.e., Enc₀(k*,a*i; F₁(s*,* (ℓ,v,r))).

$$ \mathsf{E n c}{0}(\mathsf{k},0;\mathsf{F}{1}(\mathsf{s},(\ell,v,r))) $$

$$ x,=,a,. $$

$$ \ell,==,\ \mathcal{C}{\mathsf{k},a}^{1}(i,\mathsf{F}{1}(\mathsf{s},(\ell,v,r))) $$

$$ a,i.e.,\sf E n c_{0}(k,a_{i};F_{1}(s,(l,v,r))) $$

3.If ℓ = 2, Ck2(c₁,c₂, ⊙, F₁(s*,* (ℓ,v,r))) is executed. This circuit allows an evaluator to perform (gate by gate) computations over encrypted inputs. In more detail, it outputs the encryption of the evaluation of w ⊙ z (i.e., Enc₀(k*,w ⊙ z*; F₁(s*,* (ℓ,v,r)))) where ⊙ is a binary operator, and w and z are the bits encrypted by c₁ and c₂, respectively.

$$ \ell = 2, C _ {\mathrm {k}} ^ {2} \left(c _ {1}, c _ {2}, \odot , \mathrm {F} _ {1} (\mathrm {s}, (\ell , v, r))\right) $$

$$ w\odot z\ (\ \mathtt{i.e.,}\ \mathsf{E n c}{0}(\mathsf{k},w\odot z;\mathsf{F}{1}(\mathsf{s},(\ell,v,r))). $$

$$ c_{1} $$

$$ c_{2} $$


4.If ℓ = 3, Ck3,a,b,y,e(d₁,...,dλ,F₁(s, (ℓ,v,r))) is executed. This is another circuit that presents a trigger input b. In more detail, if each diis the encryption of the i-th of b, the circuit returns (k*,a,y,e*). Otherwise, it returns Enc₀(k*,0; F₁(s,* (ℓ,v,r))).

$$ \ell=3,:C_{\mathsf{k},a,b,\mathsf{v},e}^{3}(d_{1},\ldots,d_{\lambda},\mathsf{F}_{1}(\mathsf{s},(\ell,\upsilon,r))) $$

$$ d_{i} $$

$$ b, $$

$$ (\mathsf{k},a,\mathsf{y},e) $$

$$ \mathsf{E n c}{0}(\mathsf{k},0;\mathsf{F}{1}(\mathsf{s},(\ell,v,r)), $$

$$ \ {cal Pi_{1}} $$

$$ \Pi_{0} $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ {\widetilde{C}}_{\mathrm{k}} $$

$$ (\ell,v,r) $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ \ {\widetilde{C}}_{\mathbf{k}} $$

$$ a,b,\in,0,1}^{\lambda} $$

$$ (\mathsf{k},a,b,\mathsf{y},e) $$

$$ (\mathcal{C}{\mathfrak{s},(\mathsf{k},a,b,\mathsf{y},0)}^{*},\mathcal{C}{\mathfrak{s},(\mathsf{k},a,b,\mathsf{y},1)}^{*}) $$

e$λ ∗, On the other hand, on input C ← Obf(1*,C*), an adversary can easily extract (k*,a,b,y,e*), s (k,a,b,y,e) i.e., the circuit is partially reversible. This can be done as follows:

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*}) $$

$$ (\mathsf{k},a,b,\mathsf{y},e) $$

– Evaluate Ce(1*, ·, ·*) to get the encryptions (c₁,...,c) of the a’s bits (see Item2). λ

$$ \widetilde{C}(1,\cdot,\cdot) $$

$$ (c_{1},\ldots,c_{\lambda}) $$

– Use (c₁,...,cλ) to compute (d₁,...,dλ) where diis the encryption of b’s i-th bit. Observe that this can be done by leveraging Ce(2*, ·, ·) to evaluate (gate by gate) Ce(0, ·, ·) = C (·, ·*) on a (see Item3), k0,a,b and

$$ (c_{1},\ldots,c_{\lambda}) $$

$$ (d_{1},\ldots,d_{\lambda}) $$

$$ d_{i} $$

$$ \tilde{C}(2,\cdot,\cdot) $$

$$ \tilde{C}(0,\cdot,\cdot)=C_{\mathsf{k},a.b}^{0}(\cdot,\cdot) $$

$$ (d_{1},\ldots,d_{\lambda}) $$

$$ \tilde{C}(3,\cdot,\cdot) $$

$$ (\mathsf{k},a,b,\mathsf{y},e) $$

– Compute (k*,a,b,y,e*) by Ce(3*, ·, ·*) on (d₁,...,d) (see Item4). λ

The properties of the ensemble C are formalized in Theorem6.1whose proof appears in AppendixB.8. We highlight that our technique of generating Enc₀’s randomness as F₁(s*,* (ℓ,v,r)) (instead of F₁(s*,* (ℓ,v))

$$ \mathsf{E n c_{0}}; $$

$$ \mathsf{F}_{1}(\mathsf{s},(\ell,v,r)) $$

$$ \mathrm{[B G I^{+}01,,B G I^{+}12]}, $$

$$ \mathsf{F}_{1}(\mathsf{s},(\ell,v)) $$

$$ (\ell,v) $$

$$ \left[\mathrm{B G I}^{+}01,,\mathrm{B G I}^{+}12|\right) $$

∗, Theorem 6.1. Let Π₀ = (KGen₀*,Enc₀,Dec₀), Π₁* = (Gen₁*,F₁), and C be a SKE scheme with* s (k,a,b,y,e) λ λ key space {0,1}, a PRF scheme with key space {0,1}, and the circuit defined in Figure7with respect to ∗, Π₀ and Π₁, respectively. Then, the ensemble C = *{C}*s,k,a,b,y∈{0,1}λ,e∈{0,1}satisfies the following s (k,a,b,y,e) properties:

$$ \ Pi_{0}=({\sf K G e n}{0},{\sf E n c}{0},{\sf D e c}_{0}), $$

$$ \varPi_ {1} = \left(\mathrm {G e n} _ {1}, \mathrm {F} _ {1}\right) $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ {0,1}^{\lambda} $$

$$ {0,1}^{\lambda} $$

$$ I_{0} $$

$$ \mathcal{C}={C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*}}_{\mathsf{s},\mathsf{k},a,b,\mathsf{y}\in{0,1}^{\lambda},e\in{0,1}} $$

Oracle-differing-input: If Π₀ is IND-CCA1 (DefinitionA.17) and Π₁ is secure (DefinitionA.6) then for every PPT adversary D*, we have* h i

$$ \mathit{I f}\ mathit Pi!{}_{0} $$

$$ \mathbb{P}\Big[C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},0)}^{}(\ell,v,r)\neq C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},1)}^{}(\ell,v,r)\Big]\leq\mathsf{n e g l}(\lambda), $$

where $ (\ell,v,r)\leftarrow \mathbb{s}A_{s,(k,a,b,y,0)}^{C_{\mathrm{s}}^{}(\cdot,\cdot,\cdot),C_{\mathrm{s}}^{}(k,a,b,y,1)}^{(\cdot,\cdot,\cdot)}\left(1^{\lambda}\right)$ , k $ \leftarrow \mathbb{s}KGen_{0}\left(1^{\lambda}\right)$ , s $ \leftarrow \mathbb{s}Gen_{1}\left(1^{\lambda}\right)$ , y $ \leftarrow \mathbb{s}Gen_{1}\left(1^{\lambda}\right)$ and $ (a,b)\leftarrow \mathbb{s}{0,1}^{2\lambda}. $

$$ (\ell , v, r) \leftarrow $ A ^ {C _ {\mathrm {s}}, ^ {} (\mathrm {k}, a, b, y, 0)} \left(\cdot , \cdot , \cdot\right), C _ {\mathrm {s}}, ^ {} (\mathrm {k}, a, b, y, 1) \left(\cdot , \cdot , \cdot\right) \left(1 ^ {\lambda}\right), k \leftarrow $ K G e n _ {0} \left(1 ^ {\lambda}\right), s \leftarrow $ G e n _ {1} \left(1 ^ {\lambda}\right), y \leftarrow $ G e n _ {1} \left(1 ^ {\lambda}\right) $$

$$ (a,b)\leftarrow\flat{0,1}^{2\lambda} $$

Input-indistinguishability: If Π₀ is IND-CCA1 (DefinitionA.17) and IND-CPA-key (DefinitionA.18), ∗ and Π₁ is secure (DefinitionA.6), then for every ℓ,v ∈{0,1}, every PPT adversary D*, we have* h i

$$ \mathit{I f}\ \mathit{I}\ \ !!_{\ }} $$

$$ \Pi_{1} $$

$$ \ell,v\in{0,1}^{*} $$

$$ \begin{aligned}{}&{{}\left|\mathbb{P}\left[\mathsf{D}^{C_{\bullet_{0}(b_{0},a_{0},b_{0},gamma_{0},0)}^{}(\cdot,\cdot,\cdot),C_{\bullet_{1},a_{1},b_{1},\gamma_{1},1}^{}(\cdot,\cdot,\cdot)}^{}(\mathbf{1}^{\lambda},m_{0})=1\right]-\right.}\ {}&{{}\quad\left.\quad\quad{\mathbb{P}}\left[\mathsf{D}^{C_{\bullet_{0},(b_{0},a_{0},b_{0},0_{0},0)}^{}(\cdot,\cdot,\cdot),C_{\bullet_{1},(b_{1},a_{1},b_{1},y_{1},1)}^{}(\cdot,\cdot,,\cdot)}^{}(\mathbf{1}^{\lambda},m_{1})=1\right]\right|\leq\mathsf{n e g l}(\lambda),}\ \end{aligned} $$

$$ \left(a _ {0}, b _ {0}, a _ {1}, b _ {1}\right) \leftarrow $ {0, 1 } ^ {4 \lambda} $$

$4λ$λ$λ where (a₀,b₀,a₁,b₁) ← {0,1}, kj← KGen₀(1) for j ∈ {0,1}, sj← Gen₁(1) for j ∈ {0,1}, $λ ∗$∗ yj← Gen₁(1) for j ∈{0,1}, and md= C (ℓ,v,rd) for rd← {0,1} and d ∈{0,1}. sd*,*(kd,ad,bd,yd,d)

$$ j,\in,{0,1},,\mathsf{s}{j}\gets\mathfrak{G e n}{1}(1^{\lambda}) $$

$$ j,\in,{0,1} $$

$$ m_{d}=\mathcal{C}{\mathfrak{s}{d},(\mathsf{k}{d},a{d},b_{d},\mathsf{y}{d},d)}^{*}(\ell,v,r{d}) $$

$$ {\mathsf{y}}{j}\ {\leftarrow}{\mathsf{G e n}}{1}(1^{\lambda});\mathit{f o r};j\in\left{0,1\right} $$

$$ d \in {0, 1 } $$

$$ r_{d}\leftarrow\ \ {,,1}{}^{*} $$

$$ (\mathsf{s},\mathsf{k},a,b,\mathsf{y},e)\in{0,1}^{5\lambda+1} $$

5λ+1 Partial reversibility: There exists a PPT algorithm Ext such that for every (s*,* k*,a,b,y,e*) ∈{0,1} e e(∗, ∗ and every circuit C such that C ℓ,v,r) = C (ℓ,v,r) for all ℓ,v,r ∈{0,1}, s (k,a,b,y,e)

$$ \tilde{C} $$

$$ \ddot{C}(\ell,v,r)=\mathcal{C}_{\mathfrak{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*}(\ell,v,r) $$

$$ \ell,v,r\in{0,1}^{*} $$

$$ \mathbb {P} \left[ (\mathrm {k}, a, b, \mathrm {y}, e) \leftarrow \mathrm {s} \operatorname {E x t} \left(1 ^ {\lambda}, \widetilde {C}\right) \right] = 1. $$

Theorem6.1and CorollaryA.20imply that there exists an odiO-sampler (resp. oiO-sampler) bS that cannot be odiO-obfuscated (resp. oiO-obfuscated), if OWFs exist.

$$ \widehat {S} $$


$$ \mathcal{C}{0}=\mathcal{C}{r,0}^{\sf{o w f}},\mathcal{C}{1}=\mathcal{C}{r,1}^{\sf{o w f}},\alpha=\bot $$

$$ \mathsf{S}_{\mathsf{o w f}}(1^{\lambda};r) $$

$$ (C_{0},C_{1},\alpha) $$

owf Fig. 8: The circuit Cr,band the sampler Sowf.

$$ C_{r,b}^{w w f}, $$

$$ \mathsf{S}_{\mathsf{o w f}} $$

Corollary 6.2. For type ∈{odiO,oiO}, if OWFs exist then there exists a type*-sampler* bS (Definition4.1) such that bS ̸∈S where S is defined in Definition4.3. type type

$$ \mathsf{p e}\in{\mathsf{o d i o},\mathsf{o i00}} $$

$$ 4.I) $$

$$ \widehat {S} $$

$$ S_{\mathrm{t y p e}} $$

$$ \hat{\mathsf{S}}\not\in\mathcal{S}_{\mathsf{t y p e}} $$

Proof. If a OWF exists then there exist a IND-CCA1 and IND-CPA-key SKE scheme Π₀ (CorollaryA.20) ∗, and a secure PRF scheme Π₁ = (Gen₁*,F₁). Consider C the circuit (depicted in Figure7) s (k,a,b,y,e) λ defined with respect to Π₀ and Π₁. Let bS be the sampler that, on input the security parameter 1, it ∗, ∗,$2λ$λ$λ outputs (C₀ = C,C₁ = C, ⊥) where (a,b) ← {0,1}, k ← KGen₀(1), s ← Gen₁(1), s (k,a,b,y,0) s (k,a,b,y,1) $λ and y ← Gen₁(1). Since Π₁ is a secure PRF scheme and Π₀ is IND-CCA1 and IND-CPA-key secure,* then C₀ and C₁ (output by bS) satisfy the oracle-differing-input property of Theorem6.1. This implies that bS is both an odiO-sampler and oiO-sampler (recall that any odiO-sampler is also an oiO-sampler (Theorem4.5)).

$$ \ \ {\mathit Pi!},=,(\mathsf{G e n}{1},\mathsf{F}{1}) $$

$$ \Pi_{0} $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*} $$

$$ \ _{0} $$

$$ \hat{\mathrm S} $$

$$ ({C{\mathbf{0}}}=C_{\mathtt{s},(\mathtt{k},a,b,\mathtt{v},\mathtt{0})}^{},C_{\mathtt{1}}=C_{\mathtt{s},(\mathtt{k},a,b,\mathtt{v},\mathtt{1})}^{},\bot) $$

$$ 1^{\lambda} $$

$$ (a, b) \leftarrow \mathrm {s} {0, 1 } ^ {2 \lambda}, \mathrm {k} \leftarrow \mathrm {s} \mathrm {K G e n} _ {0} \left(1 ^ {\lambda}\right), \mathrm {s} \leftarrow \mathrm {s} \mathrm {G e n} _ {1} \left(1 ^ {\lambda}\right) $$

$$ \mathsf{y}\leftarrow\mathsf{s e n}_{1}(1^{\lambda}) $$

$$ \Pi_{0} $$

$$ C_{0} $$

$$ C_{1} $$

$$ \ {\hat{S}}) $$

$$ _\mathrm{o i O-s a m p l e} $$

Moreover, the partial reversibility property of Theorem6.1implies that bS cannot be odiO-obfuscated (resp. oiO-obfusated). This is because there always exists a distinguisher D, that on input an obfuscated e$λ$λe) and outputs circuit C ← Obf(1*,C*d), executes (k*,a,b,y,e*) ← Ext(1*, C* e (observe that e = d). Hence, we conclude that bS ̸∈SodiO(resp. bS ̸∈SoiO). ⊓⊔

$$ \hat{\mathrm S{}} $$

$$ Dmathsf, $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{d}) $$

$$ (\mathsf{k},a,b,\mathsf{y},e)\ {leftarrowheadhead}\mathsf{E x t}(1^{\lambda},\widetilde{\mathcal{C}}) $$

$$ e=d) $$

$$ \widehat{\mathsf{S}}\not\in\mathcal{S}{\tt{o d i}0}:(\mathrm{r e s p.},\widehat{\mathsf{S}}\not\in\mathcal{S}{\tt{0i i}}) $$

Similarly to VBB, both odiO and oiO imply the existence of OWFs (Theorem6.3, proof in AppendixB.9). As a consequence, for type ∈{odiO,odiO}, a type-unobfuscatable type-sampler exists unconditionally.

$$ \mathsf{p e}\in{\mathsf{o d i O},\mathsf{o d i O}} $$

Theorem 6.3. s Let Obf and Sowfbe an obfuscator and the sampler as defined in Figure8. Let p(·) and F = {Fλ}λ∈Nbe a polynomial and an ensemble of functions such that Fλis defined as Fλ(b,r₀, λ owf λ p(λ) r₁) = Obf(1*,C*r,b;r₁) where (b,r₀,r₁) ∈{0,1}×{0,1} ×{0,1}. Then, the following statements 0 hold:

$$ p(\cdot) $$

$$ \mathsf{S}_{\mathsf{o w f}} $$

$$ \ {\mathcal F},=,{{mathsf F}{\lambda}}{\lambda\in\mathbb{}}, $$

$$ F _ {\lambda} $$

$$ \mathsf{F}{\lambda}(b,r{0}, $$

$$ r_{1})=\mathsf{O b b}(1^{\lambda},C_{r_{0},b}^{\mathsf{o w f}};r_{1}) $$

$$ (b,r_{0},r_{1}):\in:{0,1}:\times:{0,1}^{\lambda}:\times:{0,1}^{p(\lambda)} $$

1. Sowfis an odiO*-sampler (resp.* oiO*-sampler), and*

$$ S _ {\mathrm {o w f}} $$

2.if Obf is a ({Sowf})-odiO-obfuscator (resp. ({Sowf})-oiO-obfuscator) then Fλ∈F is a OWF (Defini- tionA.5).

$$ a({left{sf{sf S S}}_{\sf{o w f}}}),.} $$

$$ ({S_{\ f0!}})-010-0f u s c a t o r) $$

$$ \mathsf{F}_{\lambda}\in\mathcal{F} $$

$$ A.5) $$

Corollary 6.4. For type ∈{odiO,oiO}, there exists (unconditionally) a type*-sampler* S such that S ̸∈ Stypewhere Stypeas defined in Definition4.3.

$$ \in{\mathsf{o d i O},\mathsf{o d O}} $$

$$ S_{\mathrm{t y p e}} $$

$$ \textsf{S}\notin $$

$$ S_{\mathrm{t y p e}} $$

$$ 4.3 $$

Proof. By combining Corollary6.2and Theorem6.3, we obtain that either Sowf̸∈Stypeor bS ̸∈Stype(for type ∈{odiO,odiO}) where Sowfand bS defined in Figure8and Corollary6.2, respectively. ⊓⊔

$$ \mathsf{S}{\mathsf w w{}}\notin\mathcal{S}{\mathsf t y p e}} $$

$$ \hat{\mathsf{S}}\not\in\mathcal{S}_{\mathsf{t y p e}} $$

$$ \in{\mathsf{o d i O,o d i O}}. $$

$$ \mathsf{S}_{\mathsf{o w f}} $$

$$ \hat{}S $$

6.2 Impossibility of obfuscating semantically and sel-IND-CPRA-key secure SKE into sel-IND-CPA secure PKE schemes

We now demonstrate that it is inherently impossible to convert a semantically secure and sel-IND-CPRAkey SKEs into sel-IND-CPA PKEs by simply obfuscating the SKE’s encryption algorithm, as described + in our oiO-based Construction5. We prove this by leveraging a similar technique to that of [BGI 12]: ∗ We construct a SKE Π that satisfies semantic and sel-IND-CPRA-key security that, when obfuscated into a PKE (as described in Section5.5), the latter results to be completely insecure. By leveraging the ensemble C of Theorem6.1, a PRF Π = (Gen*,F), and a semantically and sel-IND-CPRA-key secure SKE e = (KGen] g g),* we build the contrived SKE ∗ scheme Π,Enc,Dec Π (see AppendixB.10) which is defined as follows: ∗ ∗g(e*∗,*e Enc (k, (ℓ,v);r) = (Enc k, (ℓ,v);r),C (ℓ,v,r),F(y, (ℓ,v,r)) ⊕ k),

$$ \varPi^ {*} $$

$$ [\mathrm{B G B^{+}12}] $$

$$ \overline{{\Pi}}=(\overline{{\mathsf{G e n}}},\overline{{\mathsf{F}}}) $$

$$ 6.1, $$

$$ \widetilde {\Pi} = (\mathrm {K G e n}, \mathrm {E n c}, \mathrm {D e c}) $$

$$ \Pi^{*} $$

$$ \ {sf E n n}^{}({\sf{k}}^{},(\ell,v);r)=(\widetilde{{\sf E n c}}(\widetilde{{\sf{k}}},(\ell,v);r),C_{{\sf{S}},(\widehat{{\sf{k}}},a,b,{\sf{y}},e)}^{*}(\ell,v,r),\bar{{\sf{F}}}({\sf{y}},(\ell,v,r))\oplus\widetilde{{\sf{k}}}), $$

(1)

∗ e ∗ where k = (bk*,* k, s*,a,b,y,e*). Π is a semantically and sel-IND-CPRA-key secure SKE for the following reasons:

$$ \mathsf{k}^{*}=\big(\widehat{\mathsf{k}},\widetilde{\mathsf{k}},\mathsf{s},a,b,\mathsf{y},e\big). $$

$$ \ ^{*} $$


∗, 1.As described in Section6.1(see also proof of Theorem6.1) oracle access to the circuit C ∈C s (bk,a,b,y,e) is computationally indistinguishable from having oracle access to a circuit Ce (see Figure10) that k ∗, always returns encryptions of 0. Hence, this implies that C does not leak the message (ℓ,v) s (bk,a,b,y,e) and that an adversary cannot leak any information about (bk*,a,b,y,e*).

$$ C_{\mathsf{s},(\widehat{k},a,b,\mathsf{y},e)}^{*}\in\mathcal{C} $$

$$ \tilde{C}_{\mathrm{k}} $$

$$ C_{\mathfrak{s},(\widehat{k},a,b,\mathsf{y},e)}^{*} $$

$$ (\dot{\mathsf{k}},a,b,\mathsf{y},e) $$

∗ 2.Conditioned to the above observation, the semantic security of Π easily follows from the semantic security of Πe and the security of Π.

$$ I^{*} $$

∗e, the 3.As for the sel-IND-CPRA-key security of Π, it follows from sel-IND-CPRA-key security of Π security of Π, and the fact that C satisfies input-indistinguishability (see Theorem6.1).

$$ \varPi^ {*} $$

$$ {\overline{{{H}}}}, $$

$$ {\widetilde{\Pi}}, $$

∗ On the other hand, when Enc is obfuscated (as in Construction5), an adversary can exploit the partial reversibility of C (Theorem6.1) to extract y and, in turn, the key ek that is used to encrypt the message m = (ℓ,v). Below, we report the formal result whose proof appears in AppendixB.10.

$$ \mathsf{E n c}^{*} $$

$$ m=(\ell,v) $$

Theorem 6.5. If OWFs exist then the following statements hold:

∗ ∗ 1.there exist a SKE Π such that Π is semantically secure (DefinitionA.16), sel-IND-CPRA-key (DefinitionA.19), and

$$ \varPi^ {*} $$

$$ \varPi^ {*} $$

∗ 2.the PKE scheme Π = (KGen*,Enc,*Dec) (output by applying to Π the transformation defined in Con- struction5) is not sel-IND-CPA (Theorem5.7).

$$ H^{*} $$

$$ 5) $$

$$ [\mathrm{B G B^{+}12}] $$

Remark 6.6(On Construction4). We highlight that the technique used to build the contrived SKE ∗ scheme Π of Equation (1) is not enough to contradict the security of our odiO-based construction from IV-based SKEs to PKEs (through puncturable PRFs). Indeed, consider the following contrived IV-based ∗e : SKE Π built starting from an IV-based SKE Π

$$ \varPi^ {*} $$

$$ 44 $$

$$ \Pi^{*} $$

$$ \mathsf{E n c}^{}(\mathsf{k}^{},(\ell,v);\mathsf{w})=(\mathsf{i v},(c^{\prime},C_{\mathsf{z},(\mathsf{\hat{k}},a,b,\mathsf{v},e)}^{*}(\ell,v,\mathsf{hat v})),\mathsf{\bar{F}}(\mathsf{y},(\ell,v,\mathsf{\hat{w}}))\oplus\mathsf{\bar{k}})), $$

(2)

∗ e g(e ′ where k = (bk*,* k, s*,a,b,y,e*) and Enc k*,* (ℓ,v); iv) = (iv*,c*). The PKE scheme Π (output by the compilation ∗e of the contrived Π into a PKE Π as described in Construction4) has public keys of the form pk = C where the obfuscated circuit Ce internally generates a new symmetric encryption key for each randomness r (see Figure5). Although, an adversary A can still exploit the partial reversibility property of C to leak ∗ the symmetric key ek (part of k, see Equation (2)) generated through a particular randomness r, A will ∗ not be able to leak the one used to encrypt the challenge ciphertext c (of the sel-IND-CPA experiment ∗ ∗ of the PKE Π). This is because c is computed using a randomly chosen randomness r (not revealed to A). Hence, in order to exploit the partial reversibility property to leak the symmetric key ek (used to ∗ ∗ encrypt part of challenge ciphertext c), A needs first to guess the randomness r. This happens with negligible probability.

$$ \mathsf{k}^{*}=(\widehat{\mathsf{k}},\widetilde{\mathsf{k}},\mathsf{s},a,b,\mathsf{y},e) $$

$$ \ n $$

$$ \ ^{*} $$

$$ \mathrm {p k} = \widetilde {C} $$

$$ \tilde{C} $$

$$ \widetilde{k} $$

$$ k^{*} $$

$$ c^{*} $$

$$ c^{*} $$

$$ r^{*} $$

$$ \ )) $$

$$ \widetilde{k}} $$

$$ r^{*} $$

$$ c^{*}) $$

$$ \mathrm{[B G I^{+}12} $$


References

+ ABG 13.Prabhanjan Ananth, Dan Boneh, Sanjam Garg, Amit Sahai, and Mark Zhandry. Differing-inputs obfuscation and applications. IACR Cryptol. ePrint Arch., 2013:689, 2013. AJ15.Prabhanjan Ananth and Abhishek Jain. Indistinguishability obfuscation from compact functional encryption. In Annual Cryptology Conference, pages 308–326. Springer, 2015. + AJL 19.Prabhanjan Ananth, Aayush Jain, Huijia Lin, Christian Matt, and Amit Sahai. Indistinguishability obfuscation without multilinear maps: new paradigms via low degree weak pseudorandomness and security amplification. In Annual International Cryptology Conference, pages 284–332. Springer, 2019. AJS15.Prabhanjan Ananth, Abhishek Jain, and Amit Sahai. Indistinguishability obfuscation from functional encryption for simple functions. Cryptology ePrint Archive, 2015. + BBC 14.Boaz Barak, Nir Bitansky, Ran Canetti, Yael Tauman Kalai, Omer Paneth, and Amit Sahai. Obfuscation for evasive functions. In Theory of Cryptography Conference, pages 26–51. Springer, 2014. BC10.Nir Bitansky and Ran Canetti. On strong simulation and composable point obfuscation. In Annual Cryptology Conference, pages 520–537. Springer, 2010. + BCC 14.Nir Bitansky, Ran Canetti, Henry Cohn, Shafi Goldwasser, Yael Tauman Kalai, Omer Paneth, and Alon Rosen. The impossibility of obfuscation with auxiliary input or a universal simulator. In Annual Cryptology Conference, pages 71–89. Springer, 2014. BCKP17.Nir Bitansky, Ran Canetti, Yael Tauman Kalai, and Omer Paneth. On virtual grey box obfuscation for general circuits. Algorithmica, 79(4):1014–1051, 2017. BCP14.Elette Boyle, Kai-Min Chung, and Rafael Pass. On extractability obfuscation. In Theory of cryptog- raphy conference, pages 52–73. Springer, 2014. BDGM20.Zvika Brakerski, Nico D¨ottling, Sanjam Garg, and Giulio Malavolta. Candidate io from homomorphic encryption schemes. In Annual International Conference on the Theory and Applications of Cryptographic Techniques, pages 79–109. Springer, 2020. + BGI 01.Boaz Barak, Oded Goldreich, Rusell Impagliazzo, Steven Rudich, Amit Sahai, Salil Vadhan, and Ke Yang. On the (im) possibility of obfuscating programs. In Annual international cryptology conference, pages 1–18. Springer, 2001. + BGI 12.Boaz Barak, Oded Goldreich, Russell Impagliazzo, Steven Rudich, Amit Sahai, Salil Vadhan, and Ke Yang. On the (im) possibility of obfuscating programs. Journal of the ACM (JACM), 59(2):1–48, 2012. + BGK 14.Boaz Barak, Sanjam Garg, Yael Tauman Kalai, Omer Paneth, and Amit Sahai. Protecting obfuscation against algebraic attacks. In Annual International Conference on the Theory and Applications of Cryptographic Techniques, pages 221–238. Springer, 2014. BP15.Elette Boyle and Rafael Pass. Limits of extractability assumptions with distributional auxiliary input. In International Conference on the Theory and Application of Cryptology and Information Security, pages 236–261. Springer, 2015. BR14.Zvika Brakerski and Guy N Rothblum. Virtual black-box obfuscation for all circuits via generic graded encoding. In Theory of Cryptography Conference, pages 1–25. Springer, 2014. BST14.Mihir Bellare, Igors Stepanovs, and Stefano Tessaro. Poly-many hardcore bits for any one-way function and a framework for differing-inputs obfuscation. In International Conference on the Theory and Application of Cryptology and Information Security, pages 102–121. Springer, 2014. BSW16.Mihir Bellare, Igors Stepanovs, and Brent Waters. New negative results on differing-inputs obfuscation. In Annual International Conference on the Theory and Applications of Cryptographic Techniques, pages 792–821. Springer, 2016. BV15.Nir Bitansky and Vinod Vaikuntanathan. Indistinguishability obfuscation from functional encryption. In 2015 IEEE 56th Annual Symposium on Foundations of Computer Science (FOCS), pages 171–190. IEEE Computer Society, 2015. BV18.Nir Bitansky and Vinod Vaikuntanathan. Indistinguishability obfuscation from functional encryption. Journal of the ACM (JACM), 65(6):1–37, 2018. + CFF 21.Matteo Campanelli, Antonio Faonio, Dario Fiore, Ana¨ıs Querol, and Hadri´an Rodr´ıguez. Lunar: a toolbox for more efficient universal and updatable zksnarks and commit-and-prove extensions. In International Conference on the Theory and Application of Cryptology and Information Security, pages 3–33. Springer, 2021. CK21.Matteo Campanelli and Hamidreza Khoshakhlagh. Succinct publicly-certifiable proofs. In Interna- tional Conference on Cryptology in India, pages 607–631. Springer, 2021. CKP15.Ran Canetti, Yael Tauman Kalai, and Omer Paneth. On obfuscation with random oracles. In Theory of Cryptography Conference, pages 456–467. Springer, 2015. CL06.Melissa Chase and Anna Lysyanskaya. On signatures of knowledge. In Annual International Cryp- tology Conference, pages 78–96. Springer, 2006.


CRV10.Ran Canetti, Guy N Rothblum, and Mayank Varia. Obfuscation of hyperplane membership. In Theory of Cryptography Conference, pages 72–89. Springer, 2010. DH76.Whitfield Diffie and Martin E. Hellman. New directions in cryptography. IEEE Trans. Inf. Theory, 22(6):644–654, 1976. Fis05.Marc Fischlin. Communication-efficient non-interactive proofs of knowledge with online extractors. In Annual International Cryptology Conference, pages 152–168. Springer, 2005. + GGH 13.Sanjam Garg, Craig Gentry, Shai Halevi, Mariana Raykova, Amit Sahai, and Brent Waters. Candidate indistinguishability obfuscation and functional encryption for all circuits. In 2013 IEEE 54th Annual Symposium on Foundations of Computer Science (FOCS), pages 40–49. IEEE Computer Society, 2013. GGHW17.Sanjam Garg, Craig Gentry, Shai Halevi, and Daniel Wichs. On the implausibility of differing-inputs obfuscation and extractable witness encryption with auxiliary input. Algorithmica, 79(4):1353–1373, 2017. GK05.Shafi Goldwasser and Yael Tauman Kalai. On the impossibility of obfuscation with auxiliary input. In 46th Annual IEEE Symposium on Foundations of Computer Science (FOCS’05), pages 553–562. IEEE, 2005. GK13.Shafi Goldwasser and Yael Tauman Kalai. A note on the impossibility of obfuscation with auxiliary input. IACR Cryptol. ePrint Arch., 2013:665, 2013. GKW17.Rishab Goyal, Venkata Koppula, and Brent Waters. Lockable obfuscation. In 2017 IEEE 58th Annual Symposium on Foundations of Computer Science (FOCS), pages 612–621. IEEE, 2017. GMM17.Sanjam Garg, Mohammad Mahmoody, and Ameer Mohammed. When does functional encryption imply obfuscation? In Theory of Cryptography Conference, pages 82–115. Springer, 2017. GP21.Romain Gay and Rafael Pass. Indistinguishability obfuscation from circular security. In Proceedings of the 53rd Annual ACM SIGACT Symposium on Theory of Computing, pages 736–749, 2021. GR07.Shafi Goldwasser and Guy N Rothblum. On best-possible obfuscation. In Theory of Cryptography Conference, pages 194–213. Springer, 2007. HKW15.Susan Hohenberger, Venkata Koppula, and Brent Waters. Adaptively secure puncturable pseudorandom functions in the standard model. In International conference on the theory and application of cryptology and information security, pages 79–102. Springer, 2015. IPS15.Yuval Ishai, Omkant Pandey, and Amit Sahai. Public-coin differing-inputs obfuscation and its applications. In Theory of Cryptography Conference, pages 668–697. Springer, 2015. JLS21.Aayush Jain, Huijia Lin, and Amit Sahai. Indistinguishability obfuscation from well-founded assumptions. In Proceedings of the 53rd Annual ACM SIGACT Symposium on Theory of Computing, pages 60–73, 2021. LPS04.Benjamin Lynn, Manoj Prabhakaran, and Amit Sahai. Positive results and techniques for obfuscation. In International conference on the theory and applications of cryptographic techniques, pages 20–39. Springer, 2004. LPST16.Huijia Lin, Rafael Pass, Karn Seth, and Sidharth Telang. Indistinguishability obfuscation with nontrivial efficiency. In Public-Key Cryptography–PKC 2016, pages 447–462. Springer, 2016. MMN16.Mohammad Mahmoody, Ameer Mohammed, and Soheil Nematihaji. On the impossibility of virtual black-box obfuscation in idealized models. In Theory of Cryptography Conference, pages 18–48. Springer, 2016. PS16.Rafael Pass and Abhi Shelat. Impossibility of vbb obfuscation with ideal constant-degree graded encodings. In Theory of Cryptography Conference, pages 3–17. Springer, 2016. PST14.Rafael Pass, Karn Seth, and Sidharth Telang. Indistinguishability obfuscation from semanticallysecure multilinear encodings. In Annual Cryptology Conference, pages 500–517. Springer, 2014. Rog04.Phillip Rogaway. Nonce-based symmetric encryption. In International workshop on fast software encryption, pages 348–358. Springer, 2004. SW13.Hovav Shacham and Brent Waters. Compact proofs of retrievability. Journal of cryptology, 26(3):442– 483, 2013. SW14.Amit Sahai and Brent Waters. How to use indistinguishability obfuscation: deniable encryption, and more. In Proceedings of the forty-sixth annual ACM symposium on Theory of computing, pages 475–484, 2014. Wee05.Hoeteck Wee. On obfuscating point functions. In Proceedings of the thirty-seventh annual ACM symposium on Theory of computing, pages 523–532, 2005. WW21.Hoeteck Wee and Daniel Wichs. Candidate obfuscation via oblivious lwe sampling. In Annual International Conference on the Theory and Applications of Cryptographic Techniques, pages 127– 156. Springer, 2021. WZ17.Daniel Wichs and Giorgos Zirdelis. Obfuscating compute-and-compare programs under lwe. In 2017 IEEE 58th Annual Symposium on Foundations of Computer Science (FOCS), pages 600–611. IEEE, 2017.


A Further Preliminaries

A.1 Notation

def We use the notation [n] = {1,...,n}. Capital boldface letters (such as X) are used to denote random variables, small letters (such as x) to denote concrete values, calligraphic letters (such as X) to denote sets, and serif letters (such as A) to denote algorithms. All of our algorithms are modeled as (possibly ∗ interactive) Turing machines. For a string x ∈{0,1}, we let |x| be its length; if X is a set, |X| represents the cardinality of X. When x is chosen randomly in X, we write x ←$ X. If A is an algorithm, we write y ←$ A(x) to denote a run of A on input x and output y; if A is randomized, y is a random variable and A(x; r) denotes a run of A on input x and (uniform) randomness r. An algorithm A is probabilistic ∗ polynomial-time (PPT) if A is randomized and for any input x,r ∈{0,1} the computation of A(x; r) terminates in a polynomial number of steps (in the input size).

$$ [n]\stackrel{\mathrm{d e f}}{=}{1,\ldots,n} $$

$$ x\in{0,1}^{*} $$

$$ x\gets\mathfrak{s}\mathcal{X} $$

$$ y\leftarrow\bullet{\mathsf{A}}(x) $$

$$ \mathsf{A}(x;r) $$

$$ x,r\in{0,1}^{*} $$

$$ \mathsf{A}(x;r) $$

Negligible functions. We denote by λ ∈ N the security parameter and we implicitly assume that every algorithm takes as input the security parameter (written in unary). A function ν : N → [0*,1] is called negligible in the security parameter λ if it vanishes faster than the inverse of any polynomial in λ, i.e. ν(λ) ∈ O(1/p*(λ)) for all positive polynomials p(λ). We sometimes write negl(λ) (resp., poly(λ)) to denote an unspecified negligible function (resp., polynomial function) in the security parameter.

$$ \lambda\in\mathbb{N} $$

$$ \nu:\mathbb{N}\rightarrow[0,1] $$

$$ \lambda,\mathrm{i.e.},\nu(\lambda)\in O(1/p(\lambda)) $$

$$ p(\lambda) $$

Computational indistinguishability. We say that X and Y are computationally indistinguishable, λ λ denoted X ≈cY, if for all PPT distinguishers D we have that P D(1*,X) = 1 − P D(1,*Y) = 1 ≤ negl(λ).

$$ \mathbf{X}\approx_{c}\mathbf{Y} $$

$$ |\mathbb{P}\big[\mathsf{D}(\ 1{\ X})=1\big]-\mathbb{P}\big[\mathsf{D}(1^{\lambda},{Y})=1\big]|\ \leq $$

A.2 Non-Interactive Argument systems

Let R be a decidable binary relation composed of pairs (x,ω) where x and ω are called statement and witness, respectively. Also, let L be the language composed of all statements for which there exists a witness ω in R, i.e., L = {x}(x,ω)∈R. A non-interactive argument system Π for a relation R is composed of the following polynomial-time algorithms:

$$ (x,\omega) $$

$$ x $$

$$ \mathcal{L} $$

$$ \mathcal{R},,\mathrm{i.e.},\mathcal{L}={x}_{(x,\omega)\in\mathcal{R}}.,\mathrm{A} $$

λ λ Setup(1*, R*): The randomized setup algorithm takes as input the security parameter 1 and a relation R. It outputs a common reference string crs and a verification key vrs.

$$ \mathfrak{I}(1^{\lambda},\mathcal{R}) $$

$$ 1^{\lambda} $$

Prove(crs*,x,ω*): The randomized prover algorithm takes as input the common reference string crs, a statement x, and a witness ω. It outputs a proof π.

$$ (mathsf c r r,x,\omega) $$

Verify(vrs*,x,π*): The deterministic verification algorithm takes as input the verification key vrs, a statement x, and a proof π. It outputs a decision bit b.

We require a non-interactive argument system to be complete, i.e., honest proofs correctly verify. As for security, we consider two different definitions with respect to DV setting: selective soundness and straight-line knowledge soundness. The former says that it must be infeasible to find a proof that correctly verifies with respect to a statement x ̸∈ L where x is chosen before the execution of Setup. On other hand, the latter says that there exists a universal extractor Ext that, on input a trapdoor td, is able to extract a witness ω (such that (x,ω) ∈ R) from any pair (x,π) that correctly verifies, i.e., Verify(vrs*,x,π*) = 1. Both definitions are for the designated verifier (DV) setting, i.e., vrs is kept secret and the adversary has oracle access to Verify(vrs*, ·, ·*)

$$ x \notin \mathcal {L} $$

$$ x $$

$$ (x,\omega),\in,\mathcal{R}) $$

$$ \omega $$

$$ (x,\pi) $$

$$ \mathsf{V e r i f y}(\mathsf{v r s},x,\pi)=1 $$

Definition A.1(Completeness). A non-interactive proof system Π for a relation R is complete if ∀λ ∈ N*, ∀*(x,ω) ∈R we have:

$$ \forall\lambda\in\mathbb{N},,\forall(x,\omega)\in\mathcal{R} $$

$$ \mathbb{P}\big[\mathsf{V e r i f y}(\mathsf{v s s},x,\mathsf{P r o v e}(\mathsf{c r s},x,\omega))=1\big|(\mathsf{c r s},\mathsf{v r s})\leftarrow\mathsf{S e t u p}(1^{\lambda},\mathcal{R})\big]\geq1-\mathsf{n e g}(\lambda). $$

Definition A.2(Selective Soundness). A non-interactive argument system Π for a relation R sat- isfies selective soundness if, for every x ̸∈L, for every PPT adversary A*, we have:*

$$ x\not\in{\mathcal{L}} $$

$$ \mathbb{P}\bigg[\mathsf{V e r i f y}(\mathsf{v r s},x,\pi)=1\bigg|\binom{\mathsf{c r s},\mathsf{v r s}}{\pi}\mathrel{\xleftarrow{\leftarrow}\mathsf{S e t u p}(1^{\lambda},\mathcal{R})}{\xleftarrow{\land}\mathsf{A}^{\mathsf{V e r i f}(\mathsf{v r s},\cdot,\cdot)}(1^{\lambda},\mathsf{c r s})}\bigg]\leq\mathsf{n e g l}(\lambda). $$


The following definition models the ability of an extractor to be able to output a prover immediately, without having to further invoke the adversary. These extractors are often called straight-line and have been shown to be interesting for compiling both interactive and idealized proof schemes into concrete + non-interactive ones [Fis05,CFF 21].

Definition A.3(Straight-line Knowledge Soundness). A non-interactive argument system Π for a relation R satisfies straight-line knowledge soundness if there exists a PPT algorithm Ext = (Ext₀*,*Ext₁) such that:

$$ \mathsf{E x t}=(\mathsf{E x t}{0},\mathsf{E x t}{1}) $$

Indistinguishability. For every PPT adversary D*, we have:*

$$ \begin{aligned}{}&{{}\Big|\mathbb{P}\Big[\mathsf{D}(1^{\lambda},\mathsf{c r s},\mathsf{v r s})=1\Big|(\mathsf{c r s},\mathsf{v r s})\leftarrow\mathsf{s t u p}(1^{\lambda},\mathcal{R})\Big]-}\ {}&{{}\quad\quad\quad\mathbb{P}\Big[\mathsf{D}(1^{\lambda},\mathsf{c r s},\mathsf{v r s})=1\Big|(\mathsf{c r s},\mathsf{v r s},\mathsf{t d})\leftarrow\mathsf{s x t}_{0}(1^{\lambda},\mathcal{R})\Big]\Big|\leq\mathsf{n e g l}(\lambda).}\ \end{aligned} $$

Extractability. For every PPT adversary A*, we have:*

$$ \mathbb {P} \left[ \begin{array}{c c c} (x, \omega) \notin \mathcal {R} \ \wedge \ \mathrm {V e r i f y} (\mathrm {v r s}, x, \pi) = 1 \end{array} \right| \begin{array}{c c c} (\mathrm {c r s}, \mathrm {v r s}, \mathrm {t d}) & \leftarrow \mathrm {s} \operatorname {E x t} _ {0} \left(1 ^ {\lambda}, \mathcal {R}\right) \ (x, \pi) & \leftarrow \mathrm {s} \mathrm {A} ^ {\mathrm {V e r i f y} (\mathrm {v r s}, \cdot , \cdot)} \left(1 ^ {\lambda}, \mathrm {c r s}\right) \ \omega & \leftarrow \mathrm {s} \operatorname {E x t} _ {1} \left(1 ^ {\lambda}, \mathrm {t d}, x, \pi\right) \end{array} ] \leq \mathrm {n e g l} (\lambda). $$

DefinitionsA.2andA.3are for designated verifier (DV) non-interactive argument systems. We extend them to the publicly verifiable (PV) case.

Definition A.4(Public Verifiability). A non-interactive argument system Π for a relation R is publicly verifiable (PV) if selective soundness (resp. Straight-line Knowledge Soundness) holds even if the verification key vrs is given to the adversary A*.*

A.3 One-way and (Puncturable) Pseudorandom Functions

ℓin(λ) ℓout(λ) One-way functions. Let ℓin(·), ℓout(·), and F = {Fλ: {0,1} →{0,1}}λ∈Nbe two polynomials and an ensemble of functions, respectively. We say a function Fλ∈F is a one-way function (OWF) ′ ℓin(λ) ′$ℓin(λ) if it is computationally infeasible to find x ∈{0,1} such that Fλ(x) = Fλ(x) where x ← {0,1}.

$$ \mathcal{F}={\mathsf{F}{\lambda}:{0,1}^{\ell{\mathrm{}{i n}}(\lambda)}\to{0,1}^{\ell_{\mathrm{}{o u t}}(\lambda)}}_{\lambda\in\mathbb{N}} $$

$$ \ell_{\mathrm{}{i n}}(\cdot),:\ell_{\mathrm{}{o u t}}(\cdot) $$

$$ \operatorname{(O W F)} $$

$$ \mathsf{F}_{\lambda}\in\mathcal{F} $$

$$ x^{\prime}\in{0,1}^{\ell_{i n}(\lambda)} $$

$$ \mathsf{F}{\lambda}(x)=\mathsf{F}{\lambda}(x^{\prime}) $$

$$ x\leftarrow\mathfrak{0,1}^{\ell_{i n}(\lambda)} $$

Definition A.5. We say Fλ∈F is a OWF if for every PPT adversary A*, we have:*

$$ \mathsf{F}_{\lambda}\in\mathcal{F} $$

$$ \ {\mathbb{P}}\Big[{\sf F}{\lambda}({\sf A}(1^{\lambda},{\sf F}{\lambda}(x)))={\sf F}{\lambda}(x)\Big|x\leftarrow\mathfrak{s}{0,1}^{\ell{\mathrm{}{i n}}(\lambda)}\Big]\leq{\sf n e g l}(\lambda). $$

Pseudorandom functions. A pseudorandom function (PRF) scheme Π = (Gen*,*F) with input space ℓin ℓout {0,1} and output space {0,1} is composed of the following polynomial-time algorithms:

$$ {0,1}^{\ell_{\mathrm{}{i n}}} $$

$$ \mathit{\Pi}=(\mathsf{G e n},\mathsf{F}) $$

$$ {0,1}^{\ell_{o u t}} $$

λ λ KGen(1): The randomized key generation algorithm takes as input the security parameter 1 and outputs a key s.

$$ {mathsf{K G e n}(1^{\lambda})} $$

$$ 1^{\lambda} $$

ℓin F(s*,x*): The deterministic function evaluation algorithm takes as input a key s and an input x ∈{0,1}, ℓout it outputs a value y ∈{0,1}.

$$ \mathsf{F}(\mathsf{s},x) $$

$$ y\in{0,1}^{\ell_{o u t}} $$

A PRF Π is considered secure (i.e., pseudorandom) if its output distribution is indistinguishable to the one of a truly random function.

Definition A.6(Security of PRF). A PRF Π is secure if for every PPT adversary D*, we have:*

$$ \Big|\mathbb{P}\Big[\ \mathsf{D}^{\mathsf{F}(\mathsf{s},\cdot)}(1^{\lambda})=1\Big]-\mathbb{P}\Big[\mathsf{D}^{\mathsf{F}_{\mathsf{r n d}}(\cdot)}(1^{\lambda})=1\Big]\Big|\leq\mathsf{n e g l}(\lambda), $$

$λ ℓin ℓout where s ← Gen(1) and Frnd: {0,1} →{0,1} is a truly random function.

$$ \mathsf{s}\leftarrow\mathsf{s e n}(1^{\lambda}) $$

$$ \mathsf{F}{\mathsf{r n d}}:{0,1}^{\ell{i n}}\to{0,1}^{\ell_{o u t}} $$


Puncturable pseudorandom functions [HKW15]. A puncturable PRF scheme Π = (Gen*,* F*,*Punct) offers an additional polynomial-time algorithm Punct defined as follows:

ℓin Punct(s*,x*): The deterministic puncturing algorithm takes as input a key s and an input x ∈{0,1}, it ′ outputs a punctured key s.

$$ \varPi = (\mathrm {G e n}, \mathrm {F}, \mathrm {P u n c t}) $$

$$ s^{\prime} $$

$$ x\in{0,1}^{\ell_{i n}} $$

We require a puncturable PRF to be correct under puncturing and pseudorandom at punctured inputs.

Definition A.7(Correctness of puncturable PRF). A puncturable PRF Π is correct if ∀λ ∈ N*,* ′ ℓin ′ ∀x,x ∈{0,1} such that x ̸= x, we have

$$ i f\forall\lambda\in\mathbb{N} $$

$$ x\neq x^{\prime} $$

$$ \forall x,x^{\prime}\in{0,1}^{\ell_{i n}} $$

$$ \mathbb{P}\big[\sf{F}(s,x^{\prime}){\ =\ }\sf{F}(s^{\prime},x^{\prime})|s\ \ s\leftarrow\ sf{G}{\ \ {sf e e n}}(1^{\lambda}),s^{\prime}=\sf{P u n c t}(s,x)\big]=1. $$

ℓin Definition A.8(Security of puncturable PRF). A PRF Π is secure if for every x ∈ {0,1}, every PPT adversary D*, we have:*

$$ x,\in,{0,1}^{\ell_{i n}} $$

$$ \left\vert{\mathbb{P}\left[\mathsf{D}(1^{\lambda},\mathsf{s}^{\prime},\mathsf{F}(\mathsf{s},x))=1\right]-\mathbb{P}\left[\mathsf{D}(1^{\lambda},\mathsf{s}^{\prime},y)=1\right]}\right\vert\leq\mathsf{n e g l}(\lambda), $$

$$ \mathrm {s} \leftarrow \mathrm {s} \operatorname {K G e n} \left(1 ^ {\lambda}\right), \mathrm {s} ^ {\prime} = \operatorname {P u n c t} (\mathrm {s}, x), a n d y \leftarrow \mathrm {s} {0, 1 } ^ {\ell_ {o u t}}. $$

A.4 Message Authentication Codes

A message authentication code (MAC) Π with message space M is composed of the following polynomialtime algorithms:

$$ \left(1^{\lambda}\right) $$

λ λ KGen(1): The randomized key generation algorithm takes as input the security parameter 1 and outq puts a key k. Optionally, KGen takes as input an additional parameter 1 and k’s size can depend on q 1.

$$ 1^{\lambda} $$

Tag(k*,m*): The randomized tagging algorithm takes as input a key sk and a message m. It outputs a tag σ.

$$ (\mathsf{k},m) $$

Verify(k*,m,σ*): The deterministic verification algorithm takes as input a key k, a message m ∈M, and a tag σ. It outputs a decision bit b.

$$ 1(k,m,\sigma) $$

$$ m\in{\mathcal{M}} $$

We consider MACs that are correct and strong existentially unforgeable under selective chosen message attacks ((q)-sEUF-sel-CMA), i.e., fresh valid tags are unforgeable if the adversary can ask a fixed number q of tags (for arbitrary messages) in a selective fashion (note that this is weaker than the standard sEUF- CMA security in which the adversary has adaptive and unbounded access to tagging oracle Tag).

$$ ((q)\mathrm{-s E U F-s e l-C M A}) $$

Definition A.9(Correctness of MACs). A MAC scheme Π is correct if ∀λ ∈ N*, ∀m ∈M, we have* that: λ P Verify(k,m, Tag(k,m)) = 1|k ← KGen(1) ≥ 1 − negl(λ).

$$ \mathit{i f}\forall\lambda\in\mathbb{N},,\forall m\in\mathcal{M} $$

$$ \mathbb{P}\big[\sf e r i f y(k,\ m,\sf a g(k,m))=1|k\leftarrow\\ G e e n(1^{\lambda})\big]\geq1-\ n e g l(\lambda). $$

Definition A.10((q)-sEUF-sel-CMA security of MACs). A MAC scheme Π with message space M is strong existentially unforgeable under selective chosen message attacks in the (q)-bounded setting q ((q)-sEUF-sel-CMA) if for every (m₁,...,mq) ∈M, every PPT adversary A*, we have that:*  

$$ \ (()\ \mathrm{s E U F-s e l-C M A} $$

$$ (m _ {1}, \dots , m _ {q}) \in \mathcal {M} ^ {q} $$

$$ \ \Lambda, $$

$$ \mathbb {P} \left[ \begin{array}{c c} \forall i \in [ q ], (m, \sigma) \neq \left(m _ {i}, \sigma_ {i}\right) \ \wedge \ \operatorname {V e r i f y} (\mathrm {k}, m, \sigma) = 1 \end{array} \right| \begin{array}{l l} \mathrm {k} \leftarrow \mathrm {s} \mathrm {K G e n} \left(1 ^ {\lambda}, 1 ^ {q}\right) \ \forall i \in [ q ], \sigma_ {i} \leftarrow \mathrm {s} \operatorname {T a g} (\mathrm {k}, m _ {i}) \ (m, \sigma) \leftarrow \mathrm {s} \mathrm {A} \left(1 ^ {\lambda}, \sigma_ {1}, \dots , \sigma_ {q}\right) \end{array} ] \leq \operatorname {n e g l} (\lambda). $$

In addition, we also consider a weaker definition of security, named existential unforgeability (EUF). In this definition, the adversary does not have oracle access to Tag.

Definition A.11(EUF security of MACs). A MAC scheme Π with message space M is existentially unforgeable (EUF) if for every m ∈M, every PPT adversary A*, we have that:*

$$ m\in{\mathcal{M}}. $$

$$ {\bf A}, $$

$$ \mathbb {P} \left[ \operatorname {V e r i f y} (\mathrm {k}, m, \sigma) = 1 | \mathrm {k} \leftarrow {} _ {\mathrm {s}} \mathrm {K G e n} \left(1 ^ {\lambda}\right), \sigma \leftarrow {} _ {\mathrm {s}} \mathrm {A} \left(1 ^ {\lambda}, m\right) \right] \leq \operatorname {n e g l} (\lambda). $$


A.5 Digital Signatures

A signature scheme Π with message space M is composed of the following polynomial-time algorithms:

λ λ KGen(1): The randomized key generation algorithm takes as input the security parameter 1 and outputs a signing key sk and a public key pk. Optionally, KGen takes as input an additional parameter q q 1 and pk’s size can depend on 1.

$$ {mathsf{K G e n}(1^{\lambda})} $$

$$ 1^{\lambda} $$

$$ 1^{q} $$

$$ 1^{q} $$

Sign(sk*,m*): The randomized signing algorithm takes as input a signing key sk and a message m. It outputs a signature σ.

$$ {sigma,{}} $$

Verify(pk*,m,σ*): The deterministic verification algorithm takes as input the public key pk, a message m ∈M, and a signature σ. It outputs a decision bit b.

$$ \mathsf{V e r i f y}(\mathsf{p k},m,\sigma) $$

$$ {\sf p k}. $$

$$ \sigma. $$

$$ m\in{\mathcal{M}} $$

Similarly to MACs, we consider correctness and strong existential unforgeability under selective chosen message attacks in the (q)-bounded setting ((q)-sEUF-sel-CMA). In addition, we consider the notion of selective existential unforgeability under (adaptive) chosen message attacks (sel-EUF-CMA), i.e., the adversary must commit on a target message m before getting adaptive access to the oracle Sign.

$$ ((q)\mathrm{-s E U F-s e l-C M A}) $$

Definition A.12(Correctness of signatures). A digital signature scheme Π is correct if ∀λ ∈ N*,* ∀m ∈M, we have that:

$$ i f\forall\lambda\in\mathbb{N} $$

$$ \forall m\in{\mathcal{M}}. $$

$$ \mathbb {P} \left[ \operatorname {V e r i f y} (\mathrm {p k}, m, \operatorname {S i g n} (\mathrm {s k}, m)) = 1 | (\mathrm {s k}, \mathrm {p k}) \leftarrow {} ^ {\prime} \mathrm {s K G e n} \left(1 ^ {\lambda}\right) \right] = 1. $$

Definition A.13((q)-sEUF-sel-CMA security of signatures). A signature scheme Π with mes- sage space M is strong existentially unforgeable under selective chosen message attacks in the (q)-bounded q setting ((q)-sEUF-sel-CMA) if for every (m₁,...,mq) ∈M, every PPT adversary A*, we have that:*  

$$ \ (()\mathrm{-s E U F-s e l-C M A} $$

$$ (q) $$

$$ ((q) - s E U F - s e l - C M A) $$

$$ \left(m_{1},\ldots,m_{q}\right)\in\mathcal{M}^{q} $$

$$ {\sf A}, $$

$$ \mathbb {P} \left[ \begin{array}{c c| c} \forall i \in [ q ], (m, \sigma) \neq \left(m _ {i}, \sigma_ {i}\right) & (\mathrm {s k}, \mathrm {p k}) \leftarrow {} ^ {\prime} \mathrm {K G e n} \left(1 ^ {\lambda}, 1 ^ {q}\right) \ \wedge & \forall i \in [ q ], \sigma_ {i} \leftarrow {} ^ {\prime} \mathrm {S i g n} (\mathrm {s k}, m _ {i}) \ \mathrm {V e r i f y} (\mathrm {p k}, m, \sigma) = 1 & (m, \sigma) \leftarrow {} ^ {\prime} \mathrm {A} \left(1 ^ {\lambda}, \mathrm {p k}, \sigma_ {1}, \dots , \sigma_ {q}\right) \end{array} \right] \leq \mathrm {n e g l} (\lambda). $$

Definition A.14(sel-EUF-CMA security of signatures). A signature scheme Π with message space M is selectively existentially unforgeable under chosen message attacks (sel-EUF-CMA) if for every m ∈M, every PPT adversary A*, we have that:* " #

$$ m\in{\mathcal{M}} $$

$$ \mathbb {P} \left[ m \notin \mathcal {Q} _ {\mathrm {S i g n}} \wedge \operatorname {V e r i f y} (\mathrm {p k}, m, \sigma) = 1 \left| \begin{array}{l l} (\mathrm {s k}, \mathrm {p k}) \leftarrow \mathrm {s} K G e n \left(1 ^ {\lambda}\right) \ \sigma \leftarrow \mathrm {s} A ^ {\mathrm {S i g n} (\mathrm {s k}, \cdot)} \left(1 ^ {\lambda}, \mathrm {p k}, m\right) \end{array} \right] \leq \mathrm {n e g l} (\lambda), \right. $$

where QSignis the set of messages submitted to the oracle Sign*.*

$$ \mathcal{Q}_{\mathsf{S i g n}} $$

A.6 Symmetric Key Encryption

A symmetric encryption (SKE) scheme with message space M is composed of the following polynomialtime algorithms:

λ λ KGen(1): The randomized key generator takes as input the security parameter 1 and outputs a symmetric key k.

$$ \left(1^{\lambda}\right) $$

$$ 1^{\lambda} $$

Enc(k*,m*): The randomized encryption algorithm takes as input a symmetric key k and a message m ∈ M, it outputs a ciphertext c.

Dec(k*,c*): The deterministic decryption algorithm takes as input a symmetric key k and a ciphertext c, it outputs a message m.

$$ C. $$

$$ m\in $$

A SKE is correct if honest ciphertexts correctly decrypt.

$$ c, $$

Definition A.15(Correctness of SKE). A SKE Π with message space M is correct if ∀λ ∈ N*,* ∀m ∈M, we have λ P Dec(k,Enc(k,m)) = m|k ← KGen(1) = 1.

$$ i f,\forall\lambda,\in,\mathbb{N} $$

$$ \forall m\in{\mathcal{M}} $$

$$ \mathbb{P}\big[\sf{c e c}(k,\sf{E n c}(k,m))=m|k\leftarrow\ast\sf{K G e n}(1^{\lambda})\big]=1. $$


| $G_{\Pi,A,m0,m1}^{\text{SKEsec}}(\lambda)$ k←$$ KGen(1^{\lambda})$ b←$$ {0,1}$ c←$$ Enc(k,m_b)$ b'←$$ A(1^{\lambda},c)$ If b'=b,return 1 return 0 | $G_{\Pi,A,m}^{\text{SKEcpakey}}(\lambda)$ k0←$$ KGen(1^{\lambda}),k1←$$ KGen(1^{\lambda})$ b←$$ {0,1}$ c←$$ Enc(k_b,m)$ b'←$$ A_{k0,\cdot;\cdot},Enc(k_1,\cdot;\cdot)(1^{\lambda},c)$ If b'=b,return 1 return 0 | $G_{\Pi,A,m0,m1}^{\text{PKEcpa}}(\lambda)$ (sk,pk)←$$ KGen(1^{\lambda})$ b←$$ {0,1}$ c←$$ Enc(pk,m_b)$ b'←$$ A(1^{\lambda},pk,c)$ If b'=b,返回 1

return 0 | | | --- | --- | --- | --- | | $G_{\Pi,A}^{\text{SKEccal}}(\lambda)$ k←$$ KGen(1^{\lambda})$ m0,m1←$$ A_{0}^{\text{Enc}(k,\cdot),Dec(k,\cdot)}(1^{\lambda})$ b←$$ {0,1}$ c←$$ Enc(k,m_b)$ b'←$$ A_{1}^{\text{Enc}(k,\cdot)}(1^{\lambda},c)$ If b'=b,返回 1 return 0 | | | $G_{\Pi,A}^{\text{SKEcpakey}}(\lambda)$ k0←$$ KGen(1^{\lambda}),k1←$$ KGen(1^{\lambda})$ m←$$ A_{0}^{\text{Enc}(k0,\cdot),Enc(k1,\cdot)}(1^{\lambda})$ b←$$ {0,1}$ c←$$ Enc(k_b,m)$ b'←$$ A_{1}^{\text{Enc}(k0,\cdot),Enc(k1,\cdot)}(1^{\lambda},c)$ If b'=b,返回 1 return 0 |

$$ \mathbf{G}{\varPi,\mathsf{A},m{0},m_{1}}^{\mathsf{P K E c p a}}(\lambda) $$

$$ \mathbf{G}{\varPi,\mathsf{A},m{0},m_{1}}^{\mathsf{S K E s e c}}(\lambda) $$

$$ \mathbb{G}_{\varPi,\mathsf A,m}^{\mathsf{S K E c p r k e e}}(\lambda) $$

$$ (\mathsf{s k},\mathsf{p k})\leftarrow\mathfrak{S}\mathbin{\mathsf{K G e n}}(1^{\lambda}) $$

$$ \ {mathsf k{}leftarrow\ }\mathsf{s}\ \mathsf{K G e n}(1^{\lambda}) $$

$$ b\gets\sharp\left{0,1\right} $$

$$ \mathsf{k}{0}\leftarrow\mathfrak{s}\mathbin{\mathsf{K G e n}}(1^{\lambda}),\mathsf{k}{1}\leftarrow\mathfrak{s}\mathbin{\mathsf{K G e n}}(1^{\lambda}) $$

$$ b\gets\mathfrak{s}\left{0,1\right} $$

$$ b\leftarrow\mathfrak{s}\left{0,1\right} $$

$$ c\leftarrow\mathfrak&\mathsf{E n c}(\mathsf{p k},m_{b}) $$

$$ c\leftarrow{\mathfrak{s}}\ {\sf E n c}({\sf k},m_{b}) $$

$$ c\leftarrow{\mathfrak{s}}\ {mathsf}\ {\mathsf{E n c}}({\mathsf{k}}_{b},m) $$

$$ b^{\prime}\leftarrow{\mathfrak{s}};{\mathsf{A}}(1^{\lambda},c) $$

$$ b ^ {\prime} \leftarrow $ A ^ {\mathrm {E n c} \left(k _ {0}, \cdot ; \cdot\right), \mathrm {E n c} \left(k _ {1}, \cdot ; \cdot\right)} \left(1 ^ {\lambda}, c\right) $$

$$ b^{\prime}\leftarrow{\mathfrak{}}\ \ mathsf A A(1^{\lambda},\mathsf{p k},c) $$

$$ {\bf I f}\ b^{\prime}=b,{\mathrm{{\bf~r e t u r n}}\ 1} $$

$$ \textbf {I f} b ^ {\prime} = b, \textbf {r e t u r n} 1 $$

$$ \mathbf{G}_{\mathit{\Pi},\mathsf{A}}^{\mathsf{S K E c c l}}(\lambda) $$

$$ \mathbb{G}_{\varPi,\mathsf{A}}^{\mathsf{s K E c p k k e y}}(\lambda) $$

$$ \mathsf{k}\leftarrow{\mathfrak{s}}\mathbin mathsf{K G e n}(1^{\lambda}) $$

$$ k_{0}\leftarrow\mathfrak{S},\mathsf{K G e n}(1^{\lambda}),k_{1}\leftarrow\mathfrak{S},\mathsf{K G e n}(1^{\lambda}) $$

$$ m\leftarrow{\mathfrak{s}}\mathsf{A}{0}^{\mathsf{E n c}(\mathsf{k}{0},\cdot),\mathsf{E n c}(\mathsf{k}_{1},\cdot)}(1^{\lambda}) $$

$$ m_{0},m_{1}\leftarrow\ {}\ mathsf A A_{0}^{\mathsf{E n c}(\ ,\cdot),\mathsf{D e c}(\mathsf{k},\cdot)}(1^{\lambda}) $$

$$ b\gets\S\left{0,1\right} $$

$$ b\gets\mathfrak{s}\left{0,1\right} $$

$$ c\leftarrow{\mathfrak{{s}}}\ mathsf E n n(\mathsf{{k}},m_{b}) $$

$$ c\leftarrow{\mathfrak{s}}\mathsf{E n c}(\mathsf{k}_{b},m) $$

$$ b^{\prime}\leftarrow{\mathtt{S}}\mathsf{A}_{1}^{\mathsf{E n c}(\mathsf{k},\cdot)}(1^{\lambda},c) $$

$$ b^{\prime}\leftarrow\mathfrak{S}\mathsf{A}{1}^{\mathsf{E n c}(\mathsf{k}{0},\cdot),\mathsf{E n c}(\mathsf{k}_{1},\cdot)}(1^{\lambda},c) $$

$$ {\bf I f}\ b^{\prime}=b,\ {\bf r e t u r n}\ 1 $$

$$ b^{\prime}=b, $$

Fig. 9: Game defining semantic, IND-CCA1, IND-CPA-key, sel-IND-CPRA-key of SKE and sel-IND-CPA of PKE. The top three games (that define semantic, sel-IND-CPRA-key, and sel-IND-CPA security) are parametrized by two (or one) messages since they only cover selective security, while the bottom games cover also the adaptive case where the adversary is allowed to choose the messages after seeing the public key.

We now define different flavors of security in both selective and adaptive setting.

First, we consider the standard semantic security and security under chosen ciphertext attacks (IND- CCA1). In the IND-CCA1 experiment, the adversary has oracle access to Enc and Dec where Dec is available only before the selection of the messages m₀ and m₁.

$$ m_{0} $$

$$ m_{1} $$

Definition A.16(Semantic security of SKE). We say that a SKE Π with message space M is semantically secure if for every m₀,m₁ ∈M, every PPT adversaries A*, we have:*

$$ m_{0},m_{1}\in\mathcal{M} $$

$$ \bigg|\mathbb{P}\big[\mathbf{G}{\varPi,\mathsf{A},m{0},m_{1}}^{\mathsf S K E s e c}(\lambda)=1\big]-\frac{1}{2}\bigg|\leq\mathsf{n e g l}(\lambda), $$

SKEsec where the experiment GΠ,A,m,m(λ) is depicted in Figure9. 0 1

$$ \mathbf {G} _ {\varPi , \mathrm {A}, m _ {0}, m _ {1}} ^ {\mathrm {S K E s e c}} (\lambda) $$

Definition A.17(IND-CCA1 security of SKE). We say that a SKE Π with message space M is secure under chosen ciphertext attacks (IND-CCA1) if for every PPT adversaries A = (A₀*,A₁), we have:*

$$ W e $$

$$ \mathsf{A}=(\mathsf{A}{0},\mathsf{A}{1}) $$

$$ \bigg|\mathbb{P}\big[\mathbf{G}_{\varPi,\mathsf{A}}^{\mathsf{S K E c c a l}}(\lambda)=1\big]-\frac{1}{2}\bigg|\leq\mathsf{n e g l}(\lambda), $$

$$ \mathbb{G}_{\mathit{I}mathit\Pi{,}\mathbb{A}}^{\mathsf{S K E c c a l}}(\lambda)} $$

SKEcca1 where the experiment GΠ,A(λ) is depicted in Figure9.

Second, we consider SKEs that are key indistinguishable, i.e., a computationally bounded adversary A cannot determine which key (between k₀ ←$ KGen(λ) and k₁ ←$ KGen(λ)) has been used to encrypt an adversarially chosen message m. We define key indistinguishability with respect to two different models: (i) adaptive message and chosen plaintext attacks (IND-CPA-key) and (ii) selective message and chosen plaintext randomness attacks (sel-IND-CPRA-key). The IND-CPA-key experiment allows an adversary, with oracle access to Enc(k₀*, ·) and Enc(k₁, ·), to adaptively choose the message m. On the other hand, in the sel-IND-CPRA-key experiment, the adversary is required to commit on the message m before getting oracle access to Enc(k₀, ·; ·) and Enc(k₁, ·*; ·) where the latter oracles accept adversarially chosen plaintexts and randomnesses.

$$ \mathsf{k}{1}\leftarrow{\mathfrak{S}}\mathsf{K G e n}(\lambda)) $$

$$ \leftarrow\ {mathsf K}{\mathsf{G e n}}(\lambda) $$

$$ (mathit{I N D_C P A}\mathit{-k e y}) $$

$$ (s{e}l\ {it\ _I N D}\ {\it C P R}A{\ \ }\ {k}e{}y{{}} $$

$$ \mathsf{E n c}(k_{0},\cdot) $$

$$ \mathsf{E n c}(k_{1},\cdot) $$

$$ \mathsf{E n c}(\mathsf{k}_{0},\cdot;\cdot) $$

$$ \mathsf{E n c}(\mathsf{k}_{1},\cdot,\cdot) $$


Definition A.18(IND-CPA-key security of SKE). We say that a SKE Π with message space M is key indistinguishable under chosen plaintext attacks (IND-CPA-key) if for every PPT adversaries A = (A₀*,A₁), we have:* h i 1

$$ \mathsf{A}=(\mathsf{A}{0},\mathsf{A}{1}) $$

$$ \left| \mathbb {P} \left[ \mathbf {G} _ {\varPi , \mathrm {A}} ^ {\mathrm {S K E c p a k e y}} (\lambda) = 1 \right] - \frac {1}{2} \right| \leq \operatorname {n e g l} (\lambda), $$

SKEcpakey where the experiment G (λ) is depicted in Figure9. Π,A

$$ \mathbf {G} _ {\varPi , \mathrm {A}} ^ {\mathrm {S K E c p a k e y}} (\lambda) $$

Definition A.19(sel-IND-CPRA-key of SKE). We say that a SKE Π with message space M is selectively key indistinguishable under chosen plaintext randomness attacks (sel-IND-CPRA-key) if for every m ∈M, every PPT adversaries A*, we have:* h i

$$ \ \mathbf{A}, $$

$$ m\in{\mathcal{M}} $$

$$ \left| \mathbb {P} \left[ \mathbf {G} _ {\varPi , \mathrm {A}, m} ^ {\mathrm {S K E c p r a k e y}} (\lambda) = 1 \right] - \frac {1}{2} \right| \leq \operatorname {n e g l} (\lambda), $$

SKEcprakey where the experiment G (λ) is depicted in Figure9. Π,A,m

$$ \mathbf{G}_{\mathit{\Pi},\mathsf{A},m}^{\mathsf{S K E c r r a k e y}}(\lambda{)} $$

Through the paper, we leverage the above definitions of security to prove two main results. In Section5.5, we show that oiO is (potentially) able to compile any semantically secure and sel-IND-CPRA-key ′ SKE Π into a sel-IND-CPA PKE Π (see AppendixA.7and definitionA.22). On the other hand, in Section3, we make use of the adaptive IND-CCA1 and IND-CPA-key definitions to prove some unconditional impossibility results for both odiO and oiO.

$$ T^{\prime} $$

Lastly, we stress that all the above definitions follow from OWFs. Indeed, the well known Enc(k*,m*; r) = (F(k*,r*) ⊕ m,r) (where F is a PRF) satifies both IND-CCA1 (and in turn semantic security) and IND- CPA-key. Moreover, any sel-IND-CPA-key SKE scheme Π = (KGen*,Enc,Dec) can be transformed ∗ ∗ ∗ ∗ ∗ into a sel-IND-CPRA-key SKE scheme Π = (KGen,Enc,Dec) by simply setting Enc (k,m*; r) = ∗ ∗ λ 15 Enc(k*,m*; F(s*,* (m,r))) where k = (k*,*s) ←$ KGen (1).

$$ (\mathsf{F}(\mathsf{k},r)\oplus m,r) $$

$$ \mathsf{n c}(\mathsf{k},m;r)= $$

$$ {\mathit{\Pi}}^{},=,{{\mathsf{(K G e n}}^{}} $$

$$ \mathsf{E n c}^{}({\mathsf{k}}^{},m;r),= $$

$$ k^{}=(k,s)\leftarrow s\ G G e^{}(1^{\lambda}),^{15} $$

$$ \mathsf{E n c}(\mathsf{k},m;\mathsf{F}(\mathsf{s},(m,r))) $$

Corollary A.20. If OWFs exist then there exists a SKE scheme Π that satifies DefinitionsA.15toA.19.

A.7 Public Key Encryption

A public key encryption (PKE) scheme with message space M is composed of the following polynomialtime algorithms:

$$ {\mathsf{K G e n}}(1^{\lambda}) $$

λ λ KGen(1): The randomized key generator takes as input the security parameter 1 and outputs a secret key sk and a public key pk.

$$ 1^{\lambda} $$

Enc(pk*,m*): The randomized encryption algorithm takes as input a public key pk and a message m ∈M, it outputs a ciphertext c.

$$ \mathsf{I c}(\mathsf{p k},m) $$

$$ m\in{\mathcal{M}}. $$

$$ {.} $$

Dec(sk*,c*): The deterministic decryption algorithm takes as input a secret key sk and a ciphertext c, it outputs a message m.

$$ c, $$

We consider PKEs that are correct and selectively secure under chosen plaintext attacks (sel-IND-CPA), i.e., the messages m₀,m₁ are chosen before executing KGen.

$$ m_{0},m_{1} $$

Definition A.21(Correctness of PKE). A PKE Π with message space M correct if ∀λ ∈ N*,* ∀m ∈M, we have λ P Dec(sk*,Enc(pk,m*)) = m|(pk*,sk) ← KGen(1) = 1.*

$$ i f\ forall lambdalambda;\in;\mathbb{} $$

$$ \forall m\in{\mathcal{M}} $$

$$ \mathbb{P}\big[\sf{c c c}(\sf{s k},\sf{E n c}(\sf{p k},m))=m\ \ \mathrm({p k},\sf{s k})\xleftarrow{\ast}\sf{K G e n}(\sf{1}^{\lambda})\big]=1. $$

Definition A.22(sel-IND-CPA security of PKE). We say that a PKE Π is selectively secure under chosen plaintext attacks (sel-IND-CPA) if for every m₀,m₁ ∈M, every PPT adversary A*:* h i

$$ m_{1}\in{\mathcal{M}}, $$

$$ \Big|\mathbb{P}\Big[\mathbf{G}{\mathrm{}{H},\mathsf{A},m{0},m_{1}}^{\mathsf{P K E c p a}}(\lambda)=1\Big]-\frac{1}{2}\Big|\leq\mathsf{n e g l}(\lambda), $$

$$ \mathbf {G} _ {\varPi , \mathrm {A}, m _ {0}, m _ {1}} ^ {\mathrm {P K E c p a}} (\lambda) $$

PKEcpa where game G (λ) is depicted in Figure9. Π,A,m0,m1

Sometimes, we will consider the (standard) adaptive version of the above definition of security, i.e., security under chosen plaintext attacks (IND-CPA).

15 We stress that the same transformation achieves adaptive security, i.e., any IND-CPA-key SKE scheme can be transformed into a IND-CPRA-key scheme (the adaptive flavor of DefinitionA.19).


B Supporting Proofs

B.1 Proof of Theorem4.6

VBB ⇒ oiO. We start by proving the following lemma.

Lemma B.1. If there exists a PPT Obf obfuscator such that Obf is a ({S₀,S₁})-VBB-obfuscator (Defi- nition3.5) then Obf is a ({S})-oiO-obfuscator (Definition4.2).

$$ \mathsf{V B B}\Rightarrow\mathsf{o i i0} $$

$$ a({S_{0},S_{1}})\cdot\lor B B\ O b f u s c a t o r(D e f). $$

$$ 4.2) $$

Proof. By contradiction, assume that Obf is not a ({S})-oiO-obfuscator, i.e., there exist a PPT adversary D such that λ λ λ λ P D(1,Obf(1,C₀),α) = 1 − P D(1,Obf(1,C₁),α) = 1 ≥ ϵ,

$$ ({S})\rightarrow010 $$

$$ \left| \mathbb {P} \left[ \mathrm {D} \left(1 ^ {\lambda}, \mathrm {O b f} \left(1 ^ {\lambda}, C _ {0}\right), \alpha\right) = 1 \right] - \mathbb {P} \left[ \mathrm {D} \left(1 ^ {\lambda}, \mathrm {O b f} \left(1 ^ {\lambda}, C _ {1}\right), \alpha\right) = 1 \right] \right| \geq \epsilon , $$

(3)

$λ where (C₀,C₁,α) ← S(1) and ϵ non-negligible. By definition of S₀*,*S₁, the following condition holds:

$$ (C_{0},C_{1},\alpha)\leftarrow_{\mathfrak{S}}\mathsf{S}(1^{\lambda}) $$

$$ \mathsf{S}{0},\mathsf{S}{1} $$

$$ \forall r\in{0,1}^{*},C_{0}=C_{0}^{\prime}\wedge C_{1}=C_{1}^{\prime}\wedge\alpha=\alpha^{\prime},b $$

λ ′ ′ λ ′ ′ λ where (C₀,C₁,α) = S(1; r),(C₀,α) = S₀(1; r), and (C₁,α) = S₁(1; r). Hence, we can rewrite Equation (3) as follows:

$$ (C_{0},C_{1},\alpha){\ =\ }\mathsf{S}(1^{\lambda};r){,}(C_{0}^{\prime},\alpha^{\prime}){\ =\ }\mathsf{S}_{0}(1^{\lambda};r) $$

$$ \left(C _ {1} ^ {\prime}, \alpha^ {\prime}\right) = S _ {1} \left(1 ^ {\lambda}; r\right) $$

$$ \left|\mathbb{P}\big[\mathsf{D}(1^{\lambda},\mathsf{O b f}(1^{\lambda},C_{0}^{\prime}),\alpha^{\prime})=1\big]-\mathbb{P}\big[\mathsf{D}(1^{\lambda},\mathsf{O b f}(1^{\lambda},C_{1}^{\prime}),\alpha^{\prime})!=!1\big]\right|\geq\epsilon, $$

(4)

$∗ ′ ′ λ ′ ′ λ where r ← {0,1}, (C₀,α)=S₀(1; r), and (C₁,α)=S₁(1; r). By leveraging the fact that Obf is a ({S₀,S₁})-VBB-obfuscator, we conclude that there exists a PPT simulator Sim such that for every Sb∈{S₀,S₁}:

$$ r\gets $$

$$ \big(C_{1}^{\prime},\alpha^{\prime}\big)=,mathsf S{{1}}big(1^{\lambda};r\big) $$

$$ ({\mathsf{S}{0},\mathsf{S}{1}}) $$

$$ \mathsf{S}{b}\in{\mathsf{S}{0},\mathsf{S}_{1}} $$

$$ \Bigg|\mathbb{P}\big[\mathsf{D}(1^{\lambda},\mathsf{O b f}(1^{\lambda},C_{b}^{\prime}),\alpha^{\prime})=1\big]-\mathbb{P}\big[\mathsf{S i m}^{C_{b}^{\prime}(\cdot)}(1^{\lambda},1^{|C_{b}^{\prime}|},\alpha^{\prime})=1\big]\Bigg|\leq\mathsf{n e g l}(\lambda), $$

(5)

$∗ ′$λ where r ← {0,1} and (Cb,α) ← Sb(1). By combining Equations (3) to (5) we conclude that

$$ r\leftarrow\mathfrak0,1}^{*} $$

$$ \big(C_{b},\alpha^{\prime}\big)\leftarrow\mathfrak{S}_{b}(1^{\lambda})big nonumber $$

$$ \Bigg|\mathbb{P}\Big[\mathsf{S i m}^{C_{0}^{\prime}(\cdot)}(1^{\lambda},1^{|C_{0}^{\prime}|},\alpha^{\prime})=1\Big]-\mathbb{P}\Big[\mathsf{S i m}^{C_{1}^{\prime}(\cdot)}(1^{\lambda},1^{|C_{1}^{\prime}|},\alpha^{\prime})=1\Big]\Bigg|\geq\epsilon+\mathsf{n e g l}(\lambda), $$

(6)

$∗ ′ ′ λ ′ ′ λ where r ← {0,1}, (C₀,α) = S₀(1; r), and (C₁,α) = S₁(1; r). Since ϵ is non-negligible, Equation (6) contradicts the fact that S is an oiO-sampler. This concludes the proof. ⊓⊔

$$ r\gets\sharp{\boldsymbol{0},\boldsymbol{1}}^{*},\left(\mathcal{C}_{0}^{\prime},\boldsymbol{\alpha}^{\prime}\right)=\S{_00}(1^{\lambda},\boldsymbol{\tau}) $$

$$ \left(C_{1}^{\prime},\alpha^{\prime}\right)=\mathsf{S}_{1}(1^{\lambda};r) $$

We now use LemmaB.1to prove Theorem4.6. By contradiction, suppose S ̸∈ SoiO. This implies that, for every ensemble of oiO-samplers S such that S ∈ S, it does not exists a PPT Obf that is a ′ (S)-oiO-obfuscator. By leveraging LemmaB.1, we can also conclude that it must not exists a PPT Obf that is a ({S₀,S₁})-VBB-obfuscator. As a consequence, it must be that either S₀ ̸∈SVBBor S₁ ̸∈SVBB. This concludes the proof.

$$ \mathsf{S}\not\in\mathcal{S}_{0\mathsf{i}0} $$

$$ S $$

$$ {mathsf\mathsf S{}}\in{{\mathcal{S}} $$

$$ ({\mathsf{S}{0},\mathsf{S}{1}})\mathsf{-V B B}. $$

$$ \mathsf{S}{0}\not\in\mathcal{S}{\mathsf{V B B}} $$

$$ \mathsf{S}{1}\not\in\mathcal{S}{\mathsf{V B B}} $$

VBB ⇒ odiO. This case follows by combining the above argument and the fact that oiO ⇒ odiO (Theorem4.5).

$$ \ \mathsf{o i O}\Rightarrow\ \mathsf{o d i O} $$

B.2 Proof of Theorem5.1

∗ (Part one) Sxis an odiO-sampler. By contradiction, suppose there exists x ̸∈L such that Sx∗ is not an odiO-sampler, i.e., there exists a PPT adversary A such that h i

$$ {bf S S}_{x} $$

$$ x^{*}\not\in{\mathcal{L}} $$

$$ S_{x} $$

$$ \mathbb{P}\Big[C_{0}(v)\neq C_{1}(v)\Big|v\leftarrow\operatorname{s\mathsf A}^{C_{0}(\cdot),C_{1}(\cdot)}(1^{\lambda},1^{|C_{0}|},\alpha)\Big]\geq\epsilon, $$

$λ ′ where (C₀,C₁,α) ← Sx∗ (1) and ϵ non-negligible. We build an adversary A that breaks the selective ∗ ∗ ′ soundness of Π with respect to the statement x ̸∈L. The adversary A proceeds as follows:

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {$} S _ {x ^ {*}} \left(1 ^ {\lambda}\right) $$

$$ {\mathsf A}^{\prime} $$

$$ \varPi^ {*} $$

$$ x^{*}\not\in\mathcal{L}. $$

∗ 1.Receive crs from the challenger.

$$ \mathsf{c r s}^{*} $$


∗ Verify Verify ∗ ∗ ∗ ′ ∗ 2.Let C₀ = Cvrs∗,C₁ = Cvrs∗,x∗ and α = crs (note that both C₀ and C₁ are unknown to A since vrs is kept secret by the challenger).

$$ C_{0}^{}=C_{\mathsf{v r s}^{}}^{\mathsf{V e r i f y}},C_{1}=C_{\mathsf{v r s}^{*},x}^{\mathsf{V e r i f y}}, $$

$$ \alpha={\mathsf{c}}{\mathsf{r}}{\mathsf{s}}^{*} $$

$$ C_{1}^{*} $$

$$ C_{0}^{*} $$

$$ \mathsf{v r s}^{*} $$

$$ {\bf A}^{\prime} $$

γ 3.Send α and 1 (where γ as defined in Figure2) to A and answer to the incoming queries as follows: ∗ ′ ∗ ∗ (a)On input (x,π) for C₀, A forwards (x,π) to the oracle Verify (vrs*, ·, ·*) and returns the answer.

$$ (x,\pi) $$

$$ C _ {0} ^ {*}, \mathrm {A} ^ {\prime} $$

$$ (x,\pi) $$

∗ ∗ ∗ ∗ (b)On input (x,π) for C₁, if x = x, return 0. Otherwise, forward (x,π) to the oracle Verify (vrs*, ·, ·*) and return the answer.

$$ \mathsf{V e r i f y}^{}(\mathsf{v r s}^{},\cdot,\cdot) $$

$$ (x,\pi) $$

$$ C_{1}^{},\operatorname{i f}x=x^{} $$

$$ \mathsf{V e r i f y}^{}(\mathsf{v r s}^{},\cdot,\cdot) $$

$$ (x,\pi) $$

′ 4.Finally, A receives v = (*x,*b πb) from A. It forwards πb to the challenger.

$$ v=\left(\widehat{x},\widehat{\pi}\right) $$

$$ \hat{\pi} $$

′ ∗ ∗ It is easy to see that A perfectly simulates the view of A. This because crs and vrs (generated by the ′ challenger) have the exact same distribution to the one generated by Sx∗. Moreover, we have that A ∗ ∗ ∗ ∗ perfectly simulates both circuits C₀ and C₁. Observe that v = (x,b πb) is a differing-input for C₀ and C₁ ∗ ∗ ∗ ∗ ′ ∗ only if xb = x and Verify (vrs,x, πb) = 1. Hence, A breaks selective soundness property of Π with the same non-negligible advantage ϵ of A. This concludes the proof.

$$ \mathsf{c r s}^{*} $$

$$ \mathsf{V r s}^{*} $$

$$ \mathsf{S}_{x^{*}} $$

$$ {\bf A}^{\prime} $$

$$ C_{\Omega}^{*} $$

$$ C_{1}^{*} $$

$$ v=\left(\widehat{x},\widehat{\pi}\right) $$

$$ C_{0}^{*} $$

$$ C_{1}^{*} $$

$$ {\widehat{x}}=x^{*} $$

$$ \mathsf{V e r i f y}^{}(\mathsf{v r s}^{},x^{*},\hat{\widehat{\pi}})=1 $$

$$ \varPi^ {*} $$

∗ (Part two) Π satisfies (publicly verifiable) selective soundness. Let x ̸∈ L. Consider the following hybrid experiments:

$$ x^{*}\ \notin\ \mathcal{L} $$

∗ x ∗ Hyb₀ (λ): This is the standard selective soundness experiment (with respect to the statement x ̸∈L) for publicly verifiable argument systems (DefinitionA.2). Recall that in the publicly verifiable setting, ∗ ∗ both crs and vrs are given in input to the adversary (DefinitionA.4).

$$ {\mathsf H{y b}}_{0}^{x^{*}}(\lambda) $$

$$ x^{*}\not\in\mathcal{L}) $$

$$ \mathsf{c r s}^{*} $$

$$ \mathsf{v r s}^{*} $$

∗ ∗Verify x x Hyb₁ (λ): Same as Hyb₀, except that the challenger obfuscates the circuit Cvrs∗,x∗ of Figure2(instead of Verify λ Verify ∗ ∗ ∗ λ C ∗). Formally, the challenger computes vrs ←$ Obf(1*,C* ∗ ∗) where (crs*,vrs) ←$ Setup (1, R*). vrs vrs,x

$$ {\mathsf H{y}}{\mathsf{b}}_{1}^{x^{*}}(\lambda) $$

$$ {\mathsf{H y b}}_{0}^{x^{*}} $$

$$ C_{\mathsf{v r s}^{*},x}^{\mathsf{V e r i f y}}. $$

$$ \leftarrow_}\mathsf{O b f}(1^{\lambda},C_{\mathsf{v r s}^{},x^{}}^{\mathsf{V e r i f y}}) $$

$$ C_{\mathsf{v r s}^{*}}^{\mathsf{V e r i f y}}] $$

$$ (\mathsf{c r s}^{},\mathsf{v r s}^{})\leftarrow_{\mathsf{s}}\mathsf{S e t u p}^{*}(1^{\lambda},\mathcal{R}) $$

∗ ∗ ∗ x λ x λ Lemma B.2. For every x ̸∈L, Hyb₀ (1) ≈cHyb₁ (1).

$$ x^{}\notin\mathcal{L},,{\sf H y h}_{0}^{x^{}}(1^{\lambda})\approx_{c}{\sf H y h}_{1}^{x^{*}}(1^{\lambda}) $$

∗ ∗ ∗ x x Proof. By contradiction, assume there exists x ̸∈L such that Hyb₀ and Hyb₁ are not computationally indistinguishable, i.e., there exists a PPT distinguisher D that has a non-negligible advantage in dis- ∗ ∗ x x ′ tinguishing between Hyb0and Hyb1. We build a distinguisher D that breaks the indistinguishability ′ property of Obf for the odiO-sampler Sx∗. The distinguisher D proceeds as follows:

$$ x^{*}\not\in\mathcal{L} $$

$$ {mathsf H y y}_{0}^{x^{*}} $$

$$ \mathsf{H y b}_{1}^{x^{*}} $$

$$ \ dot\mathrm{H y b}_{0}^{x^{*}} $$

$$ \mathsf{H y b}_{1}^{x^{*}} $$

$$ D^{\prime} $$

$$ \mathrm {S} _ {x ^ {*}} $$

e and e$λ ∗ 1.Receive in input an obfuscated circuit C α. Recall that C ← Obf(1*,C*b) and α = crs where $ $λ b ← {0,1} is the unknown challenge bit and (C₀,C₁,α) ← Sx∗ (1).

$$ \tilde{C} $$

$$ \alpha={\mathsf{c r s}}^{*} $$

$$ \ \mathfrak\ b\leftarrow\mathfrak s\,{\mathfrak s,{0,1}} $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{b}) $$

∗e to D. 2.Send crs = crs and vrs = C

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {$} S _ {x ^ {*}} \left(1 ^ {\lambda}\right) $$

$$ {\mathsf{c r s}}={\mathsf{c r s}}^{*} $$

$$ \mathsf{v r s}=\tilde{C} $$

3.Return whatever D outputs.

∗ ′ x ′ It is easy to see that, if b = 0 then D simulates Hyb₀. On the other hand, if b = 1 then D simulates ∗ x ′ Hyb₁. Hence, D retains the same non negligible advantage of D. ⊓⊔

$$ b=0 $$

$$ \mathsf{H y b}_{0}^{x^{*}} $$

$$ D^{\prime} $$

$$ b=1 $$

$$ D^{\prime} $$

$$ \mathsf{H y b}_{1}^{x^{*}} $$

$$ D^{\prime} $$

∗ Observe that, for every x ̸∈ L, A has advantage 0 against the selective soundness experiment of ∗Verify x ∗ ∗ λ Hyb. This because, for every π ∈{0,1}, Verify(vrs*,x,π*) returns 0 since vrs ←$ Obf(1*,C ∗ ∗) (see 1 vrs,x Verify the definition of Cvrs∗,x∗* depicted in Figure2). This concludes the proof.

$$ x^{*}\not\in\mathcal{L} $$

$$ {\mathrm{H y b}}_{1}^{x^{*}} $$

$$ \pi\in{0,1}^{},\mathsf{V e r i f y}(\mathsf{v r s},x^{},\pi) $$

$$ \mathrm {v r s} \leftarrow {} ^ {$} \mathrm {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {v r s} ^ {} , x ^ {}} ^ {\mathrm {V e r i f y}}\right) $$

$$ C_{\mathsf{v r s}^{*},x}^{\mathsf{V e r i f y}}. $$

B.3 Proof of Theorem5.2

(Part one) SExt∗ is an odiO-sampler. By contradiction, suppose SExt∗ is not an odiO-sampler, i.e., there exists a PPT adversary A such that: h i

$$ \mathsf{S}_{\mathsf{E}\times\mathsf{t}^{*}} $$

$$ \mathsf{S}_{\mathsf{E x t}^{*}} $$

$$ \mathbb{P}\Big[C_{0}(v)\neq C_{1}(v)\Big|v\leftarrow\mathsf{s}\mathsf{A}^{C_{0}(\cdot),C_{1}(\cdot)}(1^{\lambda},1^{|C_{0}|},\alpha)\Big]\geq\epsilon, $$

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {\mathrm {s}} \mathsf {S} _ {\mathrm {E x t} ^ {*}} \left(1 ^ {\lambda}\right) $$

$ ∗λ ′ where (C₀,C₁,α) ← SExt(1) and ϵ non-negligible. We build an adversary A that breaks the extractabil- ∗ ′ ity property of Π. The adversary A proceeds as follows:

$$ \Pi^{*} $$

∗ 1.Receive crs from the challenger.

$$ {\bf A}^{\prime} $$

$$ \mathsf{c r s^{*}} $$

∗ Verify Verify ∗ ∗ ∗ ∗ ∗ 2.Let C₀ = C ∗,C₁ = C∗ ∗ ∗ and α = crs for random r₁ ←$ {0,1} (note that both C₀ and C₁ vrs vrs,td,r1 ′ ∗ ∗ are unknown to A since both vrs and td is kept secret by the challenger).

$$ \mathcal{C}{0}^{*}=\mathcal{C}{\mathsf{v r s}^{}}^{\mathsf{V e r i f y}}\mathcal{C}{1}=\mathcal{C}{\mathsf{v r s}^{},\mathsf{t d}^{},r_{1}^{}}^{\mathsf{V e r i f y}} $$

$$ \alpha={\mathsf{c}}{\mathsf{r}}{\mathsf{s}}^{*} $$

$$ r_{1}^{}\leftarrow\ \ {,}1}^{} $$

$$ C_{0}^{*} $$

$$ C_{1}^{*} $$

$$ \ {mathsf v r r}^{*} $$

$$ \mathrm{t d}^{*} $$

γ 3.Send α and 1 (where γ as defined in Figure2) to A and answer the incoming queries as follows:

$$ \gamma $$


$$ i \in {0, 1 } $$

′ ∗ ∗ (a)On input (x,π) for the circuit Ci∗for i ∈{0,1}, A forwards (x,π) to the oracle Verify (vrs*, ·, ·*) and returns the answer.

$$ (x,\pi) $$

$$ (x,\pi) $$

$$ \mathsf{V e r i f y}^{}(\mathsf{v r s}^{},\cdot,\cdot) $$

$$ C_{i}^{*} $$

4.Receive v = (*x,*b πb) from A.

$$ vboldsymbol{=}\left(\widehat{x},\widehat{\pi}\right) $$

$$ {\bf A}. $$

$′ ′ ′$ ∗ ∗ 5.Sample a random bit b ← {0,1}. If b = 0, A returns (x,π) ← QCwhere QCare the queries 1 1 ∗ ′ ′ ′ submitted by A to the oracle C₁. Otherwise, if b = 1, A returns (x,π) = (*x,*b πb).

$$ b \leftarrow \mathrm {s} {0, 1 } $$

$$ b,=,0,,\mathsf{A}^{\prime} $$

$$ (x^{\prime},\pi^{\prime})\leftarrow\ \mathfrak{Q}{C{!}^{*}} $$

$$ \ {mathcal Q_{{1}}^{*}} $$

$$ C_{1}^{*} $$

$$ (x^{\prime},\pi^{\prime})=({\widehat{x}},{\widehat{\pi}}) $$

∗ ∗∗ First, note that (C₀,C₁,α) comes from a distribution that is identical to that of SExt; this is because ∗ ∗ ∗ ∗ ∗ vrs and td are generated by executing Ext0and r₁ is sampled at random from {0,1} (as done by SExt∗).

$$ (C_{0}^{},C_{1}^{},\alpha) $$

$$ \mathsf{S}_{\mathsf{E}\times\mathsf{t}^{*}}; $$

$$ \ {sf t t d}^{*} $$

$$ r{_{1}^{*}} $$

$$ {0,1}^{*} $$

$$ \mathsf{E t}_{0}^{*} $$

$$ \mathsf{S}_{\mathsf{E}\times\mathbf{t}^{*}},) $$

In addition, observe that

′ ∗ ∗ 1.If A correctly simulates A’s view with respect to (C₀,C₁,α) then (*x,*b πb) (output by A) contradicts ∗ the Straight-line Knowledge Soundness property of Π.

$$ (C_{0}^{},C_{1}^{},\alpha) $$

$$ (\widehat{x},\widehat{\pi}) $$

′ ∗ ∗ 2.On the other hand, if A fails to correctly simulate A’s view with respect to (C₀,C₁,α) then there ′ ′∗ exists (x,π) ∈ QC(submitted by A) that contradicts the Straight-line Knowledge Soundness 1 ∗ property of Π.

$$ I^{*} $$

$$ \big(x^{\prime},\pi^{\prime}\big);\in;\mathcal{Q}{C{1}^{*}} $$

$$ (C_{0}^{},C_{1}^{},\alpha) $$

∗ ∗ ∗ ∗ Consider the following events defined with respect to (crs*,vrs,td,r₁*):

$$ \ \ (\mathsf{c r s}^{},\mathsf{v r s}^{},\mathsf{t d}^{},r_{1}^{}) $$

$$ \ ^{*} $$

$$ \mathbf{S i m}:\exists(x,\pi)\in\mathcal{Q}{C{!}^{}},\mathsf{V e r i f y}^{}(\mathsf{v r s}^{*},x,\pi)=1\wedge(x,\omega)\not\in\mathcal{R} $$

$$ \text {w h e r e} \omega = \operatorname {E x t} _ {1} ^ {} \left(1 ^ {\lambda}, \mathrm {t d} ^ {}, x, \pi ; r _ {1} ^ {*}\right), $$

$$ \mathbf{W i n}:\mathsf{V e r i f y}^{}(\mathsf{v r s}^{},x^{\prime},\pi^{\prime})=\mathtt{1}\wedge(x^{\prime},\omega^{\prime})\not\in\mathcal{R} $$

$$ \mathrm{w h e r e};\upsilon^{I\prime}=\mathsf{E x t}{1}^{}(1^{\lambda},\mathsf{t d}^{},x^{\prime},\pi^{I};r{1}^{*}), $$

$$ \mathbf{B i t}:b=1. $$

′ We can bound the advantage of A as follows:

$$ {\mathsf A}^{\prime} $$

$$ \begin{array}{l} \mathbb {P} [ \mathbf {W i n} ] = \mathbb {P} [ \mathbf {W i n} | \mathbf {S i m}, \mathbf {B i t} ] \cdot \mathbb {P} [ \mathbf {S i m} ] \cdot \mathbb {P} [ \mathbf {B i t} ] \ + \mathbb {P} [ \mathbf {W i n} | \mathbf {S i m}, \neg \mathbf {B i t} ] \cdot \mathbb {P} [ \mathbf {S i m} ] \cdot \mathbb {P} [ \neg \mathbf {B i t} ] \ + \mathbb {P} [ \mathbf {W i n} | \neg \mathbf {S i m}, \mathbf {B i t} ] \cdot \mathbb {P} [ \neg \mathbf {S i m} ] \cdot \mathbb {P} [ \mathbf {B i t} ] \ + \mathbb {P} [ \mathbf {W i n} | \neg \mathbf {S i m}, \neg \mathbf {B i t} ] \cdot \mathbb {P} [ \neg \mathbf {S i m} ] \cdot \mathbb {P} [ \neg \mathbf {B i t} ] \ \geq \mathbb {P} [ \mathbf {W i n} | \neg \mathbf {S i m}, \mathbf {B i t} ] \cdot \mathbb {P} [ \neg \mathbf {S i m} ] \cdot \mathbb {P} [ \mathbf {B i t} ] \ + \mathbb {P} [ \mathbf {W i n} | \mathbf {S i m}, \neg \mathbf {B i t} ] \cdot \mathbb {P} [ \mathbf {S i m} ] \cdot \mathbb {P} [ \neg \mathbf {B i t} ] \ = \mathbb {P} [ \mathbf {W i n} | \neg \mathbf {S i m}, \mathbf {B i t} ] \cdot \frac {1 - p _ {\mathrm {S i m}}}{2} + \mathbb {P} [ \mathbf {W i n} | \mathbf {S i m}, \neg \mathbf {B i t} ] \cdot \frac {p _ {\mathrm {S i m}}}{2}, \ \end{array} $$

(7)

∗ Verify for pSim= P[Sim] and P[Bit] = P[¬Bit] = 1/2. A differing-input v = (x,π) for C₀ = Cvrs∗ and ∗ Verify C₁ = C∗ ∗ ∗ needs to satisfy the following condition vrs,td,r1

$$ \mathbb{P}[\mathbf{B i t}]=\mathbb{P}[\neg\mathbf{B i t}]=1/2 $$

$$ v,=,(x,\pi) $$

$$ \mathcal{C}{0}^{*}=\mathcal{C}{\mathsf{v r s}^{*}}^{\mathsf{V e r i f y}} $$

$$ C_{1}^{}=C_{\mathsf{v r s}^{},\mathsf{t d}^{},r_{1}^{}}^{\mathsf{V e r i f y}} $$

$$ \mathsf{V e r i f y}^{}(\mathsf{w r s}^{},x,\pi)=1\wedge(x,u)\notin\mathcal{R}. $$

We consider two cases:

′ ′ ′$ ∗ – When ¬Bit happens, A outputs (x,π) ← QC. Moreover, when Sim happens, we are guaranteed 1 ∗ ∗ that there exists (x,π) ∈QC∗ such that Verify (vrs,x,π) = 1*∧* (x,ω) ̸∈R. Hence, we conclude that 1 P[Win*|Sim, ¬Bit] = 1/|Q*C∗ |. 1

$$ \big(x^{\prime},\pi^{\prime}\big)\leftarrow_{\rtimes}\mathcal{Q}{C{1}^{*}} $$

$$ (x,\pi)\in\mathcal{Q}{C{1}^{*}} $$

$$ \ (mathsf v r\ \ ^{*},x,\pi)=1\wedge(x,omega\in\mathcal{R} $$

$$ \mathbb{P}[\mathrm{W i n}|\mathrm{S i m},\lnot\mathrm{B i t}]=\ 1/|\mathcal{Q}{\mathcal{C}{1}^{*}}| $$

′ ′ ′ – When Bit happens, A outputs (x,π) = (*x,*b πb) where (*x,*b πb) is the final output of A. Observe ′ that, conditioned to the event *¬*Sim, A correctly simulates the view of A. As a consequence, A outputs a valid differing-input v = (*x,b πb) with non-neglibile probability. Hence, we have that P[Win|¬Sim,*Bit] ≥ ϵ.

$$ \big(x^{\prime},\pi^{\prime}\big),=,\big(\widehat{x},\widehat{\pi}\big) $$

$$ (\widehat{x},\widehat{\pi}) $$

$$ \neg\mathbf{S i m},\ \mathsf{A}^{\prime} $$

$$ v;=;({\widehat{x}},{\widehat{\pi}}) $$

$$ \mathbb{P}[\mathbf{W i n}|\neg\mathbf{S i m},\mathbf{B i t}]\geq\epsilon. $$

By combining Equation (7) and the above conditions we conclude that

$$ \mathbb{P}[\mathbf{W i n}]\geq\epsilon\cdot\frac{1-p_{\mathbf{S i m}}}{2}+\frac{1}{|\mathcal{Q}{C{}^{}}|}\cdot\frac{p_{\mathbf{S i m}}}{2}\not\in\mathsf{n e g l}(\lambda). $$

This concludes the proof.


∗ (Part two) Π satisfies (publicly verifiable) straight-line knowledge soundness. Let Ext = ∗ ∗ ∗ (Ext0*,Ext1) be the extractor of the designated verifier non-interactive proof system Π. Consider the following extractor Ext = (Ext₀,*Ext₁) for Π:

$$ (\mathsf{E x t}{0}^{*},\mathsf{E x t}{1}^{*}) $$

$$ \mathsf{E x t}^{*}= $$

$$ \varPi^ {*} $$

$$ \mathsf{E x t}=(\mathsf{E x t}{0},\mathsf{E x t}{1}) $$

$$ \pi: $$

λ λ Ext₀(1*, R*): On input the security parameter 1 and a relation R, the algorithm outputs the common ∗ λ Verify reference string crs = crs, the verification key vrs ←$ Obf(1*,C*∗ ∗ ∗), and the trapdoor td = vrs,td,r1 ∗ ∗ ∗ ∗ ∗ ∗ λ ∗ ∗ (td*,r*) where (crs*,vrs,td ) ←$ Ext (1, R*) and r ←$ {0,1}. 1 0 1 λ λ ∗ ∗ Ext₁(1*,td,x,π*): On input the security parameter 1, a trapdoor td = (td*,r₁*), a statement x, and a ∗ λ ∗ ∗ proof π, the algorithm returns ω = Ext₁(1*,td,x,π*;r₁).

$$ \mathsf{E x t}_{0}(1^{\lambda},\mathcal{R}) $$

$$ 1^{\lambda} $$

$$ \mathcal{R} $$

$$ {\colon{\ =\ }}{mathsf c r s}{}^{*} $$

$$ \leftarrow {} ^ {\mathrm {s}} \operatorname {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {v r s} ^ {}, \mathrm {t d} ^ {} , r _ {1} ^ {*}} ^ {\mathrm {V e r i y}}\right) $$

$$

$$

$$ (\mathsf{t d}^{},r_{1}^{}) $$

$$ (\mathsf{c r S}^{},\mathsf{V r S}^{},\mathsf{t d}^{})\ {leftarrow!}\mathsf{E x t}_{0}^{}(1^{\lambda},\mathcal{R}) $$

$$ r _ {1} ^ {} \leftarrow {} ^ {\mathrm {s}} {0, 1 } ^ {} $$

$$ 1^{\lambda} $$

$$ \mathsf{E x t}_{1}(1^{\lambda},\mathsf{t d},x,\pi) $$

$$ x, $$

$$ =(\ \ {mathfrak t d}^{},r_{1}^{}) $$

$$ \omega=\mathsf{E x t}{1}^{}(1^{\lambda},\mathsf{t d}^{},x,\pi;r{1}^{*}) $$

We prove the following lemmas.

Lemma B.3. For every PPT adversary D*, we have:*

$$ \boxed{\mathbb{P}\Big[\mathsf{D}(1^{\lambda},\mathsf{c r s},\mathsf{v r s})=1\Big|(\mathsf{c r s},\mathsf{v r s},\mathsf{t d})\longleftarrow\mathsf{E x t}_{0}(1^{\lambda},\mathcal{R})\Big]-} $$

(8)

$$ \mathbb {P} \left[ \mathrm {D} \left(1 ^ {\lambda}, \mathrm {c r s} ^ {}, \mathrm {v r s}\right) = 1 \left| \begin{array}{l l} \left(\mathrm {c r s} ^ {}, \mathrm {v r s} ^ {}, \mathrm {t d} ^ {}\right) \leftarrow \mathcal {s} \operatorname {E x t} _ {0} ^ {} \left(1 ^ {\lambda}, \mathcal {R}\right) \ \mathrm {v r s} \leftarrow \mathcal {s} \operatorname {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {v r s} ^ {}} ^ {\mathrm {V e r i f y}}\right) \end{array} \right] \right| \leq \operatorname {n e g l} (\lambda). $$

(9)

Proof. By contradiction, assume there exists a PPT adversary D that distinguishes the above two dis- ′ tributions with non-neglibile advantage. We build a distinguisher D that breaks the indistinguishability ∗′ property of Obf with respect to the odiO-sampler SExt. The distinguisher D proceeds as follows:

$$ \mathsf{S}_{\mathsf{E}\times\mathsf{t}^{*}} $$

$$ D^{\prime} $$

e and e$λ$ 1.Receive in input an obfuscated circuit C α. Recall C ← Obf(1*,C*b) where b ← {0,1} is the $ ∗λ unknown challenge bit and (C₀,C₁,α) ← SExt(1).

$$ \tilde{C} $$

$$ \ \alpha. $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{b}) $$

$$ b\gets\mathfrak{s}\left{0,1\right} $$

$$ (C_{0},C_{1},\alpha)\leftarrow\S\mathsf{S}_{\mathsf{E x t}^{*}}(1^{\lambda}) $$

2.Send crs = α and vrs = Ce to D.

$$ \mathsf{v r s}=\widetilde{C} $$

3.Return the output of D.

∗ Verify ∗ Verify ∗ Let C₀ = Cvrs∗, C₁ = C∗ ∗ ∗, and α = crs. If b = 0, D’s view is distributed as in Equation (9); vrs,td,r1 ′ on the hand, if b = 1, D’s view is distributed as Equation (8). Hence, D has the same non-negligible advantage of D. This concludes the proof. ⊓⊔

$$ C _ {0} ^ {} = C _ {\mathrm {v r s} ^ {}} ^ {\mathrm {V e r i f y}}, C _ {1} ^ {} = C _ {\mathrm {v r s} ^ {}, \mathrm {t d} ^ {}, r _ {1} ^ {}} ^ {\mathrm {V e r i f y}} $$

$$ b=0 $$

$$ \alpha={\mathsf{c r s}}^{*} $$

$$ b=1 $$

$$ D^{\prime} $$

Lemma B.4. For every PPT adversary D*, we have:*

$$ \Bigg\ \ mathbb P bigg[mathsf D1^^{,\ }\mathsf{c r s}^{},\mathsf{v r s})=1\Big|\ ^{\ \ mathsf c(r s^{},\mathsf{v r s}^{},\mathsf{t d}^{})\leftarrow\leftarrow\mathsf{E x t}{0}^{*}(1^{\lambda},\mathcal R)}{\mathsf{v r s}\leftarrow\mathsf{s b b}\big(1^{\lambda},C{\mathsf{v r s}}^{\mathsf{v e r i y}}\big)}\Bigg]- $$

(10)

$$ \mathbb {P} \left[ \mathrm {D} \left(1 ^ {\lambda}, \mathrm {c r s}, \mathrm {v r s}\right) = 1 \mid (\mathrm {c r s}, \mathrm {v r s}) \leftarrow {} _ {\mathrm {s}} \operatorname {S e t u p} \left(1 ^ {\lambda}, \mathcal {R}\right) \right] \Bigg | \leq \operatorname {n e g l} (\lambda). $$

(11)

Proof. By contradiction, assume there exists a PPT adversary D that distinguishes the above two dis- ′ tributions with non-neglibile advantage. We build an adversary D that breaks the indistinguishability ∗ ′ property of Π (DefinitionA.3). D proceeds as follows:

$$ D^{\prime} $$

$$ \varPi^ {*} $$

∗ ∗ 1.Receive (crs*,*vrs) from the challenger.

$$ \left\langle\mathsf{c r s}^{},\mathsf{V r s}^{}\right\rangle $$

∗ λ Verify 2.Send (crs*,vrs) to D where vrs ←$ Obf(1,C ∗*). vrs

$$ (\mathsf{c r S}^{*},\mathsf{v r S}) $$

$$ \leftarrow_{\mathfrak{s}}\mathsf{O b f}(1^{\lambda},C_{\mathsf{v r s}^{*}}^{\mathsf{V e r i f y}}) $$

3.Return the output of D.

$$ (\mathsf{c r s}^{},\mathsf{V r s}^{}) $$

$$ \mathsf{E x t}_{0}^{*} $$

∗ ∗ ∗ Observe that if the challenger generates (crs*,vrs) by executing Ext0then D simulates the distribution ∗ ∗ ∗ ′ of Equation (10); on the other hand, if (crs,*vrs) are generated by executing Setup then D simulates ′ the distribution of Equation (11). Hence, D has the same advantage of D. This concludes the proof. ⊓⊔

$$ \left(\mathsf{c r s}^{},\mathsf{v r s}^{}\right) $$

$$ \ {\sf S e t u p}^{*} $$

$$ D^{\prime} $$

We now prove that Π satisfies (publicly verifiable) straight-line knowledge soundness DefinitionsA.3 andA.4.

Lemma B.5. For every PPT adversary A*, we have:* 

$$ {\mathsf A}, $$

$$ \begin{array}{r l}{\mathbb{P}\Bigg[(x,\omega)\not\in\mathcal{R}\land\mathsf{V e n f f y}(\mathsf{v r s},x,\pi)=1\Big|\begin matrix}{{\mathsf{c r s},\mathsf{v r s},\mathsf{t d}}&{\leftarrow\mathsf{E t t}{0}(1^{\lambda},\mathcal{R})}\ {(x,\pi)}&{\leftarrow\mathsf{s t A}(1^{\lambda},\mathsf{c t s},\mathsf{v r s})}\ {\omega}&{\leftarrow\mathsf{s t t}{1}(1^{\lambda},\mathsf{t d s},x,\pi)}\ \end{matrix}\Bigg]=0.}\ \end{array} $$


Verify ∗ ∗ ∗ ∗ ∗ Proof. Observe that Verify(vrs*,x,π*) = 1 if C∗ ∗ ∗ (x,π) = 1 where r₁ ←$ {0,1}, (crs*,vrs,td) ←$ vrs,td,r1 ∗ λ ∗ ∗ λ Verify Verify Ext (1, R*), td = (td*,r₁*), vrs ←$ Obf(1*,C*∗ ∗ ∗). In turn, the circuit C∗ ∗ ∗ (x,π) outputs 1 only 0 vrs,td,r1vrs,td,r1 ∗ ∗ ∗ λ ∗ ∗ ∗ λ ∗ ∗ if Verify (vrs*,x,π*) = 1 and (x,ω) ∈R where ω ←$ Ext (1,td,x,π; r) (recall that Ext (1,td,x,π; r) 1 1 1 1 λ ∗ = Ext₁(1*,td,x,π*; r) for every r ∈{0,1}). Hence, A’s advantage is 0. This concludes the proof. ⊓⊔

$$ C_{\mathsf{v r s}^{},\mathsf{t d}^{},r_{1}^{*}}^{\mathsf{V e r i f y}}(x,\pi)=1 $$

$$ r_{1}^{}\ \leftarrow\ \ s\ {0,1}^{},\left(\mathsf{c r s}^{},\mathsf{v r s}^{},\mathsf{t d}^{*}\right)\leftarrow\bullet} $$

$$ \mathsf{y}(\mathsf{v r s},x,\pi)=1 $$

$$ {mathsf\mathsf E x t}{0}^{}(1^{\lambda},\mathcal{R}),{\mathsf t mathsf d d}=({\mathsf t d}^{},r{1}^{*}) $$

$$ \mathrm {f} \left(1 ^ {\lambda}, C _ {\mathrm {v r s} ^ {}, \mathrm {t d} ^ {} , r _ {1} ^ {*}} ^ {\mathrm {V e r i f y}}\right) $$

$$ C_{\mathsf{v r s}^{},\mathsf{t d}^{},r_{\mathfrak{l}}^{*}}^{\mathsf{V e r i f y}}(x,\pi) $$

$$ \mathrm{i f},\mathsf{V e r i f y}^{}(\mathsf{v r s}^{},x,\pi)=1 $$

$$ (x,\omega)\in\mathcal{R} $$

$$ \omega\ {overset\-}{\mathfrak{s}},\dot{\mathsf E x t}{1}^{}(1^{\lambda},{mathsf{t d}}^{},x,\pi;r{1}^{*}) $$

$$ \mathsf{E x t}{1}^{}(1^{\lambda},\mathsf{t d}^{},x,\pi;r{1}^{*}) $$

$$ r\in{0,1}^{*}) $$

$$ ={\mathsf{E x t}}_{1}(1^{\lambda},{\mathsf{t d}},x,\pi;r) $$

By combining LemmasB.3andB.4we conclude that Π satisfies the indistinguishability property of DefinitionA.3. Moreover, LemmaB.5implies that Π satisfies the extraction property (DefinitionsA.3 andA.4).

B.4 Proof of Theorem5.4

(Part one) SYis an odiO-sampler. By contradiction, suppose there exists a q ∈ N, Y⊂M such that |Y| = q and SYis not an odiO-sampler, i.e., there exists a PPT adversary A such that h i

$$ s_{y} $$

$$ q\in\mathbb{N},\mathcal{Y}\subset\mathcal{M} $$

$$ S $$

$$ |\mathcal{Y}|=q $$

$$ \mathbb {P} \left[ C _ {0} (v) \neq C _ {1} (v) \mid v \leftarrow \mathrm {s} \mathsf {A} ^ {C _ {0} (\cdot), C _ {1} (\cdot)} \left(1 ^ {\lambda}, 1 ^ {| C _ {0} |}, \alpha\right) \right] \geq \epsilon , $$

$λ ′ where (C₀,C₁,α) ← SY(1) and ϵ non-negligible. We build an adversary A that breaks the (q)-sEUF- ∗ q ′ sel-CMA security of Π with respect to the messages (mi)mi∈Y∈M. The adversary A proceeds as follows:

$$ (C_{0},C_{1},\alpha)\leftarrow\S\mathcal{Y}(1^{\lambda}) $$

$$ (q){\mathrm{\ E E F F}} $$

$$ (m_{i}){m{i}\in\mathcal{Y}}\in\mathcal{M}^{q} $$

$$ {\bf A}^{\prime} $$

∗ 1.Receive (σ₁,...,σq∗) from the challenger.

$$ (\sigma_{1}^{},\ldots,\sigma_{q}^{}) $$

∗ ∗ Verify ∗ ∗ ∗ 2.Let C₀ = C∗,C₁ = CX∗ and α = (σ₁,...,σq∗) where X = {(mi,σi∗)}i∈[q](note that C₀ is kVerify ′ ∗ unknown to A since k is kept secret by the challenger).

$$ \alpha,=,\big(\sigma_{1}^{},\ldots,\sigma_{q}^{}\big) $$

$$ \mathcal{X}^{},=,{\ m_{i},\sigma_{i}^{}}_{i\in[q]} $$

$$ C_{0}^{*} $$

$$ k^{*} $$

γ 3.Send α and 1 (where γ as defined in Figure3) to A and answer the incoming queries as follows: ∗ (a)On input (m,σ) for the circuit Ci∗for i ∈{0,1}, if (m,σ) ∈X returns 1. Otherwise, return 0.

$$ \gamma $$

$$ (m,\sigma) $$

$$ C_{i}^{*} $$

$$ i\in{0,1} $$

$$ (m,\sigma)\in\mathcal{X}^{*} $$

4.Receive v = (*m,*b σb) from A.

$$ v=(\widehat{m},\widehat{\sigma}) $$

$′ ′ ′$ ∗ ∗ 5.Sample a random bit b ← {0,1}. If b = 0, A returns (m,σ) ← QCwhere QCare the queries 1 1 ∗ ′ ′ ′ submitted by A to the oracle C₁. Otherwise, if b = 1, A returns (m,σ) = (*m,*b σb).

$$ \ {mathcal Q_{{1}}^{*}} $$

$$ b\gets\mathfrak{s}\left{0,1\right} $$

$$ b,=,0,,\mathsf{A}^{\prime} $$

$$ \ m^{\prime},\sigma^{\prime})\leftarrow_{\mathfrak{S}}\mathcal{Q}{C{!}^{*}} $$

$$ C_{1}^{*} $$

$$ \left(m^{\prime},\dot{\sigma^{\prime}}\right)=\left(\widehat{m},\widehat{\sigma}\right) $$

∗ ∗ ∗$λ q Note that (C₀,C₁,α) comes from a distribution that is identical to that of SY; this because k ← KGen(1*,1) ∗ ∗ and σ ←$ Tag (k,m*i) for i ∈ [q]. i∗

$$ (left(\mathcal{C}{0}^{*},\mathcal{C}{1}^{*},\alpha) $$

$$ \mathsf{k}^{*}\leftarrow\ \mathsf{s}\mathsf{K G n n}(1^{\lambda},1^{q}) $$

$$ \mathsf{S}_{\mathcal{Y}}, $$

$$ \sigma_{i}^{}\leftarrow\ {mathfrak s\intercal{\mathsf{g}}^{}({\mathsf{k}}^{*},m_{i})} $$

$$ i\in[q] $$

We now demonstrate the following two points:

′ ∗ ∗ 1.If A correctly simulates A’s view with respect to (C₀,C₁,α) then (*m,*b σb) (output by A) contradicts ∗ the (q)-sEUF-sel-CMA security of Π.

$$ (left mathcal C{{}}0{{}}^{*},\ \ {{\ C{1}^{*}}},\alpha) $$

$$ {\mathsf A}^{\prime} $$

$$ (\widehat{m},\widehat{\sigma}) $$

$$ \ q{\mathrm{-s E U F-s e l-C C M}} $$

$$ \varPi^ {*} $$

′ ∗ ∗ 2.On the other hand, if A fails to correctly simulate A’s view with respect to (C₀,C₁,α) then there ′ ′∗∗ exists (x,π) ∈QC(submitted by A) that breaks the (q)-sEUF-sel-CMA security of Π. 1

$$ (C_{0}^{},C_{1}^{},\alpha) $$

$$ \ x^{\prime},\pi^{\prime})\in\mathcal{Q}{C{1}^{*}} $$

$$ (q){\mathrm{-s E U F-s e l_C M A}} $$

$$ \varPi^ {*} $$

$$ k^{*} $$

∗ Consider the following events defined with respect to k :

$$ \mathbf{S i m}:\exists(m,\sigma)\in\mathcal{Q}{C{!}^{}},\mathsf{V e r i f y}^{}(\mathsf{k}^{},m,\sigma)=1\wedge(m,\sigma)\not\in\mathcal{X}^{}, $$

$$ \mathbf{W i n}:\mathsf{V e r i f y}^{}(\mathsf{k}^{},x^{\prime},\sigma^{\prime}){\ =\ }1\wedge(m^{\prime},\sigma^{\prime})\not\in{\mathcal{X}}^{*}, $$

$$ \mathbf{B i t}:b=1. $$

′ We can bound the advantage of A as follows:

$$ {\bf A}^{\prime} $$

(12)

∗ for pSim= P[Sim] and P[Bit] = P[¬Bit] = 1/2. A differing-input v = (m,σ) for C₀ = C∗and kVerify ∗ Verify ∗ ∗ ∗ C₁ = CX∗ needs to satisfy the condition Verify (k,m,σ) = 1 ∧ (m,σ) ̸∈X. We consider two cases:

$$ p_{\mathrm{S i m}},=,\mathbb{P}[\mathbf{S i m}] $$

$$ \mathbb{P}[\ \mathrm{B i t}]=\mathbb{P}[\neg\mathrm{B i t}]=1/2.
$$

$$ v,=,(m,\sigma) $$

$$ \mathcal{C}{0}^{*}=\mathcal{C}{\mathsf{k}^{*}}^{\mathsf{V e r i f y}} $$

$$ \mathcal{C}{1}^{*}=\mathcal{C}{\chi^{*}}^{\mathsf{V e r i f y}} $$


′ ′ ′$ ∗ – When ¬Bit happens, A outputs (m,σ) ← QC. Moreover, when Sim happens, we are guaranteed 1 ∗ ∗ ∗ that there exists (m,σ) ∈QC∗ such that Verify (k,m,σ) = 1 ∧ (m,σ) ̸∈X. Hence, we conclude 1 that P[Win*|Sim, ¬Bit] = 1/|Q*C∗ |. 1

$$ \ m^{\prime},\sigma^{\prime})\leftarrow_{\mathfrak{S}}\mathcal{Q}{C{}^{}} $$

$$ \ m,\sigma,\in,\mathcal{Q}{C{1}^{*}} $$

$$ \mathsf{V e r i f y^{}}(\mathsf{k}^{},m,\sigma),=,\mathsf{1}\ \wedge\ (m,\sigma),\not\in,\mathcal{X}^{*} $$

$$ \mathbb{P}[\mathrm{W i n}|\mathrm{S i m},\neg\mathrm{B i t}]!=!1/\big|\mathring{\mathcal{Q}}{\mathcal{C}{1}^{*}} $$

′ ′ ′ – When Bit happens, A outputs (m,σ)=(*m,*b σb) where (*m,*b σb) is the final output of A. Observe ′ that, conditioned to the event *¬*Sim, A correctly simulates the view of A. As a consequence, A outputs a valid differing-input v = (*m,b σb) with non-neglibile probability. Hence, we have that P[Win|¬Sim,*Bit] ≥ ϵ.

$$ \ \ (m^{\prime},\sigma^{\prime}),=,\big\ (\widehat{m},\widehat{\sigma}\big) $$

$$ (\widehat{m},\widehat{\sigma}) $$

$$ {\bf A}^{\prime} $$

$$ \mathbb{P}[\mathbf{W i n}|\neg\mathbf{S i m},\mathbf{B i t}]\geq\epsilon. $$

$$ v,=,(\widehat{m},\widehat{\sigma}) $$

By combining Equation (12) and the above conditions we conclude that

$$ \mathbb{P}[\mathbf{W i n}]\geq\epsilon\cdot\frac{1-p_{\mathbf{S i m}}}{2}+\frac{1}{|\mathcal{Q}{C{1}^{*}}|}\cdot\frac{p_{\mathbf{S i m}}}{2}\not\in\mathsf{n e g l}(\lambda). $$

This concludes the proof.

(Part two) Π is (q)-sEUF-sel-CMA secure. Let q ∈ N and Y ⊂M such that |Y| = q. Consider the following hybrid experiments:

$$ q\in\mathbb{N} $$

$$ \mathcal{Y}\subset\mathcal{M} $$

$$ |\mathcal{Y}|=q. $$

q,Y Hyb0(λ): This is the standard (q)-sEUF-sel-CMA experiment for signatures with respect to messages (mi)mi∈Y(DefinitionA.13).

$$ {\mathsf{H y}}{mathfrak b b}_{0}^{q,{\mathcal{Y}}}(\lambda) $$

$$ (q){\mathrm{-s E U F-s e l-C M A}} $$

$$ (m_{i}){m{i}\in\mathcal{Y}} $$

q,Y q,Y ∗ Verify Hyb1(λ): Same as Hyb0, except that the challenger sets pk to the obfuscation of the circuit CX∗ ∗ λ Verify ∗ of Figure3(instead of C∗). Formally, the challenger computes pk ←$ Obf(1*,C* ∗) where X = kVerify X ∗ ∗ ∗ λ q {(mi,σ)}i∈[q], σ ←$ Tag(k*,m*i) for i ∈ [q], and k ←$ KGen (1*,*1). i∗ i∗

$$ {\mathsf{H y b}}_{1}^{q,\mathcal{Y}}(\lambda) $$

$$ \mathsf{H y b}_{0}^{q,\mathcal{Y}} $$

$$ {\mathsf{p k}}^{*} $$

$$ C_{\mathcal{X}^{*}}^{\mathsf{V e r i f y}} $$

$$ C_{\mathsf{k}^{*}}^{\mathsf{V e r i f y}}) $$

$$ \mathrm {p k} ^ {} \leftarrow {} ^ {$} \mathrm {O b f} \left(1 ^ {\lambda}, C _ {\mathcal {X} ^ {}} ^ {\mathrm {V e r i f y}}\right) $$

$$ {mathcal X^{{*}}}= $$

$$ i\in[q] $$

$$ \big{\big(m_{i},\sigma_{i}^{}\big)\big}{i\in[q]},,\sigma{i}^{}\gets\mathfrak{s}\mathsf{T a g}\big(\mathsf{k}^{*},m_{i}\big) $$

$$ \mathsf{k}^{}\leftarrow\mathsf{s}\mathsf{K G e n}^{}(1^{\lambda},1^{q}) $$

q,Y λ q,Y λ Lemma B.6. For every q ∈ N*, every Y⊆M such that |Y|* = q, Hyb0(1) ≈cHyb1(1).

$$ \mathcal {Y} \subseteq \mathcal {M} $$

$$ q\in\mathbb{N} $$

$$ \big|\mathcal{Y}\big|=q,,{\sf H y h}{0}^{q,\mathcal{Y}}\big(1^{\lambda}\big)\approx{c}{\sf H y h}_{1}^{q,\mathcal{Y}}\big(1^{\lambda}\big) $$

q,Y Proof. By contradiction, assume there exists q ∈ N, Y ⊂ M such that |Y| = q and Hyb0(λ) and q,Y Hyb1(λ) are not computationally indistinguishable, i.e., there exists a PPT distinguisher D that has a q,Y q,Y non-negligible advantage in distinguishing between Hyb0(λ) and Hyb1(λ). We build a distinguisher ′ ′ D that breaks the indistinguishability property of Obf for the odiO-sampler SY. The distinguisher D proceeds as follows:

$$ q,\in,\mathbb{N},,\mathcal{Y},\subset,\mathcal{M} $$

$$ |\mathcal{Y}|,=,q $$

$$ {\mathsf{H y b}}_{1}^{q,{\mathcal{Y}}}(\lambda) $$

$$ {\mathsf{H y b}}_{0}^{q,{\mathcal{Y}}}(\lambda) $$

$$ {\mathsf y y}_{0}^{q,\mathcal{Y}}(\lambda) $$

$$ {\mathsf{H y b}}_{1}^{q,\mathcal{Y}}(\lambda) $$

$$ S_{y} $$

$$ D^{\prime} $$

e and e$λ 1.Receive in input an obfuscated circuit C α. Recall C ← Obf(1*,C*b) and α = (σ₁,...,σq) where ∗ ∗ λ b ←$ {0,1} is the unknown challenge bit, σi←$ Tag (k*,m*i) for i ∈ [q], and (C₀,C₁,α) ←$ SY(1). ∗e and ( 2.Send pk = C σ₁,...,σq) to D.

$$ \tilde{C} $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{b}) $$

$$ b\gets\mathfrak{s}{0,1} $$

$$ \boldsymbol{\alpha}=(\sigma_{1},\ldots,\sigma_{q}) $$

$$ \sigma_{i}\leftarrow\ \mathsf{s}\mathsf{T a g}^{}(\mathsf{k}^{},m_{i}) $$

$$ {\mathsf{p k}}^{*}=C $$

$$ i\in[q] $$

$$ (C_{0},C_{1},\alpha)\stackrel{\ \ \rightarrow\ }}{\mathfrak S{}}_{\mathcal{Y}}(1^{\lambda}) $$

$$ \ \ (\sigma_{1},\ldots,\sigma_{q}) $$

3.Return whatever D outputs.

′ q,Y ′ It is easy to see that, if b = 0 then D simulates Hyb0(λ). On the other hand, if b = 1 then D simulates q,Y ′ Hyb1(λ). Hence, D retains the same non negligible advantage of D. ⊓⊔

$$ \operatorname*{i f},b=1 $$

$$ {\mathsf y y\ b_{0}^{q,\mathcal{Y}}((\lambda)} $$

$$ D^{\prime} $$

$$ {\mathsf{H y b}}_{1}^{q,\mathcal{Y}}(\lambda) $$

$$ D^{\prime} $$

q,Y Observe that, for every q ∈ poly(λ), every Y ⊆M such that |Y| = q, A has advantage 0 in Hyb₁. ∗ Verify This because, for every (m,σ), Verify(pk*,m,σ*) returns 0 if (m,σ) ̸∈ X (see the definition of CX*∗* depicted in Figure3). This concludes the proof.

$$ \mathcal{Y{\subseteq}{mathcal M} $$

$$ q\in{\mathsf{p o l y}}(\lambda) $$

$$ |mathcal Y==q, $$

$$ \mathsf{H y b}_{1}^{q,\mathcal{Y}}. $$

$$ (,sigma,,,mathsf{V e r i f y}(\mathsf{p k},m,\sigma) $$

$$ (m,\sigma),\not\in,\ \ \mathcal{X}^{*} $$

$$ C_{\mathcal{X}^{*}}^{\mathsf{V e r i f y}} $$

B.5 Proof of Theorem5.5

∗ (Part one) Smis an odiO-sampler. Let m ∈M. Consider the following hybrid experiments:

$$ m^{*}\in\mathcal{M}. $$

$$ \ {sf s}_{m} $$

∗ m Hyb₀ (λ): This is the experiment oracle-differing-input experiment with respect to sampler Sm∗ (Definition4.1).

$$ {\mathsf{H y}}{\mathfrak{b}}_{0}^{m^{*}}(\lambda) $$

$$ \ _m $$

∗ ∗ m m Hyb1(λ): Same as Hyb0(λ), except that Sm∗ is replaced with a sampler bSm∗ that computes C₀ differently. Formally, bSm∗ is defined as follows:

$$ \widehat{S}_{m^{+}} $$

$$ \mathsf{S}_{m^{*}} $$

$$ {\mathsf{H y b}}_{0}^{m^{*}}(\lambda) $$

$$ \mathsf{H y b}_{1}^{m^{*}} $$

$$ C_{0} $$

$$ \hat{\mathsf{S}}_{m^{*}} $$

$C_{s,m^{},k^{}}^{\mathrm{Verify}}(m,\sigma)$ $\widehat{\mathrm{S}}_{m^{*}}(1^{\lambda};r)$
If $m=m^{}$, return $b=\mathrm{Verify}_{0}^{}(\mathrm{k}^{},m^{},\sigma)$ Let $r=(r_{0},r_{1})$
$k=\mathrm{KGen}{0}^{*}(1^{\lambda};\mathrm{F}{1}^{*}(\mathrm{s},m))$ $s=\mathrm{Gen}{1}^{*}(1^{\lambda};r{0})$
return $b=\mathrm{Verify}_{0}^{*}(\mathrm{k},m,\sigma)$ $s^{\prime}=\mathrm{Punct}_{1}^{}(\mathrm{s},m^{})$
$k^{}=\mathrm{KGen}_{0}^{}(1^{\lambda};r_{1})$
Set $C_{0}=C_{\mathrm{s}^{\prime},m^{},k^{}}^{\mathrm{Verify}},C_{1}=C_{\mathrm{s}^{\prime},m^{*}}^{\mathrm{Verify}},\alpha=s^{\prime}$
return $(C_{0},C_{1},\alpha)$

$$ \mathcal{C}_{\mathfrak{s},m^{},\mathsf{k}^{}}^{\mathsf{V e r i f y}}(m,\sigma) $$

$$ \hat{\mathsf{S}}_{m^{*}}(1^{\lambda};r) $$

$$ \mathbf{I f}\ {m}=m^{},\ {mathbf{\ r e t u r n}}\ {b}=\mathsf{V e r i f y}_{0}^{}(\ {mathsf k^{{}}},m^{},\sigma)\ \ \ \ \operatorname{L e t}\ {r}=(r_{0},r_{1}) $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{1}^{*}(\mathsf{s},m)) $$

$$ \mathsf{s}=\mathsf{G e n}{1}^{*}(1^{\lambda};r{0}) $$

$$ b=\mathsf{V e r i f y}_{0}^{*}(\mathsf{k},m,\sigma) $$

$$ \mathsf{s}^{\prime}=\mathsf{P u n c t}_{1}^{}(\mathsf{s},m^{}) $$

$$ {\mathsf{k}}^{}={\mathsf{K G e n}}_{0}^{}(1^{\lambda};r_{1}) $$

$$ \mathrm{S e t}\ C_{0}=C_{\mathsf{s}^{\prime},m^{},\mathsf{k}^{}}^{\mathsf{V e r i f y}},C_{1}=C_{\mathsf{s}^{\prime},m^{*}}^{\mathsf{V e r i f y}},\alpha=\mathsf{s}^{\prime} $$

$$ (left_00,C_{1},\alpha) $$ where C₁ = CsVerify*′,m∗* is depicted in Figure4. C′ ∗ ∗and CsVerify′,m∗ are padded to match the size γ as sVerify,m,k defined in Figure4. Observe that the distribution of (C₁,α) output by Sm∗ and bSm∗ are identically distributed.

$$ C_{1}=C_{\mathsf{s}^{\prime},m^{*}}^{\mathsf{V e r i y}} $$

$$ C_{\mathsf{s}^{\prime},m^{},\mathsf{k}^{}}^{\mathsf{V e r i f y}} $$

$$ C_{\mathsf{s}^{\prime},m^{*}}^{\mathsf{V e r i f y}} $$

$$ \gamma $$

$$ (C_{1},\alpha) $$

$$ S_{m} $$

$$ \widehat{\mathsf{S}}_{m}{} $$

∗ ∗ ∗ m m Lemma B.7. For every m ∈M, Hyb₀ (λ) ≈cHyb₁ (λ).

$$ m^{}\in\mathcal{M},\mathsf{H y b}_{0}^{m^{}}(\lambda)\approx_{c}\mathsf{H y b}_{1}^{m^{*}}(\lambda) $$

Proof. The lemma follows by leveraging the security and correctness of the puncturable PRF scheme ∗ Π₁. ⊓⊔ h i

∗ ∗ m Lemma B.8. For every m ∈M, P Hyb₁ (λ) = 1 ≤ negl(λ).

$$ \varPi_ {1} ^ {*} $$

$$ m^{}\in\mathcal{M},:\mathbb{P}\Big|\mathsf{H y b}_{1}^{m^{}}(\lambda)=1\Big|\leq\mathsf{n e g l}(\lambda). $$

∗ Proof. By contradiction, suppose there exists a message m ∈M such that bSm∗ is not an odiO-sampler, i.e., there exists a PPT adversary A such that h i h i

$$ m^{*}\in{mathcal M M} $$

$$ \widehat{\mathsf{S}}_{m^{*}} $$

$$ \mathbb {P} \left[ \mathrm {H y b} _ {1} ^ {m ^ {*}} (\lambda) = 1 \right] = \mathbb {P} \left[ C _ {0} (v) \neq C _ {1} (v) \mid v \leftarrow {} _ {$} \mathsf {A} ^ {C _ {0} (\cdot), C _ {1} (\cdot)} \left(1 ^ {\lambda}, 1 ^ {| C _ {0} |}, \alpha\right) \right] \geq \epsilon , $$

$b λ ′ where (C₀,C₁,α) ← Sm∗ (1) and ϵ non-negligible. We build an adversary A that breaks the EUF ∗ ∗ ′ security of Π₀ with respect to the message m ∈M. The adversary A proceeds as follows:

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow^ {\mathrm {s}} \widehat {\mathsf {S}} _ {m ^ {*}} \left(1 ^ {\lambda}\right) $$

$$ {\bf A}^{\prime} $$

$$ m^{*}\in{mathcal M M} $$

$$ \Pi_{0}^{*} $$

$$ {\bf A}^{\prime} $$

$$ m^{*} $$

∗ 1.Receive m from the challenger.

∗ λ ′ ∗ ∗ 2.Compute s ←$ Gen (1) and s = Punct (s*,m*). 1 1

$$ \mathsf{s}\leftarrow\mathsf{s}\mathsf{G e n}{1}^{*}(1^{\lambda})\mathrm}{}\ {mathrm{n n d}}\ \mathsf{s}^{\prime}=\mathsf{P u n c t}{1}^{}(\mathsf{s},m^{}). $$

∗ ′ ∗ ′ ∗ 3.Let C₀ = C′ ∗ ∗,C₁ = CsVerify′,m∗ and α = s (note that C₀ is unknown to A since k is kept secret by sVerify,m,k the challenger). ∗

$$ \mathcal{C}{0}^{*}=\mathcal{C}{\mathfrak{s}^{\prime},m^{},\mathsf{k}^{}}^{\mathsf{V e r i f y}},mathcal{C}{1}=\mathcal{C}{\mathfrak{s}^{\prime},m^{*}}^{\mathsf{V e r i f y}} $$

$$ \alpha={\sf s}^{\prime} $$

$$ C_{0}^{*} $$

$$ k^{*} $$

γ m 4.Send α and 1 (where γ as defined in Hyb₁ (λ)) to A and answer the incoming queries as follows: ∗ (a)On input (m,σ) for the circuit Ci∗for i ∈ {0,1}, if m = m returns 0. Otherwise, return ∗ ∗ λ ∗ ′ Verify0(k*,m,σ*) where k = KGen0(1; F1(s*,m*)).

$$ \gamma $$

$$ {\mathsf{i y b}}{_{1}^{m^{*}}}(\lambda){} $$

$$ C_{i}^{*} $$

$$ (m,\sigma) $$

$$ i\ \in\ {0,1} $$

$$ m;=;m^{*} $$

$$ \mathsf{V e r i f y}_{0}^{*}(\mathsf{k},m,\sigma) $$

$$ \ {mathsf k={\mathsf{K G e n}}{0}^{*}(1^{\lambda};{\mathsf{F}}{1}^{*}({\mathfrak{s}}^{\prime},m)) $$

5.Receive v = (*m,*b σb) from A.

$$ \dot{v=(\widehat{m},\widehat{\sigma})} $$

$$ {\bf A}. $$

$′ ′ ′$ ∗ ∗ 6.Sample a random bit b ← {0,1}. If b = 0, A returns (m,σ) ← QCwhere QCare the queries 0 0 ∗ ′ ′ ′ submitted by A to the oracle C₀. Otherwise, if b = 1, A returns (m,σ) = (*m,*b σb).

$$ \mathcal{Q}{C{\Omega}^{*}} $$

$$ b\gets\mathfrak{s}{0,1} $$

$$ b,=,0,,\mathsf{A}^{\prime} $$

$$ \left(m ^ {\prime}, \sigma^ {\prime}\right) \leftarrow {} _ {s} ^ {\mathrm {s}} \mathcal {Q} _ {C _ {0} ^ {*}} $$

$$ \mathrm{f}b=1,,\mathsf{A^{\prime}} $$

$$ C_{0}^{*} $$

$$ \ m(m^{\prime},\ \ \hat{\sigma^{\prime}})=\ (\widehat{m},\widehat{\sigma}) $$

∗ ∗ ∗ Note that (C₀,C₁,α) comes from a distribution that is identical to that of bSm∗; this because k (generated ∗ by the challenger) is generated by executing KGen0on uniform random coins.

$$ k^{*} $$

$$ (mathcal C{{}}0{{}}{}^{*},\ \ {{}}{{}}{\mathcal{C}}{1}^{*},\alpha) $$

$$ \hat{\mathfrak{S}}_{m^{*}} $$

$$ \mathsf{K G e n}_{0}^{*} $$

We now demonstrate the following two points:

′ ∗ ∗ 1.If A correctly simulates A’s view with respect to (C₀,C₁,α) then (*m,*b σb) (output by A) contradicts ∗ the EUF security of Π₀.

$$ \left(C _ {0} ^ {}, C _ {1} ^ {}, \alpha\right) $$

$$ {\bf A}^{\prime} $$

$$ \ \Lambda) $$

$$ (\widehat{m},\widehat{\sigma}) $$

$$ \ {cal Pi_{0}^{*}} $$

′ ∗ ∗ 2.On the other hand, if A fails to correctly simulate A’s view with respect to (C₀,C₁,α) then there ′ ′∗∗ exists (x,π) ∈QC(submitted by A) that contradicts the EUF security of Π₀. 0

$$ \left(C_{0}^{},C_{1}^{},\alpha\right) $$

$$ \ x^{\prime},\pi^{\prime})\in\mathcal{Q}{C{0}^{*}} $$

$$ \ {cal Pi_{0}^{*}} $$

∗ Consider the following events defined with respect to k :

$$ k^{*} $$

$$ \mathbf{S i m}:\exists(m,\sigma)\in\mathcal{Q}{C{\hat{\alpha}}^{}},\mathsf{V e r i f y}_{0}^{}(\mathsf{k}^{},m,\sigma)=1\land m=m^{}, $$

$$ \mathbf{W i n}:\mathsf{V e r i f y}_{0}^{}(\mathsf{k}^{},m^{\prime},\sigma^{\prime})=\mathbf{1}\land m=m^{*}, $$

$$ \mathbf{B i t}:b=1. $$

′ We can bound the advantage of A as follows:

$$ {\mathsf A}^{\prime} $$

(13)

∗ for pSim= P[Sim] and P[Bit] = P[¬Bit] = 1/2. A differing-input v = (m,σ) for C₀ = C′ ∗ ∗and sVerify,m,k ∗ ∗ ∗ ∗ C₁ = CsVerify′,m∗ needs to satisfy the condition Verify (k*,m,σ*) = 1 ∧ m = m. We consider two cases:

$$ p_{\mathbf{S i m}}=\mathbb{P}[\mathbf{S i m}] $$

$$ \mathbb{P}[\mathbf{B i t}]=\mathbb{P}[\neg\mathbf{B i t}]=1/2 $$

$$ v,=,(m,\sigma) $$

$$ C_{0}^{},=,C_{\mathsf{s}^{\prime},m^{},\mathsf{k}^{*}}^{\mathsf{V e r i f y}} $$

$$ C_{1}^{}=C_{\mathsf{s}^{\prime},m^{}}^{\mathsf{V e r i f y}} $$

$$ \mathsf{V e r i f y}^{}(k^{},m,\sigma)\ 1,m m,{^*} $$


′ ′ ′$ ∗ – When ¬Bit happens, A outputs (m,σ) ← QC. Moreover, when Sim happens, we are guaranteed 0 ∗ ∗ ∗ that there exists (m,σ) ∈QC∗ such that Verify (k,m,σ) = 1 ∧ m = m. Hence, we conclude that 00 P[Win*|Sim, ¬Bit] = 1/|Q*C∗ |. 0

$$ \left(m ^ {\prime}, \sigma^ {\prime}\right) \leftarrow {} _ {s} ^ {\prime} \mathcal {Q} _ {C _ {0} ^ {*}} $$

$$ (m,\sigma)\in\mathcal{Q}{C{0}^{*}} $$

$$ \mathsf{V e r i f y}_{0}^{}(k^{},m,\sigma)=1\wedge m=m^{*} $$

$$ \mathbb{P}[\mathrm{W i n}|\mathrm{S i m},\lnot\mathrm{B i t}]=\mathrm{i}/\vert\mathcal{Q}{\mathcal{C}{0}^{*}}\vert. $$

′ ′ ′ – When Bit happens, A outputs (m,σ) = (*m,*b σb) where (*m,*b σb) is the final output of A. Observe that, ′ conditioned to the event *¬*Sim, A correctly simulates the view of A. As a consequence, A outputs a ∗ ∗ ∗ valid differing-input v = (*m,b σb) (i.e., Verify0(k, m,b σb) = 1 ∧ mb = m) with non-neglibile probability. Hence, we have that P[Win|¬Sim,*Bit] ≥ ϵ.

$$ \left(m^{\prime},\sigma^{\prime}\right)=\left(\widehat{m},\widehat{\sigma}\right) $$

$$ (\widehat{m},\widehat{\sigma}) $$

$$ v=(\widehat{m},\widehat{\sigma})\ \ {\ \mathrm{{i.e.,}}\ \mathsf{V e r i f y}_{0}^{}(\mathsf{k}^{},\widehat{m},\widehat{\sigma})=1}\wedge\widehat{m}=m^{*}) $$

$$ \mathbb{P}[\mathrm{W i n}|\neg\mathrm{S i m},\mathrm{B i t}]\geq\epsilon. $$

By combining Equation (13) and the above conditions we conclude that

$$ \mathbb{P}[\mathbf{W i n}]\geq\epsilon\cdot\frac{1-p_{\mathbf{S i m}}}{2}+\frac{1}{|\mathcal{Q}{C{0}^{*}}|}\cdot\frac{p_{\mathbf{S i m}}}{2}\not\in\mathsf{n e g l}(\lambda) $$

This concludes the proof.

By combining LemmasB.7andB.8, we conclude that Sm∗ is an odiO-sampler.

$$ S_{m} $$

∗ (Part two) Π is sel-EUF-CMA secure. Let m ∈M. Consider the following hybrid experiments:

$$ m^{*}\in\mathcal{M} $$

∗ m ∗ Hyb₀ (λ): This is the standard sel-EUF-CMA experiment for signatures with respect to message m (DefinitionA.14).

$$ {\mathsf H y b}_{0}^{m^{*}}(\lambda) $$

$$ m^{*} $$

∗ ∗ m m ∗ Hyb₁ (λ): Same as Hyb₀, except that the challenger sets pk to the obfuscation of the circuit CsVerify*′,m∗* ∗ λ of Figure4(instead of C). Formally, the challenger computes pk ←$ Obf(1*,C ′ ∗) where sVerify sVerify,m ∗ λ ′ ∗ ∗ s ←$ Gen (1) and s = Punct (s,m*). 1 1

$$ \mathrm {H y b} _ {1} ^ {m ^ {*}} (\lambda) $$

$$ \mathsf{H y b}_{0}^{m^{*}} $$

$$ {\sf p k}^{*} $$

$$ C_{s^{\prime},m^{*}}^{\mathsf{V e r i f y}} $$

$$ C_{\mathrm{s}}^{\mathrm{V e V i f y}}) $$

$$ \mathrm {p k} ^ {} \leftarrow {} _ {\mathrm {s}} \mathrm {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {s} ^ {\prime}. m ^ {}} ^ {\mathrm {V e r i f y}}\right) $$

$$ \mathsf{}mathsf s leftarrowleftarrow\mathsf{G e n}_{1}^{*}(1^{\lambda}) $$

$$ \mathrm {s} ^ {\prime} = \operatorname {P u n c t} _ {1} ^ {} (\mathrm {s}, m ^ {}) $$

∗ ∗ ∗ m λ m λ Lemma B.9. For every m ∈M, Hyb₀ (1) ≈cHyb₁ (1).

$$ m^{}\in\cal M M,;\sf H y b_{0}^{m^{}}(1^{\lambda})\approx_{c}\sf H y b_{1}^{m^{*}}(1^{\lambda}) $$

∗ ∗ ∗ m m Proof. By contradiction, assume there exists a message m ∈M such that Hyb₀ (λ) and Hyb₁ (λ) are not computationally indistinguishable, i.e., there exists a PPT distinguisher D that has a non-negligible ∗ ∗ m m ′ advantage in distinguishing between Hyb0(λ) and Hyb1(λ). We build a distinguisher D that breaks the ′ indistinguishability property of Obf for the odiO-sampler Sm∗. The distinguisher D proceeds as follows:

$$ m^{*}\in\mathcal{M} $$

$$ {\mathsf{H y b}}_{0}^{m^{*}}(\lambda) $$

$$ {\mathrm{i}}.{\mathrm{e}}. $$

$$ {\mathsf{H y}}{\mathfrak{b}}_{1}^{m^{*}}(\lambda) $$

$$ {\mathsf{H y}}{\mathsf{b}}_{0}^{m^{*}}(\lambda) $$

$$ {\mathsf{H y}}{\mathfrak{b}}_{1}^{m^{*}}(\lambda) $$

$$ D^{\prime} $$

$$ \mathsf{S}_{m^{*}} $$

$$ D^{\prime} $$

e and e$λ ′$ 1.Receive in input an obfuscated circuit C α. Recall C ← Obf(1*,C*b) and α = s where b ← {0,1} $λ is the unknown challenge bit and (C₀,C₁,α) ← Sm∗ (1).

$$ \tilde{C} $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{b}) $$

$$ \alpha={\sf s}^{\prime} $$

$$ b\gets\mathfrak{s}\left{0,1\right} $$

∗e and∗ 2.Send pk = C m to D and answer the incoming queries as follows:

$$ (\mathcal{C}{0},\mathcal{C}{1},\alpha)\ {leftarrowleftarrow},{\mathfrak{S}},\mathsf{S}{m^{*}}(1^{\lambda}) $$

$$ \mathsf{p k}^{*}=\widetilde{C} $$

$$ m^{*} $$

∗ ∗ λ ∗ ′ (a)On input m for Sign, return Tag0(k*,m*) where k = KGen0(1; F1(s*,m*)).

$$ {\sf a g_{{0}}^{*}}({\sf k},m) $$

$$ \ \mathsf k{}={\mathsf{K G e n}}{0}^{*}(1^{\lambda};\mathsf{F}{1}^{*}({\mathfrak s}^{\prime},m)) $$

3.Return whatever D outputs.

∗ In order to be valid, D cannot submit the message m to the oracle Sign. By leveraging this fact and the ∗ correctness of the puncturable PRF scheme Π₁, D’s view is correctly simulated. In particular, if b = 0 ∗ ∗ ′ m ′ m ′ then D simulates Hyb₀ (λ). On the other hand, if b = 1 then D simulates Hyb₁ (λ). Hence, D retains the same non negligible advantage of D. ⊓⊔

$$ m^{*} $$

$$ D{{}prime} $$

$$ \varPi_ {1} ^ {*}, \mathrm {D} ^ {\prime} $$

$$ b=0 $$

$$ {\mathsf{H y b}}_{0}^{m^{*}}(\lambda) $$

$$ b=1 $$

$$ D^{\prime} $$

$$ {\mathsf{H y b}}_{1}^{m^{*}}(\lambda) $$

$$ D^{\prime} $$

∗ ∗ m Observe that, for every m ∈ M, A has advantage 0 in Hyb₁ (λ). This is because, for every σ, ∗ Verify(pk*,m,σ*) returns 0 (see definition of CsVerify*′,m∗* depicted in Figure4). This concludes the proof.

$$ \mathsf{V e r i f y}(\mathsf{p k},m^{*},\sigma) $$

$$ {\mathsf{H y b}}_{1}^{m^{*}}(\lambda) $$

$$ m^{*};\in;\mathcal{M} $$

$$ {sigma}{,}} $$

$$ C_{s^{\prime},m^{*}}^{\mathsf{V e r i f y}} $$

B.6 Proof of Theorem5.6

∗ (Part one) Smis an odiO-sampler. Let m ∈M. Consider the following hybrid experiments:

$$ \ _s m\ {} $$

$$ m^{*}\in{mathcal M M} $$

∗ m Hyb₀ (λ): This is the experiment oracle-differing-input experiment with respect to sampler Sm∗ (Definition4.1).

$$ {\mathsf y y}_{0}^{m^{*}}(\lambda) $$

$$ \ {mathsf S S}_{m} $$

∗ ∗ m m Hyb₁ (λ): Same as Hyb₀ (λ), except that Sm∗ is replaced with a sampler bSm∗ that computes C₀ differently. Formally, bSm∗ is defined as follows:

$$ \mathrm {H y b} _ {1} ^ {m ^ {*}} (\lambda) $$

$$ \ \mathsf{H y b}_{0}^{m^{*}}(\lambda) $$

$$ {\sf{S}}_{m}, $$

$$ \widehat {S} _ {m ^ {\prime}} $$

$$ C_{0} $$

$$ \hat{\mathsf{S}}_{m^{*}} $$


$$ \begin{aligned}{}&{{}\widehat{\mathsf{S}}{m^{\ }11^{lambda};r}}\ {}&{{}\widehat{\mathsf{L e t}}\ r=(r{0},r_{1},r_{2},r_{3})}\ {}&{{}\mathsf{s}{1}=\mathsf{G e n}{1}^{}(1^{\lambda};r_{0}),\ \mathsf{s}{2}=\mathsf{G e n}{2}^{}(1^{\lambda};r_{1})}\ {}&{{}\mathsf{i v}=r_{3}}\ {}&{{}\mathsf{k}=\mathsf{K e e n}{0}^{*}(1^{\lambda};\mathsf{F}{2}^{\mathsf{s}}(\mathsf{s}{2},\mathsf{i v}))}\ {}&{{}\mathsf{k}=\mathsf{K e n t}{0}^{}(\mathsf{k},m;\mathsf{v})}\ {}&{{}\mathsf{s}{1}^{\prime}=\mathsf{K e n t}{1}^{}(\mathsf{s}{1},r{2}),\ \mathsf{s}{2}^{\prime}=\mathsf{P u n c t}{2}^{*}(\mathsf{s}{2},\mathsf{i v})}\ {}&{{}\mathsf{S t}\ mathsf C u{1}=C mathsf{C}{1}^{\mathsf{s k}},_{2},\mathsf{c}{1}^{\prime},\mathsf{c}{2}^{\prime},\mathsf{c}{1}=C_{1}^{\mathsf{s k}},{{}}^{\prime},\mathsf{c}{2}^{\prime},\mathsf{c}=\mathsf{c}_{1}^{\prime},\mathsf{c}}\end{aligned} $$

where C ′ and C ′ ′ are defined as in Figure5. C ′ and C ′ ′ are padded to match the sEnc1,s2,r2 sEnc1,s2,r2 sEnc1,s2,r2 sEnc1,s2,r2 size γ as defined in Figure5.

$$ C_{s_{1}^{\prime},\mathsf{s_{2}},r_{2}}^{\mathsf{E n c}} $$

$$ C_{\mathsf{s}{1}^{\prime},\mathsf{s}{2}^{\prime},r_{2}}^{\mathsf{E n c}} $$

$$ C_{\mathsf{s_{1}^{\prime},s mathsf{s_{2}},r\mathsf{}}}^{\mathsf{E n c}} $$

$$ C_{\mathsf{s}{1}^{\prime},\mathsf{s}{2}^{\prime},r_{2}}^{\mathsf{E n c}} $$

$$ \gamma $$

∗ ∗ m m Hyb2(λ): Same as Hyb1(λ), except that bSm∗ is replaced with a sampler Sm∗ that computes C₀ differently. Formally, Sm∗ is defined as follows:

$$ {\mathsf{H y}}{\mathfrak{b}}_{2}^{m^{*}}(\lambda) $$

$$ {\mathsf{H y b}}_{1}^{m^{*}}(\lambda) $$

$$ \widehat{\mathsf{S}}_{m^{*}} $$

$$ \bar {\mathrm {S}} _ {m ^ {\prime}} $$

$$ C_{0} $$

$$ \bar{S}_{m^{*}} $$

$$ \begin{aligned}{}&{{}\overline{{\mathsf{S}{m}^{*}(1^{\lambda};r)}}}\ {}&{{}\overline{{\mathsf{L e t}\ r=(r{0},r_{1},r_{2},r_{3},r_{4})}}}\ {}&{{}\mathsf{s}{1}=\mathsf{G e n}{1}^{}(1^{\lambda};r_{0}),;mathsf{s}{2}=\mathsf{G e n}{2}^{}(1^{\lambda};r_{1})}\ {}&{{}\mathsf{i v}=r_{3}}\ {}&{{}\mathsf{k e n n}{0}^{*}(1^{\lambda};r{4})}\ {}&{{}\mathsf{k e n}in\mathsf{K e n}{0}^{*}(\mathsf{k},m mathsf{u}})\ \ {}&{{}\mathsf{s}{1}^{\prime}=\mathsf{K e n n}{1}^{*}(\mathsf{s}{1},r_{2}),\ \mathsf{s}{2}^{\prime}=\mathsf{P u n c t}{2}^{*}(\mathsf{s}{2},\mathsf{w})}\ {}&{{}\mathsf{s e t}\ mathsf C u u n=C{1}=C_{1},C_{\mathsf{s}{1}^{\prime},r_{2}}^{\ \prime},\alpha=c}\ {}&{{}\mathsf{s e t}\ mathsf C u=\ {1}=C{1},\mathsf{s e n}{2}^{\ prime prime,{{mathsf}{s}{2}}},\alpha=c}\ \end{aligned} $$

where C ′ ′ is depicted in Figure5. C ′ ′ is padded to match the size γ as defined in Figure5. sEnc1,s2,r2 sEnc1,s2,r2

$$ C_{s_{1}^{\prime},\mathsf{s_{2}^{\prime}},r_{2}}^{\mathsf{E n c}} $$

$$ \gamma $$

∗ ∗ ∗ m m Lemma B.10. For every m ∈M, Hyb₀ (λ) ≈cHyb₁ (λ).

$$ m^{}\in\mathcal{M},\operatorname{\mathsf{H y b}}_{0}^{m^{}}(\lambda)\approx_{c}\operatorname{\mathsf{H y b}}_{1}^{m^{*}}(\lambda) $$

∗ Proof. The lemma follows by leveraging the security and correctness of the puncturable PRF scheme Π₁ and the fact that r₂ is sampled at random, i.e., the adversary cannot guess the punctured point r₂ (that is also a differing-input) except with negligible probability. ⊓⊔

$$ \ {cal Pi_{{}1}{}^{*}} $$

$$ r_{2} $$

$$ r_{2} $$

∗ ∗ ∗ m m Lemma B.11. For every m ∈M, Hyb₁ (λ) ≈cHyb₂ (λ).

$$ m^{}\in\mathcal{M},\mathsf{H y b}_{1}^{m^{}}(\lambda)\approx_{c}\mathsf{H y b}_{2}^{m^{*}}(\lambda) $$

∗ Proof. The lemma follows by leveraging the security and correctness of the puncturable PRF scheme Π₂ and the fact that r₂ is sampled at random, i.e., the adversary cannot guess the punctured point r₂ (that is also a differing-input) except with negligible probability. ⊓⊔

$$ \ {\boldsymbol{\Pi}}_{2}^{*} $$

$$ r_{2} $$

$$ r_{2} $$

∗ m By combining LemmasB.10andB.11and observing that in Hyb₂ (λ) the sampler Sm∗ outputs two identical circuits, we conclude that Sm∗ is an odiO-sampler.

$$ {\mathsf{H y}}{\mathfrak{b}}_{2}^{m^{*}}(\lambda) $$

$$ \ \bar{S}_{m^{*}} $$

$$ {\sf{S}}_{m}, $$

∗ ∗ (Part two) Π is sel-IND-CPA secure. Let m0,m1∈M. Consider the following hybrid experiments:

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

∗ ∗ m0,m1,b ∗ ∗ Hyb₀ (λ): This is the standard sel-IND-CPA experiment for PKE with respect to messages m₀,m₁ ∗ and the challenge bit b (DefinitionA.22). In particular, the challenge ciphertext c is computed as ∗e(∗ ∗ ∗$∗e. c = C mb,r) where r ← {0,1} and pk = C ∗ ∗ ∗ ∗

$$ {\sf H{b}}00^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ m_{0}^{},m_{1}^{} $$

$$ \mathrm{A}.22) $$

$$ c^{}=C(m_{b}^{},r^{*}) $$

$$ c^{*} $$

$$ r^{}\leftarrow\ {0,1}^{} $$

$$ {\mathfrak{p k}}=C $$

$$ {\sf H{b}}11^{m{0}^{},m_{1}^{},b}(\lambda) $$

m0,m1,b m0,m1,b ∗ Hyb₁ (λ): Same as Hyb₀, except that the challenger sets pk to the obfuscation of the circuit ∗ λ ∗ λ ∗ ∗ ′ C ′ ′ ∗of Figure5(instead of C) where s₁ ←$ Gen (1), s₂ ←$ Gen (1), r ←$ {0,1}, s = sEnc1,s2,r sEnc 1,s2 1 2 1 ∗ ∗ ′ ∗ ∗ ∗ ∗ Punct₁(s₁*,r*), s2= Punct₂(s₂*,* F1(s₁*,r*)). Recall that r is the randomness of the challenge ciphertext ∗ ∗ ∗ ∗ ∗ ∗ ∗ c. Moreover, the challenge ciphertext c is computed as c = Enc0(k*,m*b,iv) where iv = F1(s₁,r), ∗ ∗ ∗ λ ∗ ∗ m0,m1,b k = KGen₀(1; F₂(s₂,iv)). Therefore, c is computed as in Hyb₀ (λ).

$$ \ \mathsf{H y b}{0}^{m{0}^{},m_{1}^{},b} $$

$$ {\mathsf{p k}}^{*} $$

$$ C_{s_{1}^{\prime},\mathsf{s_{2}^{\prime},{r^{*}}}}^{\mathsf{k n c}} $$

$$ C_{\mathsf{s_{1},\mathsf{s_{2}}}}^{\mathsf{E n c}}) $$

$$ \mathrm {s} _ {1} \leftarrow \mathbb {s} \operatorname {G e n} _ {1} ^ {} \left(1 ^ {\lambda}\right), \mathrm {s} _ {2} \leftarrow \mathbb {s} \operatorname {G e n} _ {2} ^ {} \left(1 ^ {\lambda}\right), r ^ {} \leftarrow \mathbb {s} {0, 1 } ^ {}, \mathrm {s} _ {1} ^ {\prime} = $$

$$ i _ {1} ^ {} \left(\mathrm {s} _ {1}, r ^ {}\right), \mathrm {s} _ {2} ^ {\prime} = \operatorname {P u n c t} _ {2} ^ {} \left(\mathrm {s} _ {2}, F _ {1} ^ {} \left(\mathrm {s} _ {1}, r ^ {*}\right)\right) $$

$$ r^{*} $$

$$ c^{*} $$

$$ c^{}=\mathsf{E n c}_{0}^{}(\mathsf{k},m_{b}^{*},\dot{\mathsf{i}\mathsf{v}}) $$

$$ c^{*} $$

$$ \mathrm {i v} = \mathrm {F} _ {1} ^ {} \left(\mathrm {s} _ {1}, r ^ {}\right) $$

$$ \mathsf{k}=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{2}^{*}(\mathsf{s}_{2},\mathsf{i v})) $$

$$ c^{*} $$

$$ {\sf H{b}}00^{m{0}^{},m_{1}^{},b}(\lambda) $$


∗ ∗ ∗ ∗ m0,m1,b m0,m1,b Hyb₂ (λ): Same as Hyb₁, except that the challenger changes how it computes the challenge ∗ ∗ ∗ ∗ m0,m1,b ∗ ciphertext c. First, the challenger computes pk as in Hyb₁ (λ) and then it computes c = ∗ ∗ ∗ ∗ λ ∗ Enc (k*,m*; iv) where iv ←$ *{0,1} and k = KGen (1; F (s₂,*iv)). 0 b 0 2

$$ {\mathsf y y}{2}^{m{0}^{},m_{1}^{},b}(\lambda); $$

$$ \ {mathsf H y y}{1}^{m{0}^{},m_{1}^{},b} $$

$$ \ {\sf p k}^{*} $$

$$ \mathsf{H}y\mathfrak{b}{1}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ c^{*} $$

$$ c^{*},= $$

$$ \mathsf{E n c}{0}^{*}(\mathsf{k},m{b}^{*};\mathsf{i v}) $$

$$ \leftarrow\mathfrak{s}\left{0,1\right}^{*} $$

$$ k=\mathsf{K G e n}{0}^{*}(1^{\lambda};\mathsf{F}{2}^{*}(\mathsf{s}_{2},\mathsf{i}\mathsf{w})) $$

∗ ∗ ∗ ∗ m0,m1,b m0,m1,b Hyb₃ (λ): Same as Hyb₂, except that the challenger changes how it computes the challenge ∗ ∗ ∗ ∗ m0,m1,b ∗ ciphertext c. First, the challenger computes pk as in Hyb₂ (λ) and then it computes c = ∗ ∗ ∗ ∗ λ Enc (k*,m*; iv) where iv ←$ *{0,*1} and k ←$ KGen (1). 0 b 0

$$ \mathsf{H y b}{3}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ \ \mathsf{H y b}{2}^{m{0}^{},m_{1}^{},b} $$

$$ {\sf k k}^{*} $$

$$ c^{*},= $$

$$ \leftarrow\mathfrak{s}\left{0,1\right}^{*} $$

$$ \mathsf{H}\ mathsf y mathsf_22^m{{0}^{*},m{1}^{*},b}(\lambda) $$

$$ \mathsf{E n c}{0}^{*}(\mathsf{k},m{b}^{*};\mathsf{i v}) $$

$$ \mathsf{k}\leftarrow\mathsf{s}\mathbin{\mathsf{K G e n}}_{0}^{*}(1^{\lambda}) $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b λ m0,m1,b λ Lemma B.12. For every m₀,m₁ ∈M, Hyb₀ (1) ≈cHyb₁ (1).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},,\mathsf{H y b}{0}^{m{0}^{},m_{1}^{},b}(1^{\lambda})\approx_{c}\mathsf{H y b}{1}^{m{0}^{},m_{1}^{},b}(1^{\lambda}). $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b m0,m1,b Proof. By contradiction, assume there exist m₀,m₁ ∈M such that Hyb₀ (λ) and Hyb₁ (λ) are not computationally indistinguishable, i.e., there exists a PPT distinguisher D that has a non-negligible ∗ ∗ ∗ ∗ m0,m1,b m0,m1,b ′ advantage in distinguishing between Hyb₀ (λ) and Hyb₁ (λ). We build a distinguisher D that ∗′ breaks the indistinguishability property of Obf for the odiO-sampler Sm. The distinguisher D proceeds b as follows:

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

$$ \mathsf{H}\mathsf{y}\mathsf{b}{1}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ {\mathsf{H y b}}{0}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ {\sf H{b}}{{11}^{m{0}^{},m_{1}^{},b}}(\lambda) $$

$$ D^{\prime} $$

$$ \mathsf{S}{m{b}^{*}} $$

$$ D^{\prime} $$

e and e$λ$ 1.Receive in input an obfuscated circuit C α. Recall C ← Obf(1*,C*d) and α = c where d ← {0,1} $ ∗λ is the unknown challenge bit and (C₀,C₁,α) ← Sm(1). b

$$ \tilde{C} $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{d}) $$

$$ \alpha=c $$

$$ \leftarrow\mathfrak{s}\left{0,1\right} $$

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {$} S _ {m _ {b} ^ {*}} \left(1 ^ {\lambda}\right) $$

$$ {\mathsf{p k}}=\widetilde{C} $$

2.Send pk = Ce and c to D.

3.Return whatever D outputs.

∗ ∗ ∗ ∗ ′ m0,m1,b ′ m0,m1,b If d = 0 then D simulates Hyb₀ (λ). On the other hand, if b = 1 then D simulates Hyb₁ (λ) ′ Hence, D retains the same non-negligible advantage of D. ⊓⊔

$$ d=0 $$

$$ \mathrm {H y b} _ {0} ^ {m _ {0} ^ {}, m _ {1} ^ {}, b} (\lambda) $$

$$ b=1 $$

$$ D^{\prime} $$

$$ \mathsf{H}\mathsf{y}\mathsf{b}{1}^{m{0}^{},m_{1}^{},b}(\lambda) $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b λ m0,m1,b λ Lemma B.13. For every m₀,m₁ ∈M, Hyb₁ (1) ≈cHyb₂ (1).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},,\mathsf{H y b}{1}^{m{0}^{},m_{1}^{},b}(1^{\lambda})\approx_{c}\mathsf{H y b}{2}^{m{0}^{},m_{1}^{},b}(1^{\lambda}) $$

Proof. The lemma follows by leveraging the security and correctness of the puncturable PRF scheme ∗ Π₁. ⊓⊔

$$ \ {boldsymbol Pi\!}_{{\boldsymbol1}}^{*} $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b λ m0,m1,b λ Lemma B.14. For every m₀,m₁ ∈M, Hyb₂ (1) ≈cHyb₃ (1).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},,\mathsf{H y b}{2}^{m{0}^{},m_{1}^{},b}(1^{\lambda})\approx_{c}\mathsf{H y b}{3}^{m{0}^{},m_{1}^{},b}(1^{\lambda}). $$

Proof. The lemma follows by leveraging the security and correctness of the puncturable PRF scheme ∗ Π₂. ⊓⊔

$$ \ {\boldsymbol Pi\ }_{2}^{*} $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b λ m0,m1,1−b λ Lemma B.15. For every m₀,m₁ ∈M, Hyb₃ (1) ≈cHyb₃ (1).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},,mathsf{H y b}{3}^{m{0}^{},m_{1}^{},b}(1^{\lambda})\approx_{c}\mathsf{H y b}{3}^{m{0}^{},m_{1}^{},1-b}(1^{\lambda}) $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b m0,m1,1−b Proof. By contradiction, assume there exist m₀,m₁ ∈M such that Hyb₃ (λ) and Hyb₃ (λ) are not computationally indistinguishable, i.e., there exists a PPT distinguisher D that has a non- ∗ ∗ ∗ ∗ m0,m1,b m0,m1,1−b negligible advantage in distinguishing between Hyb₃ (λ) and Hyb₃ (λ). We build an adver- ∗ ∗ ∗ sary A that breaks the semantic security of Π₀ with respect to messages m0,m1∈M. The distinguisher A proceeds as follows:

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

$$ {\sf H{b}}33^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ {\sf H y b}{3}^{m{0}^{},m_{1}^{},1-b}(\lambda) $$

$$ {\sf H{b}}33^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ \mathsf{H y b}{3}^{m{0}^{},m_{1}^{},\tilde{},1-b}(\lambda) $$

$$ \varPi_ {0} ^ {*} $$

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

$$ c^{*}=(\mathsf{i v},c) $$

∗ 1.Receive c = (iv*,c*) from the challenger.

$$ \leftarrow_{\ \ }\mathsf{O b f}(1^{\lambda},C_{\mathsf{s}{1}^{\prime},\mathsf{s}{2}^{\prime}}^{\mathsf{E n c}}) $$

λ ∗ λ ∗ λ ∗ ∗ ′ ∗ ∗ 2.Compute pk ←$ Obf(1,C ′ ′) where s₁ ←$ Gen (1), s₂ ←$ Gen (1), r ←$ {0,1}, s = Punct (s₁,r), sEnc1,s21 2 1 1 ′ ∗ and s2= Punct2(s2*,*iv).

$$ \mathtt{s}{1}\longleftarrow\mathtt{G e n}{1}^{}(1^{\lambda}),\mathtt{s}{2}\longleftarrow\mathtt{G e n}{2}^{}(1^{\lambda}),\mathit{r}^{}\longleftarrow{0,1}^{},\mathtt{s}{1}^{\prime}=\mathtt{P u n c t}{1}^{}(\mathtt{s}_{1},\mathit{r}^{}) $$

$$ \mathsf{s}{2}^{\prime}=\mathsf{P u n c t}{2}^{*}(\mathsf{s}_{2},\mathsf{i}\mathsf{v}) $$

∗ 3.Send pk and c to D.

$$ c^{*} $$

4.Return whatever D outputs.

∗ ∗ m0,m1,b Observe that A simulates Hyb₃ (λ) where b ∈{0,1} is the challenge bit sampled by the challenger. Hence, A retains the same non-negligible advantage of D. ⊓⊔

$$ \mathsf{H y b}{3}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ b\in{0,1} $$

By combining LemmasB.12toB.15, we conclude that Π is sel-IND-CPA.


∗ (Part one) Smis an oiO-sampler. By contradiction, suppose there exists m ∈M such that Sm∗ is not an oiO-sampler, i.e., there exists a PPT adversary D such that h i h i

B.7 Proof of Theorem5.7

$$ m^{*}\in{mathcal M M} $$

$$ \mathrm {S} _ {m} $$

$$ \ \mathsf{S}_{m}{}^{*} $$

$$ \Big|\mathbb{P}\Big[\ \mathsf{D}^{C_{0}(\cdot)}(1^{\lambda},1^{|C_{0}|},\alpha)=1\Big]-\mathbb{P}\Big[\mathsf{D}^{C_{1}(\cdot)}(1^{\lambda},1^{|C_{0}|},\alpha)=1\Big]\Big|\geq\epsilon, $$

(14)

$λ where (C₀,C₁,α) ← Sm(1) where ϵ non-negligible.

$$ \left(C _ {0}, C _ {1}, \alpha\right) \leftarrow {} ^ {\mathrm {s}} \mathsf {S} _ {m} \left(1 ^ {\lambda}\right) $$

∗ We build an adversary A that breaks the sel-IND-CPRA-key security of Π with respect to the ∗ message m ∈M. The adversary A proceeds as follows:

$$ \ ^{*} $$

$$ m^{*}\in{mathcal M M} $$

∗ 1.Receive c from the challenger.

$$ c^{*} $$

∗ ∗ ∗ ∗ ∗ 2.Let C₀ = CkEnc∗, C₁ = CkEnc∗, and α = c (note that both C₀ and C₁ are unknown to A since k0and 0 1 ∗ k1are kept secret by the challenger).

$$ \alpha=c^{*} $$

$$ C_{0}^{}=C_{\mathsf{k}{\ }}^{\mathsf{E n c}},,C{1}=C_{\mathsf{k}_{1}^{}}^{\mathsf{E n c}} $$

$$ C_{0}^{*} $$

$$ \Bbbk_{1}^{*} $$

$$ \mathsf{k}_{\ {}}^{*} $$

γ 3.Send α and 1 (where γ as defined in Figure6) to D and answer to the incoming queries as follows: ∗ ∗ (a)On input (m,r), forward (m,r) to the oracle Enc (k0, ·; ·) and returns the answer. 4.Output whatever D outputs.

$$ \gamma $$

$$ (m,r) $$

$$ (m,r) $$

$$ (\mathsf{k}_{0}^{*},\cdot;\cdot) $$

∗ ∗ ∗ Note that k0, k1, and c (generated by the challenger) have the same distribution to the one generated by Sm∗. Moreover,

$$ c^{*} $$

$$ {\mathsf k_{{0}}^{}},,{\mathsf k{{}}}_{{1}}{{{mathsf{{}}}}^{}} $$

$$ \mathsf {S} _ {m ^ {*}}. \mathrm {M o r e o v e r} $$

1.if b = 0 (the challenge bit sampled by the challenger), A simulates the left distribution of Equa- ∗ ∗ ∗ tion (14). This because c is encrypted using the same key (i.e., k0) hardcoded in the oracle C₀ (see ∗ ∗ definition of Sm∗ (Figure6)) that, in turn, is simulated by A using the oracle Enc (k0, ·; ·).

$$ b=0 $$

$$ c^{*} $$

$$ (\mathrm{i.e.},\mathsf{k}_{0}^{*}) $$

$$ C_{0}^{*} $$

$$ \mathsf{S}_{m^{*}}\ {mathrm{((F F g u u e~6))}}, $$

$$ \mathsf{E n c}^{}(\mathsf{k}_{0}^{},\cdot;\cdot) $$

∗ 2.On the other hand, if b = 1, A simulates the right distribution of Equation (14), i.e., c is encrypted ∗ ∗ using (a random) key k1that is completely independent from the one of oracle C₁ since the latter is ∗ ∗ simulated using the oracle Enc (k0, ·; ·).

$$ c^{*} $$

$$ {\sf k}_{1}^{*} $$

$$ (\mathsf{k}_{0}^{*},\cdot;\cdot) $$

$$ C_{1}^{*} $$

∗ Hence, A breaks the sel-CPRA-key-ind security of Π with the same non-negligible advantage of D. This concludes the proof.

$$ \Pi^{*} $$

∗ ∗ (Part two) Π is sel-IND-CPA. Let m0,m1∈M. Consider the following hybrid experiments:

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

∗ ∗ m0,m1,b ∗ ∗ Hyb₀ (λ): This is the standard sel-CPA-sec experiment (with respect to the messages m₀,m₁ ∈M) for PKE (DefinitionA.22) where the challenge bit is b.

$$ {\sf H y b}{0}^{m{0}^{},m_{1}^{},b}(\lambda){} $$

$$ m_{0}^{},m_{1}^{}\in\mathcal{M}) $$

$$ b. $$

∗ ∗ ∗ ∗ m0,m1,b m0,m1,b ∗ ∗ ∗ ∗ Hyb₁ (λ): Same as Hyb₀, except that the challenger computes k₀ ←$ KGen (λ),k₁ ←$ KGen (λ), λ ∗ ∗ ∗ ∗ pk ←$ Obf(1,C ∗) and set the challenge ciphertext to c ←$ Enc (k*,m*). kEnc10 b

$$ {\sf H{b}}11^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ \mathsf{H y b}{0}^{m{0}^{},m_{1}^{},b} $$

$$ k_{0}^{}\leftarrow\ \ times G_{}\ \ ^{}(\lambda),k_{1}^{}\leftarrow\ \times(G_{{}}\ \ !^{}(\lambda)) $$

$$ \leftarrow_{\ }\mathsf{O b f}(1^{\lambda},C_{\mathsf{k}_{\mathfrak{l}}^{*}}^{\mathsf{E n c}}) $$

$$ c ^ {} \leftarrow $ \operatorname {E n c} ^ {} \left(\mathrm {k} _ {0} ^ {}, m _ {b} ^ {}\right) $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b λ m0,m1,b λ Lemma B.16. For every m₀,m₁ ∈M, Hyb₀ (1) ≈cHyb₁ (1).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},,,mathsf H H y_{{0}}^{m_{0}^{},m_{1}^{},b}(1^{\lambda})\approx_{c}\mathsf{H y b}{1}^{m{0}^{},m_{1}^{},b}(1^{\lambda}). $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b m0,m1,b Proof. By contradiction, assume there exist m₀,m₁ ∈M such that Hyb₀ (λ) and Hyb₁ (λ) are not computationally indistinguishable, i.e., there exists a PPT distinguisher D that has a non-negligible ∗ ∗ ∗ ∗ m0,m1,b m0,m1,b ′ advantage in distinguishing between Hyb₀ (λ) and Hyb₁ (λ). We build a distinguisher D that ∗′ breaks the indistinguishability property of Obf for the oiO-sampler Sm. The distinguisher D proceeds b as follows:

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

$$ {mathsf{H y b}}{0}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ {\sf H{b}}11^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ {\mathsf{H y b}}{0}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ {\sf H{b}}11^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ D^{\prime} $$

$$ \mathsf{S}{m{b}^{*}} $$

$$ D^{\prime} $$

e and e$λ$ 1.Receive in input an obfuscated circuit C α. Recall C ← Obf(1*,C*d) and α = c where d ← {0,1} $ ∗λ is the unknown challenge bit and (C₀,C₁,α) ← Sm(1). b

$$ \tilde{C} $$

$$ \widetilde{C}\leftarrow\mathfrak{s}\mathsf{O b f}(1^{\lambda},C_{d}) $$

$$ \mathsf{p k}=\widetilde{C} $$

$$ (C_{0},C_{1},\alpha)\underset{\ \ }\leftarrow{\mathfrak{S}}\ {{m{h}^{*}}}(1^{\lambda}) $$

$$ \alpha=c $$

$$ \leftarrow \mathrm {s} {0, 1 } $$

3.Return whatever D outputs.

$$ \ {}D{\ }} $$

2.Send pk = Ce and c to D.

∗ ∗ ′ m0,m1,be encodes a random key k∗ If d = 0 then D simulates Hyb₀ (λ). This because C0that is the same ∗ ∗ ∗ used to compute c ←$ Enc (k*,m*) (see definition of Sm∗ depicted in Figure6). On the other hand, if 0 bb ∗ ∗ ′ m0,m1,b ∗ ∗ ∗ ∗ b = 1 then D simulates Hyb₁ (λ) since c ←$ Enc (k₀*,m*) and the key k₀ is completely independent b e since eλ ∗ ∗ λ ′ to the one that is encoded into C C ←$ Obf(1*,C* ∗) for k ←$ KGen (1). Hence, D retains the kEnc11 same non-negligible advantage of D. ⊓⊔

$$ {\sf H{b}}00^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ d=0 $$

$$ D^{\prime} $$

$$ \tilde{C} $$

$$ \mathrm {k} _ {0} ^ {*} $$

$$ c\leftarrow{\mathfrak{s}}\mathsf{E n c}^{}(\mathsf{k}_{0}^{},m_{b}^{*}) $$

$$ \mathsf{S}{m{b}^{*}} $$

$$ {\sf H{b}}{{11}^{m{0}^{},m_{1}^{},b}}(\lambda) $$

$$ b=1 $$

$$ D^{\prime} $$

$$ c\leftarrow{\mathfrak{s}}\mathsf{E n c}^{}(\mathsf{k}_{0}^{},m_{b}^{*}) $$

$$ \mathsf{k}_{\mathrm{0}}^{*} $$

$$ \tilde{C} $$

$$ \widetilde {C} \leftarrow \mathrm {s} \operatorname {O b f} \left(1 ^ {\lambda}, C _ {\mathrm {k} _ {1} ^ {*}} ^ {\mathrm {E n c}}\right) $$

$$ \mathsf{k}_{1}^{}\leftarrow{mathsf s\mathsf{K G e n}}^{}(1^{\lambda}) $$

$$ D^{\prime} $$


| $\widetilde{C}{k}^{0}(x,r)$ return Enc0(k,0;r) | $\widetilde{C}{k}^{1}(i,r)$ return Enc0(k,0;r) | $\widetilde{C}{k}^{2}(c{1},c_{2},\odot,r)$ return Enc0(k,0;r) | $\widetilde{C}{k}^{3}(d{1},\ldots,d_{\lambda},r)$

return Enc0(k,0;r) | | --- | --- | --- | --- | | $C_{(k,a,b,y,e)}^{rnd}(\ell,v,r)$ | | | | | Let $v=(x,i,c_{1},c_{2},\odot,d_{1},\ldots,d_{\lambda})$ $r^{\prime}=F_{rnd}(\ell,v,r)$ | | Let $v=(x,i,c_{1},c_{2},\odot,d_{1},\ldots,d_{\lambda})$ $r^{\prime}=F_{rnd}(\ell,v,r)$ | | | If $\ell=0$, return $C_{k,a,b}^{0}(x,r^{\prime})$ | | If $\ell=0$, return $C_{k,a,b}^{0}(x,r^{\prime})$ | | | If $\ell=1$, return $C_{k,a}^{1}(i,r^{\prime})$ | | If $\ell=1$, return $C_{k,a}^{1}(i,r^{\prime})$ | | | If $\ell=2$, return $C_{k}^{2}(c_{1},c_{2},\odot,r^{\prime})$ | | If $\ell=2$, return $C_{k}^{2}(c_{1},c_{2},\odot,r^{\prime})$ | | | If $\ell=3$, return $C_{k,a,b,y,e}^{3}(d_{1},\ldots,d_{\lambda},r^{\prime})$ | | If $\ell=3$, return $\widetilde{C}{k}^{3}(d{1},\ldots,d_{\lambda},r^{\prime})$ | | | $\widetilde{C}{(k,a,b)}(\ell,v,r)$ | | | | | Let $v=(x,i,c{1},c_{2},\odot,d_{1},\ldots,d_{\lambda})$ $r^{\prime}=F_{rnd}(\ell,v,r)$ | | Let $v=(x,i,c_{1},c_{2},\odot,d_{1},\ldots,d_{\lambda})$ $r^{\prime}=F_{rnd}(\ell,v,r)$ | | | If $\ell=0$, return $C_{k,a,b}^{0}(x,r^{\prime})$ | | If $\ell=0$, return $\widetilde{C}{k}^{0}(x,r^{\prime})$ | | | If $\ell=1$, return $\widetilde{C}{k}^{1}(i,r^{\prime})$ | | If $\ell=1$, return $\widetilde{C}{k}^{1}(i,r^{\prime})$ | | | If $\ell=2$, return $\widetilde{C}{k}^{2}(c_{1},c_{2},\odot,r^{\prime})$ | | If $\ell=2$, return $\widetilde{C}{k}^{2}(c{1},c_{2},\odot,r^{\prime})$ | | | If $\ell=3$, return $\widetilde{C}{k}^{3}(d{1},\ldots,d_{\lambda},r^{\prime})$ | | If $\ell=3$, return $\widetilde{C}{k}^{3}(d{1},\ldots,d_{\lambda},r^{\prime})$ | |

$$ \widetilde{C}_{\mathsf{k}}^{0}(x,r) $$

$$ \widetilde{C}_{\mathsf{k}}^{1}(i,r) $$

$$ \mathsf{E n c}_{0}(\mathsf{k},0;r) $$

$$ \widetilde{C}{\mathsf{k}}^{2}(c{1},c_{2},\odot,\mathit{r})\qquad\qquad\widetilde{C}{\mathsf{k}}^{3}(d{1},\ldots,d_{\lambda},\mathit{r}) $$

$$ \mathsf{E n c}_{0}(\mathsf{k},0;r) $$

$$ \mathsf{E n c}_{0}(\mathsf{k},0;r) $$

$$ \mathsf{E n c}_{0}(\mathsf{k},0;r) $$

$$ C_{(\mathsf{k},a,b,\mathsf{y},e)}^{\mathsf{r n d}}(\ell,v,r) $$

$$ \widehat{C}_{(\mathsf{k},a,b)}(\ell,v,r) $$

$$ \mathrm{L e t}\ v=\left(x,i,c_{1},c_{2},\odot,d_{1},\ldots,d_{\lambda}\right) $$

$$ v=\left(x,i,c_{1},c_{2},\odot,d_{1},\ldots,d_{\lambda}\right) $$

$$ r^{\prime}={\sf F}_{\sf r n d}(\ell,v,r) $$

$$ {\bf I f};\ell=0,;{\mathrm r e t u r n};{\cal C}_{{\sf k},a,b}^{0}(x,r^{\prime}) $$

$$ r^{\prime}={\sf F}_{\sf r n d}(\ell,v,r) $$

$$ {\bf I f};\ell=0,;{\bf r e t u r n};{\cal C}_{{\sf k},a,b}^{0}(x,r^{\prime}) $$

$$ \ {bf I f f};\ell=1,;{\mathrm{r e t u r n}};{\cal C}_{\mathsf k a a}^{1}(i,r^{\prime}) $$

$$ \ {bf I f f};\ell=1,;{\mathrm{r e t u r n}};{\cal C}_{{\sf k},a}^{1}(i,r^{\prime}) $$

$$ \ {mathrm I I f};\ell=2,;{\mathrm{r e t u r n}};\mathcal{C}{\Bbbk}^{2}(c{1},c_{2},\odot,r^{\prime}) $$

$$ \ {bf I f},\ell=2,,\operatorname{r e t u r n},\mathcal{C}{\Bbbk}^{2}(c{1},c_{2},\odot,r^{\prime}) $$

$$ \text {I f} \ell = 3, \text {r e t u r n} \widetilde {C} _ {\mathrm {k}} ^ {3} \left(d _ {1}, \dots , d _ {\lambda}, r ^ {\prime}\right) $$

$$ {{\bf{I f}}}\ell=3,{{\mathrm{}{\bfr e t u r n}}}C_{{{\mathsf{k}}},a,b,{{\mathsf{y}}},e}^{3}(d_{1},\ldots,d_{\lambda},r^{\prime}) $$

$$ \widetilde{C}_{(\mathsf{k},a,b)}(\ell,v,r) $$

$$ \widetilde{C}_{\mathsf{k}}(\ell,v,r) $$

$$ \operatorname{L e t}v=\left(x,i,c_{1},c_{2},\ {widehat}\odot,d_{1},\ldots,d_{\lambda}\right) $$

$$ v = \left(x, i, c _ {1}, c _ {2}, \odot , d _ {1}, \dots , d _ {\lambda}\right) $$

$$ r^{\prime}={\sf F}_{\sf r n d}(\ell,v,r) $$

$$ r^{\prime}=\mathsf{F}_{\mathsf{r n d}}(\ell,v,r) $$

$$ {\bf I f};\ell=0,;{\bf r e t u r n};C{{bf\sf{k}}}_{a,a,b}^{0}(x,r^{\prime}) $$

$$ {bf I I};\ell=0,;{\mathrm r e t u r n};\tilde{C}_{\mathsf{k}}^{0}\big(x,r^{\prime}\big) $$

$$ \mathbf{I f};\ell=1,;\mathbf{r e t u r n};\widetilde{C}_{\mathsf{k}}^{1}(i,r^{\prime}) $$

$$ \ {bf I f},\ell=2,,\operatorname{r e t u r n},\tilde{\mathcal{C}}_{} $$

$$ \mathbf{I f};\ell=2,;\mathtt{r e t u r n};\widetilde{C}{\mathsf{k}}^{2}(c{1},c_{2},\odot,r^{\prime}) $$

$$ \mathbf{I f};\ell=3,;\ {mathsf r}e t u r n;\ \ {\ \ }\ {\tilde C{}}{\Bbbk}^{3}(d{1},\ldots,d_{\lambda},r^{\prime}) $$

$$ \mathbf{I f}:\ell=3,:\ \ {mathsf r}e t u r n:\tilde{\mathcal{C}}{\Bbbk{}}^{3}(d{1},\ldots,d_{\lambda},r^{\prime}) $$

Fig. 10: The circuits C, Cb, Ce, and Ce where F (·, ·, ·) denotes an arbitrary truly (rnd k,a,b,y,e) (k,a,b) (k,a,b) k rnd random function.

$$ C_{(\mathsf{k},a,b,\mathsf{y},e)}^{\mathsf{r n d}},;\widehat{C}{(\mathsf{k},a,b)},;\widetilde{C}{(\mathsf{k},a,b)} $$

$$ {\widetilde{C}}_{\mathrm{k}} $$

$$ \mathsf{F}_{\mathsf{r n d}}(\cdot,\cdot,\cdot) $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b λ m0,m1,1−b λ Lemma B.17. For every m₀,m₁ ∈M, Hyb₁ (1) ≈cHyb₁ (1).

$$ :,m m_{0}^{},m_{1}^{}\in\mathcal{M},,\mathsf{H y b}{1}^{m{0}^{},m_{1}^{},b}(1^{\lambda})\approx_{c}\mathsf{H y b}{1}^{m{0}^{},m_{1}^{},1-b}(1^{\lambda}) $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1,b m0,m1,1−b Proof. By contradiction, assume there exist m₀,m₁ ∈M such that Hyb₁ (λ) and Hyb₁ (λ) are not computationally indistinguishable, i.e., there exists a PPT distinguisher D that has a non- ∗ ∗ ∗ ∗ m0,m1,b m0,m1,1−b negligible advantage in distinguishing between Hyb₁ (λ) and Hyb₁ (λ). We build an adver- ∗ ∗ ∗ sary A that breaks the semantic security of Π with respect to messages m0,m1∈M. The distinguisher A proceeds as follows:

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

$$ {\sf H{b}}{{11}^{m{0}^{},m_{1}^{},b}}(\lambda) $$

$$ {\sf H y b}{1}^{m{0}^{},m_{1}^{},1-b}(\lambda) $$

$$ \mathrm{P P T} $$

$$ {\sf{H y b}}{1}^{m{0}^{},m_{1}^{},b}(\lambda) $$

$$ {\mathsf H y b}{1}^{m{0}^{},m_{1}^{},1-b}(\lambda) $$

$$ \Pi^{*} $$

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

∗ 1.Receive c from the challenger.

$$ c^{*} $$

λ ∗ λ 2.Compute pk ←$ Obf(1*,C*) where k ←$ KGen (1). kEnc

$$ \leftarrow_{\ \ }{\sf O b f}(1^{\lambda},C_{\Bbbk}^{\ E n c})} $$

$$ k \leftarrow {} ^ {$} K G e n ^ {*} \left(1 ^ {\lambda}\right) $$

$$ c^{*} $$

∗ 3.Send pk and c to D.

4.Return whatever D outputs.

∗ ∗ m0,m1,b A correctly simulates D’s view. Indeed, A simulates Hyb₁ where b ∈ {0,1} is the challenge bit sampled by the challenger. Hence, A retains the same non-negligible advantage of D. ⊓⊔

$$ \ {mathsf H y y}{1}^{m{0}^{},m_{1}^{},b} $$

$$ b;\in;{0,1} $$

By combining LemmasB.16andB.17we conclude that Π is sel-IND-CPA.

B.8 Proof of Theorem6.1

(Part one) C satisfies oracle-differing-input. Let p(·) be a polynomial in the security parameter ∗, λ. Without loss of generality, we assume that A submits p(λ) queries to the oracles C and s (k,a,b,y,0) ∗, C. Consider the following hybrid experiments: s (k,a,b,y,1)

$$ p(\cdot) $$

$$ p(\lambda) $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},0)}^{*} $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},1)}^{*} $$

Hyb₀(λ)This is the oracle-differing-input experiment of Theorem6.1.

$$ \ {mathsf H H}{\mathfrak b}_{0}(\lambda) $$


∗, ∗, Hyb₁(λ): Same as Hyb₀(λ), except that the oracle access to C and C are simulated as s (k,a,b,y,0) s (k,a,b,y,1) C and C (defined in Figure10), respectively. (rnd k,a,b,y,0) (rnd k,a,b,y,1)

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},0)}^{*} $$

$$ {\mathsf{H y b}}_{1}(\lambda) $$

$$ C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},1)}^{*} $$

$$ \mathrm {H y b} _ {0} (\lambda) $$

$$ C_{(\mathsf{k},a,b,\mathsf{y},1)}^{\mathsf{r r d}} $$

$$ C_{(\mathsf{k},a,b,\mathsf{y},0)}^{\mathsf{r n d}} $$

Hyb⁰(λ): Same as Hyb₁(λ), except that C and C are both simulated as Cb (Fig- 2 (rnd k,a,b,y,0) (rnd k,a,b,y,1) (k,a,b) ure10).

$$ {\mathsf H y b}_{2}^{0}(\lambda); $$

$$ {mathsf H}\mathsf{y}\ \ !\mathfrak{b}_{1}(\lambda) $$

$$ C_{(\mathsf{k},a,b,\mathsf{y},0)}^{\mathsf{r n d}} $$

$$ C_{(\mathsf{k},a,b,\mathsf{y},1)}^{\mathsf{r n d}} $$

$$ \widehat{C}_{({\sf k},a,b)} $$

j j−1 Hyb2(λ): Same as Hyb2(λ), except that the challenger changes how it answers to the last j-th queries. ′ ′e Formally, on input the j-th query (ℓ,v,r), if j ≥ p(λ)− j + 1, the challenger returns C(k,a,b)(ℓ,v,r). ′b Otherwise (i.e., j < p(λ) − j + 1), it returns C(k,a,b)(ℓ,v,r).

$$ {mathsf H}\mathsf{y}_{2}^{j}(\lambda) $$

$$ {\mathsf{H y b}}_{2}^{j-1}(\lambda) $$

$$ j^{\prime}\mathrm{-t h} $$

$$ j^{\prime}\geq p(\lambda)-j+1 $$

$$ \left(\mathrm{i.e.,},j^{\prime}<p(\lambda)-j+1\right) $$

$$ \widetilde{C}_{(\mathsf{k},a,b)}(\ell,v,r) $$

p(λ)e Hyb₃(λ): Same as Hyb₂ (λ), except that the two oracle circuits simulated as Ck, instead of being simulated as Ce (see Figure10). (k,a,b)

$$ \widehat{C}_{(\mathsf{k},a,b)}(\ell,v,r) $$

$$ \ {\widetilde{C}}_{\mathbf{k}} $$

$$ {\sf H y b}_{3}(\lambda){} $$

$$ {\mathsf{H y b}}_{2}^{p(\lambda)}(\lambda) $$

$$ \widetilde{C}_{({\sf k},a,b)} $$

$$ {\mathsf{H y b}}{0}(\lambda)\approx{c}{\mathsf{H y b}}_{1}(\lambda) $$

Lemma B.18. Hyb₀(λ) ≈cHyb₁(λ).

Proof. The lemma follows by the security of the PRF scheme Π₁.

$$ I_{1} $$

j j−1 Lemma B.19. For every j ∈ [p(λ)], Hyb2(λ) ≈cHyb2(λ).

$$ j\in[p(\lambda)],\ {mathsf\mathsf H y b}{2}^{j}(\lambda)\approx{c}\ \mathsf{\mathsf H y}_{2}^{j-1}(\lambda). $$

Proof. Let (ℓ,v,r) be the j-th query of A. We have the following cases:

$$ (\ell,v,r) $$

1.If ℓ ∈{0,3} by definition of Cb and Ce (ℓ,v,r) we have that Cb (ℓ,v,r) = Ce (ℓ,v,r). (k,a,b) (k,a,b) (k,a,b) (k,a,b) j j−1 Thus, the two hybrids Hyb2(λ) and Hyb2(λ) are identically distributed.

$$ \widehat{C}_{({\sf k},a,b)} $$

$$ \operatorname{f}\ell\in{0,3} $$

$$ \widetilde{C}_{(\mathsf{k},a,b)}(\ell,v,r) $$

$$ \widehat{\mathcal C}{(\mathsf k a a a,b)}(\ell,v,r)=\widetilde{\mathcal C}{(\mathsf k,a,b)}(\ell,v,r) $$

$$ {sf H}{\sf b}_{2}^{j}(\lambda) $$

$$ {\mathsf{H y b}}_{2}^{j-1}(\lambda) $$

j j−1 2.On the other hand, if ℓ ∈ {1,2}, we can show that Hyb2(λ) and Hyb2(λ) are computationally indistinguishable by leveraging the IND-CCA1 security of Π₀. This can be done by using an identical + argument to that of Barak et al. [BGI 12, Claim 3.6.1].

$$ \ell \in {1, 2 } $$

$$ {mathsf H}{\mathsf b}_{2}^{j}(\lambda) $$

$$ \mathrm {H y b} _ {2} ^ {j - 1} (\lambda) $$

This concludes the proof.

p(λ) Lemma B.20. Hyb₂ (λ) ≈cHyb₃(λ).

λ Proof. The only way to distinguish these two hybrids is to guess the trigger input a ∈ {0,1} that happens with negligible probability. ⊓⊔

$$ {\sf y b}{2}^{p(\lambda)}(\lambda)\approx{c}{\sf H y b}_{3}(\lambda). $$

$$ a;\in;{0,1}^{\lambda} $$

Lemma B.21. Hyb₁(λ) ≈cHyb⁰2(λ).

$$ {\mathsf H y b}{1}(\lambda)\approx{c}{\mathsf H y}_{2}^{0}(\lambda) $$

Proof. Suppose there exists a PPT D that distinguishes between Hyb₁(λ) and Hyb⁰2(λ). By definition of C (for e ∈ {0,1}) and Cb, this implies that D submits, with non-negligible probabil- (rnd k,a,b,y,e) (k,a,b) ∗ ∗b∗ ∗ ∗ ∗ ∗ ity ϵ, a query (3*,v,r*) such that C(k,a,b)(3*,v,r*) ̸= C (3*,v,r*) for e ∈ {0,1}, i.e., v = (rnd k,a,b,y,e) (x,i,c₁,c₂, ⊙,d₁,...,dλ) and ∀i ∈ [λ],Dec₀(k,di) = bi. By leveraging LemmasB.20andB.21, we have ∗ ∗ that Hyb⁰2(λ) ≈cHyb₃(λ); hence, D must the same query (3*,v,r*) during the experiment Hyb₃(λ) with the same non-negligible probability ϵ. However, in Hyb₃(λ) any distinguisher D has a negligible advantage in guessing b since it is sampled at random and Hyb₃(λ) is defined with respect to Ce that does k ∗ ∗ not depend on b. As a consequence, D can not submit such a query (3*,v,r*), except with negligible probability. This concludes the proof. ⊓⊔

$$ \ {sf H H b}_{1}(\lambda) $$

$$ C_{(\mathsf{k},a,b,\mathsf{y},e)}^{\mathsf{r n d}} $$

$$ e;\in;{0,1}) $$

$$ {\mathsf{H y b}}_{2}^{0}(\lambda) $$

$$ \widehat{C}_{({\sf k},a,b)} $$

$$ \epsilon_{,} $$

$$ (3,v^{},r^{}) $$

$$ \widehat{C}{(\mathsf{k},a,b)}(3,\upsilon^{},r^{})\ \neq\ C{(\mathsf{k},a,b,\mathsf{v},e)}^{\mathsf{r n d}}(3,\upsilon^{},r^{}) $$

$$ v^{*}\ = $$

$$ e,\in,{{0,1}} $$

$$ (x, i, c _ {1}, c _ {2}, \odot , d _ {1}, \dots , d _ {\lambda}) $$

$$ \forall i\in[\lambda],{\mathsf{D e c}}{0}(\mathsf{k},d{i})=b_{i} $$

$$ \mathsf{H y b}{2}^{0}(\lambda)\approx{c}\mathsf{H y b}_{3}(\lambda); $$

$$ {\mathsf H y b}_{3}(\lambda) $$

$$ (3,v^{},r^{}) $$

$$ \ {mathsf H H}{\mathfrak b}_{3}(\lambda) $$

$$ \mathrm {H y b} _ {3} (\lambda) $$

$$ \dot{C}_{\mathrm{k}} $$

$$ (3,v^{},r^{}) $$

By combining LemmasB.18toB.21, we conclude that the ensemble C satisfies the oracle-differinginput.

(Part two) C satisfies input-indistinguishability. Let p₀(·),p₁(·) be two polynomials in the security parameter λ. Without loss of generality, we assume that D submits pd(λ) queries to the oracles ∗ C for d ∈{0,1}. Consider the following hybrid experiments: sd,(kd,ad,bd,yd,d)

$$ p_{0}(\cdot),p_{1}(\cdot) $$

$$ C_{\mathsf{s}{d},(\mathsf{k}{d},a_{d},b_{d},\mathsf{y}_{d},d)}^{*} $$

$$ d\in{0,1} $$

$$ p_{d}(\lambda) $$

d Hyb0(λ)This is the input-indistinguishability experiment of Theorem6.1where the challenge bit is d, i.e., the adversary receives in input md.

$$ \ {mathsf H y y}_{0}^{d}(\lambda) $$

d d ∗ ∗ Hyb1(λ): Same as Hyb0(λ), except that the oracle access to C and C are s0,(k0,a0,b0,y0,0) s1,(k1,a1,b1,y1,1) simulates as C and C (depicted in Figure10), respectively. We stress that (rnd0 k0,a0,b0,y0,0) (rnd1 k1,a1,b1,y1,1) C and C are simulated using two independent truly random functions Frnd0(·, ·, ·) (rnd0 k0,a0,b0,y0,0) (rnd1 k1,a1,b1,y1,1) and Frnd1(·, ·, ·).

$$ d, $$

$$ m_{d}. $$

$$ \mathsf{H y}\mathfrak{b}_{0}^{d}(\lambda) $$

$$ {\mathsf{H y b}}_{1}^{d}(\lambda) $$

$$ C_{\mathsf{s}{0},(\mathsf{k}{0},a_{0},b_{0},\mathsf{y}_{0},0)}^{*} $$

$$ C_{\mathsf{s}{1},(\mathsf{k}{1},a_{1},b_{1},\mathsf{y}_{1},1)}^{*} $$

$$ C_{(\mathsf{k}{0},a{0},b_{0},\mathsf{y}_{0},0)}^{\mathsf{r n d0}} $$

$$ C_{(\mathsf{k}{1},a{1},b_{1},y_{1},1)}^{\mathsf{r n d l1}} $$

$$ C_{(\mathsf{k}{0},a{0},b_{0},\mathsf{y}_{0},0)}^{\mathsf{r n a U}} $$

$$ U_{(\mathsf{k}{1},a{1},b_{1},\mathsf{y}_{1},1)}^{\mathsf{i n u u}} $$

$$ \mathsf{F}_{\mathsf{r n d0}}(\cdot,\cdot,\cdot) $$

$$ \mathsf{F}_{\mathsf{r n d1}}(\cdot,\cdot,\cdot) $$ d, db Hyb2 0(λ): Same as Hyb1(λ), except that the oracle access to C is simulated as C(k0,a0,b0) (rnd0 k0,a0,b0,y0,0) (depicted in Figure10).

$$ C_{(\mathsf{k}{0},a{0},b_{0},\mathsf{y}_{0},0)}^{\mathsf{r n d0}} $$

$$ {\mathsf{H y b}}_{2}^{d,0}(\lambda) $$

$$ {\mathsf{H y b}}_{1}^{d}(\lambda) $$

$$ \widehat{C}{(\mathsf{k}{0},a_{0},b_{0})} $$

d,j d,j−1 Hyb2(λ): Same as Hyb2(λ), except that the challenger changes how it answers to the last j-th b′b′ queries of C(k0,a0,b0). Formally, on input the j-th query (ℓ,v,r) for C(k0,a0,b0), if j ≥ p₀(λ)− j+1, the e′b challenger returns C(k0,a0,b0)(ℓ,v,r). Otherwise (i.e., j < p₀(λ)− j + 1), it returns C(k0,a0,b0)(ℓ,v,r). d d,p0 (λ)b e Hyb₃(λ): Same as Hyb₂ (λ), except that the oracle access to C(k0,a0,b0)is simulated as Ck0(see Figure10).

$$ {\mathsf{H y b}}_{2}^{d,j}(\lambda) $$

$$ {mathsf{H y b}}_{2}^{d,j-1}(\lambda) $$

$$ \widehat{C}{(\mathsf{k}{0},a_{0},b_{0})} $$

$$ (\ell,v,r) $$

$$ \widehat{C}{(\mathsf{k}{0},a_{0},b_{0})},\mathrm{i f};j^{\prime}\geq p_{0}(\lambda)!-!j!+!1 $$

$$ \widetilde{C}{(\mathsf{k}{0},a_{0},b_{0})}(\ell,v,r) $$

$$ \left(\mathrm{i.e.,,,}^j{j}<p_{0}\big(\lambda\big)-j+1\right) $$

$$ \widehat{C}{(\mathsf{k}{0},a_{0},b_{0})}(\ell,v,r) $$

$$ {mathsf H}\mathsf{y}\ \ mathsf\mathfrak{b}_{3}^{d}(\lambda): $$

$$ \widehat{C}{(\mathsf{k}{0},a_{0},b_{0})} $$

$$ {widetilde C}{\ k{{}{0}}} $$

$$ {\sf{H y b}}{2}^{d,p{0}(\lambda)}(\lambda) $$

d, db Hyb4 0(λ): Same as Hyb3(λ), except that the oracle access to C is simulated as C(k1,a1,b1) (rnd1 k1,a1,b1,y1,1) (Figure10).

$$ {\mathsf{H y b}}_{4}^{d,0}(\lambda) $$

$$ {\mathsf{H y b}}_{3}^{d}(\lambda) $$

$$ \mathcal{C}{(\mathsf{k}{1},a_{1},b_{1},\mathsf{y}_{1},1)}^{\mathsf{r n d1}} $$

$$ \widehat{C}{(\mathsf{k}{1},a_{1},b_{1})} $$

d,j d,j−1 Hyb4(λ): Same as Hyb4(λ), except that the challenger changes how it answers to the last j-th b′b′ queries of C(k1,a1,b1). Formally, on input the j-th query (ℓ,v,r) for C(k1,a1,b1), if j ≥ p₁(λ)− j+1, the e′b challenger returns C(k1,a1,b1)(ℓ,v,r). Otherwise (i.e., j < p₁(λ)− j + 1), it returns C(k1,a1,b1)(ℓ,v,r). d d,p1 (λ)b e Hyb₅(λ): Same as Hyb₄ (λ), except that the oracle access to C(k1,a1,b1)is simulated as Ck1(see Figure10).

$$ {\mathsf{H y b}}_{4}^{d,j}(\lambda) $$

$$ \mathrm {H y b} _ {4} ^ {d, j - 1} (\lambda) $$

$$ \widehat{C}{(\mathsf{k}{1},a_{1},b_{1})} $$

$$ j^{\prime}\mathrm{-t h} $$

$$ (\ell,v,r) $$

$$ \widehat {C} _ {\left(\mathrm {k} _ {1}, a _ {1}, b _ {1}\right)}, \text {i f} j ^ {\prime} \geq p _ {1} (\lambda) - j + 1 $$

$$ C_{(\mathsf{k}{1},a{1},b_{1})}(\ell,v,r) $$

$$ \left(\mathrm{i.e.},,j^{\prime}<p_{1}(\lambda)-j+1\right) $$

$$ \widehat{C}{(\mathsf{k}{1},a_{1},b_{1})}(\ell,v,r) $$

$$ {\mathsf{H y b}}_{5}^{d}(\lambda) $$

$$ \widehat{C}{(\mathsf{k}{1},a_{1},b_{1})} $$

$$ {\mathsf y y}{4}^{d,p{1}(\lambda)}(\lambda) $$

$$ {\bar{C}}{{\bf k}{1}} $$

$$ \mathsf{H y b}{0}^{d}(\lambda)\approx{c}\mathsf{H y b}_{1}^{d}(\lambda) $$

d d Lemma B.22. Hyb0(λ) ≈cHyb1(λ).

$$ I_{1} $$

Proof. The lemma follows by the security of the PRF scheme Π₁.

d,j d,j−1 Lemma B.23. For every j ∈ [p₀(λ)], Hyb2(λ) ≈cHyb2(λ).

$$ j\in{\ [p{00}(\lambda)]},;{\sf H y b}{2}^{d,j}(\lambda)\approx_{c}{\sf H y b}_{2}^{d,j-1}(\lambda). $$

Proof. The lemma follows by the security of the IND-CCA1 security of Π₀ and using a similar argument to that of LemmaB.19. ⊓⊔

d,p₀(λ) d Lemma B.24. Hyb₂ (λ) ≈cHyb₃(λ).

$$ \mathsf{H y b}{2}^{d,p{0}(\lambda)}(\lambda)\approx_{c}\mathsf{H y b}_{3}^{d}(\lambda). $$

Proof. The proof is identical to that of LemmaB.20. The only way to distinguish these two hybrids is λ to guess the trigger input a₀ ∈{0,1} that happens with negligible probability. ⊓⊔

$$ a_{0}\in{0,1}^{\lambda} $$

d d,0 Lemma B.25. Hyb1(λ) ≈cHyb₂ (λ).

$$ {mathsf{H y b}}{1}^{d}(\lambda)\approx{c}{\mathsf{H y b}}_{2}^{d,0}(\lambda) $$

Proof. The lemma follows by using a similar argument to that of LemmaB.21.

d,j d,j−1 Lemma B.26. For every j ∈ [p₁(λ)], Hyb4(λ) ≈cHyb4(λ).

$$ j\in[p_{1}(\lambda)],,\mathsf{H y b}{4}^{d,j}(\lambda)\approx{c}\mathsf{H y b}_{4}^{d,j-1}(\lambda). $$

Proof. The lemma follows by the security of the IND-CCA1 security of Π₀ and using a similar argument to that of LemmaB.19. ⊓⊔

$$ \ !!_{\ } $$

$$ \mathsf{H y b}{4}^{d,p{1}(\lambda)}(\lambda)\approx_{c}\mathsf{H y b}_{5}^{d}(\lambda). $$

d,p₁(λ) d Lemma B.27. Hyb₄ (λ) ≈cHyb₅(λ).

Proof. The proof is identical to that of LemmaB.20. The only way to distinguish these two hybrids is λ to guess the trigger input a₁ ∈{0,1} that happens with negligible probability. ⊓⊔

$$ a_{1}\in{0,1}^{\lambda} $$

$$ \mathsf{H y b}{3}^{d}(\lambda)\approx{c}\mathsf{H y b}_{4}^{d,0}(\lambda). $$

d d,0 Lemma B.28. Hyb3(λ) ≈cHyb₄ (λ).

Proof. The lemma follows by using a similar argument to that of LemmaB.21.

$$ \mathsf{H y b}{5}^{d}(\lambda)\approx{c}\mathsf{H y b}_{5}^{1-d}(\lambda). $$

d −d Lemma B.29. Hyb5(λ) ≈cHyb¹5(λ).

Proof. The lemma follows by leveraging the IND-CPA-key security of Π₀.

By combining LemmasB.22toB.29, we conclude that the ensemble C satisfies input-indistinguishability.


(Part three) C satisfies partial reversability. The reversability property follows by using an identical

$$ \mathrm{[B G I^{+}01}, $$

$$ \mathsf{E x t}(1^{\lambda},\widetilde{\mathcal{C}}) $$

1.Let vi= (⊥,i, ⊥,..., ⊥).

$$ v_{i}=(\bot,i,\bot,\ldots,\bot) $$

e(1$∗ 2.For every i ∈ [λ], evaluate ci= C,vi,ri) where ri← {0,1}.

$$ r_{i}\leftarrow\mathfrak{s}{0,1}^{*} $$

$$ c_{i}=C(1,v_{i},r_{i}) $$

$$ i\in[\lambda] $$

3.Consider the gate representation of the circuit C(·, ·) = Ce(0*, ·, ·*).

4.Let (d₁,...,dλ) be the output of the gate-by-gate computation of C(·, ·) over the ciphertexts (c₁,...,cλ) of a (this can be accomplished by leveraging the access to Ce(2*, ·, ·*) that correspond to the C of Figk2 ure7that, in turn, permits to perform arbitrary homomorphic computation over encrypted inputs). Observe that diwill be the encryption of bisince each ciis an encryption of aiand C returns b if evaluated over a.

$$ C(\cdot,\cdot)=\dot{C}(0,\cdot,\cdot) $$

$$ C(\cdot,\cdot) $$

$$ \ c_{1},\ldots,c_{\lambda}) $$

$$ (d_{1},\ldots,d_{\lambda}) $$

$$ \dot{bar C((2\cdot,\cdot)} $$

$$ C_{\mathbf{k}}^{2} $$

$$ c_{i} $$

$$ d_{i} $$

$$ a_{i} $$

e(3$∗ 5.Compute (a,k,e,y) = C,v,r) where v = (⊥, ⊥, ⊥, ⊥, ⊥,d₁,...,dλ) and r ← {0,1}.

$$ (a,\mathsf{k},e,y)=\tilde{C}(3,v,r) $$

$$ \bot,d_{1},\ldots,d_{\lambda}) $$

$$ r\leftarrow\mathfrak{\mathfrak,s1}^{*} $$

e(0′ ′ ′ ′$∗ 6.Compute b = C,v,r) v = (a, ⊥,..., ⊥) and r ← {0,1}.

$$ b = C \left(0, v ^ {\prime}, r ^ {\prime}\right) v ^ {\prime} = (a, \bot , \dots , \bot) $$

$$ r^{\prime}\leftarrow\mathfrak{0,1}^{*} $$

7.Output (k*,a,b,y,e*).

$$ (\mathsf{k},a,b,\mathsf{y},e) $$

$$ \tilde{C} $$

By leveragng both the correctness of Π₀ (DefinitionA.15) and the definition of Ce (Theorem6.1), it is easy to see that Ext always output the correct (k*,a,b,y,e*).

$$ \ {cal Pi_{0}} $$

$$ (\mathsf{k},a,b,\mathsf{y},e) $$

B.9 Proof of Theorem6.3

λ (Part one) Sowfis an odiO-sampler. Let A be a PPT adversary. The only input x ∈{0,1} on which $λ C₀ = Cr,0,C₁ = Cr,1(output by Sb) differ is x = r where r ← {0,1}. Since α = ⊥ and A has only oracle access to C₀ and C₁ we conclude that A cannot do better than guessing r, i.e.,

$$ \ _{\mathrm{o w f}} $$

$$ x\in{0,1}^{\lambda} $$

$$ C_{0}=C_{r,0},C_{1}=C_{r,1} $$

$$ \ {\sf S_{b}}) $$

$$ x=r $$

$$ r\leftarrow{0,1}^{\lambda} $$

$$ \alpha=\bot $$

$$ C_{0} $$

$$ C_{1} $$

$$ \mathbb{P}[C_{r,0}(x)\neq C_{r,1}(x)]=\mathbb{P}[x=r]=\frac{1}{2^{\lambda}}, $$

$λ$Cr,0 (·),Cr,1 (·) λ |Cr,0 | 16 where (Cr,0,Cr,1, ⊥) ← Sowf(1) and x ← A (1*,1, ⊥*).

$$ x \leftarrow {} ^ {\mathrm {s}} A ^ {C _ {r, 0} (\cdot), C _ {r, 1} (\cdot)} \left(1 ^ {\lambda}, 1 ^ {\mid C _ {r, 0} \mid}, \bot\right). ^ {1 6} $$

$$ \left(C _ {r, 0}, C _ {r, 1}, \bot\right) \leftarrow {} ^ {$} S _ {\mathrm {o w f}} \left(1 ^ {\lambda}\right) $$

(Part two) Fλis a OWF. By contradiction, suppose Fλis not a OWF, i.e., there exists a PPT adversary A such that h i

$$ \mathrm {F} _ {\lambda} $$

$$ F _ {\lambda} $$

$$ \mathbb {P} \left[ F _ {\lambda} \left(\mathrm {A} \left(1 ^ {\lambda}, F _ {\lambda} \left(b, r _ {0}, r _ {1}\right)\right)\right) = F _ {\lambda} \left(b, r _ {0}, r _ {1}\right) | \left(b, r _ {0}, r _ {1}\right) \leftarrow \mathrm {s} {0, 1 } \times {0, 1 } ^ {\lambda} \times {0, 1 } ^ {p (\lambda)} \right] \geq \epsilon , $$

where ϵ non-negligible. We build an adversary D that breaks the indistinguishability property of Obf (Definition4.2). D proceeds as follows:

1.Receive an obfuscated circuit Ce.

$$ \tilde{C} $$

λe) and receive (λ p(λ) 2.Execute A(1*, C b,r₀,r₁*) ∈{0,1}×{0,1} ×{0,1}.

$$ \mathsf{A}(1^{\lambda},\mathcal{C}) $$

$$ \ b,\mathit{r}{0},\mathit{r}{1})\in{0,1}\times{0,1}^{\lambda}\times{0,1}^{p(\lambda)} $$

′ 3.Compute C = Obf(Cr0,b;r₁).

$$ C^{\prime}=\mathsf{O b f}(C_{r_{0},b};r_{1}) $$

′e, return 4.If C = C b.

$$ C^{\prime}=\widetilde{C}. $$

λ Observe that A’s view is perfectly simulated. Indeed, Sowfchooses r₀ ∈ {0,1} at random and the e is computed using a fresh randomness$p(λ)e obfuscated circuit C r₁ ← {0,1}. Hence, the distribution C λ p(λ) is the same of Fλon random inputs (b,r₀,r₁) ∈{0,1}×{0,1} ×{0,1}. This imply that D has the same non-negligible advantage ϵ in distinguishing between the obfuscations C₀ and C₁ output by Sowf. This concludes the proof.

$$ r_{0};\in;{0,1}^{\lambda} $$

$$ S _ {\mathrm {o w f}} $$

$$ \tilde{C} $$

$$ r_{1}\leftarrow $$

$$ (b,r_{0},r_{1}){\ \ \ \in}\ {0,1}{\ \ \times}}{0,1}^{\lambda}\times{0,1}^{p(\lambda)} $$

$$ F _ {\lambda} $$

$$ \tilde{C} $$

$$ C_{1} $$

$$ C_{0} $$

B.10 Proof of Theorem6.5

$$ S_{\mathsf{o w f}} $$

If OWFs exist then the following primitives exists:

λ 1.A secure PRF scheme Π = (Gen*,*F) with key space {0,1},

$$ \overline{{\Pi}}=(\overline{{\mathsf{G e n}}},\overline{{\mathsf{F}}}) $$

$$ {0,1}^{\lambda} $$

b [ d d) with key space λ 2.a SKE Π = (KGen*,Enc,Dec {0,1} that is IND-CCA1 and IND-CPA-key secure (CorollaryA.20),*

$$ \hat{\varPi}=(\hat{\mathsf K G e n},\hat{\mathsf C n c},\hat{\mathsf D e c}) $$

$$ {0,1}^{\lambda} $$

16 Recall that |Cr,0| = |Cr,1| by definition of sampler (Definition3.1).

$$ |C_{r,0}|=|C_{r,1}| $$


$$ \mathcal{C}={C_{\mathsf{s},(\mathsf{k},a,b,\mathsf{y},e)}^{*}}_{\mathsf{s},\mathsf{k},a,b,\mathsf{y}\in{0,1}^{\lambda},e\in{0,1}} $$

∗,b and 3.an ensemble of circuits C = {C}s,k,a,b,y∈{0,1}λ,e∈{0,1}(defined with respect to Π Π) that s (k,a,b,y,e) satisfies Theorem6.1, and

$$ \hat{\Pi} $$

$$ {\overline{{\pi}}}) $$

$$ \widetilde{\varPi}=(\widetilde{\mathsf{K G e n}},\widetilde{\mathsf{E n c}} $$

e] g g) with key space λ 4.a SKE Π = (KGen*,Enc,*Dec {0,1} that is semantically and sel-IND-CPRA-key secure (CorollaryA.20).

$$ {0,1}^{\lambda} $$

∗ ∗ ∗ ∗ Consider the following SKE scheme Π = (KGen*,Enc,Dec) with message space M = {(ℓ,v)}ℓ,v∈{0,1}∗* :

$$ \varPi^ {} = \left(\mathrm {K G e n} ^ {}, \mathrm {E n c} ^ {}, \mathrm {D e c} ^ {}\right) $$

$$ \mathcal{M}={(\ell,v)}_{\ell,v\in{0,1}^{*}} $$

∗ λ λ[ (1λ KGen (1): On input the security parameter 1, the key generation algorithm computes bk ←$ KGen), e$] (1λ$λ$λ$2λ+1 ∗ e k ← KGen), s ← Gen(1), y ← Gen(1), (a,b,e) ← {0,1}, and returns k = (bk*,* k, s*,a,b,y,e*).

$$ {\mathsf{K G e n}}^{*}(1^{\lambda}){\mathrm{}{:}} $$

$$ 1^{\lambda} $$

$$ \widehat{\mathsf{k}}\leftarrow\ {}\widehat{\mathsf{K G e n}}(1^{\lambda}) $$

$$ \widetilde {k} \leftarrow $ \widehat {\mathrm {K G e n}} \left(1 ^ {\lambda}\right), s \leftarrow $ \overline {{\mathrm {G e n}}} \left(1 ^ {\lambda}\right), y \leftarrow $ \overline {{\mathrm {G e n}}} \left(1 ^ {\lambda}\right), (a, b, e) \leftarrow $ {0, 1 } ^ {2 \lambda + 1} $$

$$ \operatorname {E n c} ^ {*} (\mathrm {k}, m; r): \text {O r} $$

$$ \mathsf{k}^{*}=\big(\widehat{\mathsf{k}},\widetilde{\mathsf{k}},\mathsf{s},a,b,\mathsf{y},e\big) $$

$$ {\bf\nabla}\ =\ (\ell,v),\in,{\mathcal M},. $$

∗ ∗ e Enc (k,m; r): On input the key k = (bk*,* k*,* s*,a,b,y,e*), a message m = (ℓ,v) ∈ M, and randomness ∗ ∗, r ∈ {0,1}, the encryption algorithm outputs c = (c₀,c₁,c₂) where c₀ = C (ℓ,v,r), c₁ = s (bk*,a,b,y,e*) Enc g(ek*,* (ℓ,v);r), and c₂ = F(y*,* (ℓ,v,r)) ⊕ ek.

$$ {\mathsf k^{{*}}}=\ {\dot{\ }}({\dot{\mathsf{k}}},{\mathsf{k}},{\mathsf{s}},a,b,{\mathsf{y}},e) $$

$$ c=(c_{0},c_{1},c_{2}) $$

$$ r,\in,{0,1}^{*} $$

$$ c_{0}=\mathcal{C}{\mathfrak{s},(\hat{\mathsf{k}},a,b,v,e)}^{*}(\ell,v,r),,c{1}= $$

$$ \widetilde{\mathsf{E n c}}(\widetilde{\mathsf{k}},(\ell,v);r) $$

$$ c_{2}=\ {bar\b F}(\ mathsf y,(\ell,v,r))\oplus{\tilde{\mathsf k}} $$

∗ ∗ e Dec (k*,c*): On input the key k = (bk*,* k, s*,a,b,y,e*) and a ciphertext c = (c₀,c₁,c₂), the deterministic decryption algorithm returns m = Dec g (ek*,c₁*).

$$ {\mathsf{D e c}}^{*}({\mathsf{k}},c){\mathrm{:n~}} $$

$$ {\sf k}^{*}={\dot(({sf\ k},{\sf k},{\sf s},a,b,y{,},e)} $$

$$ c=(c_{0},c_{1},c_{2}) $$

∗ First, we prove that Π is both semantically and sel-IND-CPRA-key secure. Second, we show that Π is ∗ not sel-IND-CPA where Π is the PKE scheme output by the application of Construction5to Π.

$$ m=\bar{\mathsf{D e c}}(\bar{\mathsf{k}},c_{1}) $$

$$ I^{*} $$

$$ \varPi^ {*} $$

$$ 5 $$

∗ ∗ ∗ Π is semantically secure. Let m0,m1∈M. Consider the following hybrid experiments:

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

$$ \Pi^{*} $$

∗ ∗ m0,m1 Hyb₀ (λ)This is the standard experiment of semantic security (DefinitionA.16) with respect to the ∗ ∗ messages m0,m1∈M.

$$ {\mathsf H y b}{0}^{m{0}^{},m_{1}^{}}(\lambda) $$

$$ m_{0}^{},m_{1}^{}\in\mathcal{M}. $$

∗ ∗ ∗ ∗ m0,m1m0,m1 ∗, Hyb₁ (λ): Same as Hyb₀ (λ), except that the challenger replaces the execution of C s (bk,a,b,y,e)

$$ {\sf H y b}{1}^{m{0}^{},m_{1}^{}}(\lambda) $$

$$ \mathsf{H}\mathsf{y}\mathsf{b}{0}^{m{0}^{},m_{1}^{}}(\lambda) $$

∗e (that is done by the encryption algorithm Enc) with the execution of Cb(depicted in Figure10). k,a,b ∗ ∗ ∗ ∗ m0,m1m0,m1 Hyb₂ (λ): Same as Hyb₁ (λ), except that the challenger samples the challenge bit b ←$ {0,1} and ∗ e ∗ e computes c₂ = Frnd(ℓb,vb∗,r) ⊕ k (instead of F(y*,* (ℓb,vb∗,r)) ⊕ k) where Frnd(·, ·, ·) is a truly random ∗ ∗$∗ function, mb= (ℓb,vb∗), and r ← {0,1}. ∗ ∗ ∗ ∗

$$ C_{\mathfrak{s},(\widehat{\mathsf{k}},a,b,\mathsf{y},e)}^{*} $$

$$ \mathsf{E n c^{*}} $$

$$ \tilde{C}_{\widehat{\mathbf{k}},a,b} $$

$$ \mathsf{H}\mathsf{y}\mathsf{b}{2}^{m{0}^{},m_{1}^{}}(\lambda); $$

$$ \mathsf{H y b}{1}^{m{0}^{},m_{1}^{}}(\lambda) $$

$$ b\gets\mathfrak\ s\left{0,1\right} $$

$$ c_{2}=\bar{\mathsf{F}}{\mathsf{r n d}}\big(\ell{b}^{},v_{b}^{},r\big)\oplus\bar{\mathsf{k}} $$

$$ \bar{\mathsf F}({mathsf\ y},(\ell_{b}^{},v_{b}^{},r))\oplus\widetilde{\mathsf k}\big) $$

$$ \bar{\mathsf{F}}_{\mathsf{r n d}}(\cdot,\cdot,\cdot) $$

$$ m_{b}^{}=(\ell_{b}^{},v_{b}^{*}) $$

$$ {mathsf\mathsf H y b}{2}^{m{0}^{},m_{1}^{}}(\lambda)\colon $$

$$ r\leftarrow\mathfrak0,1}^{*} $$

m0,m1m0,m1 g(e Hyb₂ (λ): Same as Hyb₁ (λ), except that the challenger computes c₁ = Enc k,(0,0);r) (instead g(e ∗ of c₁ = Enc k*,* (ℓb,vb∗);r)).

$$ \mathrm {H y b} _ {1} ^ {m _ {0} ^ {}, m _ {1} ^ {}} (\lambda) $$

$$ c_{1}=\widetilde{\mathsf{E n c}}(\widetilde{\mathsf{k}},(0,0);r) $$

$$ c _ {1} = \widetilde {\mathrm {E n c}} (\widetilde {\mathrm {k}}, \left(\ell_ {b} ^ {}, v _ {b} ^ {}\right); r)) $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1m0,m1 Lemma B.30. For every m₀,m₁ ∈M, Hyb₀ (λ) ≈cHyb₁ (λ).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},,{\sf H y b}{0}^{m{0}^{},m_{1}^{}}(\lambda)\approx_{c}{\sf H y b}{1}^{m{0}^{},m_{1}^{}}(\lambda). $$

Proof. The lemma follows by leveraging the fact that Π is a secure PRF scheme and Πb is IND-CCA1 secure. The proof is similar to that of oracle-differing-input of Theorem6.1. ⊓⊔

$$ \overline{{\pi}} $$

$$ \widehat{\mu} $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1m0,m1 Lemma B.31. For every m₀,m₁ ∈M, Hyb₁ (λ) ≈cHyb₂ (λ).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},\thinspace{\sf H y b}{1}^{m{0}^{},m_{1}^{}}(\lambda)\approx_{c}\mathsf{H y b}{2}^{m{0}^{},m_{1}^{}}(\lambda). $$

Proof. The lemma follows by leveraging the fact that Π is a secure PRF scheme.

$$ \overline{{m}} $$

∗ ∗ ∗ ∗ ∗ ∗ m0,m1m0,m1 Lemma B.32. For every m₀,m₁ ∈M, Hyb₁ (λ) ≈cHyb₂ (λ).

$$ m_{0}^{},m_{1}^{}\in\mathcal{M},;\mathsf{H y b}{1}^{m{0}^{},m_{1}^{}}(\lambda)\approx_{c}\mathsf{H y b}{2}^{m{0}^{},m_{1}^{}}(\lambda). $$

Proof. The lemma follows by the semantic security of Πe.

$$ \tilde{\Pi} $$

∗ By combining LemmasB.30toB.32, we obtain that Π is semantically secure.

$$ \varPi^ {*} $$

∗ ∗ Π is sel-IND-CPRA-key secure. Let m ∈M. Consider the following hybrid experiments:

$$ m^{*}\in\mathcal{M} $$

$$ \Pi^{*} $$

∗ d,m Hyb₀ (λ)This is the standard sel-IND-CPRA-key experiment (DefinitionA.19) with respect to the ∗ message m ∈M and the challenge bit d. ∗ ∗

$$ \mathsf{H y b}_{0}^{d,m^{*}}(\lambda) $$

$$ m^{*}\in{mathcal M M} $$

$$ \mathrm {H y b} _ {0} ^ {d, m ^ {*}} (\lambda) $$

$$ {\mathsf{H y b}}_{1}^{d,m^{*}}(\lambda) $$

$$ c_{0}^{*} $$

$$ c ^ {} = \left(c _ {0} ^ {}, c _ {1} ^ {}, c _ {2} ^ {}\right) $$

d,m d,m ∗ Hyb₁ (λ): Same as Hyb₀ (λ), except that the challenger changes how it computes c₀ of the chal- ∗ ∗ ∗ ∗ ∗ ∗ ∗ ∗ lenge ciphertext c = (c0,c1,c2). Formally, the challenger computes c0= C (ℓ,v,r) s1−d,(bk0,a0,b0,y0,e0) ∗ ∗ , ∗ ∗ ∗ ∗ ∗$∗ (instead of computing c0= C (ℓ,v,r)) where m = (ℓ,v) and r ← {0,1}. sd(bkd,ad,bd,yd,ed)

$$ c_{0}^{}=C_{\mathsf{s}{1-d},(\widehat{\mathsf{k}}{0},a_{0},b_{0},\mathsf{y}{0},e{0})}^{}(\ell^{},v^{},r) $$

$$ c_{0}^{}=C_{\mathsf{s}{d},(\widehat{\mathsf{k}}{d},a_{d},b_{d},\mathsf{y}{d},e{d})}^{}\big(\ell^{},v^{},r\big)\big) $$

$$ m^{}=\left(\ell^{},v^{*}\right) $$

$$ {\mathsf{H y b}}_{2}^{d,m^{*}}(\lambda) $$

$$ r\leftarrow\mathfrak{0,1}^{*} $$

∗ ∗ d,m d,m Hyb₂ (λ): Same as Hyb₁ (λ), except that the challenger changes how it answers to the oracle queries ∗ ∗ ∗ ∗ ∗ ∗ for Enc (k0, ·; ·) and Enc (k1, ·; ·). Formally, on input (m = (ℓ,v),r) for Enc (ki, ·; ·), the challenger computes c₀ = Ce (ℓ,v,r) (depicted in Figure10). bki,ai,bi

$$ {\mathsf{H y b}}_{1}^{d,m^{*}}(\lambda) $$

$$ ^{}({\sf k}_{0}^{},\cdot;\cdot) $$

$$ ^{}(\mathsf{k}_{1}^{},\cdot;\cdot) $$

$$ (m=(\ell,v),r) $$

$$ \mathsf{E n c}^{}(\mathsf{k}_{i}^{},\cdot;\cdot) $$

$$ c_{0}=\widetilde{C}{\widehat{\mathsf{k}}{i},a_{i},b_{i}}(\ell,v,r) $$


∗ ∗ d,m d,m ∗ ∗ Hyb₃ (λ): Same as Hyb₂ (λ), except that the challenger changes how Enc (k₀*, ·; ·) computes c₂. ∗ Formally, on input a message m = (ℓ,v) and a randomness r for Enc (k₀, ·*; ·), the challenger computes

$$ {\mathsf{H y b}}_{2}^{d,m^{*}}(\lambda) $$

$$ \mathsf{E n c}^{}(\mathsf{k}_{0}^{},\cdot;\cdot) $$

$$ {\mathsf{H y b}}_{3}^{d,m^{*}}(\lambda). $$

$$ \mathsf{E n c}^{*}(\mathsf{k}_{0},\cdot;\cdot) $$

$$ c_{2} $$

c₂ = F (ℓ,v,r) ⊕ ek₀ (instead of F(y₀*,* (ℓ,v,r)) ⊕ ek₀) where F (·, ·, ·) is a truly random function. rnd0 rnd0 ∗ ∗ d,m d,m ∗ ∗ Hyb₄ (λ): Same as Hyb₃ (λ), except that the challenger changes how Enc (k₁*, ·; ·) computes c₂. ∗ Formally, on input a message m = (ℓ,v) and a randomness r for Enc (k₁, ·; ·), the challenger computes c₂ = F (ℓ,v,r) ⊕ ek₁ (instead of F(y₁,* (ℓ,v,r)) ⊕ ek₁) where F (·, ·, ·) is a truly random function. rnd1 rnd1

$$ c_{2}=\bar{\mathsf{F}}{\mathsf{r n d0}}(\ell,v,r)\oplus\tilde{\mathsf{k}}{0} $$

$$ \ {bar\ \ F}({\mathsf y}{0},(\ell,v,r))\oplus{\widetilde{\mathsf k}}{0})big nonumber $$

$$ \mathsf{F}_{\mathsf{r n d0}}(\cdot,\cdot,\cdot) $$

$$ m=(\ell,v) $$

$$ {\mathsf{H y b}}_{3}^{d,m^{*}}(\lambda) $$

$$ {\mathsf{H y b}}_{4}^{d,m^{*}}(\lambda); $$

$$ \mathsf{E n c}^{}(\mathsf{k}_{1}^{},\cdot;\cdot) $$

$$ c_{2} $$

$$ m=(\ell,v) $$

$$ \cdot\mathsf{E n c}^{*}(\mathsf{k}_{1},\cdot;\cdot) $$

$$ c_{2}=\bar{\mathsf{F}}{\mathsf{r n d1}}(\ell,v,r)\oplus\widetilde{\mathsf{k}}{1} $$

$$ \bar{\mathsf{F}}_{\mathsf{r n d1}}(\cdot,\cdot,\cdot) $$

$$ \bar{\mathsf{F}}(\mathsf{y}{1},(\ell,v,r))\oplus\widetilde{\mathsf{k}}{1} $$

∗ ∗ ∗ d,m d,m Lemma B.33. For every m ∈M, Hyb₀ (λ) ≈cHyb₁ (λ).

$$ m^{}\in\mathcal{M},;\mathsf{H y b}_{0}^{d,m^{}}(\lambda)\approx_{c}\mathsf{H y b}_{1}^{d,m^{*}}(\lambda). $$

Proof. The lemma follows by leveraging the input-indistinguishability property of C (Theorem6.1). ⊓⊔

∗ ∗ ∗ d,m d,m Lemma B.34. For every m ∈M, Hyb₁ (λ) ≈cHyb₂ (λ).

$$ m^{}\in\mathcal{M},:\mathsf{H y b}_{1}^{d,m^{}}(\lambda)\approx_{c}\mathsf{H y b}_{2}^{d,m^{*}}(\lambda) $$

Proof. The lemma follows by leveraging the fact that Π is a secure PRF scheme and Πb is IND-CCA1 and IND-CPA-key secure. The proof uses a similar argument to that of input-indistinguishability of Theorem6.1. ⊓⊔

$$ \overline{{\pi}} $$

$$ \hat{\mu} $$

$$ m^{}\in\mathcal{M},;\mathsf{H y b}_{2}^{d,m^{}}(\lambda)\approx_{c}\mathsf{H y b}_{3}^{d,m^{*}}(\lambda). $$

∗ ∗ ∗ d,m d,m Lemma B.35. For every m ∈M, Hyb₂ (λ) ≈cHyb₃ (λ).

Proof. The lemma follows by leveraging the fact that Π is a secure PRF scheme. ⊓⊔

$$ \overline{{\pi}} $$

$$ m^{}\in\mathcal{M},:\mathsf{H y b}_{3}^{d,m^{}}(\lambda)\approx_{c}\mathsf{H y b}_{4}^{d,m^{*}}(\lambda). $$

∗ ∗ ∗ d,m d,m Lemma B.36. For every m ∈M, Hyb₃ (λ) ≈cHyb₄ (λ).

Proof. The lemma follows by leveraging the fact that Π is a secure PRF scheme.

$$ \overline{{}}} $$

∗ ∗ ∗ d,m 1−d,m Lemma B.37. For every m ∈M, Hyb₄ (λ) ≈cHyb₄ (λ).

$$ m^{}\in{\mathcal M},,{\sf H y b}_{4}^{d,m^{}}(\lambda)\approx_{c}{\sf H y b}_{4}^{1-d,m^{*}}(\lambda). $$

Proof. The lemma follows by leveraging the fact that Πe is sel-IND-CPRA-key secure

$$ \tilde{\Pi} $$

By combining LemmasB.33toB.37, we obtain that Π is sel-IND-CPRA-key secure.

Π is not sel-IND-CPA secure. Let Π be the PKE scheme output by the application of Theorem5.7, ∗ starting from the SKE scheme Π. It is easy to see that Π is not sel-IND-CPA (DefinitionA.22). This because there always exists an adversary A that, on input pk = Ce (recall that Ce is the obfuscation of the ∗ circuit CkEnc(Figure6) with respect to the SKE scheme Π), is able to correctly decrypt the challenge ∗ ∗ ∗ ∗ ciphertext. More formally, let m0,m1∈M such that m0̸= m1and A be the following adversary (against ∗ ∗ ∗ the sel-IND-CPA security of Π with respect to the messages m0,m1∈M):

$$ \Pi^{*} $$

$$ {\mathfrak{p}}{\mathsf{k}}={\widetilde{C}} $$

$$ \tilde{C} $$

$$ C_{\ {k}}^{\sf E{c c}} $$

$$ \Pi^{*}] $$

$$ m_{0}^{},m_{1}^{}\in\mathcal{M} $$

$$ m_{0}^{}\neq m_{1}^{} $$

$$ \varPi^ {*} $$

$$ m_{0}^{},m_{1}^{}\in\mathcal{M}) $$

∗ ∗ ∗ ∗e. 1.Receive the challenge ciphertext c = (c0,c1,c2) and the public key pk = C

$$ \ boldsymbol c{}^{}=\left(c_{0}^{},c_{1}^{},c_{2}^{}\right) $$

$$ {\mathfrak{p}}{\mathsf{k}}={\widetilde{C}}. $$

′ ′ ′ ′e(′ ′ ′ ′ ′ ′ ∗ 2.Compute c = (c0,c1,c2) = C ℓ,v,r) for some arbitrary ℓ,v,r ∈{0,1}.

$$ c^{\prime}=\left(c_{0}^{\prime},c_{1}^{\prime},c_{2}^{\prime}\right)=\widetilde{C}\left(\ell^{\prime},v^{\prime},r^{\prime}\right) $$

$$ \ell^{\prime},v^{\prime},r^{\prime}\in{0,1}^{*} $$

′e) representing the computation of e that, on input 3.Let C be the circuit (composed by the gates of C C (ℓ,v,r), output c₀, i.e.,

$$ C^{\prime} $$

$$ \tilde{C} $$

$$ {\widetilde{}}) $$

$$ (\ell,v,r) $$

$$ \forall(\ell,\upsilon,r)\in{0,1}^{*},c_{0}=c_{0}^{\prime}{\mathrm{w h e r e}}(c_{0},c_{1},c_{2})=\widetilde{C}(\ell,\upsilon,r){\mathrm{a n d}}c_{0}^{\prime}=C^{\prime}(\ell,\upsilon,r). $$

$λ ′ 4.Compute (bk*,a,b,y,e*) ← Ext(1*,C*) where Ext is the PPT algorithm satisfying the partial reversibility property of Theorem6.1.

$$ \ \ (\mathsf{hat k,,}a,b,y,e)\ \ leftarrow\mathsf{E x t}(1^{\lambda},\mathcal{C}^{\prime}) $$

′ ′ ′ ′ 5.Compute c2⊕ F(y*,* (ℓ,v,r)) = ek.

$$ c_{2}^{\prime}\oplus\bar{\mathsf{F}}(\mathsf{y},(\ell^{\prime},v^{\prime},r^{\prime}))=\tilde{\mathsf{k}}. $$

$$ c_{1}^{},\mathrm{i.e.,},{\sf D e c}(\mathsf{k},c_{1}^{})=m. $$

∗ g (e ∗ 6.Decrypt c1, i.e., Dec k*,c*1) = m.

∗ 7.If m = m0, return 0. Otherwise, return 1.

$$ m=m_{0}^{*}. $$

By leveraging the partial reversability property of C (Theorem6.1), A correctly extracts ek. As a consequence, A breaks the sel-IND-CPA security of Π.

$$ \widetilde{\mathbf k}.. $$