Transcription of How To Simulate It – A Tutorial on the Simulation Proof ...
{{id}} {{{paragraph}}}
HowToSimulateIt ATutorialontheSimulationProofTechnique ThistutorialappearedinthebookTutorialson theFoundationsofCryptography,publishedin honorofOdedGoldreich SemanticSecurity44 SecureComputation ObliviousTransfer499 TheCommonReferenceStringModel , realworld towhathappensinan idealworld , , , (thisisan idealworld thatissecurebydefinition),thisimpliestha tintherealworld,wheretheadversaryreceive stheciphertext, , snotatallclearhowtoformalizethenotiontha t nothingislearned .Ifwetrytosaythatanadversarywhoreceivesa ciphertextcannotoutputanyinformationabou ttheplaintext,thenwhathappensiftheadvers aryalreadyhasinformationabouttheplaintex t?
If the adversary receiving no ciphertext is able to output the same information as the adversary receiving the ciphertext, then this is indeed the case. It is unclear at this point why this is called “simulation”; what we have described is a comparison between two worlds. This will be explained throughout the tutorial (first in Section 3 ...
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}