There is a newer version of the record available.

Published July 25, 2026 | Version v1

Relation Rank, Not Label Count

Authors/Creators

Description

 

Introduction

Many pairing-based constructions rely on \(q\)-type assumptions, whose instances grow with an operational parameter \(q\). The canonical example is the \(q\)-Strong Diffie–Hellman (\(q\)-SDH) assumption: given

\[ g,\; g^x,\; g^{x^2},\ldots,g^{x^q}, \]

an adversary must output a pair \((c,g^{1/(x+c)})\). In applications, \(q\) often tracks the number of signing, issuing, or extraction queries supported by the security proof. Thus the assumption underlying the construction becomes larger—and potentially weaker—as the permitted usage grows. Cheon’s algorithms make this concern quantitative by showing that auxiliary powers can accelerate hidden-exponent recovery for favorable divisors of the group order.

This dependence motivates a basic foundational question: can \(q\)-SDH be based, through a black-box reduction, on a fixed-size assumption whose instance length is independent of \(q\)? Positive results are known in composite-order bilinear groups, where hidden subgroup structure can supply the missing algebraic dimensions. The prime-order setting is substantially more rigid. Lu and Zhandry showed that fully black-box reductions in generic-representation and type-safe group models cannot base prime-order \(q\)-type assumptions, including \(q\)-SDH, on genuinely fixed-size assumptions below explicit dimension thresholds. Their argument converts the transcript of a purported reduction into a low-dimensional matrix and uses a root-list procedure to simulate a perfect \(q\)-type adversary efficiently.

The generic-representation theorem, however, does not immediately settle reductions designed for one concrete group representation. Such a reduction may inspect encoding bits, validate or decompress group elements, invoke hash-to-group procedures, use precomputed tables, or apply public operations directly to structured labels. These native mechanisms can introduce group elements that do not arise from an observed generic group operation. Consequently, the usual coefficient trace may no longer remain in the span of the fixed-size challenge.

A direct response is to assign a new formal coordinate to every unexplained native label. This yields a valid but coarse separation: a reduction introducing at most \(s\) such labels can be handled by enlarging the trace dimension by \(s\). Raw label count, however, is not the correct invariant. A structured interface may generate arbitrarily many labels from a small number of seeds while simultaneously exposing exact algebraic relations among their discrete logarithms. Counting every derived label as an independent coordinate discards precisely the structure that makes the representation useful.

This work replaces label count with a relation-aware, prefix-sensitive invariant. At an execution prefix \(\tau\), let \(L_1,\ldots,L_m\) be the distinct typed source-group labels observed so far and write \(z_i=\log_g L_i\). We collect every efficiently available affine relation

\[ A_\tau z=b_\tau \]

whose validity can be verified by a group identity, and define the prefix affine trace dimension by

\[ d(\tau) =\dim_{\mathbb F_r}\{z:A_\tau z=b_\tau\} =m-\operatorname{rank}_{\mathbb F_r}(A_\tau). \]

The definition is intrinsically online. A raw label increases \(d(\tau)\) by one, whereas a label produced together with a certified affine derivation relation does not increase it. Equality discoveries and output collisions can only lower the current dimension. A relation learned after an adversary call cannot retroactively lower the dimension governing that call, which is why the relevant quantity is the maximum over actual call prefixes rather than the rank of the final transcript.

Our main theorem shows that this dimension is sufficient for the Lu–Zhandry meta-reduction. If every prefix at which a fully black-box reduction invokes its \(q\)-SDH adversary satisfies

\[ d(\tau)\le \kappa<q-1, \]

then the reduction yields a polynomial-time attack on its fixed-size premise. The proof applies online Gaussian elimination to express every current label logarithm as an affine function of \(\kappa\) unknown parameters. Each \(q\)-SDH query is therefore represented by a matrix with at most \(\kappa+1<q\) columns, allowing the original column-space root-list argument to simulate a selected perfect \(q\)-SDH adversary. Neither the unknown parameters nor any individual discrete logarithm must be recovered.

This theorem strictly strengthens the bounded-label result. If a fixed-size challenge contributes \(n\) independent source coordinates and a native representation begins with \(k\) raw seeds, then arbitrarily many labels derived through certified affine operations contribute at most \(k\) additional dimensions. The separation therefore applies whenever \(n+k<q-1\), independently of the number of derived labels. The same reasoning gives a conditional bridge to structured generic-group representations whenever factor-base exponent vectors or equivalent derivation relations are efficiently available and verifiable. Structured-label density alone does not imply such a bound.

For target-valued bilinear \(q\)-type games, a source trace of dimension \(\kappa\) spans at most the degree-two monomial space of dimension \(\binom{\kappa+2}{2}\). With \(\tau\) additional relation-independent target coordinates, this gives the conservative sufficient condition

\[ \binom{\kappa+2}{2}+\tau<q. \]

For source-valued \(q\)-SDH, pairing outputs do not enlarge the relevant source trace, and the sharper linear threshold \(\kappa<q-1\) remains applicable.

The result is deliberately scoped. It does not rule out a concrete-representation reduction whose affine trace reaches dimension \(q-1\) at an actual adversary-call prefix. It also does not cover useful native relations that are nonlinear, unavailable, or not efficiently verifiable, nor reductions that access the adversary’s code non-black-box. By isolating these cases, the relation-rank formulation turns the previously broad representation-specific gap into three explicit and falsifiable escape routes.

 
 

Files

P2.2.pdf

Files (785.5 kB)

Name Size Download all
md5:c472d994ad56cfa8d07818b27c964a55
785.5 kB Preview Download