Papers
Topics
Authors
Recent
Search
2000 character limit reached

Nearly-Linear Time Seeded Extractors with Short Seeds

Published 12 Nov 2024 in cs.CC, cs.CR, cs.IT, and math.IT | (2411.07473v1)

Abstract: (abstract shortened due to space constraints) Existing constructions of seeded extractors with short seed length and large output length run in time Ω(nlog(1/ε))\Omega(n \log(1/\varepsilon)) and often slower, where nn is the input source length and ε\varepsilon is the error of the extractor. Since cryptographic applications of extractors require ε\varepsilon to be small, the resulting runtime makes these extractors unusable in practice. Motivated by this, we explore constructions of strong seeded extractors with short seeds computable in nearly-linear time O(nlog<sup>c</sup>n)O(n \log<sup>c</sup> n), for any error ε\varepsilon. We show that an appropriate combination of modern condensers and classical approaches for constructing seeded extractors for high min-entropy sources yields strong extractors for nn-bit sources with any min-entropy kk and any target error ε\varepsilon with seed length d=O(log(n/ε))d=O(\log(n/\varepsilon)) and output length m=(1η)km=(1-\eta)k for an arbitrarily small constant $\eta&gt;0$, running in nearly-linear time, after a reasonable one-time preprocessing step (finding a primitive element of Fq\mathbb{F}_q with q=poly(n/ε)q=poly(n/\varepsilon) a power of $2$) that is only required when $k&lt;2<sup>{C\log<sup>*</sup></sup> n}\cdot\log<sup>2(n/\varepsilon)$, for a constant $C&gt;0$ and log<sup>\log<sup>* the iterated logarithm, and which can be implemented in time polylog(n/ε)polylog(n/\varepsilon) under mild conditions on qq. As a second contribution, we give an instantiation of Trevisan's extractor that can be evaluated in truly linear time in the RAM model, as long as the number of output bits is at most nlog(1/ε)polylog(n)\frac{n}{\log(1/\varepsilon)polylog(n)}. Previous fast implementations of Trevisan's extractor ran in O~(n)\widetilde{O}(n) time in this setting. In particular, these extractors directly yield privacy amplification protocols with the same time complexity and output length, and communication complexity equal to their seed length.

Authors (2)

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.