Extraction. The argument that R is nearly uniform given P is similar to the errorless case, except s has to be taken into account. For every s, the function Hi(c) = (σ, R) is universal, because for every c1, c2, there is at most one i such that Hi(c1) = Hi(c2) (because i(a1 − a2) is fixed, like in the errorless case). Because H˜ ∞(W | SS(W )) ≥ m − k, applying Lemma 1, we see that the distribution of (R, P ) = (R, (i, σ, s)) is 2(n′−v−(m−k))/2−1 = 2(n−v−m)/2−1 -close to (Un′−2v ×Un′−v ×U2v×SS(W )). Applying Lemma 3 to A = R, B = P , C = Un′−2v , D = Un′−v × U2v × SS(W ), we get that (n′−v−m)/2 (R, P ) is ε-close to Un′−2v × P , for ε = 2 .
Appears in 3 contracts
Sources: Robust Fuzzy Extractors and Authenticated Key Agreement, Robust Fuzzy Extractors and Authenticated Key Agreement, Robust Fuzzy Extractors and Authenticated Key Agreement