Search arXivSearch

arXiv subjects

Alexander Russell

Publications and source records attributed to Alexander Russell.

At least 19 recordsLinked to original sources

Evidence for anisotropic non-Maxwellian velocity distributions in the solar transition region

Spectroscopic observations of the solar transition region have long shown excess line broadening and non-Gaussian profiles, but their spatial distribution and prevalence are not well established, and their physical origin remains the subject of debate. Here we analyze SiIV line profiles in full-disk mosaics of observations with Interface Region Imaging Spectrograph (IRIS; De Pontieu et al. 2014), and find that non-Gaussian k-like profiles, indicative of suprathermal velocity distributions, are pervasive (comprising ~60% of the observed profiles). In addition, we find that their occurrence depends strongly on the angle between the line of sight and the magnetic field as inferred from NLFFF extrapolations. k-like profiles become increasingly prevalent when the magnetic field is oriented transverse to the observer, whereas Gaussian profiles become more prevalent when the field is aligned with the line of sight. This geometric dependence provides evidence that the observed velocity distributions in the transition region are non-Maxwellian and anisotropic. Our findings provide evidence for the importance, in the solar transition region, of kinetic processes, and the key role the magnetic field plays in the superposition of signals, and/or the generation or relaxation of non-Maxwellian particle distributions, likely caused by magnetic energy release through reconnection. These effects are not captured by the magnetohydrodynamic approaches that are typically invoked to study the solar atmosphere. Our results highlight the need and provide constraints for more advanced multi-fluid and/or kinetic modeling of the solar transition region.

astro-ph.SR

Sublinear Risk-Limiting Audits from Direct Ballot Selection and Statistical Ballot Manifests

Risk-limiting audits (RLAs) rigorously guarantee a specified maximum probability that an incorrect electoral outcome will not be detected. Efficient RLA methods require a software-independent count of the ballots in each batch, called a ballot manifest. While electoral procedures can efficiently provide rough estimates for batch sizes, even slight inaccuracies can invalidate conventional RLAs (Lindeman et al., EVT 2012). Thus, establishing a sufficiently accurate manifest often requires handling every ballot in the election and can dominate the cost of conducting an RLA. We propose two new risk-limiting techniques. The first is a statistical test that checks a trusted, coarse manifest against an untrusted, tabulator-supplied manifest to certify that the aggregate error is small; this bounds both the error in the reported ballot total and the distortion of the ballot-sampling distribution. The second is a new approach for election architectures that do not efficiently index ballots by identifier, as is typical of voter-facing tabulators. We call this approach direct ballot selection: it reverses the traditional comparison procedure by selecting physical ballots uniformly and comparing them to their corresponding cast vote records. This method also incorporates a new statistical test to check for identifier duplication. These techniques reduce the effort required to conduct RLAs. Our two main findings are: 1) Manifest creation time can be reduced, for California at a 3% margin, our model indicates that the overall audit time for comparison, polling, and direct selection audits is reduced by factors of approximately 438, 27, and 10, respectively and 2) Direct ballot selection improves over state-of-the-art polling for small margins. For Connecticut at a 1% margin, it requires 55% fewer ballots than the Minerva (Security 2021) and Providence (Security 2023) ballot polling methods.

cs.CR

Ion-rich acceleration during an eruptive flux rope event in a multiple null-point configuration

We report on the $γ$-ray emission above 100~MeV from the GOES M3.3 flare SOL2012-06-03. The hard X-ray (HXR) and microwave emissions have typical time profiles with a fast rise to a well-defined peak followed by a slower decay. The $>$100~MeV emission during the prompt phase displayed a double-peaked temporal structure with the first peak following the HXR and microwaves, and the second one, about three times stronger, occurring $17 \pm 2$ seconds later. The time profiles seem to indicate two separate acceleration mechanisms at work, where the second $γ$-ray peak reveals a potentially pure or at least largely dominant ion acceleration. The Atmospheric Imaging Assembly imaging shows a bright elliptical ribbon and a transient brightening in the north-western (NW) region. Nonlinear force-free extrapolations at the time of the impulsive peaks show closed field lines connecting the NW region to the south-eastern part of the ribbon and the magnetic topology revealed clusters of nulls. These observations suggest a spine-and-fan geometry, and based on these observations we interpret the second $γ$-ray peak as being due to the predominant acceleration of ions in a region with multiple null points. The $>$100 MeV emission from this flare also exhibits a delayed phase with an exponential decay of roughly 350 seconds. We find that the delayed emission is consistent with ions being trapped in a closed flux tube with gradual escape via their loss cone to the chromosphere.

astro-ph.HE

Blockwise Post-processing in Satellite-based Quantum Key Distribution

Free-space satellite communication has significantly lower photon loss than terrestrial communication via optical fibers. Satellite-based quantum key distribution (QKD) leverages this advantage and provides a promising direction in achieving long-distance QKD. While the technological feasibility of satellite-based QKD has been demonstrated experimentally, optimizing the key rate remains a significant challenge. In this paper, we argue that improving classical post-processing is an important direction in increasing key rate in satellite-based QKD, while it can also be easily incorporated in existing satellite systems. In particular, we explore one direction, blockwise post-processing, to address highly dynamic satellite channel conditions due to various environmental factors. This blockwise strategy divides the raw key bits into individual blocks that have similar noise characteristics, and processes them independently, in contrast to traditional non-blockwise strategy that treats all the raw key bits as a whole. Using a case study, we discuss the choice of blocks in blockwise strategy, and show that blockwise strategy can significantly outperform non-blockwise strategy. Our study demonstrates the importance of post-processing in satellite QKD systems, and presents several open problems in this direction.

quant-ph

Competitive Policies for Online Collateral Maintenance

Layer-two blockchain protocols emerged to address scalability issues related to fees, storage cost, and confirmation delay of on-chain transactions. They aggregate off-chain transactions into a fewer on-chain ones, thus offering immediate settlement and reduced transaction fees. To preserve security of the underlying ledger, layer-two protocols often work in a collateralized model; resources are committed on-chain to backup off-chain activities. A fundamental challenge that arises in this setup is determining a policy for establishing, committing, and replenishing the collateral in a way that maximizes the value of settled transactions. In this paper, we study this problem under two settings that model collateralized layer-two protocols. The first is a general model in which a party has an on-chain collateral C with a policy to decide on whether to settle or discard each incoming transaction. The policy also specifies when to replenish C based on the remaining collateral value. The second model considers a discrete setup in which C is divided among k wallets, each of which is of size C/k, such that when a wallet is full, and so cannot settle any incoming transactions, it will be replenished. We devise several online policies for these models, and show how competitive they are compared to optimal (offline) policies that have full knowledge of the incoming transaction stream. To the best of our knowledge, we are the first to study and formulate online competitive policies for collateral and wallet management in the blockchain setting.

cs.DS

The Decisive Power of Indecision: Low-Variance Risk-Limiting Audits and Election Contestation via Marginal Mark Recording

Risk-limiting audits (RLAs) are techniques for verifying the outcomes of large elections. While they provide rigorous guarantees of correctness, widespread adoption has been impeded by both efficiency concerns and the fact they offer statistical, rather than absolute, conclusions. We attend to both of these difficulties, defining new families of audits that improve efficiency and offer qualitative advances in statistical power. Our new audits are enabled by revisiting the standard notion of a cast-vote record so that it can declare multiple possible mark interpretations rather than a single decision; this can reflect the presence of marginal marks, which appear regularly on hand-marked ballots. We show that this simple expedient can offer significant efficiency improvements with only minor changes to existing auditing infrastructure. We consider two ways of representing these marks, both yield risk-limiting comparison audits in the formal sense of Fuller, Harrison, and Russell (IEEE Security & Privacy 2023). We then define a new type of post-election audit we call a contested audit. These permit each candidate to provide a cast-vote record table advancing their own claim to victory. We prove that these audits offer remarkable sample efficiency, yielding control of risk with a constant number of samples (that is independent of margin). This is a first for an audit with provable soundness. These results are formulated in a game-based security model that specify quantitative soundness and completeness guarantees. These audits provide a means to handle contestation of election results affirmed by conventional RLAs.

cs.CR

Correcting Subverted Random Oracles

The random oracle methodology has proven to be a powerful tool for designing and reasoning about cryptographic schemes. In this paper, we focus on the basic problem of correcting faulty or adversarially corrupted random oracles, so that they can be confidently applied for such cryptographic purposes. We prove that a simple construction can transform a "subverted" random oracle which disagrees with the original one at a small fraction of inputs into an object that is indifferentiable from a random function, even if the adversary is made aware of all randomness used in the transformation. Our results permit future designers of cryptographic primitives in typical kleptographic settings (i.e., those permitting adversaries that subvert or replace basic cryptographic algorithms) to use random oracles as a trusted black box.

cs.CR

Crooked indifferentiability of the Feistel Construction

The Feistel construction is a fundamental technique for building pseudorandom permutations and block ciphers. This paper shows that a simple adaptation of the construction is resistant, even to algorithm substitution attacks -- that is, adversarial subversion -- of the component round functions. Specifically, we establish that a Feistel-based construction with more than $2000n/\log(1/ε)$ rounds can transform a subverted random function -- which disagrees with the original one at a small fraction (denoted by $ε$) of inputs -- into an object that is \emph{crooked-indifferentiable} from a random permutation, even if the adversary is aware of all the randomness used in the transformation. We also provide a lower bound showing that the construction cannot use fewer than $2n/\log(1/ε)$ rounds to achieve crooked-indifferentiable security.

cs.CR

Blockwise Key Distillation in Satellite-based Quantum Key Distribution

Free-space satellite communication has significantly lower photon loss than terrestrial communication via optical fibers. Satellite-based quantum key distribution (QKD) leverages this advantage and provides a promising direction in achieving long-distance inter-continental QKD. Satellite channels, however, can be highly dynamic due to various environmental factors and time-of-the-day effects, leading to heterogeneous noises over time. In this paper, we compare two key distillation techniques for satellite-based QKD. One is the traditional {\em non-blockwise} strategy that treats all the signals as a whole; the other is a {\em blockwise} strategy that divides the signals into individual blocks that have similar noise characteristics and processes them independently. Through extensive simulation in a wide range of settings, we show trends in optimal parameter choices and when one strategy provides better key generation rates than the other. Our results show that the blockwise strategy can lead to up to $5\%$ key rate improvement (leading to on average $1.9\times10^{7}$ more key bits per day) when considering two types of blocks, i.e., for nighttime and daytime, respectively. The blockwise strategy only requires changes in the classical post-processing stage of QKD and can be easily deployed in existing satellite systems.

quant-ph

Quantum-secure message authentication via blind-unforgeability

Formulating and designing authentication of classical messages in the presence of adversaries with quantum query access has been a longstanding challenge, as the familiar classical notions of unforgeability do not directly translate into meaningful notions in the quantum setting. A particular difficulty is how to fairly capture the notion of "predicting an unqueried value" when the adversary can query in quantum superposition. We propose a natural definition of unforgeability against quantum adversaries called blind unforgeability. This notion defines a function to be predictable if there exists an adversary who can use "partially blinded" oracle access to predict values in the blinded region. We support the proposal with a number of technical results. We begin by establishing that the notion coincides with EUF-CMA in the classical setting and go on to demonstrate that the notion is satisfied by a number of simple guiding examples, such as random functions and quantum-query-secure pseudorandom functions. We then show the suitability of blind unforgeability for supporting canonical constructions and reductions. We prove that the "hash-and-MAC" paradigm and the Lamport one-time digital signature scheme are indeed unforgeable according to the definition. To support our analysis, we additionally define and study a new variety of quantum-secure hash functions called Bernoulli-preserving. Finally, we demonstrate that blind unforgeability is stronger than a previous definition of Boneh and Zhandry [EUROCRYPT '13, CRYPTO '13] in the sense that we can construct an explicit function family which is forgeable by an attack that is recognized by blind-unforgeability, yet satisfies the definition by Boneh and Zhandry.

quant-ph

Adaptive Risk-Limiting Ballot Comparison Audits

Risk-limiting audits (RLAs) are rigorous statistical procedures meant to detect invalid election results. RLAs examine paper ballots cast during the election to statistically assess the possibility of a disagreement between the winner determined by the ballots and the winner reported by tabulation. The most ballot efficient approaches proceed by "ballot comparison." However, ballot comparison requires an untrusted declaration of the contents of each cast ballot, rather than a simple tabulation of vote totals. This "cast-vote record table" (CVR) is then spot-checked against ballots for consistency. In many practical settings, the cost of generating a suitable CVR dominates the cost of conducting the audit, preventing widespread adoption of these sample-efficient techniques. We introduce a new RLA procedure: an "adaptive ballot comparison" audit. In this audit, a global CVR is never produced; instead, a three-stage procedure is iterated: 1) a batch is selected, 2) a CVR is produced for that batch, and 3) a ballot within the batch is sampled, inspected by auditors, and compared with the CVR. We prove that such an audit can achieve risk commensurate with standard comparison audits while generating a fraction of the CVR. We present three main contributions: 1) a formal adversarial model for RLAs; 2) definition and analysis of an adaptive audit procedure with rigorous risk limits and an associated correctness analysis accounting for the incidental errors arising in typical audits; and 3) an analysis of practical efficiency. This method can be organized in rounds (as is typical for comparison audits) where sampled CVRs are produced in parallel. Using data from Florida's 2020 presidential election with 5% risk and 1% margin, only 22% of the CVR is generated; at 10% margin, only 2% is generated.

cs.CR

Consistency of Proof-of-Stake Blockchains with Concurrent Honest Slot Leaders

We improve the fundamental security threshold of eventual consensus Proof-of-Stake (PoS) blockchain protocols under the longest-chain rule by showing, for the first time, the positive effect of rounds with concurrent honest leaders. Current security analyses reduce consistency to the dynamics of an abstract, round-based block creation process that is determined by three events associated with a round: (i) event $A$: at least one adversarial leader, (ii) event $S$: a single honest leader, and (iii) event $M$: multiple, but honest, leaders. We present an asymptotically optimal consistency analysis assuming that an honest round is more likely than an adversarial round (i.e., $\Pr[S] + \Pr[M] > \Pr[A]$); this threshold is optimal. This is a first in the literature and can be applied to both the simple synchronous communication as well as communication with bounded delays. In all existing consistency analyses, event $M$ is either penalized or treated neutrally. Specifically, the consistency analyses in Ouroboros Praos (Eurocrypt 2018) and Genesis (CCS 2018) assume that $\Pr[S] - \Pr[M] > \Pr[A]$; the analyses in Sleepy Consensus (Asiacrypt 2017) and Snow White (Fin. Crypto 2019) assume that $\Pr[S] > \Pr[A]$. Moreover, all existing analyses completely break down when $\Pr[S] < \Pr[A]$. These thresholds determine the critical trade-off between the honest majority, network delays, and consistency error. Our new results can be directly applied to improve the security guarantees of the existing protocols. We also provide an efficient algorithm to explicitly calculate these error probabilities in the synchronous setting. Furthermore, we complement these results by analyzing the setting where $S$ is rare, even allowing $\Pr[S] = 0$, under the added assumption that honest players adopt a consistent chain selection rule.

cs.DC

Germ order for one-dimensional packings

Every set of natural numbers determines a generating function convergent for $q \in (-1,1)$ whose behavior as $q \rightarrow 1^-$ determines a germ. These germs admit a natural partial ordering that can be used to compare sets of natural numbers in a manner that generalizes both cardinality of finite sets and density of infinite sets. For any finite set $D$ of positive integers, call a set $S$ "$D$-avoiding" if no two elements of $S$ differ by an element of $D$. We study the problem of determining, for fixed $D$, all $D$-avoiding sets that are maximal in the germ order. In many cases, we can show that there is exactly one such set. We apply this to the study of one-dimensional packing problems.

math.CO

Linear Consistency for Proof-of-Stake Blockchains

The blockchain data structure maintained via the longest-chain rule---popularized by Bitcoin---is a powerful algorithmic tool for consensus algorithms. Such algorithms achieve consistency for blocks in the chain as a function of their depth from the end of the chain. While the analysis of Bitcoin guarantees consistency with error $2^{-k}$ for blocks of depth $O(k)$, the state-of-the-art of proof-of-stake (PoS) blockchains suffers from a quadratic dependence on $k$: these protocols, exemplified by Ouroboros (Crypto 2017), Ouroboros Praos (Eurocrypt 2018) and Sleepy Consensus (Asiacrypt 2017), can only establish that depth $Θ(k^2)$ is sufficient. Whether this quadratic gap is an intrinsic limitation of PoS---due to issues such as the nothing-at-stake problem---has been an urgent open question, as deployed PoS blockchains further rely on consistency for protocol correctness. We give an axiomatic theory of blockchain dynamics that permits rigorous reasoning about the longest-chain rule and achieve, in broad generality, $Θ(k)$ dependence on depth in order to achieve consistency error $2^{-k}$. In particular, for the first time, we show that PoS protocols can match proof-of-work protocols for linear consistency. We analyze the associated stochastic process, give a recursive relation for the critical functionals of this process, and derive tail bounds in both i.i.d. and martingale settings via associated generating functions.

cs.CR

Efficient simulation of random states and random unitaries

We consider the problem of efficiently simulating random quantum states and random unitary operators, in a manner which is convincing to unbounded adversaries with black-box oracle access. This problem has previously only been considered for restricted adversaries. Against adversaries with an a priori bound on the number of queries, it is well-known that $t$-designs suffice. Against polynomial-time adversaries, one can use pseudorandom states (PRS) and pseudorandom unitaries (PRU), as defined in a recent work of Ji, Liu, and Song; unfortunately, no provably secure construction is known for PRUs. In our setting, we are concerned with unbounded adversaries. Nonetheless, we are able to give stateful quantum algorithms which simulate the ideal object in both settings of interest. In the case of Haar-random states, our simulator is polynomial-time, has negligible error, and can also simulate verification and reflection through the simulated state. This yields an immediate application to quantum money: a money scheme which is information-theoretically unforgeable and untraceable. In the case of Haar-random unitaries, our simulator takes polynomial space, but simulates both forward and inverse access with zero error. These results can be seen as the first significant steps in developing a theory of lazy sampling for random quantum objects.

quant-ph

Small-Support Uncertainty Principles on $\mathbb{Z}/p$ over Finite Fields

We establish an uncertainty principle for functions $f: \mathbb{Z}/p \rightarrow \mathbb{F}_q$ with constant support (where $p \mid q-1$). In particular, we show that for any constant $S > 0$, functions $f: \mathbb{Z}/p \rightarrow \mathbb{F}_q$ for which $|\text{supp}\; {f}| = S$ must satisfy $|\text{supp}\; \hat{f}| = (1 - o(1))p$. The proof relies on an application of Szemeredi's theorem; the celebrated improvements by Gowers translate into slightly stronger statements permitting conclusions for functions possessing slowly growing support as a function of $p$.

math.CO

How to Realize a Graph on Random Points

We are given an integer $d$, a graph $G=(V,E)$, and a uniformly random embedding $f : V \rightarrow \{0,1\}^d$ of the vertices. We are interested in the probability that $G$ can be "realized" by a scaled Euclidean norm on $\mathbb{R}^d$, in the sense that there exists a non-negative scaling $w \in \mathbb{R}^d$ and a real threshold $θ> 0$ so that \[ (u,v) \in E \qquad \text{if and only if} \qquad \Vert f(u) - f(v) \Vert_w^2 < θ\,, \] where $\| x \|_w^2 = \sum_i w_i x_i^2$. These constraints are similar to those found in the Euclidean minimum spanning tree (EMST) realization problem. A crucial difference is that the realization map is (partially) determined by the random variable $f$. In this paper, we consider embeddings $f : V \rightarrow \{ x, y\}^d$ for arbitrary $x, y \in \mathbb{R}$. We prove that arbitrary trees can be realized with high probability when $d = Ω(n \log n)$. We prove an analogous result for graphs parametrized by the arboricity: specifically, we show that an arbitrary graph $G$ with arboricity $a$ can be realized with high probability when $d = Ω(n a^2 \log n)$. Additionally, if $r$ is the minimum effective resistance of the edges, $G$ can be realized with high probability when $d=Ω\left((n/r^2)\log n\right)$. Next, we show that it is necessary to have $d \geq \binom{n}{2}/6$ to realize random graphs, or $d \geq n/2$ to realize random spanning trees of the complete graph. This is true even if we permit an arbitrary embedding $f : V \rightarrow \{ x, y\}^d$ for any $x, y \in \mathbb{R}$ or negative weights. Along the way, we prove a probabilistic analog of Radon's theorem for convex sets in $\{0,1\}^d$. Our tree-realization result can complement existing results on statistical inference for gene expression data which involves realizing a tree, such as [GJP15].

cs.DM

Quantum-Secure Symmetric-Key Cryptography Based on Hidden Shifts

Recent results of Kaplan et al., building on previous work by Kuwakado and Morii, have shown that a wide variety of classically-secure symmetric-key cryptosystems can be completely broken by quantum chosen-plaintext attacks (qCPA). In such an attack, the quantum adversary has the ability to query the cryptographic functionality in superposition. The vulnerable cryptosystems include the Even-Mansour block cipher, the three-round Feistel network, the Encrypted-CBC-MAC, and many others. In this work, we study simple algebraic adaptations of such schemes that replace $(\mathbb Z/2)^n$ addition with operations over alternate finite groups--such as $\mathbb Z/{2^n}$--and provide evidence that these adaptations are qCPA-secure. These adaptations furthermore retain the classical security properties (and basic structural features) enjoyed by the original schemes. We establish security by treating the (quantum) hardness of the well-studied Hidden Shift problem as a basic cryptographic assumption. We observe that this problem has a number of attractive features in this cryptographic context, including random self-reducibility, hardness amplification, and--in many cases of interest--a reduction from the "search version" to the "decisional version." We then establish, under this assumption, the qCPA-security of several such Hidden Shift adaptations of symmetric-key constructions. We show that a Hidden Shift version of the Even-Mansour block cipher yields a quantum-secure pseudorandom function, and that a Hidden Shift version of the Encrypted CBC-MAC yields a collision-resistant hash function. Finally, we observe that such adaptations frustrate the direct Simon's algorithm-based attacks in more general circumstances, e.g., Feistel networks and slide attacks.

quant-ph