1

This is probably similar to "What does 'a reduction is tight' mean rigorously?".

I am getting into security proofs, and started reading about reduction tightness. If problem P1 reduces to problem P2, I want to make sure that the reduction is "as close as possible" in terms of solving complexity. That answer provides a nice formula for a tightness gap, albeit I do not know how widely used this is.

While reading the security proofs of some papers, for example this one, I found mentions of a "tightness loss", such as

[...] no proof of adaptive security without exponential tightness loss exists for a threshold Schnorr signature scheme that is secure against [...].

I cannot seem to find a definition of "tightness loss", neither in these papers nor on the web. Is it the tightness gap again, or something different? How can we quantify it?

Perhaps this is trivial, but I'm very new and very confused by the lack of mathematical definitions.

Maarten Bodewes
  • 96,351
  • 14
  • 169
  • 323
Zahyr
  • 11
  • 4

0 Answers0