Decisional Linear Assumption (DLIN)
Proposed by: Dan Boneh, Xavier Boyen & Hovav Shacham (2004)
Category: Pairing-based
Let G be a group of prime order q equipped with a symmetric pairing e:G×G→GT.
Assumption. The distributions
(u,v,h,ua,vb,ha+b)and(u,v,h,ua,vb,hz)
with u,v,h←G, a,b,z←Zq, are computationally indistinguishable.
Motivation
In symmetric pairing groups, [[ddh]] is easy (test e(ga,gb)=?e(g,gab)). DLIN is the natural DDH substitute that survives the pairing: the pairing lets one check linear relations only pairwise, and no test distinguishes the DLIN tuple. DLIN holds in the generic group model even with a symmetric pairing. Generalizes to the k-Linear family (k=1 is DDH, k=2 is DLIN), and to Matrix-DDH (Escala et al. 2013).
Best known attacks
Discrete log. Quantum-broken via Shor.
Importance
- Introduced for short group signatures (Boneh–Boyen–Shacham 2004, >3000 citations).
- Groth–Sahai proofs (2008, >2000 citations) — efficient NIZK for bilinear groups, instantiable under DLIN — the workhorse of structure-preserving cryptography, anonymous credentials, and early SNARK-adjacent constructions.
- Linear encryption; many IBE/ABE variants proven under k-Lin, the currently preferred “weakest” pairing assumption in theoretical work.