首页> 外文会议>International conference on practice and theory in public-key cryptography >Rate-Limited Secure Function Evaluation: Definitions and Constructions
【24h】

Rate-Limited Secure Function Evaluation: Definitions and Constructions

机译:限速安全功能评估:定义和构造

获取原文

摘要

We introduce the notion of rate-limited secure function evaluation (RL-SFE). Loosely speaking, in an RL-SFE protocol participants can monitor and limit the number of distinct inputs (i.e., rate) used by their counterparts in multiple executions of an SFE, in a private and verifiable manner. The need for RL-SFE naturally arises in a variety of scenarios: e.g., it enables service providers to "meter" their customers' usage without compromising their privacy, or can be used to prevent oracle attacks against SFE constructions. We consider three variants of RL-SFE providing different levels of security. As a stepping stone, we also formalize the notion of commit-first SFE (cf-SFE) wherein parties are committed to their inputs before each SFE execution. We provide compilers for transforming any cf-SFE protocol into each of the three RL-SFE variants. Our compilers are accompanied with simulation-based proofs of security in the standard model and show a clear tradeoff between the level of security offered and the overhead required. Moreover, motivated by the fact that in many client-server applications clients do not keep state, we also describe a general approach for transforming the resulting RL-SFE protocols into stateless ones. As a case study, we take a closer look at the oblivious polynomial evaluation (OPE) protocol of Hazay and Lindell, show that it is commit-first and instantiate efficient rate-limited variants of it.
机译:我们介绍了速率受限安全功能评估(RL-SFE)的概念。宽松地说,在RL-SFE协议中,参与者可以以私有且可验证的方式监视和限制对方在SFE的多次执行中使用的不同输入(即速率)的数量。在多种情况下自然会产生对RL-SFE的需求:例如,它使服务提供商可以“计量”其客户的使用而不会损害其隐私,或者可以用来防止针对SFE结构的oracle攻击。我们考虑RL-SFE的三种变体,它们提供不同级别的安全性。作为垫脚石,我们还将正式提交优先SFE(cf-SFE)的概念形式化,在该概念中,各方在每次执行SFE之前都会对其输入进行承诺。我们提供了用于将任何cf-SFE协议转换为三个RL-SFE变体中的每一个的编译器。我们的编译器随附标准模型中基于仿真的安全性证明,并在提供的安全性级别和所需的开销之间显示出明显的权衡。此外,出于在许多客户端服务器应用程序中客户端不保持状态的事实的动机,我们还描述了一种用于将生成的RL-SFE协议转换为无状态协议的通用方法。作为案例研究,我们仔细研究了Hazay和Lindell的遗忘多项式评估(OPE)协议,表明它是首先提交并实例化其有效速率限制的变体。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号