首页> 外文会议>International Conference on the Theory and Application of Cryptology and Information Security >Secure Two-Party Computation with Reusable Bit-Commitments, via a Cut-and-Choose with Forge-and-Lose Technique
【24h】

Secure Two-Party Computation with Reusable Bit-Commitments, via a Cut-and-Choose with Forge-and-Lose Technique

机译:通过剪切和丢失技术确保使用可重复使用的位承诺来确保双方计算

获取原文

摘要

A secure two-party computation (S2PC) protocol allows two parties to compute over their combined private inputs, as if intermediated by a trusted third party. In the malicious model, this can be achieved with a cut-and-choose of garbled circuits (C&C-GCs), where some GCs are verified for correctness and the remaining are evaluated to determine the circuit output. This paper presents a new C&C-GCs-based S2PC protocol, with significant advantages in efficiency and applicability. First, in contrast with prior protocols that require a majority of evaluated GCs to be correct, the new protocol only requires that at least one evaluated GC is correct. In practice this reduces the total number of GCs to approximately one third, for the same statistical security goal. This is accomplished by augmenting the C&C with a new forge-and-lose technique based on bit commitments with trapdoor. Second, the output of the new protocol includes reusable XOR-homomorphic bit commitments of all circuit input and output bits, thereby enabling efficient linkage of several S2PCs in a reactive manner. The protocol has additional interesting characteristics (which may allow new comparison tradeoffs), such as needing a low number of exponentiations, using a 2-out-of-1 type of oblivious transfer, and using the C&C structure to statistically verify the consistency of input wire keys.
机译:一个安全的双方计算(S2PC)协议允许两方通过其组合的私有输入计算,仿佛由受信任的第三方中介。在恶意模型中,这可以通过切割和选择的乱码(C-GCS)来实现,其中一些GCS被验证以进行正确性,并评估其余的剩余时间以确定电路输出。本文提出了一种新的C&C-GCS的S2PC协议,效率和适用性具有显着优势。首先,与需要大多数评估GCS正确的先前协议相比,新协议只要求至少一个评估的GC是正确的。在实践中,对于相同的统计安全目标,这将GCS的总数减少到大约三分之一。这是通过增加C&C基于与Trapdoor的Bit承诺的新锻造和丢失技术来实现的。其次,新协议的输出包括所有电路输入和输出位的可重复使用的XOR-同型位承诺,从而能够以反应性方式实现几个S2PC的有效连接。该协议具有额外的有趣特性(这可能允许新的比较权衡),例如需要少量的指数,使用1次或使用C&C结构在统计上验证输入的一致性电线键。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号