首页> 外文会议>PKC 2013 >Rate-Limited Secure Function Evaluation: Definitions and Constructions
【24h】

Rate-Limited Secure Function Evaluation: Definitions and Constructions

机译:速率有限的安全功能评估:定义和结构

获取原文

摘要

We introduce the notion of rate-limited secure function evaluation (RL-SFE). Loosely speaking, in an RL-SFE protocol participants can monitor and limit the number of distinct inputs (i.e., rate) used by their counterparts in multiple executions of an SFE, in a private and verifiable manner. The need for RL-SFE naturally arises in a variety of scenarios: e.g., it enables service providers to “meter” their customers’ usage without compromising their privacy, or can be used to prevent oracle attacks against SFE constructions. We consider three variants of RL-SFE providing different levels of security. As a stepping stone, we also formalize the notion of commit-first SFE (cf-SFE) wherein parties are committed to their inputs before each SFE execution. We provide compilers for transforming any cf-SFE protocol into each of the three RL-SFE variants. Our compilers are accompanied with simulation-based proofs of security in the standard model and show a clear tradeoff between the level of security offered and the overhead required. Moreover, motivated by the fact that in many client-server applications clients do not keep state, we also describe a general approach for transforming the resulting RL-SFE protocols into stateless ones. As a case study, we take a closer look at the oblivious polynomial evaluation (OPE) protocol of Hazay and Lindell, show that it is commitfirst and instantiate efficient rate-limited variants of it.
机译:我们介绍了速率限定的安全功能评估(RL-SFE)的概念。在RL-SFE协议中,参与者可以以私人和可验证的方式监控和限制其对应于SFE的多个执行中的不同输入(即,速率)的数量。 RL-SFE的需求自然地出现了各种场景:例如,它使服务提供商能够在不影响其隐私的情况下“仪表”客户的使用情况,或者可用于防止Oracle对SFE结构的攻击。我们考虑三种RL-SFE的变种,提供不同的安全级别。作为踏脚石,我们还将提交第一SFE(CF-SFE)的概念正式化,其中缔约方在每个SFE执行之前致力于其输入。我们提供用于将任何CF-SFE协议转换为三个RL-SFE变体的编译器。我们的编译器伴随着标准模型中的仿真安全证据,并在所提供的安全性和所需的开销之间显示明确的权衡。此外,由于许多客户端 - 服务器应用程序的客户端不保留状态,我们还描述了一种将结果RL-SFE协议转换为无状态的方法。作为一个案例研究,我们仔细看看哈瓦和林德尔的绝密多项式评价(OPE)协议,表明它是致力于和实例化的速率有限的变体。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号