首页> 外文会议>Annual International Cryptology Conference >Adaptively Secure Garbled Circuits from One-Way Functions
【24h】

Adaptively Secure Garbled Circuits from One-Way Functions

机译:从单向功能自适应地固定乱码电路

获取原文

摘要

A garbling scheme is used to garble a circuit C and an input x in a way that reveals the output C(x) but hides everything else. In many settings, the circuit can be garbled off-line without strict efficiency constraints, but the input must be garbled very efficiently on-line, with much lower complexity than evaluating the circuit. Yao's garbling scheme [31] has essentially optimal on-line complexity, but only achieves selective security, where the adversary must choose the input x prior to seeing the garbled circuit. It has remained an open problem to achieve adaptive security, where the adversary can choose x after seeing the garbled circuit, while preserving on-line efficiency. In this work, we modify Yao's scheme in a way that allows us to prove adaptive security under one-way functions. In our main instantiation we achieve on-line complexity only proportional to the width w of the circuit. Alternatively we can also get an instantiation with on-line complexity only proportional to the depth d (and the output size) of the circuit, albeit incurring in a 2~(O(d)) security loss in our reduction. More broadly, we relate the on-line complexity of adaptively secure garbling schemes in our framework to a certain type of pebble complexity of the circuit. As our main tool, of independent interest, we develop a new notion of somewhere equivocal encryption, which allows us to efficiently equivocate on a small subset of the message bits.
机译:摇摇欲坠的方案用于以揭示输出C(x)的方式摇动电路C和输入X,但是隐藏其他一切。在许多设置中,电路可以在没有严格的效率约束的情况下乱码,但输入必须在线上非常有效地乱码,复杂性远低于评估电路。姚明的摇摇欲坠方案[31]具有基本上最佳的在线复杂性,但仅实现了选择性安全性,在看到乱码的电路之前必须选择输入X.实现自适应安全性仍然是一个开放的问题,而对手可以在看到乱码电路后选择x,同时保持在线效率。在这项工作中,我们以一种方式修改姚明的方案,使我们能够在单向函数下证明适应性安全性。在我们的主要实例化中,我们在线复杂性仅与电路的宽度W成比例。或者,我们还可以在线复杂度实例,仅与电路的深度d(和输出大小)成比例,尽管在减少的2〜(d))安全损失中仍然存在。更广泛地,我们在我们的框架中涉及自适应安全的摇摇欲坠方案的在线复杂性,以某种类型的电路卵石复杂性。作为我们的主要工具,独立兴趣,我们开发了某个地点的新概念,该概念等待着加密,这使我们能够有效地在消息比特的小子集上实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号