Adaptively Secure Broadcast

Adaptively Secure Broadcast
复制标题

自适应安全广播

DOI:
10.1007/978-3-642-13190-5_24
复制
发表时间:
2010
期刊:
2021 IEEE 46th Conference on Local Computer Networks (LCN)
影响因子:
--
通讯作者:
Vassilis Zikas
Vassilis Zikas
中科院分区:
--
文献类型:
--
作者:
M. Hirt;Vassilis Zikas

文献摘要

被引文献

相似文献

广播协议允许发送者通过点对点网络将消息分发给一组参与方,从而(I)所有参与方接收相同的消息,即使发送者被破坏,并且(Ii)这是发送者的消息,如果发送者是诚实的。满足这些性质的广播协议是已知存在的,当且仅当t;n/3,其中n表示各方的总数,t表示最大破坏数。当允许签名的设置对双方可用时,即使对于t<n,这样的协议也存在。 自[LSP82]发明以来,广播已被用作众多多方协议的原语,使其成为分布式协议文献中的基本原语之一。在一个模型中分析了这些协议的安全性,其中假定广播原语的行为方式是理想的。显然,广播的定义应该允许安全的组合,也就是说,用满足该定义的协议替换假定的广播原语应该是安全的。根据最近的密码推理,为了允许安全合成,广播的理想行为可以被描述为理想的功能,并且可以使用基于模拟的定义。 在这项工作中,我们证明了基于属性的广播定义并不意味着基于模拟的自然广播功能的定义。事实上,文献中的大多数广播协议没有安全地实现这一功能,这就提出了这些广播协议的可组合性问题。具体地,我们不知道可以在安全信道模型中的多方计算协议中安全地调用的任何广播协议。问题在于,现有的广播协议在广播消息时不保护消息的保密性,尤其是允许对手破坏发送者(并更改消息),这取决于正在广播的消息。例如,当每一方都应该广播随机比特时,对手可能破坏那些打算广播0的方,并使它们广播1。 更具体地说,我们证明了在具有安全信道的模型中模拟广播是可能的,当且仅当当签名设置可用时,分别t<n/3,t≤n/2。通过构造安全的广播协议,验证了该协议的有效性。
A broadcast protocol allows a sender to distribute a message through a point-to-point network to a set of parties, such that (i) all parties receive the same message, even if the sender is corrupted, and (ii) this is the sender’s message, if he is honest. Broadcast protocols satisfying these properties are known to exist if and only if t<n/3, where n denotes the total number of parties, and t denotes the maximal number of corruptions. When a setup allowing signatures is available to the parties, then such protocols exist even for t<n. Since its invention in [LSP82], broadcast has been used as a primitive in numerous multi-party protocols making it one of the fundamental primitives in the distributed-protocols literature. The security of these protocols is analyzed in a model where a broadcast primitive which behaves in an ideal way is assumed. Clearly, a definition of broadcast should allow for secure composition, namely, it should be secure to replace an assumed broadcast primitive by a protocol satisfying this definition. Following recent cryptographic reasoning, to allow secure composition the ideal behavior of broadcast can be described as an ideal functionality, and a simulation-based definition can be used. In this work, we show that the property-based definition of broadcast does not imply the simulation-based definition for the natural broadcast functionality. In fact, most broadcast protocols in the literature do not securely realize this functionality, which raises a composability issue for these broadcast protocols. In particular, we do not know of any broadcast protocol which could be securely invoked in a multi-party computation protocol in the secure-channels model. The problem is that existing protocols for broadcast do not preserve the secrecy of the message while being broadcasted, and in particular allow the adversary to corrupt the sender (and change the message), depending on the message being broadcasted. For example, when every party should broadcast a random bit, the adversary could corrupt those parties who intend to broadcast 0, and make them broadcast 1. More concretely, we show that simulatable broadcast in a model with secure channels is possible if and only if t<n/3, respectively t≤n/2 when a signature setup is available. The positive results are proven by constructing secure broadcast protocols.