Fair and Robust Multi-party Computation Using a Global Transaction Ledger

Fair and Robust Multi-party Computation Using a Global Transaction Ledger
复制标题

DOI:
10.1007/978-3-662-49896-5_25
复制
发表时间:
2016-05
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
A. Kiayias;Hong-Sheng Zhou;Vassilis Zikas
A. Kiayias;Hong-Sheng Zhou;Vassilis Zikas
中科院分区:
其他
文献类型:
--
作者:
A. Kiayias;Hong-Sheng Zhou;Vassilis Zikas

文献摘要

被引文献

相似文献

安全多方计算(MPC)的经典结果意味着完全安全的计算,包括公平性(所有各方都得到输出或没有)和鲁棒性(输出交付得到保证),是不可能的,除非大多数当事人是诚实的。最近,像比特币这样的加密货币被用来利用MPC中的公平损失来对抗不诚实的大多数。这个想法是,当协议以不公平的方式中止时(即,在对手收到输出后),那么诚实的一方就会得到对手控制的一方的补偿。我们的贡献是三倍的。首先,我们提出了一个新的带补偿的安全MPC的形式化模型,并展示了引入合适的分类账和同步功能如何使使用标准交互式图灵机(ITM)来描述此类协议成为可能,从而避免了像以前的作品那样需要使用标准模型之外的额外功能。其次,我们的模型,表示在通用的组合设置与全球设置,并配备了一个组合定理,使设计的协议,安全地组成彼此和更大的环境中,其他协议与补偿发生的MPC协议的组合定理是未知的。第三,我们介绍了第一个具有补偿的鲁棒MPC协议,即,MPC协议,其中不仅公平性得到保证(通过补偿),而且协议还保证将输出传递给参与的各方,因此在初始一轮存款之后,对手甚至不能够在不遭受金钱惩罚的情况下发起拒绝服务攻击。重要的是,我们强大的MPC协议只需要常数数量的(硬币转移和通信)轮。
Classical results on secure multi-party computation (MPC) imply that fully secure computation, including fairness (either all parties get output or none) and robustness (output delivery is guaranteed), is impossible unless a majority of the parties is honest. Recently, cryptocurrencies like Bitcoin where utilized to leverage the fairness loss in MPC against a dishonest majority. The idea is that when the protocol aborts in an unfair manner (i.e., after the adversary receives output) then honest parties get compensated by the adversarially controlled parties.Our contribution is three-fold. First, we put forth a new formal model of secure MPC with compensation and show how the introduction of suitable ledger and synchronization functionalities makes it possible to describe such protocols using standard interactive Turing machines (ITM) circumventing the need for the use of extra features that are outside the standard model as in previous works. Second, our model, is expressed in the universal composition setting with global setup and is equipped with a composition theorem that enables the design of protocols that compose safely with each other and within larger environments where other protocols with compensation take place; a composition theorem for MPC protocols with compensation was not known before. Third, we introduce the first robust MPC protocol with compensation, i.e., an MPC protocol where not only fairness is guaranteed (via compensation) but additionally the protocol is guaranteed to deliver output to the parties that get engaged and therefore the adversary, after an initial round of deposits, is not even able to mount a denial of service attack without having to suffer a monetary penalty. Importantly, our robust MPC protocol requires only aconstantnumber of (coin-transfer and communication) rounds.