Secure Two-Party Computation with Fairness - A Necessary Design Principle

Secure Two-Party Computation with Fairness - A Necessary Design Principle
复制标题

安全、公平的两方计算——必要的设计原则

DOI:
--
复制
发表时间:
2017
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
T. Rabin
T. Rabin
中科院分区:
--
文献类型:
--
作者:
Yehuda Lindell;T. Rabin

文献摘要

被引文献

相似文献

用于安全两方计算的协议使相互不信任的双方能够对他们的私有输入执行联合计算,而不会泄露除输出之外的任何信息。考虑到的一个重要的安全属性是公平性,它保证如果一方学习了输出,另一方也会学习。在两方计算的情况下,公平并不总是可能的,尤其是双方不能公平地掷硬币(Cleve,1986)。尽管如此,实际上还是有可能安全地计算许多公平的两方函数(Gordon等人,2008年和后续工作)。然而,所有已知的实现公平的双方协议都具有唯一的属性,即在协议中的任意点确定被破坏方的有效输入。这与几乎所有其他已知的协议形成了鲜明的对比,这些协议有一个明确的固定回合,输入是在哪个回合提交的。
Protocols for secure two-party computation enable a pair of mutually distrustful parties to carry out a joint computation of their private inputs without revealing anything but the output. One important security property that has been considered is that of fairness which guarantees that if one party learns the output then so does the other. In the case of two-party computation, fairness is not always possible, and in particular two parties cannot fairly toss a coin (Cleve, 1986). Despite this, it is actually possible to securely compute many two-party functions with fairness (Gordon et al., 2008 and follow-up work). However, all known two-party protocols that achieve fairness have the unique property that the effective input of the corrupted party is determined at an arbitrary point in the protocol. This is in stark contrast to almost all other known protocols that have an explicit fixed round at which the inputs are committed.