Secure Two-Party Computation with Fairness - A Necessary Design Principle
Secure Two-Party Computation with Fairness - A Necessary Design Principle
复制标题
安全、公平的两方计算——必要的设计原则
DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
T. Rabin
中科院分区:
文献类型:
--
作者:
Yehuda Lindell;T. Rabin
Protocols for secure two-party computation enable a pair of mutually distrustful parties to carry out a joint computation of their private inputs without revealing anything but the output. One important security property that has been considered is that of fairness which guarantees that if one party learns the output then so does the other. In the case of two-party computation, fairness is not always possible, and in particular two parties cannot fairly toss a coin (Cleve, 1986). Despite this, it is actually possible to securely compute many two-party functions with fairness (Gordon et al., 2008 and follow-up work). However, all known two-party protocols that achieve fairness have the unique property that the effective input of the corrupted party is determined at an arbitrary point in the protocol. This is in stark contrast to almost all other known protocols that have an explicit fixed round at which the inputs are committed.