Brief Announcement: Federated Code Auditing and Delivery for MPC

Brief Announcement: Federated Code Auditing and Delivery for MPC
复制标题

简短公告:MPC 的联合代码审计和交付

DOI:
10.1007/978-3-319-69084-1_20
复制
发表时间:
2017
期刊:
and Security of Distributed Systems
影响因子:
--
通讯作者:
Varia, Mayank
Varia, Mayank
中科院分区:
--
文献类型:
--
作者:
Jansen, Frederick;Dak Albab, Kinan;Lapets, Andrei;Varia, Mayank

文献摘要

参考文献

被引文献

相似文献

安全多方计算(MPC)是一种加密原语,它使多方能够在其集体私有数据集上联合计算。MPC的目标是在若干计算实体上联合信任,使得大阈值(例如,大多数)必须在敏感或私人输入数据被破坏之前串通。在过去的十年中,已经开发了几个通用和专用软件框架,这些框架为数据贡献者提供了控制权,可以决定信任谁来执行计算和(单独)接收输出。然而,一个关键的组件仍然集中在所有现有的MPC框架中:MPC软件应用程序本身的分发。对于桌面应用程序,必须在下载时确定对代码的信任。对于每次使用都受信任的基于Web的JavaScript应用程序,跨多个MPC调用的所有数据贡献者必须在单个代码交付服务中保持集中的信任。在这项工作中,我们设计并实现了一个基于Web的MPC的联邦代码交付机制,使数据贡献者只执行已被几个可信的审计员认可的代码(贡献者中止,如果没有达成共识)。我们的客户端Chrome浏览器扩展程序独立于任何MPC方案,并且具有少于100行代码的可信计算基础。
Secure multi-party computation (MPC) is a cryptographic primitive that enables several parties to compute jointly over their collective private data sets. MPC’s objective is to federate trust over several computing entities such that a large threshold (e.g., a majority) must collude before sensitive or private input data can be breached. Over the past decade, several general and special-purpose software frameworks have been developed that provide data contributors with control over deciding whom to trust to perform the calculation and (separately) to receive the output. However, one crucial component remains centralized within all existing MPC frameworks: the distribution of the MPC software application itself. For desktop applications, trust in the code must be determined once at download time. For web-based JavaScript applications subject to trust on every use, all data contributors across several invocations of MPC must maintain centralized trust in a single code delivery service. In this work, we design and implement a federated code delivery mechanism for web-based MPC such that data contributors only execute code that has been accredited by several trusted auditors (the contributor aborts if consensus is not reached). Our client-side Chrome browser extension is independent of any MPC scheme and has a trusted computing base of fewer than 100 lines of code.
爱沙尼亚税务和海关委员会如何评估基于安全多方计算的税务欺诈检测系统
DOI: --
发表时间: 2015
期刊: Financial Cryptography
影响因子: --
作者:
D. Bogdanov;Marko Jõemets;Sander Siim;Meril Vaht
通讯作者: Meril Vaht
以用户为中心的分布式隐私保护分析解决方案
DOI: --
发表时间: 2017
影响因子: 22.7
作者:
Azer Bestavros;A. Lapets;Mayank Varia
通讯作者: Mayank Varia
作为 Web 应用程序进行分析的安全 MPC
DOI: --
发表时间: 2016
期刊: IEEE Cybersecurity Development
影响因子: --
作者:
A. Lapets;Nikolaj Volgushev;Azer Bestavros;Frederick Jansen;Mayank Varia
通讯作者: Mayank Varia
DOI: 10.1145/359168.359176
发表时间: 1979-01-01
影响因子: 22.7
作者:
SHAMIR, A
通讯作者: SHAMIR, A
SCAPI:安全计算应用程序编程接口
DOI: --
发表时间: 2012
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Yael Ejgenberg;Moriya Farbstein;Meital Levy;Yehuda Lindell
通讯作者: Yehuda Lindell