Size-Hiding Computation for Multiple Parties

Size-Hiding Computation for Multiple Parties
复制标题

DOI:
10.1007/978-3-662-53890-6_31
复制
发表时间:
2016-12
期刊:
--
影响因子:
--
通讯作者:
Kazumasa Shinagawa;K. Nuida;T. Nishide;Goichiro Hanaoka;E. Okamoto
Kazumasa Shinagawa;K. Nuida;T. Nishide;Goichiro Hanaoka;E. Okamoto
中科院分区:
其他
文献类型:
--
作者:
Kazumasa Shinagawa;K. Nuida;T. Nishide;Goichiro Hanaoka;E. Okamoto

文献摘要

被引文献

相似文献

Lindell,Nissim和Orlandi(ASIACRYPT 2013)研究了一般两方协议的可行性和不可行性,这些协议不仅隐藏了各方输入的内容,还隐藏了输入和/或输出的某些大小。在本文中,我们将他们的结果推广到一方协议,并证明了它是不可行的,以安全地计算每个功能,同时隐藏两个或两个以上(输入或输出)的大小。然后,为了规避不可行性,我们自然地扩展了通信模型,使任何对手都无法了解消息的内容,也无法了解诚实方之间交换的比特数。我们注意到,即使使用我们的“大小隐藏“通道,这种“大小隐藏“计算也不是一个微不足道的问题,因为某些函数的大小隐藏计算仍然是不可行的,正如我们在文中所示。然后,作为我们的主要结果,我们给出了一个必要和充分条件的可行性大小隐藏计算的任意函数,在输入和输出的大小必须隐藏从thenparties。特别是,现在可以让每个输入/输出大小对某些方隐藏,而以前的模型只允许隐藏最多一个输入的大小。我们的结果是基于一个安全模型略强于诚实但好奇的模型。
Lindell, Nissim, and Orlandi (ASIACRYPT 2013) studied feasibility and infeasibility of general two-party protocols that hide not only the contents of the inputs of parties, but also some sizes of the inputs and/or the output. In this paper, we extend their results ton-party protocols for, and prove that it is infeasible to securely compute every function while hiding two or more (input or output) sizes. Then, to circumvent the infeasibility, we naturally extend the communication model in a way that any adversary can learn neither the contents of the messages nor the numbers of bits exchanged among honest parties. We note that such “size-hiding”computation is never a trivial problem even by using our “size-hiding”channel, since size-hiding computation of some function remains infeasible as we show in the text. Then, as our main result, we give a necessary and sufficient condition for feasibility of size-hiding computation of an arbitrary function, in terms of which of the input and output sizes must be hidden from which of thenparties. In particular, it is now possible to let each input/output size be hidden from some parties, while the previous model only allows the size of at most one input to be hidden. Our results are based on a security model slightly stronger than the honest-but-curious model.