Lightweight, Maliciously Secure Verifiable Function Secret Sharing

Lightweight, Maliciously Secure Verifiable Function Secret Sharing
复制标题

轻量级、恶意安全、可验证功能秘密共享

DOI:
--
复制
发表时间:
2022
期刊:
International Conference on the Theory and Application of Cryptographic Techniques
影响因子:
--
通讯作者:
Anitgoni Polychroniadou
Anitgoni Polychroniadou
中科院分区:
--
文献类型:
--
作者:
Leo de Castro;Anitgoni Polychroniadou

文献摘要

参考文献

被引文献

相似文献

.在这项工作中,我们提出了一个轻量级的可验证的两方函数秘密共享(FSS)的点函数和多点函数的建设。我们的验证方法在两个方面是轻量级的。首先,它是具体高效的,只使用对称密钥操作,而不涉及公钥或MPC技术。我们的性能与最先进的不可验证的DPF构造相当,并且我们在计算和通信复杂性方面优于所有先前的DPF验证技术,我们通过实现我们的方案来证明这一点。其次,我们的核查程序基本上不受限制。它将验证分布式点函数(DPF)份额对应于某个点函数,而不管输出组大小、DPF输出的结构或DPF必须在其上进行评估的点集。这与先前的作品形成鲜明对比,先前的作品依赖于至少一个并且通常是所有三个约束。此外,我们的构造是第一个DPF验证协议,可以验证一般的DPF,同时保持安全,即使一个服务器是恶意的。先前关于恶意安全DPF验证的工作只能验证非零输出为二进制且输出空间为大字段的DPF。作为一个额外的功能,我们的验证过程可以进行批处理,以便验证多项式数量的DPF共享需要与验证一对DPF共享完全相同的通信量。我们结合联合收割机这种包装DPF验证与一种新的方法包装DPF到一个多点函数的份额,其中的评估时间,验证时间,和验证通信是独立的非零点的功能的数量。和PSI,当三方中的任何一方是恶意的(客户端或服务器之一)时仍然安全。
. In this work, we present a lightweight construction of verifiable two-party function secret sharing (FSS) for point functions and multi-point functions. Our verifiability method is lightweight in two ways. Firstly, it is concretely efficient, making use of only symmetric key operations and no public key or MPC techniques are involved. Our performance is comparable with the state-of-the-art non-verifiable DPF constructions, and we outperform all prior DPF verification techniques in both computation and communication complexity, which we demonstrate with an implementation of our scheme. Secondly, our verification procedure is essentially unconstrained. It will verify that distributed point function (DPF) shares correspond to some point function irrespective of the output group size, the structure of the DPF output, or the set of points on which the DPF must be evaluated. This is in stark contrast with prior works, which depend on at least one and often all three of these constraints. In addition, our construction is the first DPF verification protocol that can verify general DPFs while remaining secure even if one server is malicious. Prior work on maliciously secure DPF verification could only verify DPFs where the non-zero output is binary and the output space is a large field. As an additional feature, our verification procedure can be batched so that verifying a polynomial number of DPF shares requires the exact same amount of communication as verifying one pair of DPF shares. We combine this packed DPF verification with a novel method for packing DPFs into shares of a multi-point function where the evaluation time, verification time, and verification communication are independent of the number of non-zero points in the function. and PSI that remain secure when any one of the three parties is malicious (either the client or one of the servers).
DOI: 10.1145/3319535.3363228
发表时间: 2019-11
期刊: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Phillipp Schoppmann;Adrià Gascón;Leonie Reichert;Mariana Raykova
通讯作者: Phillipp Schoppmann;Adrià Gascón;Leonie Reichert;Mariana Raykova