Lightweight, Maliciously Secure Verifiable Function Secret Sharing
Lightweight, Maliciously Secure Verifiable Function Secret Sharing
复制标题
轻量级、恶意安全、可验证功能秘密共享
DOI:
--
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Anitgoni Polychroniadou
中科院分区:
文献类型:
--
作者:
Leo de Castro;Anitgoni Polychroniadou
. In this work, we present a lightweight construction of verifiable two-party function secret sharing (FSS) for point functions and multi-point functions. Our verifiability method is lightweight in two ways. Firstly, it is concretely efficient, making use of only symmetric key operations and no public key or MPC techniques are involved. Our performance is comparable with the state-of-the-art non-verifiable DPF constructions, and we outperform all prior DPF verification techniques in both computation and communication complexity, which we demonstrate with an implementation of our scheme. Secondly, our verification procedure is essentially unconstrained. It will verify that distributed point function (DPF) shares correspond to some point function irrespective of the output group size, the structure of the DPF output, or the set of points on which the DPF must be evaluated. This is in stark contrast with prior works, which depend on at least one and often all three of these constraints. In addition, our construction is the first DPF verification protocol that can verify general DPFs while remaining secure even if one server is malicious. Prior work on maliciously secure DPF verification could only verify DPFs where the non-zero output is binary and the output space is a large field. As an additional feature, our verification procedure can be batched so that verifying a polynomial number of DPF shares requires the exact same amount of communication as verifying one pair of DPF shares. We combine this packed DPF verification with a novel method for packing DPFs into shares of a multi-point function where the evaluation time, verification time, and verification communication are independent of the number of non-zero points in the function. and PSI that remain secure when any one of the three parties is malicious (either the client or one of the servers).
DOI:
10.1145/3319535.3363228
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Phillipp Schoppmann;Adrià Gascón;Leonie Reichert;Mariana Raykova
通讯作者:
Phillipp Schoppmann;Adrià Gascón;Leonie Reichert;Mariana Raykova