Non-committing Encryption from Φ-hiding

Non-committing Encryption from Φ-hiding
复制标题

DOI:
10.1007/978-3-662-46494-6_24
复制
发表时间:
2015-03
期刊:
--
影响因子:
--
通讯作者:
B. Hemenway;R. Ostrovsky;Alon Rosen
B. Hemenway;R. Ostrovsky;Alon Rosen
中科院分区:
其他
文献类型:
--
作者:
B. Hemenway;R. Ostrovsky;Alon Rosen

文献摘要

被引文献

相似文献

一个多方计算协议被称为是自适应安全的,如果它保持其安全性,即使在存在的对手谁可以腐败的参与者作为协议的进展。这与静态破坏模型相反,在静态破坏模型中,对手被迫在协议开始之前选择要破坏哪些参与者。构造自适应安全协议的核心工具是非提交加密(Canetti,Feige,Goldreich和Naor,STOC '96)。Canetti等人的原始协议具有在安全参数中为二次的密文扩展,并且在这项工作之前,最知名的构造具有在安全参数中为线性的密文扩展。在这项工作中,我们提出了第一个非提交加密方案,实现了密文扩展是对数的消息长度。我们的建设有最佳轮复杂度(2轮),其中(正如在所有以前的建设)的第一个消息由一个大小的公钥,其中是消息长度和λ是安全参数。第二条消息由大小为的密文组成。基于Φ-隐藏问题证明了该方案的安全性。
A multiparty computation protocol is said to be adaptively secure if it retains its security even in the presence of an adversary who can corrupt participants as the protocol proceeds. This is in contrast to the static corruption model where the adversary is forced to choose which participants to corrupt before the protocol begins.A central tool for constructing adaptively secure protocols is noncommitting encryption (Canetti, Feige, Goldreich and Naor, STOC ’96). The original protocol of Canetti et al. had ciphertext expansion that was quadratic in the security parameter, and prior to this work, the best known constructions had ciphertext expansion that was linear in the security parameter. In this work, we present the first non-committing encryption scheme that achieves ciphertext expansion that is logarithmic in the message length.Our construction has optimal round complexity (2-rounds), where (just as in all previous constructions) the first message consists of a public-key of sizewherenis the message length andλis the security parameter. The second message consists of a ciphertext of size. The security of our scheme is proved based on the Φ-hiding problem.