Black-Box Constructions of Protocols for Secure Computation

Black-Box Constructions of Protocols for Secure Computation
复制标题

安全计算协议的黑盒构造

DOI:
--
复制
发表时间:
2011
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
E. Petrank
E. Petrank
中科院分区:
--
文献类型:
--
作者:
Iftach Haitner;Yuval Ishai;E. Kushilevitz;Yehuda Lindell;E. Petrank

文献摘要

被引文献

相似文献

在本文中,我们研究了一个问题,即在恶意对手的情况下是否可以为一般安全计算构建协议,并且没有诚实的多数,这些诚实的多数席位使用基础原始原始(例如增强的陷阱置换量),以黑盒的方式使用仅有的。到目前为止,此设置的所有已知常规构造都是固有的非黑盒,因为它们要求当事方证明与基础原始原始性计算相关的零知识语句。我们的主要技术结果是从对恶意当事方的安全转移到安全方案的安全转让,并与Security对Semihonest政党进行安全转让。作为推论,我们获得了一般多方协议的第一个结构(具有针对恶意对手的安全性,而没有诚实多数),这些构造只能使黑盒使用半honemest遗忘的转移,或者是对低级基础的黑盒子的使用例如增强的板门排列或同形加密。为了构建此减少,我们在存在可辩护的对手的情况下引入了一种称为隐私的新型安全概念。该概念指出,如果对手可以产生(协议终止之后)的输入和随机磁带,使其动作看起来很诚实,那么它可以保证它不过是学到的,只有其规定的输出。然后,我们展示了如何以黑盒方式构建从半洪遗嘱的转移中构建可辩护的遗忘转移,以及从可辩护的遗忘转移中构建恶意的遗忘转移。
In this paper, we study the question of whether or not it is possible to construct protocols for general secure computation in the setting of malicious adversaries and no honest majority that use the underlying primitive (e.g., enhanced trapdoor permutation) in a black-box way only. Until now, all known general constructions for this setting were inherently non-black-box since they required the parties to prove zero-knowledge statements that are related to the computation of the underlying primitive. Our main technical result is a fully black-box reduction from oblivious transfer with security against malicious parties to oblivious transfer with security against semihonest parties. As a corollary, we obtain the first constructions of general multiparty protocols (with security against malicious adversaries and without an honest majority) which make only a black-box use of semihonest oblivious transfer, or alternatively a black-box use of lower-level primitives such as enhanced trapdoor permutations or homomorphic encryption. In order to construct this reduction we introduce a new notion of security called privacy in the presence of defensible adversaries. This notion states that if an adversary can produce (retroactively, after the protocol terminates) an input and random tape that make its actions appear to be honest, then it is guaranteed that it learned nothing more than its prescribed output. We then show how to construct defensible oblivious transfer from semihonest oblivious transfer, and malicious oblivious transfer from defensible oblivious transfer, all in a black-box way.