Actively Secure Half-Gates with Minimum Overhead under Duplex Networks

Actively Secure Half-Gates with Minimum Overhead under Duplex Networks
复制标题

DOI:
10.1007/978-3-031-30617-4_2
复制
发表时间:
2023
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Hongrui Cui;Xiao Wang;Kang Yang;Yu Yu-Yu
Hongrui Cui;Xiao Wang;Kang Yang;Yu Yu-Yu
中科院分区:
其他
文献类型:
--
作者:
Hongrui Cui;Xiao Wang;Kang Yang;Yu Yu-Yu

文献摘要

相似文献

主动安全的两方计算(2PC)是现代密码学中的一个典型构件。与半诚实2PC协议相比,设计主动安全2PC协议的一个主要目标是减少通信开销。本文提出了一个新的主动安全的常数轮2PC协议,它具有每个与门单向通信位数(位计算安全和任何统计安全),本质上与单向通信的半诚实半门协议相匹配。这是通过两种新技术来实现的:Dittmer等人最近的压缩技术(Crypto 2022)表明,宽松的预处理对于认证的乱码是足够的,不会向乱码者透露被掩蔽的线值。本文提出了一种新的认证位形式,并提出了一种新的认证与三元组的生成技术,将预处理的单向通信量从位压缩到每与门2位,以保证位的统计安全性。我们设计了一个新的认证混淆,不使用信息理论MAC,而是双重执行无泄漏认证电路中的线值。这使得我们可以使用一个更紧凑的半门的认证乱码电路的大小每个与门,同时保持兼容的压缩技术。我们的新技术可以实现每个与门位的单向通信。我们的产生认证AND三元组的技术也可以用来优化双向通信(即,总通信)通过将其与Dittmer等人的认证的乱码电路相结合,这导致了每个与门具有位的双向通信的主动安全2PC协议。
Actively secure two-party computation (2PC) is one of the canonical building blocks in modern cryptography. One main goal for designing actively secure 2PC protocols is to reduce the communication overhead, compared to semi-honest 2PC protocols. In this paper, we propose a new actively secure constant-round 2PC protocol with one-way communication ofbits per AND gate (for-bit computational security and any statistical security), essentially matching the one-way communication of semi-honest half-gates protocol. This is achieved by two new techniques:The recent compression technique by Dittmer et al. (Crypto 2022) shows that a relaxed preprocessing is sufficient for authenticated garbling that does not reveal masked wire values to the garbler. We introduce a new form of authenticated bits and propose a new technique of generating authenticated AND triples to reduce the one-way communication of preprocessing frombits to 2 bits per AND gate for-bit statistical security.Unfortunately, the above compressing technique is only compatible with a less compact authenticated garbled circuit of sizebits per AND gate. We designed a new authenticated garbling that does not use information theoretic MACs but rather dual execution without leakage to authenticate wire values in the circuit. This allows us to use a more compact half-gates based authenticated garbled circuit of sizebits per AND gate, and meanwhile keep compatible with the compression technique. Our new technique can achieve one-way communication ofbits per AND gate.Our technique of yielding authenticated AND triples can also be used to optimize the two-way communication (i.e., the total communication) by combining it with the authenticated garbled circuits by Dittmer et al., which results in an actively secure 2PC protocol with two-way communication ofbits per AND gate.