Achieving Correctness in Fair Rational Secret Sharing

Achieving Correctness in Fair Rational Secret Sharing
复制标题

DOI:
10.1007/978-3-319-02937-5_8
复制
发表时间:
2013-11
期刊:
--
影响因子:
--
通讯作者:
S. De;A. K. Pal
S. De;A. K. Pal
中科院分区:
其他
文献类型:
--
作者:
S. De;A. K. Pal

文献摘要

被引文献

相似文献

在理性的秘密分享中,各方可能更愿意误导他人,让他们相信错误的秘密是正确的,而不是每个人都获得了秘密(即公平的结果)。用于非同时信道的现有的有理秘密重建协议仅处理这样的情况,即优选公平的结果而不是误导的结果,因此是公平的但不正确的。阿沙罗夫和林德尔(2010)提出了第一个也是唯一一个兼顾这两种偏好的协议。在本文中,我们提出了一种新的Rational秘密共享协议,该协议在非同时信道模型下既考虑了用户的偏好,又是公平和正确的。此外,它与误导的效用无关。理性的每一方都被给予了一份真实秘密股份和虚假股份的子股名单。在协议的每一轮中,每一方都将其列表中的当前元素发送给另一方,然后从子份额中重建份额。其主要思想是使用原始秘密的一部分作为协议诱导的成员资格辅助信息来检查直到某一轮获得的份额是否可以用于重构正确的秘密。我们通过使用Lysyanskaya和Segal(2010)协议使用的延时加密方案克服了存在辅助信息的缺点,该方案允许玩家使用任意的边信息。在我们的例子中,使用的辅助信息不是任意的,而是由机制/协议设计者引入的,以使所有参与者处于平等的地位。我们证明了在存在协议诱导的辅助信息的情况下,我们的协议是计算严格的纳什均衡。
In rational secret sharing, parties may prefer to mislead others in believing a wrong secret as the correct one over everybody obtaining the secret (i.e. a fair outcome). Prior rational secret reconstruction protocols for non-simultaneous channel only address the case where a fair outcome is preferred over misleading and hence are fair but not correct. Asharov and Lindell (2010) proposed the first and the only protocol that takes care of both the preferences. In this paper, we propose a new rational secret sharing protocol that addresses both the preferences and is fair and correct in the non-simultaneous channel model. Additionally, it is independent of the utility of misleading. Each rational party is given a list of sub-shares of shares of the actual secret and fake shares. In each round of the protocol each party sends the current element in its list to the other party and then reconstructs a share from the sub-shares obtained. The main idea is to use a checking share which is a share of the original secret as a protocol–induced membership auxiliary information to check whether the shares obtained till a certain round can be used to reconstruct the correct secret. We overcome the disadvantages of the presence of auxiliary information by using the time-delayed encryption scheme used by the protocol of Lysyanskaya and Segal (2010) that tolerates players with arbitrary side information. In our case, the side information used is not arbitrary but introduced by the mechanism/protocol designer to put all players on equal footing. We show that our protocol is in computational strict Nash equilibrium in the presence of protocol-induced auxiliary information.