Concurrent Secure Computation with Optimal Query Complexity
Concurrent Secure Computation with Optimal Query Complexity
复制标题
DOI:
10.1007/978-3-662-48000-7_3
复制
发表时间:
2015-08
期刊:
影响因子:
--
通讯作者:
R. Canetti;Vipul Goyal;Abhishek Jain
中科院分区:
文献类型:
--
作者:
R. Canetti;Vipul Goyal;Abhishek Jain
The multiple ideal query (MIQ) model [Goyal, Jain, and Ostrovsky, Crypto’10] offers a relaxed notion of security for concurrent secure computation, where the simulator is allowed to query the ideal functionalitymultiple times per session(as opposed to just once in the standard definition). The model provides a quantitative measure for the degradation in security under concurrent self-composition, where the degradation is measured by the number of ideal queries. However, to date, all known MIQ-secure protocols guarantee only an overallaveragebound on the number of queries per session throughout the execution, thus allowing the adversary to potentially fully compromise some sessions of its choice. Furthermore, [Goyal and Jain, Eurocrypt’13] rule out protocols where the simulator makes only an adversary-independent constant number of ideal queries per session.We show the first MIQ-secure protocol with worst-case per-session guarantee. Specifically, we show a protocol for any functionality that matches the [GJ13] bound: The simulator makes only aconstantnumber of ideal queries ineverysession. The constant depends on the adversary but is independent of the security parameter.As an immediate corollary of our main result, we obtain the first password authenticated key exchange (PAKE) protocol for the fully concurrent, multiple password setting in the standard model with no set-up assumptions.