Non-Interactive MPC with Trusted Hardware Secure Against Residual Function Attacks

Non-Interactive MPC with Trusted Hardware Secure Against Residual Function Attacks
复制标题

具有可信硬件的非交互式 MPC 可抵御残留功能攻击

DOI:
--
复制
发表时间:
2019
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Taeho Jung
Taeho Jung
中科院分区:
--
文献类型:
--
作者:
Ryan Karl;Timothy Burchfield;Jonathan Takeshita;Taeho Jung

文献摘要

被引文献

相似文献

对安全多方计算(MPC)进行了反复优化,实现了具有两轮通信和强安全保证的协议。虽然已经在构建仅具有一轮在线通信的非交互式协议(即,非交互式MPC或NI-MPC),由于必须仅用一轮来保证正确的评估,因此这些协议本质上易受标准模型中的残差函数攻击的影响。这是因为接收乱码电路的一方可能会在本地重复评估电路,同时改变自己的输入并固定其他参与者的输入以学习其他参与者输入的值。我们提出了第一个MPC协议与一轮在线阶段,是安全的剩余函数攻击。我们还提出了严格的证据的正确性和安全性的隐蔽对手模型,减少恶意模型,是强于半诚实的模型,更适合于在真实的世界中的行为建模的各方,我们的协议。此外,我们严格地分析了目前最先进的协议,需要两轮通信或一轮在网上阶段的安全性要求降低,通信和计算的复杂性,并证明我们的协议是可比的或优于他们的复杂性。
Secure multiparty computation (MPC) has been repeatedly optimized, and protocols with two communication rounds and strong security guarantees have been achieved. While progress has been made constructing non-interactive protocols with just one-round of online communication (i.e., non-interactive MPC or NI-MPC), since correct evaluation must be guaranteed with only one round, these protocols are by their nature vulnerable to the residual function attack in the standard model. This is because a party that receives a garbled circuit may repeatedly evaluate the circuit locally, while varying their own inputs and fixing the inputs of others to learn the values entered by other participants. We present the first MPC protocol with a one-round online phase that is secure against the residual function attack. We also present rigorous proofs of correctness and security in the covert adversary model, a reduction of the malicious model that is stronger than the semi-honest model and better suited for modeling the behaviour of parties in the real world, for our protocol. Furthermore, we rigorously analyze the communication and computational complexity of current state of the art protocols which require two rounds of communication or one round during the online-phase with a reduced security requirement, and demonstrate that our protocol is comparable to or outperforms their complexity.