On the (Ir)Replaceability of Global Setups, or How (Not) to Use a Global Ledger

On the (Ir)Replaceability of Global Setups, or How (Not) to Use a Global Ledger
复制标题

DOI:
10.1007/978-3-030-90453-1_22
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Christian Badertscher;Julia Hesse;Vassilis Zikas
Christian Badertscher;Julia Hesse;Vassilis Zikas
中科院分区:
其他
文献类型:
--
作者:
Christian Badertscher;Julia Hesse;Vassilis Zikas

文献摘要

相似文献

在通用可组合(UC)安全中,全局设置旨在捕获可由多个协议访问的原语的理想行为,允许它们共享状态。一个典型的例子是Bitcoin ledger。事实上,由于比特币-以及更普遍的区块链分类账-在各种情况下都很有用,因此捕获这种分类账作为全局设置变得越来越流行。直觉上,人们会期望UC允许我们对使用这种全局设置的协议进行安全声明,例如,一个全局分类账,然后可以自动转换为设置,其中设置被替换为实现它的协议,如Bitcoin.我们表明,上述推理是有缺陷的,这样一个通用的安全保护替换只能在全局设置和安全声明的非常(通常是不现实的)强的条件下工作。例如,Badertscheret等人证明了比特币实现账本的UC安全性。[2017年9月17日]本身并不足以让我们在作为全球设置时用比特币取代账本。特别是,我们不能期望在使用比特币作为分类账时,全球分类账混合世界中的所有安全声明都将被保留。从积极的方面来看,我们为使用全球设置的协议提供了安全声明的特征,对于这些协议来说,替换是合理的。我们的研究结果可以被看作是第一个指导如何导航的非常棘手的问题,什么构成了一个“好”的全球设置,以及如何使用它,以保持模块化的协议设计方法的完整性。
In universally composable (UC) security, a global setup is intended to capture the ideal behavior of a primitive which is accessible by multiple protocols, allowing them to share state. A representative example is the Bitcoin ledger. Indeed, since Bitcoin—and more generally blockchain ledgers—are known to be useful in various scenarios, it has become increasingly popular to capture such ledgers as global setup. Intuitively, one would expect UC to allow us to make security statements about protocols that use such a global setup, e.g., a global ledger, which can then be automatically translated into the setting where the setup is replaced by a protocol implementing it, such as Bitcoin.We show that the above reasoning is flawed and such a generic security-preserving replacement can only work under very (often unrealistic) strong conditions on the global setup and the security statement. For example, the UC security of Bitcoin for realizing a ledger proved by Badertscheret al.[CRYPTO’17] isnotsufficient per se to allow us to replace the ledger by Bitcoin when used as a global setup. In particular, we cannot expect that all security statements in the global ledger-hybrid world would be preserved when using Bitcoin as a ledger.On the positive side, we provide characterizations of security statements for protocols that make use of global setups, for which the replacement is sound. Our results can be seen as a first guide on how to navigate the very tricky question of what constitutes a “good” global setup and how to use it in order to keep the modular protocol-design approach intact.