安全多方计算公平性问题分析-analysis of fairness in secure multi-party computing.docx

安全多方计算公平性问题分析-analysis of fairness in secure multi-party computing.docx

安全多方计算公平性问题分析-analysis of fairness in secure multi-party computing

模型严格地形式化证明。和GradRel构造(从公开文献看,它是唯一的“承诺-证明-公平-打开”协议)相比,新协议具有两点优势:计算量及通信量不到GradRel构造的1/5,并且克服了GradRel构造的另一弱点——承诺值不可以为0。接着,基于协议NewGradRel,以及Camenisch-Shoup(CS)/SimplifiedCamenisch-Shoup(sCS)密码体制、CS/sCS承诺协议、承诺不经意传输协议,我们构造了一个抵抗恶意敌手的公平姚加密电路协议RsFairS2PC,新协议不仅具有协议FairS2PC的所有优点,并且其安全性可以基于资源公平的理想/现实世界仿真模型严格地形式化证明。从公开文献看,RsFairS2PC协议首次解决了公平安全两方计算协议在UC框架下的构造与形式化证明问题。此外,我们引入了“承诺-证明-公平-打开”函数的一个变种——“承诺-证明-诚实-公平-打开”函数(FCPHFO),并基于FCPHFO函数构造了抵抗恶意敌手的资源公平的安全两方抛币协议,新协议的优势是其偏差为0,且遵循标准仿真模型形式化证明了其安全性。关键词:安全多方计算,公平安全多方计算,姚加密电路协议,时控承诺,资源公平AbstractSecuremulti-partycomputation(SMPC)isoneofthehottopicsinmoderncryptography.Generally,SMPCdealswithcomputinganarbitrarydesiredfunctionalityf(x1,,xn)??(O1,,On)amongnmutuallyuntrustedpartiesP1,,Pn,whereeachpartyPiholdshisprivateinputxiandwantstoknowtheoutputOiwithoutleakingtoothersanyadditionalinformation.Thedesignofanycryptographicschemeoranycooperativecomputationmaybeviewedasthedesignofasecureprotocolforimplementingasuitablefunctionality.FairnessisaverydesirablepropertyindesigningsuchSMPCprotocols,it’sveryimportantinmanyapplicationssuchasfair(secret)exchange,e-contractnegotiation,andsoon.Informally,aprotocolisfairifeitherallthepartiesknowtheir(private)outputs,ornoneofthemknowsanything.TimedcommitmentisacryptographictoolfortheconstructionoffairSMPCprotocols.First,weconstructedanefficienttimedcommitmentandanefficientgradualreleasetimedcommitmentbasedonPedersencommitmentandtime-linestechnique.Thesetwoprotocolsbothhadtwoadvantadgesthattheyweremoreefficientthanothertimedcommitmentprotocolsandhadanotherimportantproperty:homomorphism.Then,basedonournewgradualreleasetimedcommitment,Pedersencommitment,andcommittedoblivioustransfer,weproposedafairSMPCprotocol,FairS2PC,whichwasafairandsecureYao’sgarbledcircuitprotocolagainstthemaliviousadversary.FairS2PCdidn’trequiredanytrustedthirdpartytobeinvolvedwhichisveryimportantinmanyapplications;itwasmoreefficientthanotherprotocolsaccordingtothegradualreleasemodel,especiallyforthebandwidth.Timedcommitmentcouldbealsousedto

您可能关注的文档

文档评论(0)

1亿VIP精品文档

相关文档