PoS4MPC: Automated Security Policy Synthesis for Secure Multi-party Computation
Yuxin Fan, Fu Song, Taolue Chen, Liangfeng Zhang, Wanwei Liu
Abstract
Abstract Secure multi-party computation (MPC) is a promising technique for privacy-persevering applications. A number of MPC frameworks have been proposed to reduce the burden of designing customized protocols, allowing non-experts to quickly develop and deploy MPC applications. To improve performance, recent MPC frameworks allow users to declare variables secret only for these which are to be protected. However, in practice, it is usually highly non-trivial for non-experts to specify secret variables: declaring too many degrades the performance while declaring too less compromises privacy. To address this problem, in this work we propose an automated security policy synthesis approach to declare as few secret variables as possible but without compromising security. Our approach is a synergistic integration of type inference and symbolic reasoning. The former is able to quickly infer a sound—but sometimes conservative—security policy, whereas the latter allows to identify secret variables in a security policy that can be declassified in a precise manner. Moreover, the results from symbolic reasoning are fed back to type inference to refine the security types even further. We implement our approach in a new tool PoS4MPC. Experimental results on five typical MPC applications confirm the efficacy of our approach.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 85d205c5-9f03-43b7-942e-71c4cace6ef6Cited by top-tier papers1
Ask how each one uses itBuilds on5
- ABY2.0: Improved Mixed-Protocol Secure Two-Party ComputationArpita Patra, Thomas Schneider, Ajith Suresh, Hossein YalameUSENIX Security 2021 · 307 citations
- HyCC: Compilation of Hybrid Protocols for Practical Secure ComputationNiklas Büscher, Daniel Demmler, Stefan Katzenbeisser, David Kretzmer et al.CCS 2018 · 97 citations
- Senate: A Maliciously-Secure MPC Platform for Collaborative AnalyticsRishabh Poddar, Sukrit Kalra, Avishay Yanai, Ryan Deng et al.USENIX Security 2021 · 89 citations
- Precise Detection of Side-Channel Vulnerabilities using Quantitative Cartesian Hoare LogicJia Chen, Yu Feng, Isil DilligCCS 2017 · 74 citations
- MP-SPDZ: A Versatile Framework for Multi-Party ComputationMarcel KellerCCS 2020 · 24 citations
Related papers
- Silph: A Framework for Scalable and Accurate Generation of Hybrid MPC ProtocolsEdward Chen, Jinhao Zhu, Alex Ozdemir, Riad S. Wahby et al.S&P 2023
- Taypsi: Static Enforcement of Privacy Policies for Policy-Agnostic Oblivious ComputationQianchuan Ye, Benjamin DelawareOOPSLA 2024 · 1 citation
- SECRECY: Secure collaborative analytics in untrusted cloudsJohn Liagouris, Vasiliki Kalavri, Muhammad Faisal, Mayank VariaNSDI 2023 · 53 citations
- Metamorphic Testing of Secure Multi-party Computation (MPC) CompilersYichen Li, Dongwei Xiao, Zhibo Liu, Qi Pang et al.FSE 2024 · 5 citations
- SoK: General Purpose Compilers for Secure Multi-Party ComputationMarcella Hastings, Brett Hemenway, Daniel Noble, Steve ZdancewicS&P 2019 · 181 citations
