Lune

EUROCRYPT2024Top-tier venue

How to Garble Mixed Circuits that Combine Boolean and Arithmetic Computations

Hanjun Li, Tianren Liu

2024Year
6Citations

Abstract

The study of garbling arithmetic circuits is initiated by Applebaum, Ishai, and Kushilevitz [FOCS'11], which can be naturally extended to mixed circuits. The basis of mixed circuits includes Boolean operations, arithmetic operations over a large ring and bit-decomposition that converts an arithmetic value to its bit representation. We construct efficient garbling schemes for mixed circuits.

In the random oracle model, we construct two garbling schemes: ∙\bullet The first scheme targets mixed circuits modulo some N≈2bN\approx 2^b. Addition gates are free. Each multiplication gate costs O(λ⋅b1.5)O(\lambda \cdot b^{1.5}) communication. Each bit-decomposition costs O(λ⋅b2/log⁡b)O(\lambda \cdot b^{2} / \log{b}). ∙\bullet The second scheme targets mixed circuit modulo some N≈2bN\approx 2^b. Each addition gate and multiplication gate costs O(λ⋅b⋅log⁡b/log⁡log⁡b)O(\lambda \cdot b \cdot \log b / \log \log b). Every bit-decomposition costs O(λ⋅b2/log⁡b)O(\lambda \cdot b^2 / \log b). Our schemes improve on the work of Ball, Malkin, and Rosulek [CCS'16] in the same model.

Additionally relying on the DCR assumption, we construct in the programmable random oracle model a more efficient garbling scheme targeting mixed circuits over Z2b\mathbb{Z}_{2^b}, where addition gates are free, and each multiplication or bit-decomposition gate costs O(λDCR⋅b)O(\lambda_{\text{DCR}} \cdot b) communication. We improve on the recent work of Ball, Li, Lin, and Liu [Eurocrypt'23] which also relies on the DCR assumption.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines