Multi-Server Verifiable Computation of Low-Degree Polynomials
Liang Feng Zhang, Huaxiong Wang
Abstract
The conflicts between input privacy and efficiency in single-server non-interactive verifiable computation (NIVC) makes it interesting to consider the multi-server models of NIVC. Although the existing multi-server NIVC schemes provide meaningful improvements, they either require the servers to communicate or leave the client’s data unprotected. It has been an open problem to design multi-server NIVC with both input privacy and non-communicating servers. In this paper we define a multi-server verifiable computation (MSVC) model where the client secret-shares its input x among non-communicating servers, each server locally computes a function F to get a partial result, and finally the client reconstructs F(x) from all partial results. We construct five MSVC schemes for outsourcing low-degree polynomials and thus answer the open question for such polynomials. Our schemes are t-private such that any t servers learn no information about x. Our schemes are t-secure such that any t servers cannot persuade the client to output wrong results. The privacy and security can be either information-theoretic or computational. Comparing with the existing schemes, our servers can be at least two orders faster.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Hash First, Argue Later: Adaptive Verifiable Computations on Outsourced DataDario Fiore, Cédric Fournet, Esha Ghosh, Markulf Kohlweiss et al.CCS 2016 · 71 citations
- Multiparty Reusable Non-interactive Secure Computation from LWEFabrice Benhamouda, Aayush Jain, Ilan Komargodski, Huijia LinEUROCRYPT 2021 · 26 citations
- Non-interactive Secure Multiparty Computation for Symmetric Functions, Revisited: More Efficient Constructions and ExtensionsReo Eriguchi, Kazuma Ohara, Shota Yamada, Koji NuidaCRYPTO 2021 · 5 citations
- Sublinear-Communication Secure Multiparty Computation Does Not Require FHEElette Boyle, Geoffroy Couteau, Pierre MeyerEUROCRYPT 2023 · 16 citations
- How to Share an NP Statement or Combiners for Zero-Knowledge ProofsBenny Applebaum, Eliran KachlonCRYPTO 2025 · 2 citations
