Lune

EUROCRYPT2022顶会

Batch-OT with Optimal Rate

Zvika Brakerski, Pedro Branco, Nico Döttling, Sihang Pu

2022年份
13被引次数
4顶会引用

摘要

We show that it is possible to perform nn independent copies of 11-out-of-22 oblivious transfer in two messages, where the communication complexity of the receiver and sender (each) is n(1+o(1))n(1+o(1)) for sufficiently large nn. Note that this matches the information-theoretic lower bound. Prior to this work, this was only achievable by using the heavy machinery of rate-11 fully homomorphic encryption (Rate-11 FHE, Brakerski et al., TCC 2019).

To achieve rate-11 both on the receiver's and sender's end, we use the LPN assumption, with slightly sub-constant noise rate 1/mϵ1/m^{\epsilon} for any ϵ>0\epsilon>0 together with either the DDH, QR or LWE assumptions. In terms of efficiency, our protocols only rely on linear homomorphism, as opposed to the FHE-based solution which inherently requires an expensive ``bootstrapping'' operation. We believe that in terms of efficiency we compare favorably to existing batch-OT protocols, while achieving superior communication complexity. We show similar results for Oblivious Linear Evaluation (OLE).

For our DDH-based solution we develop a new technique that may be of independent interest. We show that it is possible to ``emulate'' the binary group Z2\mathbb{Z}_2 (or any other small-order group) inside a prime-order group Zp\mathbb{Z}_p in a function-private manner. That is, Z2\mathbb{Z}_2 operations are mapped to Zp\mathbb{Z}_p operations such that the outcome of the latter do not reveal additional information beyond the Z2\mathbb{Z}_2 outcome. Our encoding technique uses the discrete Gaussian distribution, which to our knowledge was not done before in the context of DDH.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper4

问问它们各自怎么用它

它引用的顶会 Paper2

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖