Lune

EUROCRYPT2026顶会

On Succinct Non-interactive Secure Computation with Malicious Security

Maya Farber Brodsky, Arka Rai Choudhuri, Abhishek Jain, Omer Paneth

2026年份

摘要

A non-interactive secure computation (NISC) protocol allows a client with input xx and a server with input yy to compute f(x,y)f(x,y) using a single message from the client and a single response from the server. The protocol is called succinct if the size of the server’s message depends only on the output length and is independent of the size of yy and the complexity of ff. In the semi-honest setting, succinct NISC is known from fully homomorphic encryption (FHE). In contrast, malicious security is currently known only from non-standard assumptions, such as SNARKs for NP.

In this work, we construct maliciously secure succinct NISC protocols for natural and widely studied functionalities from standard assumptions, namely, FHE and batch arguments (BARGs). Our first result is a protocol for private set membership (PSM): the client holds an element xx, the server holds a large set SS, and the function outputs 11 if and only if x∈Sx \in S. We then give several generalizations:

  • Dictionary lookup: The server holds a dictionary DD of key–value pairs, the client’s input is a key kk, and the output is D[k]D[k].
  • Verifiable dictionary lookup: The server’s dictionary must additionally satisfy a predicate PP, computable by a read-once machine with small state.
  • UP search: The client input is an instance xx, and the output is D[w]D[w], where ww is the unique witness for xx under some UP relation.

Our protocols achieve split-simulation security against a malicious server and standard security against a malicious client. Split-simulation is a relaxation of the standard real-ideal paradigm, where correctness of the client’s output and indistinguishability of the server’s view are guaranteed separately.

At the heart of our results lies a new simulation technique in which the server’s large input is extracted piece by piece and reconstructed into a coherent input. This reconstruction is enabled by a new monotone coupling argument based on Strassen’s theorem.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get c3bc8900-6f4c-4386-bdfd-ddcb9bd7bdbb

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖