[Paper Review] Impossibility of composable Oblivious Transfer in relativistic quantum cryptography
This paper proves that composable oblivious transfer (OT) cannot be securely constructed using only classical or quantum communication among distrustful parties in relativistic quantum cryptography settings. The authors formalize multiple versions of OT, establish their equivalence in relativistic quantum frameworks, and demonstrate via impossibility theorems that no composable construction is possible—even when leveraging relativistic constraints like signal speed limits. The result extends to oblivious string transfer and multi-party computation, and the paper further establishes a mutual construction between OT and bit commitment, highlighting foundational limits in secure multiparty computation under relativistic quantum assumptions.
We study the cryptographic primitive Oblivious Transfer; a composable construction of this resource would allow arbitrary multi-party computation to be carried out in a secure way, i.e. to compute functions in a distributed way while keeping inputs from different parties private. First we review a framework that allows us to analyze composability of classical and quantum cryptographic protocols in special relativity: Abstract Cryptography implemented with Causal Boxes. We then (1) explore and formalize different versions of oblivious transfer found in the literature, (2) prove that their equivalence holds also in relativistic quantum settings, (3) show that it is impossible to composably construct any of these versions of oblivious transfer from only classical or quantum communication among distrusting agents in relativistic settings, (4) prove that the impossibility also extends to multi-party computation, and (5) provide a mutual construction between oblivious transfer and bit commitment.
Motivation & Objective
- To investigate whether composable oblivious transfer can be securely constructed in relativistic quantum cryptography settings.
- To formalize and compare different versions of oblivious transfer found in the literature within a relativistic quantum framework.
- To prove that no composable construction of oblivious transfer is possible using only classical or quantum communication among distrustful agents under relativistic constraints.
- To extend the impossibility result to oblivious string transfer and multi-party computation.
- To establish a mutual construction between oblivious transfer and bit commitment in the relativistic quantum setting.
Proposed method
- The authors employ the Abstract Cryptography framework instantiated by Causal Boxes to analyze composable security in relativistic quantum settings.
- They define and formalize multiple variants of oblivious transfer, including 1-out-of-2 OT and oblivious string transfer, and prove their equivalence under relativistic quantum conditions.
- Using the difference lemma and probabilistic bounds, they show that any attempt to construct composable OT from classical or quantum communication fails with exponentially small success probability.
- The impossibility is extended to multi-party computation by showing that OT is a necessary primitive for secure computation, and its infeasibility implies broader infeasibility.
- A mutual construction between OT and bit commitment is derived, demonstrating that each can be used to construct the other under specific conditions.
- Simulators are constructed to model dishonest behavior, and the security of the constructions is analyzed via indistinguishability under adversarial strategies.
Experimental results
Research questions
- RQ1Can composable oblivious transfer be constructed from classical or quantum communication alone in a relativistic quantum setting?
- RQ2Are different variants of oblivious transfer equivalent in the context of relativistic quantum cryptography?
- RQ3Does the impossibility of composable OT extend to oblivious string transfer and multi-party computation?
- RQ4Can oblivious transfer and bit commitment be mutually constructed in a relativistic quantum framework?
- RQ5What are the fundamental limitations of secure multiparty computation when relying on relativistic constraints and quantum communication?
Key findings
- It is impossible to construct composable oblivious transfer from classical or quantum communication among distrustful agents in relativistic quantum cryptography, even when leveraging relativistic constraints such as finite signal speed.
- All standard variants of oblivious transfer—such as 1-out-of-2 OT and oblivious string transfer—are equivalent in the relativistic quantum setting, and the impossibility result applies uniformly across them.
- The impossibility of composable OT extends to multi-party computation, as OT is a complete primitive for secure function evaluation, and its infeasibility blocks secure computation in general.
- A mutual construction between oblivious transfer and bit commitment is established: k instances of OT can be used to construct a bit commitment with security parameter 2−k, and vice versa.
- The security of the constructions is bounded by exponentially small error probabilities (e−Ω(n) and 2−k), proving that any deviation from perfect indistinguishability is exponentially unlikely.
- The results hold under the Abstract Cryptography framework, with formal proofs relying on causal boxes and simulator-based indistinguishability arguments, ensuring composable security definitions are rigorously applied.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.