Skip to main content
QUICK REVIEW

[论文解读] Assisted Common Information with Applications to Secure Two-Party Computation

Vinod M. Prabhakaran, Manoj Prabhakaran|arXiv (Cornell University)|Feb 9, 2010
Wireless Communication Security Techniques参考文献 18被引用 8
一句话总结

本文引入了一个三维速率区域——称为协助共同信息区域——以推广Gács-Körner的共同信息,用于捕捉相关随机变量中的非平凡、近乎共同的依赖关系。通过证明加密协议单调扩展该区域,作者得出了安全两方计算效率的更紧上界,表明当考虑区域整体形状时,基于单一度量(如Gács-Körner)的先前上界可能显著次优。

ABSTRACT

Secure multi-party computation is a central problem in modern cryptography. An important sub-class of this are problems of the following form: Alice and Bob desire to produce sample(s) of a pair of jointly distributed random variables. Each party must learn nothing more about the other party's output than what its own output reveals. To aid in this, they have available a set up - correlated random variables whose distribution is different from the desired distribution - as well as unlimited noiseless communication. In this paper we present an upperbound on how efficiently a given set up can be used to produce samples from a desired distribution. The key tool we develop is a generalization of the concept of common information of two dependent random variables [Gacs-Korner, 1973]. Our generalization - a three-dimensional region - remedies some of the limitations of the original definition which captured only a limited form of dependence. It also includes as a special case Wyner's common information [Wyner, 1975]. To derive the cryptographic bounds, we rely on a monotonicity property of this region: the region of the "views" of Alice and Bob engaged in any protocol can only monotonically expand and not shrink. Thus, by comparing the regions for the target random variables and the given random variables, we obtain our upperbound.

研究动机与目标

  • 为解决Gács-Körner共同信息的局限性,该局限性在于无法捕捉相关随机变量中的'近乎共同'依赖关系。
  • 开发一种广义的共同信息度量,以捕捉显式共享组件之外的残余依赖关系。
  • 将此度量应用于推导安全两方计算协议效率的更紧上界。
  • 形式化加密协议视图的单调性性质,以实现目标与可用相关分布之间的比较。

提出的方法

  • 提出一个三维速率区域,记为$\mathbb{K}(X;Y)$,表示在引信协助通信速率与可实现共同信息或残余依赖关系之间的权衡。
  • 定义一个满足四个公理的单调区域$\mathbb{M}$:局部计算不会缩小它,通信不会缩小它,安全推导的输出保持或扩展它,且独立对通过闵可夫斯基和相加。
  • 利用协议执行过程中$\mathbb{K}(X;Y)$的单调性,证明任何安全协议中视图区域只能扩展,从不缩小。
  • 将此单调性应用于比较目标与源相关对的$\mathbb{K}$-区域,从而得出协议效率的上界。
  • 推导出安全实现的必要条件:若$n_1$份$(U,V)$可从$n_2$份$(X,Y)$实现,则$n_1 \mathbb{K}(X;Y) \subseteq n_2 \mathbb{K}(U;V)$。
  • 采用$\mathbb{K}$-区域的几何分析,包括与平面的交点及点包含关系,以计算比仅基于轴截距的先前方法更紧的上界。

实验结果

研究问题

  • RQ1Gács-Körner的共同信息能否被推广,以捕捉无法通过显式共享组件检测到的'近乎共同'依赖关系?
  • RQ2在相关随机变量中,引信协助通信速率与可实现共同信息之间的权衡区域结构是什么?
  • RQ3安全两方协议中视图区域的演化过程如何?其演化过程能否被界定?
  • RQ4$\mathbb{K}$-区域的形状(而不仅其轴截距)能否提供比先前标量度量更紧的保密计算效率上界?
  • RQ5所提出的基于区域整体结构的上界是否紧致,或可进一步改进?

主要发现

  • 所提出的单调区域$\mathbb{K}(X;Y)$是凸的且上闭的,完整捕获了相关对$(X,Y)$的密码学内容,包括非平凡的残余依赖关系。
  • $\mathbb{K}(X;Y)$区域同时推广了Gács-Körner的共同信息(作为轴截距)和Wyner的共同信息作为特例。
  • 在第III节的示例中,基于区域整体形状的上界得出$n_2/n_1 \geq 1.8161$,显著超过仅基于轴截距分析的先前下界0.5182。
  • $\mathbb{K}$在协议执行下的单调性意味着任何安全协议中视图区域只能扩展,从不缩小,从而可对源分布与目标分布进行严格比较。
  • 条件$n_1 \mathbb{K}(X;Y) \subseteq n_2 \mathbb{K}(U;V)$是安全实现$n_1$份$(U,V)$从$n_2$份$(X,Y)$的必要条件,提供了可行性的一个几何判据。
  • 区域$\mathbb{K}(X;Y)$的形状——特别是其向原点凸出的程度——量化了密码学质量:凸出越少,表示密码学内容越高。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。