Breaking the 1/λ-Rate Barrier for Arithmetic Garbling

Geoffroy Couteau, Carmit Hazay, Aditya Hegde, Naman Kumar

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Garbled circuits, introduced in the seminal work of Yao (FOCS, 1986), have received considerable attention in the boolean setting due to their efficiency and application to round-efficient secure computation. In contrast, arithmetic garbling schemes have received much less scrutiny. The main efficiency measure of garbling schemes is their rate, defined as the bit size of each gate’s output divided by the size of the (amortized) garbled gate. Despite recent progress, state-of-the-art garbling schemes for arithmetic circuits suffer from important limitations: all existing schemes are either restricted to B-bounded integer arithmetic circuits (a computational model where the arithmetic is performed over Z and correctness is only guaranteed if no intermediate computation exceeds the bound B) and achieve constant rate only for very large bounds B=2Ω(λ3), or have a rate at most O(1/λ) otherwise, where λ denotes a security parameter. In this work, we improve this state of affairs in both settings. As our main contribution, we introduce the first arithmetic garbling scheme over modular rings ZB with rate O(logλ/λ), breaking for the first time the 1/λ-rate barrier for modular arithmetic garbling. Our construction relies on the power-DDH assumption.As a secondary contribution, we introduce a new arithmetic garbling scheme for B-bounded integer arithmetic that achieves a constant rate for bounds B as low as 2O(λ). Our construction relies on a new non-standard KDM-security assumption on Paillier encryption with small exponents. As our main contribution, we introduce the first arithmetic garbling scheme over modular rings ZB with rate O(logλ/λ), breaking for the first time the 1/λ-rate barrier for modular arithmetic garbling. Our construction relies on the power-DDH assumption. As a secondary contribution, we introduce a new arithmetic garbling scheme for B-bounded integer arithmetic that achieves a constant rate for bounds B as low as 2O(λ). Our construction relies on a new non-standard KDM-security assumption on Paillier encryption with small exponents.

Original languageEnglish
Title of host publicationAdvances in Cryptology – EUROCRYPT 2025 - 44th Annual International Conference on the Theory and Applications of Cryptographic Techniques, 2025, Proceedings
EditorsSerge Fehr, Pierre-Alain Fouque
PublisherSpringer Science and Business Media Deutschland GmbH
Pages182-213
Number of pages32
ISBN (Print)9783031910944
DOIs
StatePublished - 2025
Event44th Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2025 - Madrid, Spain
Duration: 4 May 20258 May 2025

Publication series

NameLecture Notes in Computer Science
Volume15606 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference44th Annual International Conference on the Theory and Applications of Cryptographic Techniques, EUROCRYPT 2025
Country/TerritorySpain
CityMadrid
Period4/05/258/05/25

Bibliographical note

Publisher Copyright:
© International Association for Cryptologic Research 2025.

Fingerprint

Dive into the research topics of 'Breaking the 1/λ-Rate Barrier for Arithmetic Garbling'. Together they form a unique fingerprint.

Cite this