Concurrent composition of secure protocols in the timing model

Yael Tauman Kalai, Yehuda Lindell, Manoj Prabhakaran

Research output: Contribution to journalArticlepeer-review

16 Scopus citations

Abstract

In the setting of secure multiparty computation, a set of mutually distrustful parties wish to securely compute some joint function of their inputs. In the stand-alone case it has been shown that every efficient function can be securely computed. However, in the setting of concurrent composition, broad impossibility results have been proven for the case of no honest majority and no trusted setup phase. These results hold both for the case of general composition (where a secure protocol is run many times concurrently with arbitrary other protocols) and self-composition (where a single secure protocol is run many times concurrently). In this paper we investigate the feasibility of obtaining security in the concurrent setting, assuming that each party has a local clock and that these clocks proceed at approximately the same rate. We show that under this mild timing assumption, it is possible to securely compute any multiparty functionality under concurrent self-composition. Loosely speaking, we also show that it is possible to securely compute any multiparty functionality under concurrent general composition, as long as the secure protocol is run only with protocols whose messages are delayed by a specified amount of time. On the negative side, we show that it is impossible to achieve security under concurrent general composition with no restrictions whatsoever on the network (like the aforementioned delays), even in the timing model.

Original languageEnglish
Pages (from-to)431-492
Number of pages62
JournalJournal of Cryptology
Volume20
Issue number4
DOIs
StatePublished - Oct 2007

Keywords

  • Concurrent composition
  • Secure multiparty computation
  • Theory of cryptography
  • Timing assumptions

Fingerprint

Dive into the research topics of 'Concurrent composition of secure protocols in the timing model'. Together they form a unique fingerprint.

Cite this