Abstract
In a multi-party fair coin-flipping protocol, the parties output a common (close to) unbiased bit, even when some adversarial parties try to bias the output. In this work, we focus on the case of an arbitrary number of corrupted parties. Cleve [20] [STOC 1986] has shown that in any such m-round coin-flipping protocol, the corrupted parties can bias the honest parties’ common output bit by Θ(1/m). For more than two decades, however, the best-known coin-flipping protocol was the one of Awerbuch, Blum, Chor, Goldwasser, and Micali [10] [Manuscript 1985], who presented a t-party, m-round protocol with bias Θ(t/m). This was changed by the breakthrough result of Moran, Naor, and Segev [51] [Journal of Cryptology 2016], who constructed an m-round, two-party coin-flipping protocol with optimal bias Θ(1/m). More recently, Haitner and Tsfadia [37] [SIAM Journal on Computing 2017] constructed an m-round, three-party coin-flipping protocol with bias O(log3m/m). Still for the case of more than three parties, the best-known protocol remained the Θ(t/m)-bias protocol of [10]. We make a step toward eliminating the above gap, presenting a t-party, m-round coin-flipping protocol, with bias Ot4·2t·logmm1/2+1/(2t-1-2) for any t≤12·loglogm. This improves upon the Θ(t/m)-bias protocol of [10], and in particular, for t∈O(1) it is an 1/m12+Θ(1)-bias protocol. For the three-party case, it is an O(logm/m)-bias protocol, improving over the O(log3m/m)-bias protocol of [37]. Our protocol generalizes that of [37], by presenting an appropriate “recovery protocol” for the remaining parties to interact in, in the case that some parties abort or are caught cheating ([37] only presented a two-party recovery protocol, which limits their final protocol to handle three parties). We prove the fairness of the new protocol by presenting a new paradigm for analyzing fairness of coin-flipping protocols; the claimed fairness is proved by mapping the set of adversarial strategies that try to bias the honest parties’ outcome in the protocol to the set of the feasible solutions of a linear program. The gain each strategy achieves is the value of the corresponding solution. We then bound the optimal value of the linear program by constructing a feasible solution to its dual.
| Original language | English |
|---|---|
| Article number | 4 |
| Journal | Journal of Cryptology |
| Volume | 39 |
| Issue number | 1 |
| DOIs | |
| State | Published - Jan 2026 |
Bibliographical note
Publisher Copyright:© The Author(s) 2025.
Keywords
- Coin-flipping
- Fair computation
- Stopping time problems
Fingerprint
Dive into the research topics of 'Fair Coin Flipping: Tighter Analysis and the Many-Party Case'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver