Oblivious polynomial evaluation

Moni Naor, Benny Pinkas

Research output: Contribution to journalArticlepeer-review

94 Scopus citations


Oblivious polynomial evaluation is a protocol involving two parties, a sender whose input is a polynomial P, and a receiver whose input is a value α. At the end of the protocol the receiver learns P (α) and the sender learns nothing. We describe efficient constructions for this protocol, which are based on new intractability assumptions that are closely related to noisy polynomial reconstruction. Oblivious polynomial evaluation can be used as a primitive in many applications. We describe several such applications, including protocols for private comparison of data, for mutually authenticated key exchange based on (possibly weak) passwords, and for anonymous coupons.

Original languageEnglish
Pages (from-to)1254-1281
Number of pages28
JournalSIAM Journal on Computing
Issue number5
StatePublished - 2006
Externally publishedYes


  • Cryptography
  • Noisy polynomial reconstruction
  • Secure computation


Dive into the research topics of 'Oblivious polynomial evaluation'. Together they form a unique fingerprint.

Cite this