Efficient Composable Oblivious Transfer from CDH in the Global Random Oracle Model
- ,
- Rafael Dowsley
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOpen access
Publication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOriginal language
EnglishPages from-to (Number of pages)
Pages 462-481|Publication milestones
- Published - 2020
Publication status
Published - 2020
Publisher
Springer, United States, GermanyBook series
- Book series name: Lecture Notes in Computer Science
Volume: 12579
ISSN: 0302-9743
ISBN (Print)
978-3-030-65410-8ISBN (Electronic)
978-3-030-65411-5Publication IDs
- Scopus: 85098282166
Host publication title
Cryptology and Network Security. CANS 2020.Host publication editors
- Stephan Krenn
- Haya Schulman
- Serge Vaudenay
Abstract
Oblivious Transfer (OT) is a fundamental cryptographic protocol that finds a number of applications, in particular, as an essential building block for two-party and multi-party computation. We construct the first universally composable (UC) protocol for oblivious transfer secure against active static adversaries based on the Computational Diffie-Hellman (CDH) assumption. Our protocol is proven secure in the observable Global Random Oracle model. We start by constructing a protocol that realizes an OT functionality with a selective failure issue, but shown to be sufficient to instantiate efficient OT extension protocols. In terms of complexity, this protocol only requires the computation of 6 modular exponentiations and the communication of 5 group elements, five binary strings of security parameter length, and two binary strings of message length. Finally, we lift this weak construction to obtain a protocol that realizes the standard OT functionality (without any selective failures) at an additional cost of computing 9 modular exponentiations and communicating 4 group elements, four binary strings of security parameter length and two binary strings of message length. As an intermediate step before constructing our CDH based protocols, we design generic OT protocols from any OW-CPA secure public-key encryption scheme with certain properties, which could potentially be instantiated from more assumptions other than CDH.
Publication metrics
PlumX, opens in new tab
Citations
3
Captures
8
Access to documents
Accepted author manuscript, 518.06 KB
Related Event
Title
Cryptology and Network Security
