Efficient UC Commitment Extension with Homomorphism for Free (and Applications)
- Ignacio Cascudo,
- Ivan Damgård,
- ,
- Rafael Dowsley,
- Nico Döttling,
- Irene Giacomelli
- The IMDEA Software Institute,
- Aarhus University,
- ,
- Bar-Ilan University,
- CISPA Helmholz Center for Information Security,
- Protocol Labs
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOpen access
Publication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewHost publication Subtitle
25th International Conference on the Theory and Application of Cryptology and Information Security, Kobe, Japan, December 8–12, 2019, Proceedings, Part IIOriginal language
EnglishPages from-to (Number of pages)
Pages 606-635Publication milestones
- Published - 22/11/2019
Publication status
Published - 22/11/2019
Publisher
Springer, United States, GermanyBook series
- Book series name: Lecture Notes in Computer Science
Volume: 11922
ISSN: 0302-9743
ISBN (Print)
978-3-030-34620-1ISBN (Electronic)
978-3-030-34621-8Publication IDs
- Scopus: 85074983945
Host publication title
Advances in Cryptology – ASIACRYPT 2019Host publication editors
- Steven Galbraith
- Shiho Moriai
Abstract
Homomorphic universally composable (UC) commitments allow for the sender to reveal the result of additions and multiplications of values contained in commitments without revealing the values themselves while assuring the receiver of the correctness of such computation on committed values. In this work, we construct essentially optimal additively homomorphic UC commitments from any (not necessarily UC or homomorphic) extractable commitment. We obtain amortized linear computational complexity in the length of the input messages and rate 1. Next, we show how to extend our scheme to also obtain multiplicative homomorphism at the cost of asymptotic optimality but retaining low concrete complexity for practical parameters. While the previously best constructions use UC oblivious transfer as the main building block, our constructions only require extractable commitments and PRGs, achieving better concrete eciency and oering new insights into the sucient conditions for obtaining homomorphic UC commitments. Moreover, our techniques yield public coin protocols, which are compatible with the Fiat-Shamir heuristic. These results come at the cost of realizing a restricted version of the homomorphic commitment functionality where the sender is allowed to perform any number of commitments and operations on committed messages but is only allowed to perform a single batch opening of a number of commitments. Although this functionality seems restrictive, we show that it can be used as a building block for more ecient instantiations of recent protocols for secure multiparty computation and zero knowledge non-interactive arguments of knowledge.
Publication metrics
PlumX
Captures
14
Citations
8
Access to documents
Accepted author manuscript, 656.29 KB
Accepted author manuscript
Related Event
Title
Asiacrypt 2019
