Recently, time-based primitives such as time-lock puzzles (TLPs) and verifiable delay functions (VDFs) have received a lot of attention due to their power as building blocks for cryptographic protocols. However, even though exciting improvements on their efficiency and security ( e.g. achieving non-malleability) have been made, most of the existing constructions do not offer general composability guarantees and thus have limited applicability. Baum et al. (EUROCRYPT 2021) presented in TARDIS the first (im)possibility results on constructing TLPs with Universally Composable (UC) security and an application to secure two-party computation with output-independent abort (OIA-2PC), where an adversary has to decide to abort before learning the output. While these results establish the feasibility of UC-secure TLPs and applications, they are limited to the two-party scenario and suffer from complexity overheads. In this paper, we introduce the first UC constructions of VDFs and of the related notion of publicly verifiable TLPs (PV-TLPs). We use our new UC VDF to prove a folklore result on VDF-based randomness beacons used in industry and build an improved randomness beacon from our new UC PV-TLPs. We moreover construct the first multiparty computation protocol with punishable output-independent aborts (POIA-MPC), i.e. MPC with OIA and financial punishment for cheating. Our novel POIA-MPC both establishes the feasibility of (non-punishable) OIA-MPC and significantly improves on the efficiency of state-of-the-art OIA-2PC and (non-OIA) MPC with punishable aborts.
In a distributed network, we consider two special nodes called the sender S and the receiver R that are connected by n node-disjoint (except for S and R) bi-directional wires. Out of these n wires, the adversary can control at most t wires (of its choice) in Byzantine fashion. In this setting, our goal is to design a message transmission protocol Pi that assures the following two conditions hold: (1) by the end of the protocol Pi, R gets the correct messagem transmitted by S without any error (perfect reliability), and (2) the adversary learns no information aboutm, whatsoever, in information theoretic sense (perfect secrecy). Protocols that satisfy these two conditions are known as the Perfectly Secure Message Transmission (PSMT) protocols. However, out of the n wires that exist, if some number of wires say n(s), fortunately, happen to be synchronous (serendipitous synchrony) then we ask under what conditions do PSMT protocols tolerating t-Byzantine faults exist. In the literature, it is known that, if either n(s) > 2t or n > 3t then PSMT protocols trivially exist. Therefore, we consider the case where we have at most 2t synchronous wires (i.e., n(s) <= 2t) and at most 3t wires overall (i.e., n <= 3t). Interestingly, we prove that in this case, no PSMT protocol exists. This concludes that, in designing PSMT protocols (tolerating the given fixed number of faults), either (serendipitous) synchronous wires alone are sufficient or we get absolutely no extra advantage of a wire being synchronous over asynchronous.
We present a privacy-assured multiplication protocol using which an arbitrary arithmetic formula with inputs from two parties over a finite field can be jointly computed on encrypted data using an additively homomorphic encryption scheme. Our protocol is secure against malicious adversaries. To motivate and illustrate applications of this technique, we demonstrate an attack on a class of known protocols showing how to compromise location privacy of honest users by manipulating messages in protocols with additively homomorphic encryption. We demonstrate how to apply the technique in order to solve different problems in geometric applications. We evaluate our approach using a prototypical implementation. The results show that the added overhead of our approach is small compared to insecure outsourced multiplication.
In a synchronous distributed network of n nodes, the goal of a Secure Message Transmission (SMT) protocol is to securely deliver the sender's message at the receiver's end in the presence of a computationally unbounded adversary that can partially control the network by corrupting some of its nodes (except the sender and the receiver). In a network modelled as a directed graph, to achieve unconditional security tolerating tb Byzantine faults, it is known that: (1) if all the paths are one-way connected from the sender to the receiver – called as forward channels – then 2tb+1 vertex-disjoint forward channels are necessary and sufficient (2) for 1≤u≤tb, if there exist 2tb+1−u vertex-disjoint forward channels then u vertex-disjoint paths from the receiver to the sender – known as feedback channels – are necessary and sufficient. Moreover, similar characterization exists for tolerating mixed faults – up to tf fail-stop faults in addition to tp passive faults.We notice that these results characterized the networks by studying the required number of extra vertex-disjoint feedback channels, conditioned on the existence of a certain number of forward channels. In this work, we give a generic characterization without attaching any such if condition. Specifically, we answer the following questions. In a given directed graph, that is abstracted as a collection of strong paths from S to R and R to S, under what conditions is SMT (im)possible tolerating: (1) up to tp passive faults?, (2) mixed faults – up to tf fail-stop faults in addition to tp passive faults?, and (3) up to tb Byzantine faults? Also, for each of these three problems, we explicitly show that there are networks in which SMT protocols exist whereas the existing results do not characterize such networks.
In a network of $n$ nodes (modeled as a digraph), the goal of a perfectly secret message transmission ( PSMT ) protocol is to replicate sender’s message $m$ at the receiver’s end without revealing any information about $m$ to a computationally unbounded adversary that eavesdrops on any $t$ nodes. The adversary may be mobile too that is, it may eavesdrop on a different set of $t$ nodes in different rounds. We prove a necessary and sufficient condition on the synchronous network for the existence of $r$ -round PSMT protocols, for any given $r > 0$ ; further, we show that round-optimality is achieved without trading-off the communication complexity; specifically, our protocols have an overall communication complexity of $O(n)$ elements of a finite field to perfectly transmit one field element. Apart from optimality/scalability, two interesting implications of our results are: 1) adversarial mobility does not affect its tolerability: PSMT tolerating a static $t$ -adversary is possible if and only if PSMT tolerating mobile $t$ -adversary is possible; and 2) mobility does not affect the round optimality: the fastest PSMT protocol tolerating a static $t$ -adversary is not faster than the one tolerating a mobile $t$ -adversary.
Consider a synchronous distributed network which is partly controlled by an adversary. In a Perfectly Secret Message Transmission(PSMT) protocol, the sender S wishes to transmit a message to the receiver R such that the adversary learns nothing about the message. We characterize the set of directed graphs that admit PSMT protocols tolerating a dual failure model where up to tp nodes are passively corrupted and further up to any tf nodes may fail.
Consider an arbitrary network of n nodes, up to any t of which are eavesdropped on by an adversary. A sender S wishes to send a message m to a receiver R such that the adversary learns nothing about m (unless it eavesdrops on one among {S,R}). We prove a necessary and sufficient condition on the (synchronous) network for the existence of r-round protocols for perfect communication, for any given r > 0. Our results/protocols are easily adapted to asynchronous networks too and are shown to be optimal in asynchronous “rounds”. Further, we show that round-optimality is achieved without trading-off the communication complexity; specifically, our protocols have an overall message complexity of O(n) elements of a finite field to perfectly transmit one field element. Interestingly, optimality (of protocols) also implies: (a) when the shortest path between S and R has Ω(n) nodes, perfect secrecy is achieved for “free”, because any (insecure routing) protocol would also take O(n) rounds and send O(n) messages (one message along each edge in the shortest path) for transmission and (b) it is well-known that (t + 1) vertex disjoint paths from S to R are necessary for a protocol to exist; a consequent folklore is that the length of the (t + 1) th ranked (disjoint shortest) path would dictate the round complexity of protocols; we show that the folklore is false; round-optimal protocols can be substantially faster than the aforementioned length.