<p>Oblivious Transfer (<InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_824_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="25" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf{OT}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">OT</mi> </math></EquationSource> </InlineEquation>) is a fundamental cryptographic primitive that becomes a crucial component of a practical secure protocol. <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_824_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="25" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf{OT}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">OT</mi> </math></EquationSource> </InlineEquation> is typically implemented in software, and one way to accelerate its running time is by using hardware implementations. However, such implementations are vulnerable to side-channel attacks (SCAs). On the other hand, protecting interactive protocols against SCA is highly challenging due to their longer secrets (which include inputs and randomness), more complex design, and the need to run multiple instances. Consequently, there are no truly practical leakage-resistant <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_824_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="25" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf{OT}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">OT</mi> </math></EquationSource> </InlineEquation> protocols yet. In this paper, we introduce two tailored indistinguishability-based security definitions for leakage-resilient <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_824_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="25" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf{OT}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">OT</mi> </math></EquationSource> </InlineEquation>, focusing on protecting the sender’s state. Second, we propose a practical semi-honest secure <InlineEquation ID="IEq5"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12095_2025_824_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="25" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf{OT}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">OT</mi> </math></EquationSource> </InlineEquation> protocol that achieves these security levels while minimizing the assumptions on the protocol’s building blocks and the use of a secret state.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

LR-OT: Leakage-resilient oblivious transfer

  • Francesco Berti,
  • Carmit Hazay,
  • Itamar Levi

摘要

Oblivious Transfer ( \(\textsf{OT}\) OT ) is a fundamental cryptographic primitive that becomes a crucial component of a practical secure protocol. \(\textsf{OT}\) OT is typically implemented in software, and one way to accelerate its running time is by using hardware implementations. However, such implementations are vulnerable to side-channel attacks (SCAs). On the other hand, protecting interactive protocols against SCA is highly challenging due to their longer secrets (which include inputs and randomness), more complex design, and the need to run multiple instances. Consequently, there are no truly practical leakage-resistant \(\textsf{OT}\) OT protocols yet. In this paper, we introduce two tailored indistinguishability-based security definitions for leakage-resilient \(\textsf{OT}\) OT , focusing on protecting the sender’s state. Second, we propose a practical semi-honest secure \(\textsf{OT}\) OT protocol that achieves these security levels while minimizing the assumptions on the protocol’s building blocks and the use of a secret state.