Homomorphic Secret Sharing (HSS) allows clients to encrypt their inputs and send them to several servers, who can then homomorphically evaluate public functions over the ciphertexts. Homomorphic secret sharing guarantees input privacy against honest servers. However, to the best of our knowledge, existing HSS schemes do not discuss accountability for the misbehavior of dishonest servers. In this work, we initiate the study of the accountability of HSS in the scenario where a coalition of dishonest servers constructs a pirate decoder. In particular, we consider two types of decoders, universal decoders and exact decoders, which enable unauthorized parties to obtain the correct reconstruction result of HSS. And we propose two HSS schemes that support accountability for the misbehavior of servers: Our constructions are generic and compatible with existing HSS frameworks. Notably, the traitor tracing scheme does not increase the communication complexity, while the traitor confirmation variant slightly increases the output share size.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Accountability for Server Misbehavior in Homomorphic Secret Sharing

  • Xinzhou Wang,
  • Shi-Feng Sun,
  • Dawu Gu,
  • Yuan Luo

摘要

Homomorphic Secret Sharing (HSS) allows clients to encrypt their inputs and send them to several servers, who can then homomorphically evaluate public functions over the ciphertexts. Homomorphic secret sharing guarantees input privacy against honest servers. However, to the best of our knowledge, existing HSS schemes do not discuss accountability for the misbehavior of dishonest servers. In this work, we initiate the study of the accountability of HSS in the scenario where a coalition of dishonest servers constructs a pirate decoder. In particular, we consider two types of decoders, universal decoders and exact decoders, which enable unauthorized parties to obtain the correct reconstruction result of HSS. And we propose two HSS schemes that support accountability for the misbehavior of servers: Our constructions are generic and compatible with existing HSS frameworks. Notably, the traitor tracing scheme does not increase the communication complexity, while the traitor confirmation variant slightly increases the output share size.