arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.27129cs.CR

SLIDE:以线性在线通信和保证输出交付均匀置乱Shamir秘密共享份额

SLIDE: Shuffle Shamir Secret Shares Uniformly with Linear Online Communication and Guaranteed Output Delivery

Jiacheng Gao, Moyang Xie, Yuan Zhang, Sheng Zhong

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对Shamir秘密共享的置乱协议问题,提出两种新协议,其中SLIDE协议是首个兼具线性在线通信和保证输出交付的均匀置乱协议,可提升安全计算的效率与可扩展性。

中文摘要 AI 辅助

我们重新研究Shamir秘密共享的置乱协议。现有构造要么产生非均匀置乱,要么通信和轮次复杂度高,有时随参与方数量呈指数增长。我们提出两种新的置乱协议,对于n个参与方共享的m×l矩阵,实现均匀置乱的通信复杂度为O((k+l)n²mlog m/log k),其中k≤m是可调参数。第一种协议具有具体效率,第二种协议实现了已知最优的O(nml)在线通信和O(n)轮次。实验表明,与现有工作相比,在线效率和总成本有显著提升。我们的关键技术要素是一种新颖的置换共享技术,该技术用更小的置换矩阵表示置换,使其应用效率大幅提高。第一种协议依次应用独立的秘密置换,第二种协议基于置乱相关性实现最优在线复杂度。我们进一步扩展置乱相关性以支持线性在线通信下的保证输出交付,得到SLIDE,这是首个同时实现O(nml)在线通信和保证输出交付的协议。我们的构造仅依赖大小大于n的任意域上的基本Shamir秘密共享。由于置乱是MPC任务(如排序和不经意数据结构)的基础原语,我们的结果使实践中更高效、可扩展的安全计算成为可能。

英文摘要

We revisit shuffle protocols for Shamir secret sharing. Existing constructions either produce non-uniform shuffles or incur high communication and round complexity, sometimes exponential in the number of parties. We propose two new shuffle protocols that achieve uniform shuffling with communication complexity $O((k+l)n^2m\log m/\log k)$ for an $m$-by-$l$ matrix shared among $n$ parties, where $k\leq m$ is a tunable parameter. The first protocol is concretely efficient, while the second achieves the best-known $O(nml)$ online communication and $O(n)$ rounds. Experiments show significant improvements in online efficiency and total cost over prior work. Our key technical ingredient is a novel permutation sharing technique that represents permutations using smaller permutation matrices, making their application significantly more efficient. The first protocol applies independent secret permutations sequentially, while the second builds on shuffle correlation to achieve optimal online complexity. We further extend shuffle correlation to support guaranteed output delivery with linear online communication, yielding SLIDE, the first protocol to achieve both $O(nml)$ online communication and guaranteed output delivery. Our constructions rely only on basic Shamir secret sharing over any field of size greater than $n$. As shuffling is a fundamental primitive for MPC tasks such as sorting and oblivious data structures, our results enable more efficient and scalable secure computation in practice.

补充信息

↑