Additive Conditional Disclosure of Secrets And Applications
Sven Laur, Helger Lipmaa · 2005
During a conditional disclosure of secrets (CDS) protocol, Alice obtains a secret, held by Bob, if and only if her inputs to the protocol were "valid". As an output masking technique, CDS protocol can be used as a subroutine in other protocols to guarantee either Bob-privacy or correctness against a malicious Alice. Using a simple seeded randomness extractor, we extend the Aiello-Ishai-Reingold CDS protocol to work over additively homomorphic public-key cryptosystems. Based on this, we construct several new two-message protocols like an oblivious transfer protocol with log-squared communication and a millionaire's protocol with logarithmic communication.