On the Reversibility of Oblivious Transfer
UniversitP de Paris-Sud · 1991
i (:)-OT, (one-out-of-two Bit Oblivious Transfer) is a technique by which a party S owning two secret bits b,bl, can transfer one of them b, to another party R, who chooses c. This is done in a way that does not release any bias about bz to R nor any bias about c to S. How can one build a 2TO-(i) ((;)-OT2 from R to S) given a (i)-OT, (from S to a)? This question is interesting because in many scenarios, one of the two parties will be much more powerful than the other. In the current paper we answer this question and show a number of related extensions. One interesting extension of this transfer is the (:)-OTk (one-out-of-two String O.T.) in which the two secrets qo, q1 are elements of CFk(2) instead of bits. We show that $TO-(:) can be obtained at about the same cost as (3-OT:, in terms of number of cab to (i)-OTz.