Half-Tree: Halving the Cost of Tree Expansion in COT and DPFOpen Website

Published: 01 Jan 2023, Last Modified: 11 Jul 2023EUROCRYPT (1) 2023Readers: Everyone
Abstract: GGM tree is widely used in the design of correlated oblivious transfer (COT), subfield vector oblivious linear evaluation (sVOLE), distributed point function (DPF), and distributed comparison function (DCF). Often, the cost associated with GGM tree dominates the computation and communication of these protocols. In this paper, we propose a suite of optimizations that can reduce this cost by half. All protocols are provably secure in the random-permutation model and can be accelerated based on fixed-key AES-NI. We also improve the state-of-the-art schemes of puncturable pseudorandom function (PPRF), DPF, and DCF, which are of independent interest in dealer-available scenarios.
0 Replies

Loading