We construct a 1-out-of-N oblivious transfer (OT) protocol based on the Module-Learning with Errors assumption, which considers the scenario where the sender has N private values \(x_1,...,x_{N}\) , the receiver holds a chosen index i and is allowed to obtain \(x_i\) but nothing else, and the sender cannot know the receiver’s choice. Under the semi-honest model, our protocol achieves statistical sender security and computational receiver security, which means such protocol guarantees sender’s security against computationally unbounded adversaries. In terms of communication cost, our protocol achieves the minimal interaction between the sender and the receiver, which is two-round. Our main technical contribution is breaking away from the traditional framework of OTs based on public key encryption. Specifically, such traditional framework of (1-out-of-2) OTs either requires the receiver to generate two different public keys and the sender to encrypt messages under these two public keys separately, or it requires the sender to encrypt messages using two different encryption ways under the same public key generated by the receiver. In contrast, our work only involves one pair of keys and one “packed” encryption way, thereby directly achieving 1-out-of-N OTs.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

1-Out-of-N Oblivious Transfer from MLWE

  • Jingting Xu,
  • Yanbin Pan

摘要

We construct a 1-out-of-N oblivious transfer (OT) protocol based on the Module-Learning with Errors assumption, which considers the scenario where the sender has N private values \(x_1,...,x_{N}\) , the receiver holds a chosen index i and is allowed to obtain \(x_i\) but nothing else, and the sender cannot know the receiver’s choice. Under the semi-honest model, our protocol achieves statistical sender security and computational receiver security, which means such protocol guarantees sender’s security against computationally unbounded adversaries. In terms of communication cost, our protocol achieves the minimal interaction between the sender and the receiver, which is two-round. Our main technical contribution is breaking away from the traditional framework of OTs based on public key encryption. Specifically, such traditional framework of (1-out-of-2) OTs either requires the receiver to generate two different public keys and the sender to encrypt messages under these two public keys separately, or it requires the sender to encrypt messages using two different encryption ways under the same public key generated by the receiver. In contrast, our work only involves one pair of keys and one “packed” encryption way, thereby directly achieving 1-out-of-N OTs.