Table of contents

  • This session has been presented July 01, 2005.

Description

  • Speaker

    Martin Hirt - ETH Zurich

Consider a set of $n$ players, each holding a value $x_1,...,x_n$, and an $n$-ary function $f$, specified as an arithmetic circuit over a finite field. How can the players compute $y=f(x_1,...,x_n)$ in such a way that no (small enough) set of dishonest players obtains any joint information about the input values of the honest players (beyond of what they can infer from $y$)? In this talk, we present a protocol that allows the players to compute an arbitrary function $f$, such that any subset of up to $t< n/2$ dishonest players do not obtain any information about the other players' inputs.<br/> Finally, we briefly sketch an extension of the protocol, which guarantees the correctness of the outcome even when the dishonest players misbehave in arbitrary manner.

Next sessions

  • MIKE: An efficient and compact NIKE Based on a Commutative Monoidal Action 

    • July 03, 2026 (13:45 - 14:45)

    • IRMAR - Université de Rennes - Campus Beaulieu Bat. 22, RDC, Rennes - Amphi Lebesgue

    Speaker : Jonathan Komada Eriksen - COSIC, KU Leuven

    Robert recently described a powerful correspondence between certain (Hermitian) modules and (polarized) abelian varieties, which simultaneously generalizes both the class-group action underlying protocols such as CSIDH, and the Deuring correspondence, underlying protocols such as SQIsign. Using this correspondence, he also proposed how to construct a post-quantum NIKE, called MIKE, which, at a[…]
    • Cryptography

  • TBA

    • September 25, 2026 (13:45 - 14:45)

    • IRMAR - Université de Rennes - Campus Beaulieu Bat. 22, RDC, Rennes - Amphi Lebesgue

    Speaker : Anmoal Porwal - Technical University of Munich

    • Cryptography

    • Asymmetric primitive

Show previous sessions