Computational Hardness of Optimal Fair Computation: Beyond Minicrypt Hemanta K. Maji Department of Computer Science, Purdue University, USA
[email protected] Mingyuan Wang Department of Computer Science, Purdue University, USA
[email protected] Abstract Secure multi-party computation allows mutually distrusting parties to compute securely over their private data. However, guaranteeing output delivery to honest parties when the adversarial parties may abort the protocol has been a challenging objective. As a representative task, this work considers two-party coin-tossing protocols with guaranteed output delivery, a.k.a., fair coin- tossing. In the information-theoretic plain model, as in two-party zero-sum games, one of the parties can force an output with certainty. In the commitment-hybrid, any r-message coin-tossing proto- √ √ col is 1/ r-unfair, i.e., the adversary can change the honest party’s output distribution by 1/ r in the statistical distance. Moran, Naor, and Segev (TCC–2009) constructed the first 1/r-unfair protocol in the oblivious transfer-hybrid. No further security improvement is possible because Cleve (STOC–1986) proved that 1/r-unfairness is unavoidable. Therefore, Moran, Naor, and Segev’s coin-tossing protocol is optimal. However, is oblivious transfer necessary for optimal fair coin-tossing? Maji and Wang (CRYPTO–2020) proved that any coin-tossing protocol using one-way func- √ tions in a black-box manner is at least 1/ r-unfair. That is, optimal fair coin-tossing is impossible in Minicrypt. Our work focuses on tightly characterizing the hardness of computation assump- tion necessary and sufficient for optimal fair coin-tossing within Cryptomania, outside Minicrypt.