We introduce the notion of traceable mixnets. In a traditional mixnet, multiple mix-servers jointly permute and decrypt a list of ciphertexts to produce a list of plaintexts, along with a proof of correctness, such that the association between individual ciphertexts and plaintexts remains completely hidden. However, in many applications, the privacy-utility tradeoff requires answering some specific queries about this association, without revealing any information beyond the query result. We consider queries of the following type: a) given a ciphertext in the mixnet input list, whether it encrypts one of a given subset of plaintexts in the output list, and b) given a plaintext in the mixnet output list, whether it is a decryption of one of a given subset of ciphertexts in the input list. Traceable mixnets allow the mix-servers to jointly prove answers to the above queries to a querier such that neither the querier nor a threshold number of mix-servers learn any information beyond the query result. Further, if the querier is not corrupted, the corrupted mix-servers do not even learn the query result. We first comprehensively formalise these security properties of traceable mixnets and then propose a construction of traceable mixnets using novel distributed zero-knowledge proofs (ZKPs) of set membership and of a statement we call reverse set membership. Although set membership has been studied in the single-prover setting, the main challenge in our distributed setting lies in making sure that none of the mix-servers learn the association between ciphertexts and plaintexts during the proof. We implement our distributed ZKPs and show that they are faster than state-of-the-art by at least one order of magnitude.
翻译:我们引入了可追溯混合网络的概念。在传统混合网络中,多个混合服务器共同对一组密文进行置换与解密,生成对应的明文列表及正确性证明,同时保持单个密文与明文之间的关联完全隐藏。然而在许多应用中,隐私与效用的权衡要求能够针对该关联回答特定查询,且不泄露查询结果之外的任何信息。我们考虑以下两种查询类型:a) 给定混合网络输入列表中的某个密文,判断其是否加密了输出列表指定子集中的某个明文;b) 给定混合网络输出列表中的某个明文,判断其是否为输入列表指定子集中某个密文的解密结果。可追溯混合网络允许混合服务器联合向查询者证明上述查询答案,使得查询者及不超过阈值数量的混合服务器均无法获知查询结果之外的任何信息。若查询者未被攻破,被攻破的混合服务器甚至无法得知查询结果。我们首先系统形式化了可追溯混合网络的这些安全属性,随后提出了一种基于新型分布式零知识证明(ZKP)的构造方案,该方案涉及集合成员关系证明及我们称之为逆向集合成员关系的陈述。尽管集合成员关系已在单证明者场景下得到研究,但分布式场景的主要挑战在于确保任何混合服务器在证明过程中都无法获知密文与明文的关联。我们实现了该分布式ZKP方案,并证明其速度比当前最优方案至少快一个数量级。