We introduce the notion of \emph{traceable mixnets}. In a traditional mixnet, multiple mix-servers jointly permute and decrypt a list of ciphertexts to produce a list of plaintexts, along with a proof of correctness, such that the association between individual ciphertexts and plaintexts remains completely hidden. However, in many applications, the privacy-utility tradeoff requires answering some specific queries about this association, without revealing any information beyond the query result. We consider queries of the following type: a) given a ciphertext in the mixnet input list, whether it encrypts one of a given subset of plaintexts in the output list, and b) given a plaintext in the mixnet output list, whether it is a decryption of one of a given subset of ciphertexts in the input list. Traceable mixnets allow the mix-servers to jointly prove answers to the above queries to a querier such that neither the querier nor a threshold number of mix-servers learn any information beyond the query result. If the querier is not corrupted, the corrupted mix-servers do not even learn the query result. We propose a construction of a traceable mixnet using novel distributed zero-knowledge proofs of \emph{set membership} and a related primitive we introduce called \emph{reverse set membership}. Although the set membership problem has been studied in the single-prover setting, the main challenge in our distributed setting lies in making sure that none of the mix-servers learn the association between ciphertexts and plaintexts during the proof. Our construction is faster than existing techniques by at least one order of magnitude.
翻译:我们引入了*可追踪混合网络*的概念。在传统混合网络中,多个混合服务器共同对一份密文列表进行置乱和解密,以生成明文列表及其正确性证明,同时确保单个密文与明文之间的关联性完全隐藏。然而在许多应用中,隐私与效用的权衡要求能够针对该关联性回答某些特定查询,且不泄露查询结果之外的任何信息。我们考虑以下两种类型的查询:a) 给定混合网络输入列表中的某个密文,查询其是否加密了输出列表中某给定子集的某个明文;b) 给定混合网络输出列表中的某个明文,查询其是否为输入列表中某给定子集的某个密文的解密结果。可追踪混合网络允许混合服务器共同向查询者证明上述查询的答案,使得查询者或不超过阈值数量的混合服务器无法获知查询结果之外的任何信息。若查询者未被攻破,被攻破的混合服务器甚至无法获知查询结果。我们提出了一种可追踪混合网络的构建方案,该方案采用了新型的分布式*集合成员*零知识证明,以及我们引入的称为*反向集合成员*的相关原语。尽管集合成员问题已在单一证明者场景下得到研究,但分布式场景的主要挑战在于确保证明过程中没有任何混合服务器获知密文与明文之间的关联性。我们的构建方案比现有技术至少快一个数量级。