Simultaneous broadcast (SBC) protocols [Chor et al., FOCS 1985] constitute a special class of broadcast channels which have proved extremely useful in the design of various distributed computing constructions (e.g., multiparty computation, coin flipping, e-voting, fair bidding). As with any communication channel, it is crucial that SBC security is composable, i.e., it is preserved under concurrent protocol executions. The work of [Hevia, SCN 2006] proposes a formal treatment of SBC in the Universal Composability (UC) framework [Canetti, FOCS 2001] and a construction secure assuming an honest majority. In this work, we provide a comprehensive revision of SBC in the UC setting and improve the results of [Hevia, SCN 2006]. In particular, we present a new SBC functionality that captures both simultaneity and liveness by considering a broadcast period such that (i) within this period all messages are broadcast independently and (ii) after the period ends, the session is terminated without requiring participation of all parties. Next, we employ time-lock encryption (TLE) over a standard broadcast channel to devise an SBC protocol that realizes our functionality against any adaptive adversary corrupting up to all-but-one parties. In our study, we capture synchronicity via a global clock [Katz et al., TCC 2013], thus lifting the restrictions of the original synchronous communication setting used in [Hevia, SCN 2006]. As a building block of independent interest, we prove the first TLE protocol that is adaptively secure in the UC setting, strengthening the main result of [Arapinis et al., ASIACRYPT 2021]. Finally, we formally exhibit the power of our SBC construction in the design of UC-secure applications by presenting two interesting use cases: (i) distributed generation of uniform random strings, and (ii) decentralized electronic voting systems, without the presence of a special trusted party.
翻译:同步广播(SBC)协议 [Chor 等人,FOCS 1985] 是一类特殊的广播信道,已被证明在各种分布式计算构造(例如,多方计算、抛硬币、电子投票、公平竞标)的设计中极为有用。与任何通信信道一样,SBC 的安全性必须是可组合的,即在并发协议执行下得以保持。[Hevia, SCN 2006] 的工作提出了通用可组合性(UC)框架 [Canetti, FOCS 2001] 中 SBC 的形式化处理,以及一个假设诚实多数方的安全构造。在本文中,我们对 UC 设置下的 SBC 进行了全面修订,并改进了 [Hevia, SCN 2006] 的结果。特别地,我们提出了一种新的 SBC 功能,通过考虑一个广播周期来同时捕捉同时性和活跃性,使得 (i) 在该周期内所有消息被独立广播,且 (ii) 周期结束后,会话在不需要所有方参与的情况下终止。接着,我们利用标准广播信道上的时间锁加密(TLE)来设计一个 SBC 协议,该协议能够针对任意自适应敌手(可腐败除一方外的所有方)实现我们的功能。在我们的研究中,我们通过全局时钟 [Katz 等人,TCC 2013] 来捕捉同步性,从而解除了 [Hevia, SCN 2006] 中原始同步通信设置的限制。作为一个具有独立意义的基础模块,我们证明了首个在 UC 设置下满足自适应安全性的 TLE 协议,强化了 [Arapinis 等人,ASIACRYPT 2021] 的主要结果。最后,我们通过展示两个有趣的应用案例: (i) 均匀随机字符串的分布式生成,以及 (ii) 无需特殊可信方的去中心化电子投票系统,正式展示了我们的 SBC 构造在 UC 安全应用设计中的强大能力。