We introduce the notion of \emph{traceable mixnets}. In a traditional mixnet, multiple mix-servers jointly permute and decrypt a list of ciphertexts to produce a list of plaintexts, along with a proof of correctness, such that the association between individual ciphertexts and plaintexts remains completely hidden. However, in many applications, the privacy-utility tradeoff requires answering some specific queries about this association, without revealing any information beyond the query result. We consider queries of the following types: a) given a ciphertext in the mixnet input list, whether it encrypts one of a given subset of plaintexts in the output list, and b) given a plaintext in the mixnet output list, whether it is a decryption of one of a given subset of ciphertexts in the input list. Traceable mixnets allow the mix-servers to jointly prove answers to the above queries to a querier such that neither the querier nor a threshold number of mix-servers learn any information beyond the query result. Further, if the querier is not corrupted, the corrupted mix-servers do not even learn the query result. We first comprehensively formalise these security properties of traceable mixnets and then propose a construction of traceable mixnets using novel distributed zero-knowledge proofs (ZKPs) of set membership and of a statement we call reverse set membership. Although set membership has been studied in the single-prover setting, the main challenge in our distributed setting lies in making sure that none of the mix-servers learn the association between ciphertexts and plaintexts during the proof. We implement our distributed ZKPs and show that they are faster than state-of-the-art by at least one order of magnitude.
翻译:我们提出了“可追踪混合网络”(traceable mixnets)的概念。在传统混合网络中,多个混合服务器共同对密文列表进行排列和脱密,生成明文列表及正确性证明,同时确保单个密文与明文间的对应关系完全隐藏。然而,在许多应用中,隐私与效用的权衡要求在不泄露查询结果之外任何信息的前提下,回答关于这种对应关系的特定查询。我们考虑以下两类查询:a)给定混合网络输入列表中的某个密文,判断其是否加密了输出列表中某个子集的明文;b)给定混合网络输出列表中的某个明文,判断其是否为输入列表中某个子集密文的脱密结果。可追踪混合网络允许混合服务器向查询者联合证明上述查询的答案,使得查询者或达到阈值数量的混合服务器除查询结果外不获知任何信息。此外,若查询者未被腐化,被腐化的混合服务器甚至无法获知查询结果。我们首先全面形式化定义了可追踪混合网络的安全属性,然后利用新型分布式零知识证明(ZKPs)——集合成员证明及其逆命题(称为“逆集合成员证明”)——提出可追踪混合网络的构造方案。尽管集合成员证明已在单证明者场景下得到研究,但分布式场景的主要挑战在于确保任何混合服务器在证明过程中均不获知密文与明文的对应关系。我们实现了所提出的分布式零知识证明,并证明其速度比现有最优方案至少快一个数量级。