In classic settings of garbled circuits, each gate type is leaked to improve both space and speed optimization. Zahur et al. have shown in EUROCRYPT 2015 that a typical linear garbling scheme requires at least two $\lambda$-bit elements per gate with a security parameter of $\lambda$, which limits their efficiency. In contrast to typical garbled circuits, gate-hiding garbled circuits have the potential to drastically reduce time costs, although they have been underappreciated. We propose the first skipping scheme for gate-hiding garbled circuits to enhance the efficiency of evaluation by observing prime implicants. Our scheme introduces skip gates to eliminate the need to calculate the entire circuit, enabling unnecessary execution paths to be avoided. We also introduce two variants of our scheme that balance security with parallelism. A proof of hybrid security that combines simulation-based and symmetry-based security in semi-honest scenarios is presented to demonstrate its security under gate-hiding conditions. Our scheme will inspire new directions to improve the general garbling scheme and lead to more practical ones.
翻译:在经典混淆电路设置中,门类型被泄露以优化空间和速度。Zahur等人在EUROCRYPT 2015会议上证明,典型线性混淆方案每个门至少需要两个λ比特元素(安全参数为λ),这限制了其效率。与经典混淆电路不同,遮蔽门电路虽未被充分重视,但具有大幅降低时间成本的潜力。我们首次提出针对遮蔽门电路的跳跃方案,通过观察质蕴含项来提升评估效率。该方案引入跳跃门以规避计算整个电路的必要性,从而避免执行非必要路径。我们还提出了两种平衡安全性与并行性的变体方案。通过结合半诚实场景下基于模拟和基于对称性的混合安全证明,展示了其在门遮蔽条件下的安全性。本方案将为改进通用混淆方案提供新方向,并推动其实用化发展。