Skip to content

Question about security of 64-bit additive secret sharing over Z_{2^64} in the semi-honest setting #1749

@rantong-research

Description

@rantong-research

Hi, I have a simple question about ring-based MPC in MP-SPDZ.

In the semi-honest (passive) setting, is two-party additive secret sharing over the 64-bit ring Z_{2^64} considered fully secure from a privacy perspective?

More specifically:

  • Do we need to lift computations to a larger ring such as Z_{2^{128}} for privacy reasons?
  • Or is ring extension only required in the active/malicious setting (because MACs and integrity checks need extra statistical security bits), while semi-honest computations are perfectly private already in Z_{2^64}?

I'm trying to confirm whether staying in Z_{2^64} is cryptographically safe enough for passive security, or whether MP-SPDZ recommends using a larger ring even in that case.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions