IP Library Granted Patent US 10,797,866
Granted Patent B1
US 10,797,866 · App. 16/833,697 · Granted Oct 6, 2020

System and method for enforcement of correctness of inputs of multi-party computations

Inventor: Yehuda Lindell (Givat Shmuel, IL)
Assignee: BAR-ILAN UNIVERSITY
H04L9/083H04L9/0656H04L9/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,797,866
App. No.
16/833,697
Granted
Oct 6, 2020
Kind
B1
Abstract

A method of performing a Multi-Party Computation (MPC) process between two parties and a server, the parties generating initial garbled labels to an initial garbled circuit and sending the initial garbled labels corresponding to an input to the server, the parties generating a fresh garbled circuit and generating multiple bridge gates for translating the initial garbled labels to garbled values for the inputs to the fresh garbled circuit, where each of the bridge gates is associated with a specific input wire of the fresh garbled circuit and maps a value of the initial garbled labels to a value of garbled labels of the fresh garbled circuit, where the server computes fresh garbled values for the fresh garbled circuit using the bridge gates and the initial garbled values and evaluates the fresh garbled circuit using the fresh garbled labels.

Claims (30)

1. A method of performing a Multi-Party Computation (MPC) process between two parties and a server, the method comprising an initialization phase comprising:

the two parties generating initial garbled labels to an initial garbled circuit;

each of the two parties sending the initial garbled labels corresponding to an input from each of the two parties to the server;

the method also comprises an evaluation phase comprising:

the two parties generating a fresh garbled circuit;

the two parties generating multiple bridge gates for translating the initial garbled labels to garbled values for the inputs to the fresh garbled circuit;

wherein each bridge gate of the multiple bridge gates is associated with a specific input wire of the fresh garbled circuit;

wherein each bridge gate of the multiple bridge gates maps a value of the initial garbled labels to a value of garbled labels of the fresh garbled circuit;

the two parties sending the garbled circuit and bridge gates to the server;

the server computing fresh garbled values for the fresh garbled circuit using the bridge gates and the initial garbled values;

the server evaluating the fresh garbled circuit using the fresh garbled labels.

2. The method of claim 1 , wherein the bridge gates encrypt a garbled value representing “0” on a wire with a garbled value representing “0” in the initial garbled values, and like encrypt a garbled value representing “1” on a wire with a garbled value representing “1” in the initial garbled values.

3. The method of claim 1 , wherein the initialization phase further comprises of the server storing the initial garbled labels corresponding to the inputs of the first party and the second party.

4. The method of claim 1 , wherein the initialization phase further comprises:

the first party sending a commitment of its initial garbled labels to the second party without revealing the garbled labels;

the second party sending a commitment of its initial garbled labels to the first party without revealing the garbled labels;

and the evaluation phase further comprises:

the first party sending the server the commitment to the second party's initial garbled labels and the commitment opening to its own garbled labels;

the second party sending the server the commitment to the first party's initial garbled labels and the commitment opening to its own garbled labels;

the server using the commitment openings to open the commitments and obtain the initial garbled values of the first party and second party.

5. The method of claim 4 , wherein the commitment to the initial garbled labels is the result of a hash function applied to the initial garbled labels.

6. The method of claim 1 , wherein the initialization phase comprising:

the first party generating an initialization seed for a pseudorandom generator;

the first party sending the initialization seed to the second party;

each of the two parties computing initial garbled labels based on the same initialization seed.

7. The method of claim 6 , wherein the evaluation phase comprising:

the first party generating a fresh seed for the pseudorandom generator;

the first party sending the fresh seed to the second party;

each of the two parties computing a garbled circuit based on the fresh seed.

8. The method of claim 1 , further comprising the server sending the output to the first party.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2022
From: BAR ILAN UNIVERSITY
To: UNBOUND SECURITY LTD
Reel/Frame 059289/0592 →
CHANGE OF NAME Recorded Mar 17, 2022
From: UNBOUND SECURITY LTD
To: COINBASE IL RD LTD
Reel/Frame 059380/0994 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2020
From: LINDELL, YEHUDA
To: BAR-ILAN UNIVERSITY
Reel/Frame 052888/0497 →