Secure Multiplication of Shared Secrets in the Exponent

Mario Di Raimondo and Rosario Gennaro

Abstract

We present a new protocol for the following task. Given tow secrets a,b shared among n players, compute the value g^{ab}. The protocol uses the generic BGW approach for multiplication of shared secrets, but we show that if one is computing multiplications in the exponent'' the polynomial randomization step can be avoided (assuming the Decisional Diffie-Hellman Assumption holds). This results in a non-interactive and more efficient protocol.

Cryptographic protocols
secret sharingmultiparty computation
rosario @ watson ibm com
2003-04-10: revised
https://ia.cr/2003/057

