Paper 2025/1730
On the Impossibility of Actively Secure Distributed Samplers
Abstract
One-round secure computation is generally believed impossible due to the residual function attack: any honest-but-curious participant can replay the protocol in their head changing their input, and learn, in this way, a new output. Inputless functionalities are among the few that are immune to this problem. This paper studies one-round, multi-party computation protocols (MPC) that implement the most natural inputless functionality: one that generates a random sample from a fixed distribution. These are called distributed samplers. At Eurocrypt 2022, Abram, Scholl and Yakoubov showed how to build this primitive in the semi-honest model with dishonest majority. In this work, we give a lower bound for constructing distributed samplers with a malicious adversary in the standard model. More in detail, we show that for any construction in the stand-alone model with black-box simulation, even with a CRS and honest majority, the output of the sampling protocol must have low entropy. This essentially implies that this type of construction is useless in applications. Our proof is based on an entropic argument, drawing a new connection between computationally secure MPC, information theory and learning theory.
Note: A preliminary version of this work was uploaded on ePrint (see 2023/863). In this paper, we strengthen the impossibility to honest majority in the standalone model.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published by the IACR in TCC 2025
- Keywords
- Non-Interactive MPClower bounds
- Contact author(s)
-
abram damiano @ protonmail com
serge fehr @ cwi nl
cqtmlo @ nus edu sg
peter scholl @ cs au dk - History
- 2025-09-23: approved
- 2025-09-22: received
- See all versions
- Short URL
- https://ia.cr/2025/1730
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1730,
author = {Damiano Abram and Serge Fehr and Maciej Obremski and Peter Scholl},
title = {On the Impossibility of Actively Secure Distributed Samplers},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1730},
year = {2025},
url = {https://eprint.iacr.org/2025/1730}
}