Paper 2026/2089
Is it safe to lie? Revisiting Incoercible Multi-Party Computation in the Universal Composability Framework
Abstract
In a multi-party protocol, incoercibility aims to protect protocol participants by allowing them to use their honest inputs even in the presence of a coercer. A coercer is an adversary who pressures protocol parties into deviating from the protocol. One goal of an incoercible protocol is that the coercer cannot distinguish if the coerced party obeys their command or is deceiving: The coerced party should be able to plausibly deny their deception to ensure their safety. In the past, several attempts at modeling incoercibility in the Universal Composability framework have been made. In Alwen, Ostrovsky, Zhou, and Zikas’ model (CRYPTO 2015), the deception is modeled as a mapping of protocol messages that are sent and received by the coerced party beyond the reach of the coercer. Similar to proofs in plain UC, in order to prove the incoercibility of a protocol, one shows the indistinguishability of ideal and real worlds. Alwen et al.’s incoercibility definition makes use of four worlds: In both the ideal and the real worlds either coercion or deception takes place. If the environment can neither distinguish between the two coercion worlds nor between the two deception worlds for all ideal deception strategies, the protocol incoercibly UC-realizes the ideal functionality. While this shows that it is always possible for a coerced party to deviate from the coercer’s instructions and deceive them, it does not cover if this deception can be detected by the coercer. In this paper, we tackle the question how the perceived difference between deception and coercion can be modeled in UC. In particular, we make the following contributions. First, we refine the incoercibility notion by Alwen et al. by limiting the deception strategies to ones that allow the coerced party to plausibly deny the deception. We propose a multi-party computation protocol, derived from the one presented by Alwen et al., that fulfills this notion. The protocol uses hardware tokens to make UC-protocols, now including reactive functionalities, incoercible, where coerced parties can deceive the coercer about inputs as well as outputs. Secondly, we define a notion for plausible deniability, which we call Γ-deniability, and show that when the evaluated function is a differentially private mechanism, the deceiving party can plausibly deny their actions.
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- Preprint.
- Keywords
- IncoercibilityPlausible DeniabilityUniversal ComposabilityDifferential Privacy
- Contact author(s)
-
saskia bayreuther @ kit edu
robin berger @ kit edu
eva hetzel @ kit edu
joern mueller-quade @ kit edu - History
- 2026-09-22: approved
- 2026-09-18: received
- See all versions
- Short URL
- https://ia.cr/2026/2089
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2089,
author = {Saskia Bayreuther and Robin Berger and Eva Hetzel and Jörn Müller-Quade},
title = {Is it safe to lie? Revisiting Incoercible Multi-Party Computation in the Universal Composability Framework},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2089},
year = {2026},
url = {https://eprint.iacr.org/2026/2089}
}