Paper 2026/2089

Is it safe to lie? Revisiting Incoercible Multi-Party Computation in the Universal Composability Framework

Saskia Bayreuther, Karlsruhe Institute of Technology
Robin Berger, Karlsruhe Institute of Technology
Eva Hetzel, Karlsruhe Institute of Technology
Jörn Müller-Quade, Karlsruhe Institute of Technology
Abstract

In a multi-party protocol, incoercibility aims to protect protocol participants by allowing them to use their honest inputs even in the presence of a coercer. A coercer is an adversary who pressures protocol parties into deviating from the protocol. One goal of an incoercible protocol is that the coercer cannot distinguish if the coerced party obeys their command or is deceiving: The coerced party should be able to plausibly deny their deception to ensure their safety. In the past, several attempts at modeling incoercibility in the Universal Composability framework have been made. In Alwen, Ostrovsky, Zhou, and Zikas’ model (CRYPTO 2015), the deception is modeled as a mapping of protocol messages that are sent and received by the coerced party beyond the reach of the coercer. Similar to proofs in plain UC, in order to prove the incoercibility of a protocol, one shows the indistinguishability of ideal and real worlds. Alwen et al.’s incoercibility definition makes use of four worlds: In both the ideal and the real worlds either coercion or deception takes place. If the environment can neither distinguish between the two coercion worlds nor between the two deception worlds for all ideal deception strategies, the protocol incoercibly UC-realizes the ideal functionality. While this shows that it is always possible for a coerced party to deviate from the coercer’s instructions and deceive them, it does not cover if this deception can be detected by the coercer. In this paper, we tackle the question how the perceived difference between deception and coercion can be modeled in UC. In particular, we make the following contributions. First, we refine the incoercibility notion by Alwen et al. by limiting the deception strategies to ones that allow the coerced party to plausibly deny the deception. We propose a multi-party computation protocol, derived from the one presented by Alwen et al., that fulfills this notion. The protocol uses hardware tokens to make UC-protocols, now including reactive functionalities, incoercible, where coerced parties can deceive the coercer about inputs as well as outputs. Secondly, we define a notion for plausible deniability, which we call Γ-deniability, and show that when the evaluated function is a differentially private mechanism, the deceiving party can plausibly deny their actions.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
IncoercibilityPlausible DeniabilityUniversal ComposabilityDifferential Privacy
Contact author(s)
saskia bayreuther @ kit edu
robin berger @ kit edu
eva hetzel @ kit edu
joern mueller-quade @ kit edu
History
2026-09-22: approved
2026-09-18: received
See all versions
Short URL
https://ia.cr/2026/2089
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2089,
      author = {Saskia Bayreuther and Robin Berger and Eva Hetzel and Jörn Müller-Quade},
      title = {Is it safe to lie? Revisiting Incoercible Multi-Party Computation in the Universal Composability Framework},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2089},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2089}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.