🤖 AI Summary
Asymptotic security in secure multiparty computation (MPC) lacks quantifiable guarantees in practice.
Method: We propose the first method for automatically computing concrete security bounds within the Universal Composability (UC) framework, inspired by IPDL-based modeling and implemented via the Maude logical rewriting system to formally capture the precise relationship between protocol execution time and adversary advantage.
Contribution/Results: Our approach significantly simplifies simulation-based proofs and enables automated concrete security analysis. We conduct four case studies, including the first formal verification of concrete security bounds for the N-party GMW protocol—achieving a 72% reduction in proof size (567 lines of code) compared to prior work. This establishes the first concrete security analysis framework for MPC protocols that is simultaneously rigorous, computationally tractable, and scalable.
📝 Abstract
The concrete security paradigm aims to give precise bounds on the probability that an adversary can subvert a cryptographic mechanism. This is in contrast to asymptotic security, where the probability of subversion may be eventually small, but large enough in practice to be insecure. Fully satisfactory concrete security bounds for Multi-Party Computation (MPC) protocols are difficult to attain, as they require reasoning about the running time of cryptographic adversaries and reductions. In this paper we close this gap by introducing a new foundational approach that allows us to automatically compute concrete security bounds for MPC protocols. We take inspiration from the meta-theory of IPDL, a prior approach for formally verified distributed cryptography, to support reasoning about the runtime of protocols and adversarial advantage. For practical proof developments, we implement our approach in Maude, an extensible logic for equational rewriting. We carry out four case studies of concrete security for simulation-based proofs. Most notably, we deliver the first formal verification of the GMW MPC protocol over N parties. To our knowledge, this is the first time that formally verified concrete security bounds are computed for a proof of an MPC protocol in the style of Universal Composability. Our tool provides a layer of abstraction that allows the user to write proofs at a high level, which drastically simplifies the proof size. For comparison, a case study that in prior works required 2019 LoC only takes 567 LoC, thus reducing proof size by 72%