Robust Coin Flipping
Abstract
Alice seeks an information-theoretically secure source of private random data. Unfortunately, she lacks a personal source and must use remote sources controlled by other parties. Alice wants to simulate a coin flip of specified bias , as a function of data she receives from sources; she seeks privacy from any coalition of of them. We show: If , the bias can be any rational number and nothing else; if , the bias can be any algebraic number and nothing else. The proof uses projective varieties, convex geometry, and the probabilistic method. Our results improve on those laid out by Yao, who asserts one direction of the case in his seminal paper [Yao82]. We also provide an application to secure multiparty computation.
View on arXivComments on this paper
