{"catalogVersion":"mpc-v1-theory-practice-measurement-atlas","topic":{"id":"mpc","title":"Secure Multi-Party Computation","stage":"representative_analytical_atlas","firstQuestion":"Which atomic contributions changed the way general MPC evaluates circuits, generates correlations, enforces active security, composes domains, or survives network and delivery failures?","unknownSemantics":["conditional","unknown","not_reported","not_applicable","not_separate","optional_external"],"tracks":[{"id":"theory","label":"Theory and configurations","object_types":["paper","contribution","component","protocol_configuration"],"evidence_focus":"theorem scope, exact adversary and network model, reusable mechanisms, and one complete protocol configuration"},{"id":"practice","label":"Implementations","object_types":["implementation_version"],"evidence_focus":"immutable revision, realized configurations, language, availability, maturity, and protocol binding"},{"id":"measurement","label":"Measurements","object_types":["benchmark_run"],"evidence_focus":"exact artifact, party and security profile, workload, hardware, network, phase accounting, metric definition, and evidence state"}]},"lenses":[{"id":"generality-feasibility","label":"Generality and feasibility","question":"Which functionalities, models, and corruption thresholds become possible?","description":"Completeness, access structures, composability, and model-specific feasibility boundaries."},{"id":"garbled-circuit-efficiency","label":"Garbled-circuit efficiency","question":"How are garbling cost and online rounds reduced?","description":"Wire encodings, table size, distributed garbling, and systems integration."},{"id":"active-security","label":"Active security","question":"How are arbitrary deviations detected or tolerated?","description":"VSS, authentication, sacrifice, consistency checks, and specialized compilers."},{"id":"preprocessing-correlation","label":"Preprocessing and correlation","question":"Which input-independent resources make the online phase light?","description":"Triples, OT/OLE/VOLE, HE-generated correlations, PCGs, and silent expansion."},{"id":"round-communication","label":"Rounds and communication","question":"Which bottleneck is reduced—depth, bytes, party scaling, or weak links?","description":"Constant rounds, online/offline splits, communication complexity, and topology-aware costs."},{"id":"mixed-protocol-compilation","label":"Mixed-protocol compilation","question":"How are subcomputations assigned and converted across domains?","description":"Arithmetic, Boolean, and garbled representations with typed conversion boundaries."},{"id":"network-delivery","label":"Network and delivery","question":"What happens under delay, abort, fairness, and output-recovery constraints?","description":"Asynchrony, agreement, fairness, guaranteed delivery, robustness, and deployment topology."},{"id":"adaptive-proactive","label":"Adaptive and proactive security","question":"Can security survive changing corruptions and long-lived state?","description":"Adaptive corruption, state explanation, erasures, share refresh, and mobile adversaries."},{"id":"implementation-systems","label":"Implementation systems","question":"Which complete stacks are realized as usable software?","description":"Compilers, runtimes, protocol providers, immutable revisions, and artifacts."}],"stats":{"entities":140,"relationships":277,"propertyAssertions":130,"protocols":13,"components":41,"claims":39,"openProblems":5,"backboneClaims":18,"implementations":4,"benchmarkRuns":1,"comparableBenchmarkRuns":0,"countsByType":{"benchmark_run":1,"component":41,"contribution":39,"implementation":4,"open_problem":5,"paper":37,"protocol":13},"unresolvedReferences":0,"lineageRelationships":9},"nodes":[{"id":"MPC-CONTRIB-1982-YAO-2PC","type":"contribution","title":"Two-party private computation becomes a general protocol problem","subtitle":"Protocols for Secure Computations","status":"published","evidence":"primary_source_checked","year":1982,"venue":"FOCS 1982","primaryUrl":"https://research.cs.wisc.edu/areas/sec/yao1982-ocr.pdf","summary":"Yao formulates and gives protocols for two parties to compute functions of private inputs while limiting what each party learns, establishing secure two-party computation as a general cryptographic task.","tags":["atomic-contribution","backbone","feasibility","feasibility_and_construction","garbled-circuit-efficiency","generality-feasibility","private-computation","secure-two-party-computation"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1982-YAO-2PC","paper_id":"MPC-PAPER-1982-YAO","year":1982,"title":"Two-party private computation becomes a general protocol problem","claim_slug":"yao-two-party-private-computation","contribution_kind":"capability_result","contribution_role":"feasibility_and_construction","statement":"Yao formulates and gives protocols for two parties to compute functions of private inputs while limiting what each party learns, establishing secure two-party computation as a general cryptographic task.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Cryptographic protocols protected communication or solved specialized coordination tasks, but there was no comparably general protocol formulation for computing on two parties' private data.","technical_delta":"The paper treats private function evaluation itself as the object to construct and presents protocols that separate the desired output from the parties' hidden inputs.","significance_at_publication":"It supplied the problem boundary from which general secure-computation compilers and the garbled-circuit tradition could be developed.","narrative":"Earlier cryptographic protocols protected messages or addressed particular coordination problems, but they did not yet provide a general language for two parties computing on private inputs. Yao made the computation itself the cryptographic object: specify a function, let each party retain its input, and reveal only the prescribed result within the protocol's security model. The contribution is this general secure two-party computation paradigm and its protocol feasibility, not every detail later associated with modern garbled circuits. At publication time it created a common problem statement against which later circuit compilers, garbling techniques, oblivious-transfer optimizations, and concrete systems could be compared."},"source_locator":{"dossier_section":"MPC-PAPER-1982-YAO § Atomic contribution","primary_source":"Abstract and protocol constructions","primary_source_url":"https://research.cs.wisc.edu/areas/sec/yao1982-ocr.pdf","status":"section_checked"},"qualifiers":["two-party setting","private inputs","function evaluation"],"limitations":["the record does not attribute every modern garbled-circuit formalization to this paper","the exact security formulation predates contemporary simulation frameworks"],"facet_status":"normalized","facets":{"task":["secure-function-evaluation"],"party_model":["two-party"],"adversary_behavior":["paper-specific"],"mechanism":["protocol-construction"]},"status":"published","evidence":"primary_source_checked","research_lenses":["generality-feasibility","garbled-circuit-efficiency"],"keywords":["secure-two-party-computation","private-computation","feasibility"],"work_id":"MPC-PAPER-1982-YAO","role":"feasibility_and_construction","lens":"generality-feasibility","visibility":"backbone"},"sections":[{"heading":"Overview","content":"Two-party private computation This card records the task and feasibility boundary rather than treating a paper title as a lineage node."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1982-YAO-2PC"},{"id":"MPC-PAPER-1982-YAO","type":"paper","title":"Protocols for Secure Computations","subtitle":"Andrew C. Yao · 1982","status":"published","evidence":"primary_source_checked","year":1982,"venue":"FOCS 1982","primaryUrl":"https://research.cs.wisc.edu/areas/sec/yao1982-ocr.pdf","summary":"The atlas treats this as the conceptual 2PC root. Later formal proofs and modern garbling optimizations are separate contributions.","tags":["garbled-circuit-efficiency","generality-feasibility"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1982-YAO","title":"Protocols for Secure Computations","authors":["Andrew C. Yao"],"year":1982,"venue":"FOCS 1982","primary_url":"https://research.cs.wisc.edu/areas/sec/yao1982-ocr.pdf","status":"published","evidence":"primary_source_checked","keywords":["generality-feasibility","garbled-circuit-efficiency"],"contribution_ids":["MPC-CONTRIB-1982-YAO-2PC"]},"sections":[{"heading":"Boundary note","content":"The atlas treats this as the conceptual 2PC root. Later formal proofs and modern garbling optimizations are separate contributions."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1982-YAO"},{"id":"MPC-CONTRIB-1987-GMW-COMPILER","type":"contribution","title":"Circuit compilation gives general MPC with explicit adversary upgrades","subtitle":"How to Play ANY Mental Game","status":"published","evidence":"primary_source_checked","year":1987,"venue":"STOC 1987","primaryUrl":"https://www.math.ias.edu/~avi/PUBLICATIONS/MYPAPERS/GMW87/GMW87.pdf","summary":"Goldreich, Micali, and Wigderson give a general circuit-based method for secure multiparty computation and separate passive evaluation from compilation techniques that enforce security against stronger adversarial behavior.","tags":["active-security","atomic-contribution","backbone","circuit-compilation","completeness","feasibility_and_compiler","generality-feasibility","gmw","malicious-security"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1987-GMW-COMPILER","paper_id":"MPC-PAPER-1987-GMW","year":1987,"title":"Circuit compilation gives general MPC with explicit adversary upgrades","claim_slug":"gmw-general-mpc-compiler","contribution_kind":"transform","contribution_role":"feasibility_and_compiler","statement":"Goldreich, Micali, and Wigderson give a general circuit-based method for secure multiparty computation and separate passive evaluation from compilation techniques that enforce security against stronger adversarial behavior.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Secure computation was represented by early two-party protocols and specialized tasks rather than a general compiler from arbitrary polynomial-time functionality to a secure multiparty protocol.","technical_delta":"GMW reduces general computation to secure gate evaluation and organizes the treatment of passive and malicious behavior through distinct protocol and compilation steps.","significance_at_publication":"It established generality as a theorem-level MPC boundary and made adversary handling an explicit layer rather than an informal property of one protocol.","narrative":"Early secure-computation results showed that privacy-preserving interaction was possible, but did not yet provide a uniform recipe for arbitrary multiparty functionalities under clearly separated adversary models. GMW represents the target computation as a circuit, evaluates its gates on distributed values, and distinguishes the machinery needed for passive execution from the additional enforcement required against malicious behavior. The atomic change is a general compilation architecture, not a single optimized gate protocol. This mattered because subsequent MPC research could improve sharing, oblivious transfer, consistency checks, or setup while retaining a recognizable completeness contract for general computation."},"source_locator":{"dossier_section":"MPC-PAPER-1987-GMW § Atomic contribution","primary_source":"Introduction and general protocol construction","primary_source_url":"https://www.math.ias.edu/~avi/PUBLICATIONS/MYPAPERS/GMW87/GMW87.pdf","status":"section_checked"},"qualifiers":["circuit-represented polynomial-time functionalities","computational cryptography","model-specific security compilation"],"limitations":["round and communication costs depend on the circuit and subprotocols","later frameworks refine the security and composition contract"],"facet_status":"normalized","facets":{"task":["general-mpc"],"mechanism":["circuit-compilation","gate-evaluation"],"adversary_behavior":["passive","malicious"],"party_model":["multiparty"]},"status":"published","evidence":"primary_source_checked","research_lenses":["generality-feasibility","active-security"],"keywords":["gmw","completeness","circuit-compilation","malicious-security"],"work_id":"MPC-PAPER-1987-GMW","role":"feasibility_and_compiler","lens":"generality-feasibility","visibility":"backbone"},"sections":[{"heading":"Overview","content":"GMW compiler The complete GMW protocol family remains a construction object; this record isolates the compiler-level research delta."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1987-GMW-COMPILER"},{"id":"MPC-PAPER-1987-GMW","type":"paper","title":"How to Play ANY Mental Game","subtitle":"Oded Goldreich, Silvio Micali, Avi Wigderson · 1987","status":"published","evidence":"primary_source_checked","year":1987,"venue":"STOC 1987","primaryUrl":"https://www.math.ias.edu/~avi/PUBLICATIONS/MYPAPERS/GMW87/GMW87.pdf","summary":"GMW is represented by its general Boolean secret-sharing configuration, not by every later optimized protocol carrying the name.","tags":["active-security","generality-feasibility"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1987-GMW","title":"How to Play ANY Mental Game","authors":["Oded Goldreich","Silvio Micali","Avi Wigderson"],"year":1987,"venue":"STOC 1987","primary_url":"https://www.math.ias.edu/~avi/PUBLICATIONS/MYPAPERS/GMW87/GMW87.pdf","status":"published","evidence":"primary_source_checked","keywords":["generality-feasibility","active-security"],"contribution_ids":["MPC-CONTRIB-1987-GMW-COMPILER"]},"sections":[{"heading":"Role","content":"GMW is represented by its general Boolean secret-sharing configuration, not by every later optimized protocol carrying the name."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1987-GMW"},{"id":"MPC-CONTRIB-1988-BGW-THRESHOLDS","type":"contribution","title":"Honest-majority thresholds characterize information-theoretic general MPC","subtitle":"Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation","status":"published","evidence":"primary_source_checked","year":1988,"venue":"STOC 1988","primaryUrl":"https://mit6875.github.io/PAPERS/BGW.pdf","summary":"BGW establishes unconditional general MPC over private channels for passive corruption below one half and Byzantine corruption below one third, together with matching threshold limitations in its model.","tags":["active-security","atomic-contribution","backbone","bgw","feasibility_boundary","generality-feasibility","honest-majority","network-delivery","thresholds","unconditional-security"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1988-BGW-THRESHOLDS","paper_id":"MPC-PAPER-1988-BGW","year":1988,"title":"Honest-majority thresholds characterize information-theoretic general MPC","claim_slug":"bgw-information-theoretic-thresholds","contribution_kind":"boundary_result","contribution_role":"feasibility_boundary","statement":"BGW establishes unconditional general MPC over private channels for passive corruption below one half and Byzantine corruption below one third, together with matching threshold limitations in its model.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"General secure computation was becoming possible under computational assumptions, but the exact unconditional feasibility frontier as a function of corruptions and communication assumptions was not yet settled.","technical_delta":"BGW combines polynomial secret sharing, degree reduction, and verifiable sharing to obtain general protocols at honest-majority thresholds and proves the corresponding model-specific limitations.","significance_at_publication":"It turned party threshold and adversary behavior into explicit feasibility coordinates and founded the arithmetic secret-sharing line of MPC.","narrative":"General MPC feasibility did not by itself answer whether cryptographic hardness was necessary or how many corrupt parties an information-theoretic protocol could tolerate. BGW uses polynomial sharing to represent values and compute arithmetic circuits, adding verifiability for Byzantine behavior. In the private-channel model, the resulting boundaries separate passive corruption below one half from active corruption below one third, with matching impossibility statements for the relevant thresholds. This was more than a new construction: it made corruption threshold and adversary behavior first-class coordinates of an MPC claim. The result anchored later honest-majority protocols, generalized sharing schemes, and comparisons between synchronous and asynchronous feasibility."},"source_locator":{"dossier_section":"MPC-PAPER-1988-BGW § Atomic contribution","primary_source":"Abstract; completeness and impossibility theorems","primary_source_url":"https://mit6875.github.io/PAPERS/BGW.pdf","status":"theorem_checked"},"qualifiers":["private channels","information-theoretic security","synchronous communication model"],"limitations":["thresholds are model-dependent","dishonest-majority feasibility requires different assumptions or guarantees"],"facet_status":"normalized","facets":{"task":["general-mpc"],"mechanism":["polynomial-secret-sharing","verifiable-secret-sharing"],"adversary_behavior":["passive","malicious"],"majority_regime":["honest-majority"],"network_model":["synchronous-private-channels"]},"status":"published","evidence":"primary_source_checked","research_lenses":["generality-feasibility","active-security","network-delivery"],"keywords":["bgw","honest-majority","thresholds","unconditional-security"],"work_id":"MPC-PAPER-1988-BGW","role":"feasibility_boundary","lens":"generality-feasibility","visibility":"backbone"},"sections":[{"heading":"Overview","content":"BGW threshold frontier The threshold values are preserved together with their network and adversary qualifications."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1988-BGW-THRESHOLDS"},{"id":"MPC-PAPER-1988-BGW","type":"paper","title":"Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation","subtitle":"Michael Ben-Or, Shafi Goldwasser, Avi Wigderson · 1988","status":"published","evidence":"primary_source_checked","year":1988,"venue":"STOC 1988","primaryUrl":"https://mit6875.github.io/PAPERS/BGW.pdf","summary":"The threshold statements are model-specific; they are not global limits for computational MPC with other setup or output guarantees.","tags":["active-security","generality-feasibility","network-delivery"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1988-BGW","title":"Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation","authors":["Michael Ben-Or","Shafi Goldwasser","Avi Wigderson"],"year":1988,"venue":"STOC 1988","primary_url":"https://mit6875.github.io/PAPERS/BGW.pdf","status":"published","evidence":"primary_source_checked","keywords":["generality-feasibility","active-security","network-delivery"],"contribution_ids":["MPC-CONTRIB-1988-BGW-THRESHOLDS"]},"sections":[{"heading":"Boundary note","content":"The threshold statements are model-specific; they are not global limits for computational MPC with other setup or output guarantees."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1988-BGW"},{"id":"MPC-PROTOCOL-BGW-ACTIVE","type":"protocol","title":"BGW active honest-majority field MPC","subtitle":"polynomial secret sharing · 1988","status":"published","evidence":"primary_source_checked","year":1988,"venue":null,"primaryUrl":null,"summary":"Private channels and broadcast are part of this row's model; removing or emulating them changes the construction.","tags":["active-security","generality-feasibility","network-delivery"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-BGW-ACTIVE","title":"BGW active honest-majority field MPC","name":"BGW active MPC","paper_ids":["MPC-PAPER-1988-BGW"],"claim_ids":["MPC-CONTRIB-1988-BGW-THRESHOLDS"],"year":1988,"protocol_family":"polynomial_secret_sharing","research_lenses":["generality-feasibility","active-security","network-delivery"],"tasks":["general_mpc","arithmetic_circuit_evaluation","guaranteed_output"],"properties":{"parties":"n","corruption_threshold":"t < n/3 active","majority_regime":"honest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_information_theoretic","network_model":"synchronous_private_channels_with_broadcast","setup":"no_cryptographic_preprocessing","output_guarantee":"robust_reconstruction_and_delivery_in_model","privacy_basis":"information_theoretic"},"stack":{"representation":["MPC-COMP-REP-ARITH-FIELD"],"value_encoding":["MPC-COMP-ENC-SHAMIR"],"evaluation_protocol":["MPC-COMP-EVAL-BGW"],"correlation_source":[],"active_security_enforcement":["MPC-COMP-ACT-BGW-VSS"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-HONEST-MAJORITY"]},"stack_status":{"correlation_source":"not_separate","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_arithmetic_multiplicative_depth","communication_driver":"verifiable_sharing_and_degree_reduction","preprocessing":"not_separate"},"configuration_note":"Active, synchronous BGW field configuration; the passive t<n/2 result is a different model profile.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Boundary","content":"Private channels and broadcast are part of this row's model; removing or emulating them changes the construction."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-BGW-ACTIVE"},{"id":"MPC-CONTRIB-1990-BMR-CONSTANT","type":"contribution","title":"Distributed garbling removes circuit depth from MPC round complexity","subtitle":"The Round Complexity of Secure Protocols","status":"published","evidence":"primary_source_checked","year":1990,"venue":"STOC 1990","primaryUrl":"https://web.cs.ucdavis.edu/~rogaway/papers/bmr90","summary":"Beaver, Micali, and Rogaway construct constant-round multiparty computation by distributing garbled-circuit preparation so that the online interaction does not grow with circuit depth.","tags":["atomic-contribution","backbone","bmr","constant-round","distributed-garbling","garbled-circuit-efficiency","round-communication","round_reduction"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1990-BMR-CONSTANT","paper_id":"MPC-PAPER-1990-BMR","year":1990,"title":"Distributed garbling removes circuit depth from MPC round complexity","claim_slug":"bmr-constant-round-distributed-garbling","contribution_kind":"construction","contribution_role":"round_reduction","statement":"Beaver, Micali, and Rogaway construct constant-round multiparty computation by distributing garbled-circuit preparation so that the online interaction does not grow with circuit depth.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Gate-by-gate circuit protocols naturally incurred interaction proportional to circuit depth, making round complexity a structural cost of general MPC.","technical_delta":"BMR has the parties jointly prepare a garbled representation whose later evaluation is predominantly local, separating communication rounds from the depth of the evaluated circuit.","significance_at_publication":"It opened distributed garbling as a distinct architecture and showed that depth-dependent rounds were not inherent to general secure computation.","narrative":"Circuit-based MPC was general, but evaluating shared gates in sequence tied interaction to circuit depth. BMR changes the execution architecture: parties cooperate to prepare a garbled circuit and then evaluate that representation without repeating an interactive protocol at every level. The resulting protocol achieves a constant number of rounds under its stated cryptographic model even when the circuit is deep. The contribution is this distributed-garbling route to round reduction, not a claim that communication or computation becomes constant. It mattered because later work could optimize the distributed preparation, strengthen it against malicious parties, or combine it with preprocessing while retaining the same low-round online structure."},"source_locator":{"dossier_section":"MPC-PAPER-1990-BMR § Atomic contribution","primary_source":"Abstract and constant-round protocol construction","primary_source_url":"https://web.cs.ucdavis.edu/~rogaway/papers/bmr90","status":"section_checked"},"qualifiers":["constant communication rounds","circuit-based multiparty computation","distributed garbling"],"limitations":["constant rounds do not imply constant communication","concrete costs depend on distributed garbling and cryptographic subprotocols"],"facet_status":"normalized","facets":{"task":["round-reduction"],"mechanism":["distributed-garbling"],"party_model":["multiparty"],"cost_coordinate":["rounds"]},"status":"published","evidence":"primary_source_checked","research_lenses":["garbled-circuit-efficiency","round-communication"],"keywords":["bmr","constant-round","distributed-garbling"],"work_id":"MPC-PAPER-1990-BMR","role":"round_reduction","lens":"garbled-circuit-efficiency","visibility":"backbone"},"sections":[{"heading":"Overview","content":"BMR round reduction Round complexity remains separate from bandwidth and local work in the normalized claim."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1990-BMR-CONSTANT"},{"id":"MPC-PAPER-1990-BMR","type":"paper","title":"The Round Complexity of Secure Protocols","subtitle":"Donald Beaver, Silvio Micali, Phillip Rogaway · 1990","status":"published","evidence":"primary_source_checked","year":1990,"venue":"STOC 1990","primaryUrl":"https://web.cs.ucdavis.edu/~rogaway/papers/bmr90","summary":"BMR anchors the multiparty distributed-garbling thread; later work changes how the garbling is produced and actively secured.","tags":["garbled-circuit-efficiency","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1990-BMR","title":"The Round Complexity of Secure Protocols","authors":["Donald Beaver","Silvio Micali","Phillip Rogaway"],"year":1990,"venue":"STOC 1990","primary_url":"https://web.cs.ucdavis.edu/~rogaway/papers/bmr90","status":"published","evidence":"primary_source_checked","keywords":["garbled-circuit-efficiency","round-communication"],"contribution_ids":["MPC-CONTRIB-1990-BMR-CONSTANT"]},"sections":[{"heading":"Role","content":"BMR anchors the multiparty distributed-garbling thread; later work changes how the garbling is produced and actively secured."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1990-BMR"},{"id":"MPC-PROTOCOL-BMR-PASSIVE","type":"protocol","title":"BMR constant-round multiparty garbling","subtitle":"multiparty garbled circuit · 1990","status":"published","evidence":"primary_source_checked","year":1990,"venue":null,"primaryUrl":null,"summary":"The original mechanism establishes the constant-round line; BMR+SPDZ changes its enforcement and preprocessing layers.","tags":["garbled-circuit-efficiency","round-communication"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-BMR-PASSIVE","title":"BMR constant-round multiparty garbling","name":"BMR passive MPC","paper_ids":["MPC-PAPER-1990-BMR"],"claim_ids":["MPC-CONTRIB-1990-BMR-CONSTANT"],"year":1990,"protocol_family":"multiparty_garbled_circuit","research_lenses":["garbled-circuit-efficiency","round-communication"],"tasks":["general_mpc","constant_round_online"],"properties":{"parties":"n","corruption_threshold":"paper configurations vary; displayed row is passive","majority_regime":"configuration_specific","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"distributed_garbling_phase","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-MULTI-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BMR"],"correlation_source":[],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"correlation_source":"not_separate","active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"constant","communication_driver":"distributed_garbling_tables_and_input_labels","preprocessing":"distributed_garbling"},"configuration_note":"Passive BMR core shown separately from the later actively secure BMR+SPDZ composition.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Why separate","content":"The original mechanism establishes the constant-round line; BMR+SPDZ changes its enforcement and preprocessing layers."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-BMR-PASSIVE"},{"id":"MPC-CONTRIB-1991-BEAVER-TRIPLES","type":"contribution","title":"Input-independent multiplication triples separate MPC preprocessing from online work","subtitle":"Efficient Multiparty Protocols Using Circuit Randomization","status":"published","evidence":"primary_source_checked","year":1991,"venue":"CRYPTO 1991","primaryUrl":"https://doi.org/10.1007/3-540-46766-1_34","summary":"Beaver's circuit-randomization method uses input-independent correlated multiplication values so arithmetic products can be opened and completed online with lightweight interaction once the correlations are available.","tags":["arithmetic-mpc","atomic-contribution","backbone","beaver-triples","preprocessing","preprocessing-correlation","reusable_mechanism","round-communication"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1991-BEAVER-TRIPLES","paper_id":"MPC-PAPER-1991-BEAVER","year":1991,"title":"Input-independent multiplication triples separate MPC preprocessing from online work","claim_slug":"beaver-multiplication-triples","contribution_kind":"mechanism","contribution_role":"reusable_mechanism","statement":"Beaver's circuit-randomization method uses input-independent correlated multiplication values so arithmetic products can be opened and completed online with lightweight interaction once the correlations are available.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Arithmetic MPC evaluated multiplication through interactive protocols whose expensive cryptographic work remained coupled to the parties' live inputs and circuit execution.","technical_delta":"Random triples satisfying a multiplicative relation are prepared independently of inputs and later mask the online multiplication, moving the hard work into a reusable offline phase.","significance_at_publication":"It supplied the enduring online/offline abstraction behind many arithmetic MPC protocols and made correlation generation an independent optimization target.","narrative":"Arithmetic sharing makes addition local, but multiplication normally forces the parties back into an interactive cryptographic subprotocol. Beaver's circuit randomization prepares correlated random values before the actual inputs are known. During execution, parties reveal only masked differences and combine them with the preprocessed correlation to obtain a sharing of the product. The atomic contribution is the input-independent multiplication correlation and the clean separation it creates between offline generation and online evaluation. This mattered because subsequent protocols could preserve a simple online phase while replacing the way triples are generated—using homomorphic encryption, oblivious transfer, pseudorandom generators, or specialized honest-majority techniques."},"source_locator":{"dossier_section":"MPC-PAPER-1991-BEAVER § Atomic contribution","primary_source":"Circuit-randomization construction for multiplication","primary_source_url":"https://doi.org/10.1007/3-540-46766-1_34","status":"section_checked"},"qualifiers":["arithmetic circuits","input-independent preprocessing","secret-shared multiplication"],"limitations":["the mechanism assumes correctly generated correlations","security and cost depend on the surrounding protocol and triple generator"],"facet_status":"normalized","facets":{"task":["online-offline-separation"],"mechanism":["multiplication-triples","circuit-randomization"],"representation":["arithmetic-sharing"],"phase":["preprocessing","online"]},"status":"published","evidence":"primary_source_checked","research_lenses":["preprocessing-correlation","round-communication"],"keywords":["beaver-triples","preprocessing","arithmetic-mpc"],"work_id":"MPC-PAPER-1991-BEAVER","role":"reusable_mechanism","lens":"preprocessing-correlation","visibility":"backbone"},"sections":[{"heading":"Overview","content":"Beaver triples This mechanism record is distinct from any complete SPDZ-style protocol configuration that consumes triples."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1991-BEAVER-TRIPLES"},{"id":"MPC-PAPER-1991-BEAVER","type":"paper","title":"Efficient Multiparty Protocols Using Circuit Randomization","subtitle":"Donald Beaver · 1991","status":"published","evidence":"primary_source_checked","year":1991,"venue":"CRYPTO 1991","primaryUrl":"https://doi.org/10.1007/3-540-46766-1_34","summary":"The modern term “Beaver triple” is used in the interface; the paper is the source for the circuit-randomization mechanism.","tags":["preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1991-BEAVER","title":"Efficient Multiparty Protocols Using Circuit Randomization","authors":["Donald Beaver"],"year":1991,"venue":"CRYPTO 1991","primary_url":"https://doi.org/10.1007/3-540-46766-1_34","status":"published","evidence":"primary_source_checked","keywords":["preprocessing-correlation","round-communication"],"contribution_ids":["MPC-CONTRIB-1991-BEAVER-TRIPLES"]},"sections":[{"heading":"Terminology","content":"The modern term “Beaver triple” is used in the interface; the paper is the source for the circuit-randomization mechanism."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1991-BEAVER"},{"id":"MPC-CONTRIB-1993-ASYNC-FEASIBILITY","type":"contribution","title":"General MPC remains feasible with arbitrarily delayed messages","subtitle":"Asynchronous Secure Computation","status":"published","evidence":"primary_source_checked","year":1993,"venue":"STOC 1993","primaryUrl":"https://doi.org/10.1145/167088.167109","summary":"Ben-Or, Canetti, and Goldreich establish general secure computation in a completely asynchronous private-channel network with optimal resilience below one third for fail-stop faults and below one fourth for Byzantine faults.","tags":["agreement","asynchronous-mpc","atomic-contribution","backbone","generality-feasibility","model_transformation","network-delivery","verifiable-sharing"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1993-ASYNC-FEASIBILITY","paper_id":"MPC-PAPER-1993-ASYNC","year":1993,"title":"General MPC remains feasible with arbitrarily delayed messages","claim_slug":"asynchronous-mpc-feasibility","contribution_kind":"capability_result","contribution_role":"model_transformation","statement":"Ben-Or, Canetti, and Goldreich establish general secure computation in a completely asynchronous private-channel network with optimal resilience below one third for fail-stop faults and below one fourth for Byzantine faults.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Classical completeness results assumed a synchronous progression in which missing messages could be interpreted through known rounds and timing bounds.","technical_delta":"The protocol replaces round-based coordination with asynchronous verifiable sharing, agreement, and online error correction, with separate optimal resilience bounds for fail-stop and Byzantine faults.","significance_at_publication":"It showed that network timing and fault behavior jointly determine the exact feasibility frontier rather than merely slowing a synchronous MPC protocol.","narrative":"Honest-majority MPC completeness had been established in synchronous networks, where rounds and delivery bounds help parties decide when to continue. An asynchronous network removes that signal: a delayed message is indistinguishable from a failed sender. Ben-Or, Canetti, and Goldreich combine asynchronous agreement, errorless verifiable sharing, and online error correction so a computation can finish without hearing from faulty parties. The exact frontier depends on fault behavior: fewer than one third of parties may fail-stop, whereas Byzantine faults must remain below one fourth in this errorless construction. The contribution is therefore a model-specific feasibility theorem, not merely a slower implementation of synchronous MPC, and its two resilience bounds should not be collapsed into one generic honest-majority label."},"source_locator":{"dossier_section":"MPC-PAPER-1993-ASYNC § Atomic contribution","primary_source":"Abstract and main asynchronous secure-computation construction","primary_source_url":"https://doi.org/10.1145/167088.167109","status":"theorem_checked"},"qualifiers":["completely asynchronous private channels","fewer than one-third fail-stop faults","fewer than one-fourth Byzantine faults","errorless general computation"],"limitations":["the two fault types have different optimal resilience bounds","later probabilistic-error protocols reach different Byzantine thresholds","the result is not a claim for arbitrary dishonest majorities"],"facet_status":"normalized","facets":{"task":["general-mpc"],"network_model":["completely-asynchronous-private-channels"],"fault_model":["fail-stop","byzantine"],"corruption_threshold":["fail-stop-below-one-third","byzantine-below-one-fourth"],"majority_regime":["honest-majority"],"mechanism":["asynchronous-verifiable-sharing","agreement","online-error-correction"]},"status":"published","evidence":"primary_source_checked","research_lenses":["network-delivery","generality-feasibility"],"keywords":["asynchronous-mpc","agreement","verifiable-sharing"],"work_id":"MPC-PAPER-1993-ASYNC","role":"model_transformation","lens":"network-delivery","visibility":"backbone"},"sections":[{"heading":"Overview","content":"Asynchronous feasibility Network timing is recorded as a facet while the technical transition remains an atomic contribution."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1993-ASYNC-FEASIBILITY"},{"id":"MPC-PAPER-1993-ASYNC","type":"paper","title":"Asynchronous Secure Computation","subtitle":"Michael Ben-Or, Ran Canetti, Oded Goldreich · 1993","status":"published","evidence":"primary_source_checked","year":1993,"venue":"STOC 1993","primaryUrl":"https://doi.org/10.1145/167088.167109","summary":"Asynchrony is a network facet, not a protocol family. This model-changing result can combine with different evaluation mechanisms.","tags":["generality-feasibility","network-delivery"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1993-ASYNC","title":"Asynchronous Secure Computation","authors":["Michael Ben-Or","Ran Canetti","Oded Goldreich"],"year":1993,"venue":"STOC 1993","primary_url":"https://doi.org/10.1145/167088.167109","status":"published","evidence":"primary_source_checked","keywords":["network-delivery","generality-feasibility"],"contribution_ids":["MPC-CONTRIB-1993-ASYNC-FEASIBILITY"]},"sections":[{"heading":"Boundary note","content":"Asynchrony is a network facet, not a protocol family. This model-changing result can combine with different evaluation mechanisms."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1993-ASYNC"},{"id":"MPC-CONTRIB-1995-PROACTIVE-REFRESH","type":"contribution","title":"Periodic share refresh prevents mobile corruptions from accumulating secrets","subtitle":"Proactive Secret Sharing or: How to Cope With Perpetual Leakage","status":"published","evidence":"primary_source_checked","year":1995,"venue":"CRYPTO 1995","primaryUrl":"https://research.google/pubs/proactive-secret-sharing-or-how-to-cope-with-perpetual-leakage/","summary":"Proactive secret sharing periodically rerandomizes distributed shares without changing the protected secret, preventing an adversary that compromises different parties in different epochs from accumulating a reconstructing set.","tags":["adaptive-proactive","atomic-contribution","mobile-adversary","proactive-security","reviewed_related","security_transformation","share-refresh"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1995-PROACTIVE-REFRESH","paper_id":"MPC-PAPER-1995-PROACTIVE","year":1995,"title":"Periodic share refresh prevents mobile corruptions from accumulating secrets","claim_slug":"proactive-share-refresh","contribution_kind":"security_result","contribution_role":"security_transformation","statement":"Proactive secret sharing periodically rerandomizes distributed shares without changing the protected secret, preventing an adversary that compromises different parties in different epochs from accumulating a reconstructing set.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Threshold sharing protected a secret only while the adversary remained below the threshold over the lifetime of one fixed sharing; compromises could otherwise accumulate over time.","technical_delta":"Parties refresh their shares and erase obsolete state so exposure in one period does not combine with exposure from another period to reveal the secret.","significance_at_publication":"It introduced an epoch-based security mechanism for long-lived distributed state and separated mobile-adversary resilience from one-shot MPC correctness.","narrative":"A static threshold guarantee limits how many shares an adversary sees at one moment, but a long-lived service may face compromises of different machines over time. If shares never change, those exposures accumulate. Proactive secret sharing periodically replaces each party's share with a fresh one representing the same secret, while old state is discarded. The atomic contribution is this cross-epoch rerandomization mechanism and its mobile-adversary boundary, not a complete general-purpose MPC stack. It mattered because distributed cryptographic services could reason about a bounded number of corruptions per period rather than a single lifetime compromise set, and later proactive MPC could reuse the refresh abstraction."},"source_locator":{"dossier_section":"MPC-PAPER-1995-PROACTIVE § Atomic contribution","primary_source":"Abstract and share-renewal protocol","primary_source_url":"https://research.google/pubs/proactive-secret-sharing-or-how-to-cope-with-perpetual-leakage/","status":"section_checked"},"qualifiers":["epoch-based corruption bound","share refresh","secure erasure of obsolete state"],"limitations":["requires the per-epoch corruption threshold and refresh assumptions","does not itself provide a complete MPC protocol"],"facet_status":"normalized","facets":{"task":["long-lived-security"],"mechanism":["share-refresh"],"corruption_timing":["mobile-proactive"],"state_model":["epochs"]},"status":"published","evidence":"primary_source_checked","research_lenses":["adaptive-proactive"],"keywords":["proactive-security","mobile-adversary","share-refresh"],"work_id":"MPC-PAPER-1995-PROACTIVE","role":"security_transformation","lens":"adaptive-proactive","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"Proactive refresh The map uses this as a reusable long-lived-security mechanism rather than a peer protocol configuration."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1995-PROACTIVE-REFRESH"},{"id":"MPC-PAPER-1995-PROACTIVE","type":"paper","title":"Proactive Secret Sharing or: How to Cope With Perpetual Leakage","subtitle":"Amir Herzberg, Stanislaw Jarecki, Hugo Krawczyk et al. · 1995","status":"published","evidence":"primary_source_checked","year":1995,"venue":"CRYPTO 1995","primaryUrl":"https://research.google/pubs/proactive-secret-sharing-or-how-to-cope-with-perpetual-leakage/","summary":"Proactive refresh is included as a reusable distributed-state mechanism; it does not by itself specify a complete MPC evaluation protocol.","tags":["adaptive-proactive"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1995-PROACTIVE","title":"Proactive Secret Sharing or: How to Cope With Perpetual Leakage","authors":["Amir Herzberg","Stanislaw Jarecki","Hugo Krawczyk","Moti Yung"],"year":1995,"venue":"CRYPTO 1995","primary_url":"https://research.google/pubs/proactive-secret-sharing-or-how-to-cope-with-perpetual-leakage/","status":"published","evidence":"primary_source_checked","keywords":["adaptive-proactive"],"contribution_ids":["MPC-CONTRIB-1995-PROACTIVE-REFRESH"]},"sections":[{"heading":"Scope","content":"Proactive refresh is included as a reusable distributed-state mechanism; it does not by itself specify a complete MPC evaluation protocol."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1995-PROACTIVE"},{"id":"MPC-CONTRIB-1996-ADAPTIVE-NCE","type":"contribution","title":"Non-committing techniques secure MPC against execution-dependent corruptions","subtitle":"Adaptively Secure Multi-party Computation","status":"published","evidence":"primary_source_checked","year":1996,"venue":"STOC 1996","primaryUrl":"https://www.wisdom.weizmann.ac.il/~oded/PSX/dynamic.pdf","summary":"Canetti, Feige, Goldreich, and Naor use non-committing encryption to obtain computational MPC over insecure channels against adaptive corruptions of non-erasing parties under the paper's threshold and trapdoor assumptions.","tags":["active-security","adaptive-proactive","adaptive-security","atomic-contribution","non-committing-encryption","reviewed_related","security_transformation","simulation"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-1996-ADAPTIVE-NCE","paper_id":"MPC-PAPER-1996-ADAPTIVE","year":1996,"title":"Non-committing techniques secure MPC against execution-dependent corruptions","claim_slug":"adaptive-mpc-noncommitting-techniques","contribution_kind":"security_result","contribution_role":"security_transformation","statement":"Canetti, Feige, Goldreich, and Naor use non-committing encryption to obtain computational MPC over insecure channels against adaptive corruptions of non-erasing parties under the paper's threshold and trapdoor assumptions.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Adaptive MPC was known with secure channels or trusted erasures, but ordinary ciphertexts over insecure channels could bind a simulator before a later corruption exposed the sender's retained state.","technical_delta":"Non-committing encryption lets simulated ciphertexts be explained consistently after corruption; the principal construction handles fewer than one third adaptive corruptions of non-erasing parties, with a stated modification below one half.","significance_at_publication":"The work separated corruption timing and erasure behavior from ordinary malicious security and supplied a cryptographic compiler for the insecure-channel setting.","narrative":"Adaptive security over insecure channels creates a simulation problem absent from static proofs: a ciphertext sent before corruption must later agree with every piece of state retained by the newly compromised sender. Earlier routes avoided that conflict with secure channels or trusted erasures. Canetti, Feige, Goldreich, and Naor introduce non-committing encryption, allowing simulated ciphertexts to be explained consistently only when a corruption occurs. Their main construction gives general computational MPC for non-erasing parties below the stated corruption threshold using common-domain trapdoor systems, with RSA and Diffie-Hellman instantiations. This is an adaptive-simulation compiler, not an epoch-based proactive refresh mechanism."},"source_locator":{"dossier_section":"MPC-PAPER-1996-ADAPTIVE § Atomic contribution","primary_source":"Abstract and main adaptive-security construction","primary_source_url":"https://www.wisdom.weizmann.ac.il/~oded/PSX/dynamic.pdf","status":"section_checked"},"qualifiers":["adaptive corruption","non-erasing parties","insecure channels","non-committing encryption","common-domain trapdoor systems"],"limitations":["the principal theorem handles fewer than one-third corruptions and notes a modification below one half","the compiler inherits its secure-channel protocol and trapdoor assumptions","proactive mobile corruption is a distinct contract"],"facet_status":"normalized","facets":{"task":["adaptive-security"],"mechanism":["non-committing-encryption","adaptive-simulation"],"corruption_timing":["adaptive"],"state_model":["non-erasing"],"network_model":["insecure-channels"],"corruption_threshold":["principal-construction-below-one-third"]},"status":"published","evidence":"primary_source_checked","research_lenses":["adaptive-proactive","active-security"],"keywords":["adaptive-security","non-committing-encryption","simulation"],"work_id":"MPC-PAPER-1996-ADAPTIVE","role":"security_transformation","lens":"adaptive-proactive","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"Adaptive corruption This contribution is distinguished from proactive refresh, which changes shares across epochs rather than transcript explainability after corruption."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-1996-ADAPTIVE-NCE"},{"id":"MPC-PAPER-1996-ADAPTIVE","type":"paper","title":"Adaptively Secure Multi-party Computation","subtitle":"Ran Canetti, Uriel Feige, Oded Goldreich et al. · 1996","status":"published","evidence":"primary_source_checked","year":1996,"venue":"STOC 1996","primaryUrl":"https://www.wisdom.weizmann.ac.il/~oded/PSX/dynamic.pdf","summary":"Adaptive security is displayed independently of active behavior and threshold; those axes must still be fixed.","tags":["active-security","adaptive-proactive"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-1996-ADAPTIVE","title":"Adaptively Secure Multi-party Computation","authors":["Ran Canetti","Uriel Feige","Oded Goldreich","Moni Naor"],"year":1996,"venue":"STOC 1996","primary_url":"https://www.wisdom.weizmann.ac.il/~oded/PSX/dynamic.pdf","status":"published","evidence":"primary_source_checked","keywords":["adaptive-proactive","active-security"],"contribution_ids":["MPC-CONTRIB-1996-ADAPTIVE-NCE"]},"sections":[{"heading":"Boundary note","content":"Adaptive security is displayed independently of active behavior and threshold; those axes must still be fixed."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-1996-ADAPTIVE"},{"id":"MPC-CONTRIB-2000-CDM-LSSS","type":"contribution","title":"Multiplicative linear secret sharing extends general MPC beyond thresholds","subtitle":"General Secure Multi-party Computation from any Linear Secret-Sharing Scheme","status":"published","evidence":"primary_source_checked","year":2000,"venue":"EUROCRYPT 2000","primaryUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070321-new.pdf","summary":"Cramer, Damgård, and Maurer construct general MPC from multiplicative linear secret-sharing schemes, extending polynomial-threshold sharing to access structures whose multiplication and robustness conditions are stated algebraically.","tags":["abstraction_and_construction","access-structures","active-security","arithmetic-mpc","atomic-contribution","backbone","generality-feasibility","lsss","multiplicativity"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2000-CDM-LSSS","paper_id":"MPC-PAPER-2000-CDM","year":2000,"title":"Multiplicative linear secret sharing extends general MPC beyond thresholds","claim_slug":"cdm-multiplicative-lsss-mpc","contribution_kind":"mechanism","contribution_role":"abstraction_and_construction","statement":"Cramer, Damgård, and Maurer construct general MPC from multiplicative linear secret-sharing schemes, extending polynomial-threshold sharing to access structures whose multiplication and robustness conditions are stated algebraically.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Arithmetic MPC constructions were closely tied to threshold polynomial sharing, so their access structures and multiplication arguments did not directly cover general monotone corruption patterns.","technical_delta":"The paper identifies multiplicativity in a linear secret-sharing scheme as the algebraic interface needed to lift secure circuit evaluation to general access structures.","significance_at_publication":"It separated the sharing representation from the MPC compiler and made access-structure generality a reusable construction coordinate.","narrative":"BGW-style arithmetic MPC used the multiplication structure of polynomial threshold sharing, but many trust policies are not captured by a single threshold. Cramer, Damgård, and Maurer recast the protocol around linear secret-sharing schemes and isolate multiplicativity as the property that permits shared products to be combined correctly. The resulting construction supports general access structures under the paper's stated conditions. The atomic contribution is this representation-level abstraction and compiler, not merely another threshold protocol. At publication time it clarified which algebraic feature of sharing powers general MPC and enabled later work to design, analyze, and optimize protocols against richer corruption structures."},"source_locator":{"dossier_section":"MPC-PAPER-2000-CDM § Atomic contribution","primary_source":"Abstract, introduction, and main protocol theorem","primary_source_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070321-new.pdf","status":"theorem_checked"},"qualifiers":["linear secret-sharing schemes","multiplicativity","monotone access structures"],"limitations":["security and robustness depend on the access structure and sharing properties","not every LSSS automatically satisfies the required multiplication condition"],"facet_status":"normalized","facets":{"task":["access-structure-generality"],"mechanism":["multiplicative-lsss"],"representation":["linear-secret-sharing"],"adversary_structure":["monotone-access-structure"]},"status":"published","evidence":"primary_source_checked","research_lenses":["generality-feasibility","active-security"],"keywords":["lsss","multiplicativity","access-structures","arithmetic-mpc"],"work_id":"MPC-PAPER-2000-CDM","role":"abstraction_and_construction","lens":"generality-feasibility","visibility":"backbone"},"sections":[{"heading":"Overview","content":"Multiplicative LSSS MPC The component abstraction and any complete instantiated protocol configuration remain separate records."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2000-CDM-LSSS"},{"id":"MPC-PAPER-2000-CDM","type":"paper","title":"General Secure Multi-party Computation from any Linear Secret-Sharing Scheme","subtitle":"Ronald Cramer, Ivan Damgard, Ueli Maurer · 2000","status":"published","evidence":"primary_source_checked","year":2000,"venue":"EUROCRYPT 2000","primaryUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070321-new.pdf","summary":"This is the abstraction bridge between arithmetic gate evaluation and general access structures.","tags":["active-security","generality-feasibility"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2000-CDM","title":"General Secure Multi-party Computation from any Linear Secret-Sharing Scheme","authors":["Ronald Cramer","Ivan Damgard","Ueli Maurer"],"year":2000,"venue":"EUROCRYPT 2000","primary_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070321-new.pdf","status":"published","evidence":"primary_source_checked","keywords":["generality-feasibility","active-security"],"contribution_ids":["MPC-CONTRIB-2000-CDM-LSSS"]},"sections":[{"heading":"Role","content":"This is the abstraction bridge between arithmetic gate evaluation and general access structures."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2000-CDM"},{"id":"MPC-CONTRIB-2001-UC-COMPOSITION","type":"contribution","title":"Environment-based simulation makes concurrent protocol composition explicit","subtitle":"Universally Composable Security: A New Paradigm for Cryptographic Protocols","status":"published","evidence":"primary_source_checked","year":2001,"venue":"FOCS 2001","primaryUrl":"https://eprint.iacr.org/2000/067","summary":"Canetti defines universally composable security through an external environment and proves a composition theorem that preserves protocol security when secure subroutines are replaced inside arbitrary surrounding executions.","tags":["atomic-contribution","composition","generality-feasibility","ideal-functionality","network-delivery","reviewed_related","security_definition","simulation","uc-security"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2001-UC-COMPOSITION","paper_id":"MPC-PAPER-2001-UC","year":2001,"title":"Environment-based simulation makes concurrent protocol composition explicit","claim_slug":"universally-composable-security-contract","contribution_kind":"definition","contribution_role":"security_definition","statement":"Canetti defines universally composable security through an external environment and proves a composition theorem that preserves protocol security when secure subroutines are replaced inside arbitrary surrounding executions.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Stand-alone simulation proofs did not automatically justify using a secure protocol concurrently or as a subroutine inside a larger system.","technical_delta":"The UC framework quantifies over an interactive environment and formalizes ideal-functionality replacement so composition follows from a theorem under explicit setup assumptions.","significance_at_publication":"It changed the contract attached to MPC security claims by separating stand-alone privacy from security that survives arbitrary protocol context.","narrative":"A stand-alone MPC proof compares one execution with an ideal process, but a real protocol may run concurrently with other sessions or serve as a component of a larger application. The UC framework places the execution inside an interactive environment and asks whether replacing a real subprotocol with its ideal functionality remains indistinguishable. Its composition theorem then licenses modular replacement under the framework's assumptions. The contribution is a security definition and composition contract, not a new gate-evaluation mechanism. It mattered because later MPC papers had to state whether their setup, corruption model, and simulator supported composable use rather than treating every simulation argument as interchangeable."},"source_locator":{"dossier_section":"MPC-PAPER-2001-UC § Atomic contribution","primary_source":"Framework definition and universal composition theorem","primary_source_url":"https://eprint.iacr.org/2000/067","status":"theorem_checked"},"qualifiers":["environment-based simulation","ideal functionalities","theorem-scoped composition"],"limitations":["composition guarantees inherit the framework and setup assumptions","stand-alone security does not imply UC security"],"facet_status":"normalized","facets":{"task":["composable-security"],"security_framework":["universal-composability"],"mechanism":["ideal-functionality-replacement"],"execution_model":["concurrent-environment"]},"status":"published","evidence":"primary_source_checked","research_lenses":["generality-feasibility","network-delivery"],"keywords":["uc-security","composition","simulation","ideal-functionality"],"work_id":"MPC-PAPER-2001-UC","role":"security_definition","lens":"generality-feasibility","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"UC composition This object is a security contract and remains distinct from the MPC protocols proved within it."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2001-UC-COMPOSITION"},{"id":"MPC-PAPER-2001-UC","type":"paper","title":"Universally Composable Security: A New Paradigm for Cryptographic Protocols","subtitle":"Ran Canetti · 2001","status":"published","evidence":"primary_source_checked","year":2001,"venue":"FOCS 2001","primaryUrl":"https://eprint.iacr.org/2000/067","summary":"UC is a security framework facet, not a mechanism component and not automatically inherited by protocols proved only standalone secure.","tags":["active-security","generality-feasibility"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2001-UC","title":"Universally Composable Security: A New Paradigm for Cryptographic Protocols","authors":["Ran Canetti"],"year":2001,"venue":"FOCS 2001","primary_url":"https://eprint.iacr.org/2000/067","status":"published","evidence":"primary_source_checked","keywords":["generality-feasibility","active-security"],"contribution_ids":["MPC-CONTRIB-2001-UC-COMPOSITION"]},"sections":[{"heading":"Scope","content":"UC is a security framework facet, not a mechanism component and not automatically inherited by protocols proved only standalone secure."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2001-UC"},{"id":"MPC-CONTRIB-2003-IKNP-OTEXT","type":"contribution","title":"Symmetric-key OT extension expands a small public-key seed into many transfers","subtitle":"Extending Oblivious Transfers Efficiently","status":"published","evidence":"primary_source_checked","year":2003,"venue":"CRYPTO 2003","primaryUrl":"https://www.iacr.org/archive/crypto2003/27290145/27290145.pdf","summary":"IKNP extends a small number of base oblivious transfers into a large batch using primarily symmetric-key operations, reducing the public-key cost of OT-intensive secure computation.","tags":["atomic-contribution","backbone","correlation_amplification","garbled-circuit-efficiency","iknp","oblivious-transfer","ot-extension","preprocessing-correlation","symmetric-key"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2003-IKNP-OTEXT","paper_id":"MPC-PAPER-2003-IKNP","year":2003,"title":"Symmetric-key OT extension expands a small public-key seed into many transfers","claim_slug":"iknp-oblivious-transfer-extension","contribution_kind":"mechanism","contribution_role":"correlation_amplification","statement":"IKNP extends a small number of base oblivious transfers into a large batch using primarily symmetric-key operations, reducing the public-key cost of OT-intensive secure computation.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Protocols that consumed one oblivious transfer per wire or correlation inherited a public-key operation cost that scaled with the full OT batch.","technical_delta":"IKNP uses a small base-OT seed and matrix-style symmetric-key expansion to generate many additional transfers with only inexpensive hash and pseudorandom operations per item.","significance_at_publication":"It made OT a scalable correlation source for Boolean MPC and shifted optimization attention from public-key count to batch expansion and consistency.","narrative":"Oblivious transfer was a powerful complete primitive for secure computation, but invoking a public-key protocol for every required transfer made OT-heavy designs expensive. IKNP performs only a small base set of such transfers and expands them into a much larger batch using symmetric-key operations and correlated bit matrices. The atomic contribution is the amortized OT-extension mechanism and its reduction in public-key work, not a complete MPC protocol. This mattered because Boolean sharing, garbled circuits, and later authenticated-bit preprocessing could treat large OT batches as a practical resource. Subsequent work could then strengthen malicious security or make expansion silent without changing the underlying role of OT as correlation infrastructure."},"source_locator":{"dossier_section":"MPC-PAPER-2003-IKNP § Atomic contribution","primary_source":"Abstract and OT-extension protocol","primary_source_url":"https://www.iacr.org/archive/crypto2003/27290145/27290145.pdf","status":"section_checked"},"qualifiers":["batched oblivious transfer","small base-OT seed","primarily symmetric-key expansion"],"limitations":["security inherits the base OTs and extension model","malicious security requires additional consistency mechanisms"],"facet_status":"normalized","facets":{"task":["correlation-amplification"],"mechanism":["ot-extension"],"correlation_type":["oblivious-transfer"],"cost_coordinate":["public-key-operations"]},"status":"published","evidence":"primary_source_checked","research_lenses":["preprocessing-correlation","garbled-circuit-efficiency"],"keywords":["iknp","oblivious-transfer","ot-extension","symmetric-key"],"work_id":"MPC-PAPER-2003-IKNP","role":"correlation_amplification","lens":"preprocessing-correlation","visibility":"backbone"},"sections":[{"heading":"Overview","content":"IKNP OT extension This card captures the reusable correlation mechanism rather than any one protocol stack that consumes it."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2003-IKNP-OTEXT"},{"id":"MPC-PAPER-2003-IKNP","type":"paper","title":"Extending Oblivious Transfers Efficiently","subtitle":"Yuval Ishai, Joe Kilian, Kobbi Nissim et al. · 2003","status":"published","evidence":"primary_source_checked","year":2003,"venue":"CRYPTO 2003","primaryUrl":"https://www.iacr.org/archive/crypto2003/27290145/27290145.pdf","summary":"IKNP is a correlation-generation component used by many protocols; it is not a complete MPC configuration.","tags":["preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2003-IKNP","title":"Extending Oblivious Transfers Efficiently","authors":["Yuval Ishai","Joe Kilian","Kobbi Nissim","Erez Petrank"],"year":2003,"venue":"CRYPTO 2003","primary_url":"https://www.iacr.org/archive/crypto2003/27290145/27290145.pdf","status":"published","evidence":"primary_source_checked","keywords":["preprocessing-correlation","round-communication"],"contribution_ids":["MPC-CONTRIB-2003-IKNP-OTEXT"]},"sections":[{"heading":"Role","content":"IKNP is a correlation-generation component used by many protocols; it is not a complete MPC configuration."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2003-IKNP"},{"id":"MPC-PROTOCOL-GMW-PASSIVE","type":"protocol","title":"GMW / OT-extension passive Boolean MPC","subtitle":"boolean secret sharing · 2003","status":"published","evidence":"primary_source_checked","year":2003,"venue":null,"primaryUrl":null,"summary":"GMW typically favors low AND depth; Yao typically favors constant rounds with cost per non-XOR gate.","tags":["generality-feasibility","preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-GMW-PASSIVE","title":"GMW / OT-extension passive Boolean MPC","name":"GMW passive Boolean MPC","paper_ids":["MPC-PAPER-1987-GMW","MPC-PAPER-2003-IKNP"],"claim_ids":["MPC-CONTRIB-1987-GMW-COMPILER","MPC-CONTRIB-2003-IKNP-OTEXT"],"year":2003,"protocol_family":"boolean_secret_sharing","research_lenses":["generality-feasibility","preprocessing-correlation","round-communication"],"tasks":["general_mpc","boolean_circuit_evaluation"],"properties":{"parties":"2 or more","corruption_threshold":"configuration-dependent passive threshold","majority_regime":"supports_dishonest_majority_passive","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"base_OT_then_OT_extension","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-XOR"],"evaluation_protocol":["MPC-COMP-EVAL-GMW"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_boolean_multiplicative_depth","communication_driver":"pairwise_ot_correlations_per_and_gate","preprocessing":"ot_extension"},"configuration_note":"A normalized passive GMW configuration using OT extension; stronger-security compilers require separate rows.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Comparison note","content":"GMW typically favors low AND depth; Yao typically favors constant rounds with cost per non-XOR gate."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-GMW-PASSIVE"},{"id":"MPC-CONTRIB-2008-FREEXOR","type":"contribution","title":"A global wire-label offset makes XOR gates free in garbled circuits","subtitle":"Improved Garbled Circuit: Free XOR Gates and Applications","status":"published","evidence":"primary_source_checked","year":2008,"venue":"ICALP 2008","primaryUrl":"https://www.thomaschneider.de/papers/KS08XOR.pdf","summary":"Free-XOR correlates the two labels on every wire through one global offset so XOR gates require neither garbled ciphertexts nor cryptographic operations, concentrating garbling cost on non-XOR gates.","tags":["atomic-contribution","backbone","free-xor","garbled-circuit-efficiency","garbled-circuits","gate-optimization","gate_cost_reduction","wire-labels"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2008-FREEXOR","paper_id":"MPC-PAPER-2008-FREEXOR","year":2008,"title":"A global wire-label offset makes XOR gates free in garbled circuits","claim_slug":"free-xor-garbling-invariant","contribution_kind":"optimization","contribution_role":"gate_cost_reduction","statement":"Free-XOR correlates the two labels on every wire through one global offset so XOR gates require neither garbled ciphertexts nor cryptographic operations, concentrating garbling cost on non-XOR gates.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Standard garbling treated XOR gates like other binary gates, assigning them ciphertext tables and cryptographic evaluation work even though XOR has linear structure.","technical_delta":"A shared global difference between zero and one wire labels lets the evaluator derive an XOR output label directly from the two input labels.","significance_at_publication":"It changed the practical cost model of garbled circuits and made XOR-rich circuit design a central optimization objective.","narrative":"Garbled-circuit cost had been accounted for gate by gate, with XOR operations consuming table entries and cryptographic calls alongside nonlinear gates. Free-XOR imposes one global offset between the two encodings of every wire. Under that invariant, XORing the evaluator's input labels already produces the correct output label, so the garbler sends no ciphertext for the gate. The atomic change is this wire-label invariant and the resulting zero garbling cost for XOR, under the paper's correlation-robustness assumptions. It mattered because the relevant concrete metric became the number of non-XOR gates, encouraging circuit representations and later garbling optimizations that preserve Free-XOR compatibility."},"source_locator":{"dossier_section":"MPC-PAPER-2008-FREEXOR § Atomic contribution","primary_source":"Abstract and Free-XOR construction","primary_source_url":"https://www.thomaschneider.de/papers/KS08XOR.pdf","status":"section_checked"},"qualifiers":["Yao-style garbling","global label offset","XOR gates"],"limitations":["security requires the stated hash/correlation assumptions","nonlinear gates still incur garbling cost"],"facet_status":"normalized","facets":{"task":["garbled-circuit-efficiency"],"mechanism":["global-wire-offset"],"gate_type":["xor"],"cost_coordinate":["ciphertexts","cryptographic-operations"]},"status":"published","evidence":"primary_source_checked","research_lenses":["garbled-circuit-efficiency"],"keywords":["free-xor","garbled-circuits","wire-labels","gate-optimization"],"work_id":"MPC-PAPER-2008-FREEXOR","role":"gate_cost_reduction","lens":"garbled-circuit-efficiency","visibility":"backbone"},"sections":[{"heading":"Overview","content":"Free-XOR The optimization remains connected to Yao-style garbling rather than becoming a protocol family of its own."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2008-FREEXOR"},{"id":"MPC-PAPER-2008-FREEXOR","type":"paper","title":"Improved Garbled Circuit: Free XOR Gates and Applications","subtitle":"Vladimir Kolesnikov, Thomas Schneider · 2008","status":"published","evidence":"primary_source_checked","year":2008,"venue":"ICALP 2008","primaryUrl":"https://www.thomaschneider.de/papers/KS08XOR.pdf","summary":"Free-XOR relies on a correlation-robustness assumption profile; the interface does not silently replace that with a standard-model claim.","tags":["garbled-circuit-efficiency"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2008-FREEXOR","title":"Improved Garbled Circuit: Free XOR Gates and Applications","authors":["Vladimir Kolesnikov","Thomas Schneider"],"year":2008,"venue":"ICALP 2008","primary_url":"https://www.thomaschneider.de/papers/KS08XOR.pdf","status":"published","evidence":"primary_source_checked","keywords":["garbled-circuit-efficiency"],"contribution_ids":["MPC-CONTRIB-2008-FREEXOR"]},"sections":[{"heading":"Security boundary","content":"Free-XOR relies on a correlation-robustness assumption profile; the interface does not silently replace that with a standard-model claim."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2008-FREEXOR"},{"id":"MPC-CONTRIB-2009-PRACTICAL2PC","type":"contribution","title":"End-to-end co-design makes semi-honest garbled-circuit 2PC practical","subtitle":"Secure Two-Party Computation Is Practical","status":"published","evidence":"primary_source_checked","year":2009,"venue":"ASIACRYPT 2009","primaryUrl":"https://eprint.iacr.org/2009/314","summary":"Pinkas, Schneider, Smart, and Williams integrate circuit design, garbling, oblivious transfer, and systems optimizations into an end-to-end semi-honest two-party computation implementation evaluated on representative functions.","tags":["atomic-contribution","garbled-circuit-efficiency","garbled-circuits","implementation-systems","practical-2pc","reviewed_related","semi-honest","systems-codesign","systems_integration"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2009-PRACTICAL2PC","paper_id":"MPC-PAPER-2009-PRACTICAL2PC","year":2009,"title":"End-to-end co-design makes semi-honest garbled-circuit 2PC practical","claim_slug":"practical-semi-honest-garbled-circuit-2pc","contribution_kind":"optimization","contribution_role":"systems_integration","statement":"Pinkas, Schneider, Smart, and Williams integrate circuit design, garbling, oblivious transfer, and systems optimizations into an end-to-end semi-honest two-party computation implementation evaluated on representative functions.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Garbled-circuit feasibility and isolated optimizations were known, but their combined end-to-end cost had not yet been demonstrated convincingly across a reusable implementation pipeline.","technical_delta":"The system coordinates circuit generation, Free-XOR-compatible garbling, OT handling, memory, and networking so the complete protocol rather than a single primitive is measured.","significance_at_publication":"It established implementation-aware co-design as a research contribution between abstract protocol construction and a versioned software artifact.","narrative":"By 2009, garbled circuits and oblivious transfer were established techniques, but practical claims could still be dominated by an unoptimized circuit, memory movement, public-key setup, or network handling. This work integrates those layers into one semi-honest two-party system and evaluates complete executions on representative functions. The atomic contribution is the end-to-end co-design showing how protocol and systems choices interact, not the invention of Yao garbling or Free-XOR. It mattered because MPC performance work gained a concrete whole-stack baseline and a systems methodology: optimize and account for the circuit, correlations, cryptographic kernels, and communication together rather than extrapolating practicality from one asymptotic component."},"source_locator":{"dossier_section":"MPC-PAPER-2009-PRACTICAL2PC § Atomic contribution","primary_source":"Abstract; system design and evaluation sections","primary_source_url":"https://eprint.iacr.org/2009/314","status":"section_checked"},"qualifiers":["two-party","semi-honest security","end-to-end implementation study"],"limitations":["the security model is semi-honest","performance observations are bound to the paper's implementation and workloads"],"facet_status":"normalized","facets":{"task":["practical-2pc"],"mechanism":["garbled-circuit-codesign"],"adversary_behavior":["passive"],"party_model":["two-party"],"contribution_stage":["implementation-aware-codesign"]},"status":"published","evidence":"primary_source_checked","research_lenses":["garbled-circuit-efficiency","implementation-systems"],"keywords":["practical-2pc","garbled-circuits","systems-codesign","semi-honest"],"work_id":"MPC-PAPER-2009-PRACTICAL2PC","role":"systems_integration","lens":"garbled-circuit-efficiency","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"Practical 2PC co-design This research delta is not collapsed into the mutable implementation identity or its individual measurements."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2009-PRACTICAL2PC"},{"id":"MPC-CONTRIB-2010-FAIR-FUNCTIONS","type":"contribution","title":"Boolean OR and three-party majority admit complete fairness without an honest majority","subtitle":"Complete Fairness in Multi-Party Computation Without an Honest Majority","status":"published","evidence":"primary_source_checked","year":2009,"venue":"TCC 2009","primaryUrl":"https://eprint.iacr.org/2008/458","summary":"Gordon and Katz construct completely fair protocols tolerating any t<n corruptions for n-party Boolean OR and three-party majority under suitable cryptographic assumptions, while proving that the latter requires super-logarithmic rounds.","tags":["atomic-contribution","dishonest-majority","fairness","feasibility_refinement","functionality-dependent","generality-feasibility","network-delivery","reviewed_related"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2010-FAIR-FUNCTIONS","paper_id":"MPC-PAPER-2010-FAIR","year":2009,"title":"Boolean OR and three-party majority admit complete fairness without an honest majority","claim_slug":"function-dependent-complete-fairness","contribution_kind":"boundary_result","contribution_role":"feasibility_refinement","statement":"Gordon and Katz construct completely fair protocols tolerating any t<n corruptions for n-party Boolean OR and three-party majority under suitable cryptographic assumptions, while proving that the latter requires super-logarithmic rounds.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Cleve's general impossibility and the immediately preceding two-party feasibility results left open whether any nontrivial multiparty functionality could achieve complete fairness without an honest majority.","technical_delta":"The paper gives an O(n)-round completely fair protocol for n-party Boolean OR and a super-logarithmic-round protocol for three-party majority, together with a round lower bound for the latter.","significance_at_publication":"It supplied the first positive multiparty examples in this regime and showed that feasibility and round complexity depend on the functionality rather than only the corruption threshold.","narrative":"Complete fairness was impossible for general dishonest-majority MPC, but earlier two-party results had already shown that this did not rule out every nontrivial function. Gordon and Katz carried that question into the multiparty setting. Under suitable cryptographic assumptions and a private broadcast channel or PKI, they give completely fair protocols for Boolean OR with any number of parties and for three-party majority while tolerating any t<n corruptions. The majority protocol requires super-logarithmic rounds, exposing a separation from its easier two-party partitions. The mapped boundary is therefore function-specific multiparty feasibility, not a generic upgrade from abort to fairness."},"source_locator":{"dossier_section":"MPC-PAPER-2010-FAIR § Atomic contribution","primary_source":"Abstract and main complete-fairness theorems","primary_source_url":"https://eprint.iacr.org/2008/458","status":"theorem_checked"},"qualifiers":["n-party Boolean OR","three-party majority","any t<n corruptions","private broadcast channel or PKI","complete fairness"],"limitations":["does not overturn general fairness impossibility","results use suitable cryptographic assumptions","the three-party-majority protocol requires super-logarithmic rounds"],"facet_status":"normalized","facets":{"task":["fair-output-delivery"],"output_guarantee":["fairness"],"majority_regime":["dishonest-majority"],"applicability":["function-dependent"]},"status":"published","evidence":"primary_source_checked","research_lenses":["network-delivery","generality-feasibility"],"keywords":["fairness","dishonest-majority","functionality-dependent"],"work_id":"MPC-PAPER-2010-FAIR","role":"feasibility_refinement","lens":"network-delivery","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"Function-dependent fairness The card keeps complete fairness distinct from privacy, robustness, and guaranteed output delivery."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2010-FAIR-FUNCTIONS"},{"id":"MPC-PAPER-2009-PRACTICAL2PC","type":"paper","title":"Secure Two-Party Computation Is Practical","subtitle":"Benny Pinkas, Thomas Schneider, Nigel P. Smart et al. · 2009","status":"published","evidence":"primary_source_checked","year":2009,"venue":"ASIACRYPT 2009","primaryUrl":"https://eprint.iacr.org/2009/314","summary":"This is a practice milestone, distinct from the individual garbling and OT components it instantiates.","tags":["garbled-circuit-efficiency","implementation-systems"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2009-PRACTICAL2PC","title":"Secure Two-Party Computation Is Practical","authors":["Benny Pinkas","Thomas Schneider","Nigel P. Smart","Stephen C. Williams"],"year":2009,"venue":"ASIACRYPT 2009","primary_url":"https://eprint.iacr.org/2009/314","status":"published","evidence":"primary_source_checked","keywords":["garbled-circuit-efficiency","implementation-systems"],"contribution_ids":["MPC-CONTRIB-2009-PRACTICAL2PC"]},"sections":[{"heading":"Role","content":"This is a practice milestone, distinct from the individual garbling and OT components it instantiates."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2009-PRACTICAL2PC"},{"id":"MPC-PAPER-2010-FAIR","type":"paper","title":"Complete Fairness in Multi-Party Computation Without an Honest Majority","subtitle":"S. Dov Gordon, Jonathan Katz · 2009","status":"published","evidence":"primary_source_checked","year":2009,"venue":"TCC 2009","primaryUrl":"https://eprint.iacr.org/2008/458","summary":"Fairness is functionality-dependent here and is not attached to every dishonest-majority protocol.","tags":["network-delivery"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2010-FAIR","title":"Complete Fairness in Multi-Party Computation Without an Honest Majority","authors":["S. Dov Gordon","Jonathan Katz"],"year":2009,"venue":"TCC 2009","primary_url":"https://eprint.iacr.org/2008/458","status":"published","evidence":"primary_source_checked","keywords":["network-delivery"],"contribution_ids":["MPC-CONTRIB-2010-FAIR-FUNCTIONS"]},"sections":[{"heading":"Boundary note","content":"Fairness is functionality-dependent here and is not attached to every dishonest-majority protocol."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2010-FAIR"},{"id":"MPC-CONTRIB-2010-TASTY-MIXED-COMPILER","type":"contribution","title":"Typed HE and garbled values support mixed-protocol description and generation","subtitle":"TASTY: Tool for Automating Secure Two-partY computations","status":"published","evidence":"fulltext_checked","year":2010,"venue":"ACM CCS 2010","primaryUrl":"https://eprint.iacr.org/2010/365","summary":"TASTY provides a typed protocol-description language and runtime that generate and execute semi-honest two-party computations combining additively homomorphic encryption and garbled circuits, with explicit conversions between their value representations within one computation.","tags":["atomic-contribution","catalog_only","garbled-circuits","homomorphic-encryption","implementation-systems","mixed-protocol","mixed-protocol-compilation","mixed_protocol_framework","tasty","typed-values"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2010-TASTY-MIXED-COMPILER","paper_id":"MPC-PAPER-2010-TASTY","year":2010,"title":"Typed HE and garbled values support mixed-protocol description and generation","claim_slug":"tasty-typed-mixed-protocol-compiler","contribution_kind":"transform","contribution_role":"mixed_protocol_framework","statement":"TASTY provides a typed protocol-description language and runtime that generate and execute semi-honest two-party computations combining additively homomorphic encryption and garbled circuits, with explicit conversions between their value representations within one computation.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Existing high-level SFE tools discussed by TASTY generally generated a single protocol family, while mixed HE/GC protocols and lower-level ways to describe cryptographic operations already existed.","technical_delta":"TASTYL exposes plain, homomorphic, and garbled value types and conversion operators in one protocol-description interface, from which the runtime generates and executes the specified mixed protocol.","significance_at_publication":"The interface made mixed HE/GC protocols describable and executable without spelling out each underlying cryptographic message, while leaving representation choices visible to the programmer.","narrative":"Arithmetic and Boolean subcomputations can favor different secure-computation protocols, but using both requires explicit treatment of their intermediate values. Mixed HE/GC constructions already existed; TASTY brought them into a common protocol-description language and runtime. TASTYL distinguishes plain, homomorphic, and garbled values, and its typed operations and conversions describe how one computation crosses representation boundaries. The runtime generates and executes that description while abstracting away lower-level cryptographic messages. This supplied a practical mixed-protocol programming interface under a semi-honest two-party model. The programmer still specifies the representations: automatic selection between HE and garbled circuits is identified as future work, not as a capability established by this contribution."},"source_locator":{"dossier_section":"MPC-PAPER-2010-TASTY § Atomic contribution","primary_source":"IACR ePrint 2010/365 full version: §2 (model), PDF pp. 3–5; §2.3 and Figure 2, p. 5; §4–§4.1 and Figures 5–7, pp. 6–8; §6 (automatic-selection boundary), p. 12","primary_source_url":"https://eprint.iacr.org/2010/365.pdf","status":"section_checked"},"qualifiers":["Semi-honest two-party computation using the instantiated HE and garbled-circuit building blocks.","The program specifies typed representations and conversions; local inference of output types and bitlengths is not automatic protocol assignment.","The design separates input-independent setup from online work; this does not establish an unconditional reduction in total cost."],"limitations":["The underlying modular conversion framework and cryptographic primitives are prior building blocks, not separately claimed inventions of this atom.","Automatic compilation from a function-description language and automatic HE/GC selection are future work in §6.","No malicious or UC security guarantee, universal performance optimum, or portable benchmark ranking is admitted."],"facet_status":"normalized","facets":{"task":["mixed-protocol-compilation"],"mechanism":["typed-conversions","protocol-description-language"],"representation":["homomorphic-encryption","yao-garbling"],"party_model":["two-party"],"adversary":["semi-honest"]},"status":"published","evidence":"fulltext_checked","research_lenses":["mixed-protocol-compilation","implementation-systems"],"keywords":["tasty","mixed-protocol","typed-values","homomorphic-encryption","garbled-circuits"],"work_id":"MPC-PAPER-2010-TASTY","role":"mixed_protocol_framework","lens":"mixed-protocol-compilation","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"TASTY typed mixed-protocol compiler The atomic object is the shared programming and execution interface for a programmer-specified mixture. In the example of §4.1.2 (Figures 6–7, PDF pages 7–8), products are computed homomorphically and the minimum is computed with garbled circuits after conversion. This supports direct mixed-domain membership; it does not make the card a new garbling construction or a new security-composition theorem. The source check covers the sections supporting this claim and its stated boundaries. It is not an independent proof verification or implementation reproduction."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2010-TASTY-MIXED-COMPILER"},{"id":"MPC-PAPER-2010-TASTY","type":"paper","title":"TASTY: Tool for Automating Secure Two-partY computations","subtitle":"Wilko Henecka, Stefan Kögl, Ahmad-Reza Sadeghi et al. · 2010","status":"published","evidence":"fulltext_checked","year":2010,"venue":"ACM CCS 2010","primaryUrl":"https://eprint.iacr.org/2010/365","summary":"TASTY: Tool for Automating Secure Two-partY computations","tags":["implementation-systems","mixed-protocol-compilation","tasty"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2010-TASTY","title":"TASTY: Tool for Automating Secure Two-partY computations","authors":["Wilko Henecka","Stefan Kögl","Ahmad-Reza Sadeghi","Thomas Schneider","Immo Wehrenberg"],"year":2010,"venue":"ACM CCS 2010","versions":["ACM CCS 2010 conference paper","IACR ePrint 2010/365 full version"],"primary_url":"https://eprint.iacr.org/2010/365","status":"published","evidence":"fulltext_checked","keywords":["mixed-protocol-compilation","implementation-systems","tasty"],"contribution_ids":["MPC-CONTRIB-2010-TASTY-MIXED-COMPILER"]},"sections":[{"heading":"Overview","content":"TASTY: Tool for Automating Secure Two-partY computations"},{"heading":"Version and bibliographic notes","content":"The conference paper appeared at ACM CCS 2010, pages 451–462, DOI 10.1145/1866307.1866358. The author-hosted conference copy has 12 PDF pages. The ePrint record identifies its 16-page PDF as the full version of that conference paper; the downloaded full version also states this on its first page. The record lists an initial submission on 2010-06-25 and the latest revision on 2014-02-12, with a note about a corrected typo and updated reference. The publication year remains 2010. Locators below use one-based PDF pages of the ePrint full version, not the conference pagination."},{"heading":"Atomic contribution","content":"MPC-CONTRIB-2010-TASTY-MIXED-COMPILER records the typed mixed-protocol description and generation interface: homomorphically encrypted values and garbled values can be used within one computation with explicit conversions. Relevant evidence is §2, PDF pages 3–5; §2.3 and Figure 2, page 5; and §4–§4.1, pages 6–8, especially Figures 5–7."},{"heading":"Limitations and unresolved review","content":"The reviewed security setting is semi-honest two-party computation (§2). TASTY implements the modular conversion framework reviewed in §2; this record does not attribute the invention of every conversion or primitive to TASTY. Section 6, PDF page 12, places both automatic compilation from a function-description language into TASTYL and automatic GC/HE selection among future goals. The admitted contribution therefore does not claim automatic domain assignment, a universal optimum, or malicious security. The paper's multiplication, AES, and application measurements are not separate admitted claims or portable benchmark comparisons in this intake. No exact protocol configuration, implementation version, or measurement record is created by this paper card."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2010-TASTY"},{"id":"MPC-CONTRIB-2011-SPDZ-AUTH","type":"contribution","title":"Authenticated arithmetic shares enable a light dishonest-majority online phase","subtitle":"Multiparty Computation from Somewhat Homomorphic Encryption","status":"published","evidence":"primary_source_checked","year":2012,"venue":"CRYPTO 2012","primaryUrl":"https://eprint.iacr.org/2011/535","summary":"SPDZ combines somewhat-homomorphic-encryption preprocessing with information-theoretic MACs on arithmetic shares, obtaining a light online phase that is statistically UC-secure against active, adaptive corruption of up to n-1 parties in its synchronous secure-channel model.","tags":["active-security","atomic-contribution","authenticated-shares","backbone","malicious-security","preprocessing","preprocessing-correlation","protocol_construction","round-communication","spdz"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2011-SPDZ-AUTH","paper_id":"MPC-PAPER-2011-SPDZ","year":2012,"title":"Authenticated arithmetic shares enable a light dishonest-majority online phase","claim_slug":"spdz-authenticated-sharing","contribution_kind":"construction","contribution_role":"protocol_construction","statement":"SPDZ combines somewhat-homomorphic-encryption preprocessing with information-theoretic MACs on arithmetic shares, obtaining a light online phase that is statistically UC-secure against active, adaptive corruption of up to n-1 parties in its synchronous secure-channel model.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Actively secure dishonest-majority arithmetic MPC carried expensive cryptographic checks through the live computation or relied on less efficient general compilers.","technical_delta":"SPDZ preprocesses authenticated multiplication correlations and attaches a global-MAC invariant to every shared value, leaving online arithmetic to local operations, openings, and batched verification.","significance_at_publication":"It established authenticated sharing as a durable active-security architecture whose online phase could survive repeated replacement of the offline generator.","narrative":"Dishonest-majority arithmetic MPC needed both multiplication resources and a way to detect parties that submitted inconsistent shares. SPDZ moves expensive somewhat-homomorphic computation into an input-independent preprocessing phase and equips each secret share with an information-theoretic MAC tied to a global hidden key. Online additions and triple-based multiplications remain simple, while batched checks detect forged openings. The atomic contribution is this authenticated-sharing architecture for active security, including its separation of offline correlation generation from online evaluation. It mattered because later systems could replace the original public-key-heavy preprocessing with OT-based or other generators while preserving the recognizable SPDZ online contract."},"source_locator":{"dossier_section":"MPC-PAPER-2011-SPDZ § Atomic contribution","primary_source":"Abstract; preprocessing overview and online protocol","primary_source_url":"https://eprint.iacr.org/2011/535","status":"section_checked"},"qualifiers":["arithmetic sharing","up to n-1 active adaptive corruptions","statistical UC security","synchronous secure point-to-point channels","preprocessing model"],"limitations":["original preprocessing uses somewhat homomorphic encryption","successful termination is not guaranteed with a dishonest majority","the optimality statements are scoped to the paper's field-size and accounting conditions"],"facet_status":"normalized","facets":{"task":["active-security"],"mechanism":["authenticated-sharing","global-mac","preprocessing"],"adversary_behavior":["malicious"],"corruption_timing":["adaptive"],"corruption_threshold":["up-to-n-minus-one"],"majority_regime":["dishonest-majority"],"security_framework":["statistical-uc"],"network_model":["synchronous-secure-point-to-point"],"representation":["arithmetic-sharing"]},"status":"published","evidence":"primary_source_checked","research_lenses":["active-security","preprocessing-correlation","round-communication"],"keywords":["spdz","authenticated-shares","malicious-security","preprocessing"],"work_id":"MPC-PAPER-2011-SPDZ","role":"protocol_construction","lens":"active-security","visibility":"backbone"},"sections":[{"heading":"Overview","content":"SPDZ authenticated sharing The mechanism is kept separate from exact SPDZ configurations and from later preprocessing replacements."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2011-SPDZ-AUTH"},{"id":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","type":"contribution","title":"OT-generated authenticated bits give specialized malicious Boolean 2PC","subtitle":"A New Approach to Practical Active-Secure Two-Party Computation","status":"published","evidence":"primary_source_checked","year":2012,"venue":"CRYPTO 2012","primaryUrl":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf","summary":"TinyOT builds actively secure Boolean two-party computation from OT-generated authenticated bits and shares, making XOR local and using amortized consistency checks instead of a generic malicious compiler or garbled-circuit cut-and-choose.","tags":["active-security","atomic-contribution","authenticated-bits","backbone","boolean-mpc","malicious-2pc","preprocessing-correlation","protocol_construction","tinyot"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","paper_id":"MPC-PAPER-2012-TINYOT","year":2012,"title":"OT-generated authenticated bits give specialized malicious Boolean 2PC","claim_slug":"tinyot-authenticated-bit-preprocessing","contribution_kind":"construction","contribution_role":"protocol_construction","statement":"TinyOT builds actively secure Boolean two-party computation from OT-generated authenticated bits and shares, making XOR local and using amortized consistency checks instead of a generic malicious compiler or garbled-circuit cut-and-choose.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Practical malicious Boolean 2PC commonly strengthened passive protocols through generic compilation or replicated garbled circuits and cut-and-choose, both carrying substantial concrete overhead.","technical_delta":"TinyOT authenticates shared bits during OT-based preprocessing and evaluates Boolean circuits with cheap XORs, authenticated AND correlations, and batched checks tailored to the representation.","significance_at_publication":"It demonstrated that active security could be built into a Boolean-sharing architecture rather than added as a generic wrapper.","narrative":"Malicious two-party computation had often paid for security by compiling a passive protocol generically or checking many garbled circuits through cut-and-choose. TinyOT takes a representation-specific route. Its preprocessing uses oblivious transfer to create authenticated bits and related correlations; XOR remains local, while nonlinear operations and openings are protected by amortized consistency checks. The atomic contribution is the authenticated-bit architecture for active Boolean computation, not OT extension by itself and not a universal replacement for every garbling protocol. It mattered because it showed that specialized authentication could reduce the concrete cost of malicious security and created a Boolean counterpart to authenticated arithmetic-sharing designs."},"source_locator":{"dossier_section":"MPC-PAPER-2012-TINYOT § Atomic contribution","primary_source":"Abstract and authenticated-bit protocol sections","primary_source_url":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf","status":"section_checked"},"qualifiers":["two-party Boolean circuits","malicious security","OT-based preprocessing"],"limitations":["relies on preprocessing and OT assumptions","the architecture is specialized to Boolean sharing"],"facet_status":"normalized","facets":{"task":["active-security"],"mechanism":["authenticated-bits","ot-preprocessing"],"representation":["boolean-sharing"],"adversary_behavior":["malicious"],"party_model":["two-party"]},"status":"published","evidence":"primary_source_checked","research_lenses":["active-security","preprocessing-correlation"],"keywords":["tinyot","authenticated-bits","malicious-2pc","boolean-mpc"],"work_id":"MPC-PAPER-2012-TINYOT","role":"protocol_construction","lens":"active-security","visibility":"backbone"},"sections":[{"heading":"Overview","content":"TinyOT authenticated bits This atomic protocol architecture is not merged with the IKNP correlation mechanism it consumes."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2012-TINYOT-AUTHBITS"},{"id":"MPC-PAPER-2011-SPDZ","type":"paper","title":"Multiparty Computation from Somewhat Homomorphic Encryption","subtitle":"Ivan Damgard, Valerio Pastro, Nigel P. Smart et al. · 2012","status":"published","evidence":"primary_source_checked","year":2012,"venue":"CRYPTO 2012","primaryUrl":"https://eprint.iacr.org/2011/535","summary":"This card anchors the original SHE-preprocessed SPDZ configuration. OT-generated MASCOT preprocessing is a distinct configuration.","tags":["active-security","preprocessing-correlation"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2011-SPDZ","title":"Multiparty Computation from Somewhat Homomorphic Encryption","authors":["Ivan Damgard","Valerio Pastro","Nigel P. Smart","Sarah Zakarias"],"year":2012,"venue":"CRYPTO 2012","primary_url":"https://eprint.iacr.org/2011/535","status":"published","evidence":"primary_source_checked","keywords":["active-security","preprocessing-correlation"],"contribution_ids":["MPC-CONTRIB-2011-SPDZ-AUTH"]},"sections":[{"heading":"Configuration boundary","content":"This card anchors the original SHE-preprocessed SPDZ configuration. OT-generated MASCOT preprocessing is a distinct configuration."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2011-SPDZ"},{"id":"MPC-PAPER-2012-TINYOT","type":"paper","title":"A New Approach to Practical Active-Secure Two-Party Computation","subtitle":"Jesper Buus Nielsen, Peter Sebastian Nordholt, Claudio Orlandi et al. · 2012","status":"published","evidence":"primary_source_checked","year":2012,"venue":"CRYPTO 2012","primaryUrl":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf","summary":"TinyOT connects OT extension to authenticated Boolean sharing and later OT-based active preprocessing.","tags":["active-security","preprocessing-correlation"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2012-TINYOT","title":"A New Approach to Practical Active-Secure Two-Party Computation","authors":["Jesper Buus Nielsen","Peter Sebastian Nordholt","Claudio Orlandi","Sai Sheshank Burra"],"year":2012,"venue":"CRYPTO 2012","primary_url":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf","status":"published","evidence":"primary_source_checked","keywords":["active-security","preprocessing-correlation"],"contribution_ids":["MPC-CONTRIB-2012-TINYOT-AUTHBITS"]},"sections":[{"heading":"Role","content":"TinyOT connects OT extension to authenticated Boolean sharing and later OT-based active preprocessing."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2012-TINYOT"},{"id":"MPC-PROTOCOL-SPDZ-SHE","type":"protocol","title":"SPDZ with SHE preprocessing","subtitle":"authenticated arithmetic preprocessing · 2012","status":"published","evidence":"primary_source_checked","year":2012,"venue":null,"primaryUrl":null,"summary":"The name “SPDZ” alone is insufficient for implementation or benchmark comparison because several offline phases can feed the online protocol.","tags":["active-security","preprocessing-correlation"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-SPDZ-SHE","title":"SPDZ with SHE preprocessing","name":"SPDZ · SHE preprocessing","paper_ids":["MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ"],"claim_ids":["MPC-CONTRIB-1991-BEAVER-TRIPLES","MPC-CONTRIB-2011-SPDZ-AUTH"],"year":2012,"protocol_family":"authenticated_arithmetic_preprocessing","research_lenses":["active-security","preprocessing-correlation"],"tasks":["general_mpc","dishonest_majority_active_arithmetic"],"properties":{"parties":"n","corruption_threshold":"t < n","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"adaptive","security_framework":"statistical_UC_with_abort","network_model":"synchronous_secure_point_to_point_channels","setup":"input_independent_SHE_preprocessing","output_guarantee":"security_with_abort","privacy_basis":"computational_preprocessing_and_information_theoretic_online_checks"},"stack":{"representation":["MPC-COMP-REP-ARITH-FIELD"],"value_encoding":["MPC-COMP-ENC-AUTH-ADDITIVE"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER"],"correlation_source":["MPC-COMP-CORR-SHE"],"active_security_enforcement":["MPC-COMP-ACT-SPDZ-MAC"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_arithmetic_multiplicative_depth","communication_driver":"openings_per_multiplication_layer","preprocessing":"expensive_SHE_based_authenticated_triples"},"configuration_note":"Original SPDZ configuration; MASCOT changes only the preprocessing source and its consistency machinery, so it receives a separate row.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Full-stack identity","content":"The name “SPDZ” alone is insufficient for implementation or benchmark comparison because several offline phases can feed the online protocol."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-SPDZ-SHE"},{"id":"MPC-PROTOCOL-TINYOT","type":"protocol","title":"TinyOT active Boolean 2PC","subtitle":"authenticated boolean preprocessing · 2012","status":"published","evidence":"primary_source_checked","year":2012,"venue":null,"primaryUrl":null,"summary":"TinyOT is placed in the Boolean-sharing and authenticated-preprocessing threads, not in the garbled-circuit thread.","tags":["active-security","preprocessing-correlation"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-TINYOT","title":"TinyOT active Boolean 2PC","name":"TinyOT","paper_ids":["MPC-PAPER-2003-IKNP","MPC-PAPER-2012-TINYOT"],"claim_ids":["MPC-CONTRIB-2003-IKNP-OTEXT","MPC-CONTRIB-2012-TINYOT-AUTHBITS"],"year":2012,"protocol_family":"authenticated_boolean_preprocessing","research_lenses":["active-security","preprocessing-correlation"],"tasks":["general_2pc","malicious_boolean_computation"],"properties":{"parties":"2","corruption_threshold":"1 active corruption","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_authenticated_channels","setup":"base_OT_and_OT_extension","output_guarantee":"security_with_abort","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-AUTH-BITS"],"evaluation_protocol":["MPC-COMP-EVAL-GMW"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":["MPC-COMP-ACT-TINYOT"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_and_depth","communication_driver":"authenticated_and_evaluation_and_openings","preprocessing":"OT_generated_authenticated_bits"},"configuration_note":"OT-based authenticated-sharing design, distinct from malicious Yao cut-and-choose protocols.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Comparison note","content":"TinyOT is placed in the Boolean-sharing and authenticated-preprocessing threads, not in the garbled-circuit thread."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-TINYOT"},{"id":"MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION","type":"contribution","title":"Conversion-aware cost models drive automatic HE and garbled-circuit assignment","subtitle":"Automatic Protocol Selection in Secure Two-Party Computations","status":"published","evidence":"fulltext_checked","year":2014,"venue":"ACNS 2014","primaryUrl":"https://eprint.iacr.org/2014/200","summary":"For a specified single-static-assignment intermediate program and forecast cost model, Kerschbaum, Schneider, and Schröpfer formulate assignment of operations to HE-assisted arithmetic sharing or garbled circuits with conversion costs, and give a 0–1 integer-programming formulation and a cost-decreasing greedy heuristic for choosing the mixed protocol.","tags":["atomic-contribution","catalog_only","conversion-costs","cost-model","implementation-systems","integer-programming","mixed-protocol","mixed-protocol-compilation","mixed_protocol_assignment","protocol-selection"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION","paper_id":"MPC-PAPER-2014-KSS","year":2014,"title":"Conversion-aware cost models drive automatic HE and garbled-circuit assignment","claim_slug":"kss-conversion-aware-protocol-selection","contribution_kind":"optimization","contribution_role":"mixed_protocol_assignment","statement":"For a specified single-static-assignment intermediate program and forecast cost model, Kerschbaum, Schneider, and Schröpfer formulate assignment of operations to HE-assisted arithmetic sharing or garbled circuits with conversion costs, and give a 0–1 integer-programming formulation and a cost-decreasing greedy heuristic for choosing the mixed protocol.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Mixed-protocol systems such as TASTY exposed representation choices, but the programmer still selected which subcomputations used each protocol; choosing operations independently could overlook conversion costs.","technical_delta":"The assignment objective combines operation forecasts with costs for converting each reused intermediate value at most once, and is addressed by integer programming and a greedy protocol-selection algorithm.","significance_at_publication":"Protocol selection became an explicit optimization problem over the intermediate program and deployment cost parameters rather than only a manual decomposition of the function.","narrative":"Mixed-protocol interfaces already allowed arithmetic and Boolean subcomputations to use different representations, but the programmer had to choose the partition. Kerschbaum, Schneider, and Schröpfer make that choice an explicit cost-model problem. Their intermediate program exposes operation dependencies, while the objective accounts for both protocol execution and conversions, reusing a converted value across its consumers. An integer-programming formulation and a cost-decreasing greedy heuristic address the same assignment problem. The resulting contribution is automatic, conversion-aware selection between the instantiated HE-assisted sharing and garbled-circuit protocols. Its optimality target is the forecast objective, not universal wall-clock performance; the source also leaves hardness of the specific partitioning problem as a conjecture."},"source_locator":{"dossier_section":"MPC-PAPER-2014-KSS § Atomic contribution","primary_source":"IACR ePrint 2014/200 full version: §3.2–§3.4, PDF pp. 3–4; §4–§4.2, pp. 4–5; §5 and Definition 1, pp. 5–6; §5.1–§5.2 and Algorithm 1, pp. 6–7; §6 and Tables 1–2 for forecast-only evaluation context","primary_source_url":"https://eprint.iacr.org/2014/200.pdf","status":"section_checked"},"qualifiers":["Semi-honest two-party setting; the instantiated arithmetic protocol maintains additive shares modulo 2^l and uses Paillier-assisted operations.","Assignment is over the supported three-operand single-static-assignment intermediate language, with program bitlengths, security parameters, local operation costs, and network parameters supplied to the forecast model.","Conversion between the HE-assisted share representation and garbled values is charged at most once per intermediate value and reused by its consumers.","The instantiated security assumptions and cited composition argument are those in §3; protocol selection itself supplies no stronger adversary guarantee."],"limitations":["Integer-programming optimality is relative to the modeled objective; the source discusses approximation of execution costs, including neighboring-operation effects.","The greedy method starts with garbled-circuit assignments and accepts cost-decreasing changes to HE; no general approximation ratio is admitted.","Section 5 conjectures NP-hardness of the specific partitioning problem and explicitly does not prove it.","The use-case comparisons are forecast results in specified settings, not universal measured speedups or cross-system rankings.","This atom is not a general automatic compiler for all MPC representations, a new malicious or UC security theorem, or a separate garbling construction."],"facet_status":"normalized","facets":{"task":["mixed-protocol-compilation"],"mechanism":["conversion-aware-cost-model","integer-programming","greedy-assignment"],"representation":["arithmetic-sharing","yao-garbling"],"party_model":["two-party"],"adversary":["semi-honest"]},"status":"published","evidence":"fulltext_checked","research_lenses":["mixed-protocol-compilation","implementation-systems"],"keywords":["protocol-selection","mixed-protocol","conversion-costs","cost-model","integer-programming"],"work_id":"MPC-PAPER-2014-KSS","role":"mixed_protocol_assignment","lens":"mixed-protocol-compilation","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Conversion-aware automatic protocol selection The HE label in the selection problem refers to the HE-assisted computation on additive shares described in §3.2, not to the direct ciphertext value representation used by TASTY. Section 3.3 converts those shares into garbled inputs, or garbled outputs into shares, using circuits over their bitlength. Section 4.2 incorporates the conversion boundary into the assignment cost. These details support the one assignment claim; they do not automatically create distinct sharing, garbling, or security-foundation contributions. The source check covers the sections supporting this claim and its stated boundaries. It is not an independent proof verification, solver audit, or implementation reproduction."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION"},{"id":"MPC-PAPER-2014-KSS","type":"paper","title":"Automatic Protocol Selection in Secure Two-Party Computations","subtitle":"Florian Kerschbaum, Thomas Schneider, Axel Schröpfer · 2014","status":"published","evidence":"fulltext_checked","year":2014,"venue":"ACNS 2014","primaryUrl":"https://eprint.iacr.org/2014/200","summary":"Automatic Protocol Selection in Secure Two-Party Computations","tags":["cost-model","mixed-protocol-compilation","protocol-selection"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2014-KSS","title":"Automatic Protocol Selection in Secure Two-Party Computations","authors":["Florian Kerschbaum","Thomas Schneider","Axel Schröpfer"],"year":2014,"venue":"ACNS 2014","versions":["NDSS 2013 extended abstract","ACNS 2014 conference paper","IACR ePrint 2014/200 full version"],"primary_url":"https://eprint.iacr.org/2014/200","status":"published","evidence":"fulltext_checked","keywords":["mixed-protocol-compilation","protocol-selection","cost-model"],"contribution_ids":["MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION"]},"sections":[{"heading":"Overview","content":"Automatic Protocol Selection in Secure Two-Party Computations"},{"heading":"Version and bibliographic notes","content":"The publisher record identifies the ACNS 2014 conference paper in LNCS 8479, pages 566–584. The ePrint record identifies the ACNS publication and lists receipt on 2014-03-17 and revision on 2014-06-13. The first-page footnote of the 18-page full version distinguishes an earlier NDSS 2013 extended abstract from the ACNS 2014 conference version, which it asks readers to cite; these are references [30] and [31] in that PDF. This card uses the 2014 conference identity, not a separate 2013 full-paper claim. All contribution locators use one-based PDF pages of the ePrint full version, rather than the publisher's page numbers."},{"heading":"Atomic contribution","content":"MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION records conversion-aware assignment of operations to the paper's two protocol representations under a forecast cost model. The full version's §3.2–§3.4 (PDF pages 3–4) fixes the instantiated arithmetic sharing, conversion, and semi-honest setting; §4–§4.2 (pages 4–5) gives the model; and §5, Definition 1, §5.1, and §5.2 (pages 5–7, including Algorithm 1) give the assignment objective and its integer-programming and greedy solution methods."},{"heading":"Limitations and unresolved review","content":"The objective concerns a specified intermediate program and forecast cost model, not every protocol, machine, or network. Section 5 explicitly states that no hardness proof is provided for the specific partitioning problem; NP-hardness is a conjecture there. The greedy method has no admitted general approximation guarantee. The use-case costs reported in §6, including Tables 1–2, are model-based forecasts, not a universal measured ranking or a new reproduction result. The supporting conversion mechanism is retained within the assignment claim rather than split into an additional atomic contribution in this intake. No exact protocol configuration or benchmark record is created by this paper card."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2014-KSS"},{"id":"MPC-CONTRIB-2015-ABY-MIXED","type":"contribution","title":"Typed conversions compose arithmetic, Boolean, and garbled 2PC domains","subtitle":"ABY — A Framework for Efficient Mixed-Protocol Secure Two-Party Computation","status":"published","evidence":"primary_source_checked","year":2015,"venue":"NDSS 2015","primaryUrl":"https://www.ndss-symposium.org/wp-content/uploads/2017/09/08_2_1.pdf","summary":"ABY provides a two-party framework whose computation can move through explicit conversion gates among arithmetic sharing, Boolean sharing, and Yao garbling, allowing each subcomputation to use a domain-specific cost profile.","tags":["aby","atomic-contribution","backbone","conversions","implementation-systems","mixed-protocol","mixed-protocol-compilation","mixed_protocol_framework","secure-computation-framework"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2015-ABY-MIXED","paper_id":"MPC-PAPER-2015-ABY","year":2015,"title":"Typed conversions compose arithmetic, Boolean, and garbled 2PC domains","claim_slug":"aby-mixed-protocol-conversions","contribution_kind":"transform","contribution_role":"mixed_protocol_framework","statement":"ABY provides a two-party framework whose computation can move through explicit conversion gates among arithmetic sharing, Boolean sharing, and Yao garbling, allowing each subcomputation to use a domain-specific cost profile.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Mixed HE/GC frameworks such as TASTY and conversion-aware automatic protocol selection already existed; ABY's related-work discussion distinguishes that assignment problem from expanding the available sharing representations and conversions.","technical_delta":"ABY exposes typed sharing domains and conversion protocols so a circuit can cross representation boundaries at explicit, costed points chosen by the programmer or compiler.","significance_at_publication":"It expanded the mixed-protocol design space with arithmetic, Boolean, and Yao sharing in one framework, complementing rather than originating automatic protocol assignment.","narrative":"Mixed-protocol computation preceded ABY: TASTY described and executed HE/GC mixtures, and conversion-aware automatic assignment had already been studied. ABY expands the available design space by providing arithmetic, Boolean, and Yao sharing in a common framework with explicit conversions. Different subcomputations can use different sharing representations while their conversion boundaries remain visible. The atomic contribution is this typed interface and conversion layer, not the invention of mixed computation or automatic partitioning. The paper treats earlier assignment methods as complementary: they choose among protocol options, whereas ABY broadens those options. This distinction explains its place in the literature without attributing prior compiler work to it."},"source_locator":{"dossier_section":"MPC-PAPER-2015-ABY § Atomic contribution","primary_source":"NDSS 2015 version: §I.A and Figure 1, PDF p. 2; §I.B (mixed protocols and automated generation), p. 3; references [35] and [44], p. 14","primary_source_url":"https://www.ndss-symposium.org/wp-content/uploads/2017/09/08_2_1.pdf","status":"section_checked"},"qualifiers":["two-party setting","passive configurations","arithmetic/Boolean/Yao domains"],"limitations":["conversion costs can dominate a poor partition","security properties are configuration-specific rather than inherited by the framework name"],"facet_status":"normalized","facets":{"task":["mixed-protocol-compilation"],"mechanism":["typed-conversions"],"representation":["arithmetic-sharing","boolean-sharing","yao-garbling"],"party_model":["two-party"]},"status":"published","evidence":"primary_source_checked","research_lenses":["mixed-protocol-compilation","implementation-systems"],"keywords":["aby","mixed-protocol","conversions","secure-computation-framework"],"work_id":"MPC-PAPER-2015-ABY","role":"mixed_protocol_framework","lens":"mixed-protocol-compilation","visibility":"backbone"},"sections":[{"heading":"Overview","content":"ABY mixed protocols Exact ABY configurations retain their own party, adversary, and component-stack identities. Historical-context maintenance, 2026-09-05: the related-work comparison was checked against §I.B to avoid crediting ABY with originating automatic protocol assignment. The atomic statement, security facets, map configuration, and evidence grade are unchanged; this is not a new audit of every construction or benchmark in the paper."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2015-ABY-MIXED"},{"id":"MPC-CONTRIB-2015-BMR-SPDZ","type":"contribution","title":"SPDZ preprocessing makes BMR garbling actively secure with a two-round online phase","subtitle":"Efficient Constant Round Multi-Party Computation Combining BMR and SPDZ","status":"published","evidence":"primary_source_checked","year":2015,"venue":"CRYPTO 2015","primaryUrl":"https://eprint.iacr.org/2015/523","summary":"Lindell, Pinkas, Smart, and Yanai use actively secure arithmetic MPC to prepare a BMR garbled circuit, obtaining malicious dishonest-majority MPC whose online phase takes two rounds and is dominated by local garbled-circuit evaluation.","tags":["active-security","atomic-contribution","bmr","malicious-mpc","preprocessing-correlation","protocol-composition","protocol_composition","reviewed_related","round-communication","spdz"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2015-BMR-SPDZ","paper_id":"MPC-PAPER-2015-BMR-SPDZ","year":2015,"title":"SPDZ preprocessing makes BMR garbling actively secure with a two-round online phase","claim_slug":"bmr-spdz-active-two-round-online","contribution_kind":"construction","contribution_role":"protocol_composition","statement":"Lindell, Pinkas, Smart, and Yanai use actively secure arithmetic MPC to prepare a BMR garbled circuit, obtaining malicious dishonest-majority MPC whose online phase takes two rounds and is dominated by local garbled-circuit evaluation.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"BMR offered constant-round distributed garbling, while practical active security and authenticated preprocessing had matured largely in arithmetic MPC architectures such as SPDZ.","technical_delta":"The construction runs SPDZ-style arithmetic computation offline to generate and verify the distributed BMR garbling, then leaves a short online input and local-evaluation phase.","significance_at_publication":"It demonstrated a principled cross-architecture composition in which arithmetic authenticated preprocessing secures low-round Boolean evaluation.","narrative":"Distributed BMR garbling promised online rounds independent of circuit depth, but maliciously secure preparation of the garbled circuit remained a concrete obstacle. SPDZ, meanwhile, provided actively secure arithmetic computation with authenticated shares. This work uses the arithmetic engine during preprocessing to construct and check the BMR garbling, after which the parties enter a two-round online phase and evaluate locally. The atomic contribution is this division of labor between authenticated arithmetic preparation and garbled Boolean evaluation. It mattered because it showed that a useful protocol stack need not belong to one mechanism family: components could be composed across domains while preserving an explicit malicious dishonest-majority contract."},"source_locator":{"dossier_section":"MPC-PAPER-2015-BMR-SPDZ § Atomic contribution","primary_source":"Abstract and Sections 3–4","primary_source_url":"https://eprint.iacr.org/2015/523","status":"section_checked"},"qualifiers":["dishonest majority","malicious security","preprocessing model","two-round online phase"],"limitations":["offline preparation remains substantial","the two-round claim concerns the online phase rather than total execution"],"facet_status":"normalized","facets":{"task":["low-round-active-mpc"],"mechanism":["bmr-garbling","spdz-preprocessing"],"adversary_behavior":["malicious"],"majority_regime":["dishonest-majority"],"phase":["offline","online"]},"status":"published","evidence":"primary_source_checked","research_lenses":["active-security","round-communication","preprocessing-correlation"],"keywords":["bmr","spdz","protocol-composition","malicious-mpc"],"work_id":"MPC-PAPER-2015-BMR-SPDZ","role":"protocol_composition","lens":"active-security","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"BMR with SPDZ preprocessing The complete configuration is represented separately from this paper-level composition delta."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2015-BMR-SPDZ"},{"id":"MPC-CONTRIB-2015-HALFGATES","type":"contribution","title":"Half-gates reduce each Free-XOR-compatible AND gate to two ciphertexts","subtitle":"Two Halves Make a Whole: Reducing Data Transfer in Garbled Circuits Using Half Gates","status":"published","evidence":"primary_source_checked","year":2015,"venue":"EUROCRYPT 2015","primaryUrl":"https://www.cs.virginia.edu/~evans/pubs/ec2015/","summary":"Half-gates decomposes a garbled AND into evaluator and garbler halves, reaching two ciphertexts per AND gate while remaining compatible with the Free-XOR wire-label invariant.","tags":["and-gate","atomic-contribution","backbone","free-xor","garbled-circuit-efficiency","garbled-circuits","gate_cost_reduction","half-gates","round-communication"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2015-HALFGATES","paper_id":"MPC-PAPER-2015-HALFGATES","year":2015,"title":"Half-gates reduce each Free-XOR-compatible AND gate to two ciphertexts","claim_slug":"half-gates-two-ciphertext-and","contribution_kind":"optimization","contribution_role":"gate_cost_reduction","statement":"Half-gates decomposes a garbled AND into evaluator and garbler halves, reaching two ciphertexts per AND gate while remaining compatible with the Free-XOR wire-label invariant.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Free-XOR removed the cost of linear gates, leaving garbled non-XOR gates as the dominant communication term and prior compatible techniques above the two-ciphertext target.","technical_delta":"The construction splits the AND function into two correlated half-gates whose outputs combine under the global offset, requiring one ciphertext for each half.","significance_at_publication":"It established a new concrete communication point for standard Free-XOR-compatible garbling and sharpened the non-XOR gate cost metric.","narrative":"Once Free-XOR made linear gates costless, the bandwidth of a garbled circuit was governed primarily by its AND gates. Existing Free-XOR-compatible garbling still sent more material per nonlinear gate. Half-gates decomposes each AND into a garbler half and an evaluator half, arranging the label algebra so that each half needs one ciphertext and their outputs recombine correctly. The atomic contribution is the two-ciphertext AND construction under the compatible garbling model, not a claim about total protocol latency. It mattered because it set a widely used concrete cost point for garbled-circuit implementations and made AND count an even cleaner predictor of communication."},"source_locator":{"dossier_section":"MPC-PAPER-2015-HALFGATES § Atomic contribution","primary_source":"Abstract and half-gates construction","primary_source_url":"https://www.cs.virginia.edu/~evans/pubs/ec2015/","status":"section_checked"},"qualifiers":["garbled AND gates","two ciphertexts","Free-XOR compatibility"],"limitations":["the bound is per AND gate rather than end-to-end cost","assumes the stated garbling and hash model"],"facet_status":"normalized","facets":{"task":["garbled-circuit-efficiency"],"mechanism":["half-gates"],"gate_type":["and"],"cost_coordinate":["ciphertexts"]},"status":"published","evidence":"primary_source_checked","research_lenses":["garbled-circuit-efficiency","round-communication"],"keywords":["half-gates","free-xor","garbled-circuits","and-gate"],"work_id":"MPC-PAPER-2015-HALFGATES","role":"gate_cost_reduction","lens":"garbled-circuit-efficiency","visibility":"backbone"},"sections":[{"heading":"Overview","content":"Half-gates The title names both the optimized object and the exact communication coordinate."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2015-HALFGATES"},{"id":"MPC-PAPER-2015-ABY","type":"paper","title":"ABY — A Framework for Efficient Mixed-Protocol Secure Two-Party Computation","subtitle":"Daniel Demmler, Thomas Schneider, Michael Zohner · 2015","status":"published","evidence":"primary_source_checked","year":2015,"venue":"NDSS 2015","primaryUrl":"https://www.ndss-symposium.org/wp-content/uploads/2017/09/08_2_1.pdf","summary":"The displayed ABY row is the paper's passive two-party configuration; malicious or multiparty descendants are separate records.","tags":["implementation-systems","mixed-protocol-compilation"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2015-ABY","title":"ABY — A Framework for Efficient Mixed-Protocol Secure Two-Party Computation","authors":["Daniel Demmler","Thomas Schneider","Michael Zohner"],"year":2015,"venue":"NDSS 2015","primary_url":"https://www.ndss-symposium.org/wp-content/uploads/2017/09/08_2_1.pdf","status":"published","evidence":"primary_source_checked","keywords":["mixed-protocol-compilation","implementation-systems"],"contribution_ids":["MPC-CONTRIB-2015-ABY-MIXED"]},"sections":[{"heading":"Configuration boundary","content":"The displayed ABY row is the paper's passive two-party configuration; malicious or multiparty descendants are separate records."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2015-ABY"},{"id":"MPC-PAPER-2015-BMR-SPDZ","type":"paper","title":"Efficient Constant Round Multi-Party Computation Combining BMR and SPDZ","subtitle":"Yehuda Lindell, Benny Pinkas, Nigel P. Smart et al. · 2015","status":"published","evidence":"primary_source_checked","year":2015,"venue":"CRYPTO 2015","primaryUrl":"https://eprint.iacr.org/2015/523","summary":"This is a cross-thread composition: authenticated arithmetic preprocessing produces a multiparty garbled-circuit online phase.","tags":["active-security","preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2015-BMR-SPDZ","title":"Efficient Constant Round Multi-Party Computation Combining BMR and SPDZ","authors":["Yehuda Lindell","Benny Pinkas","Nigel P. Smart","Avishay Yanai"],"year":2015,"venue":"CRYPTO 2015","primary_url":"https://eprint.iacr.org/2015/523","status":"published","evidence":"primary_source_checked","keywords":["round-communication","active-security","preprocessing-correlation"],"contribution_ids":["MPC-CONTRIB-2015-BMR-SPDZ"]},"sections":[{"heading":"Role","content":"This is a cross-thread composition: authenticated arithmetic preprocessing produces a multiparty garbled-circuit online phase."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2015-BMR-SPDZ"},{"id":"MPC-PAPER-2015-HALFGATES","type":"paper","title":"Two Halves Make a Whole: Reducing Data Transfer in Garbled Circuits Using Half Gates","subtitle":"Samee Zahur, Mike Rosulek, David Evans · 2015","status":"published","evidence":"primary_source_checked","year":2015,"venue":"EUROCRYPT 2015","primaryUrl":"https://www.cs.virginia.edu/~evans/pubs/ec2015/","summary":"Half-gates is a reusable garbling component, not a complete security configuration.","tags":["garbled-circuit-efficiency","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2015-HALFGATES","title":"Two Halves Make a Whole: Reducing Data Transfer in Garbled Circuits Using Half Gates","authors":["Samee Zahur","Mike Rosulek","David Evans"],"year":2015,"venue":"EUROCRYPT 2015","primary_url":"https://www.cs.virginia.edu/~evans/pubs/ec2015/","status":"published","evidence":"primary_source_checked","keywords":["garbled-circuit-efficiency","round-communication"],"contribution_ids":["MPC-CONTRIB-2015-HALFGATES"]},"sections":[{"heading":"Role","content":"Half-gates is a reusable garbling component, not a complete security configuration."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2015-HALFGATES"},{"id":"MPC-PROTOCOL-ABY-PASSIVE","type":"protocol","title":"ABY passive mixed-protocol 2PC","subtitle":"mixed protocol 2pc · 2015","status":"published","evidence":"primary_source_checked","year":2015,"venue":null,"primaryUrl":null,"summary":"ABY is compared as a mixed configuration, not as a fourth sharing type competing with its A/B/Y components.","tags":["implementation-systems","mixed-protocol-compilation"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-ABY-PASSIVE","title":"ABY passive mixed-protocol 2PC","name":"ABY","paper_ids":["MPC-PAPER-2015-ABY"],"claim_ids":["MPC-CONTRIB-2015-ABY-MIXED"],"year":2015,"protocol_family":"mixed_protocol_2pc","research_lenses":["mixed-protocol-compilation","implementation-systems"],"tasks":["general_2pc","mixed_domain_computation"],"properties":{"parties":"2","corruption_threshold":"1 passive corruption","majority_regime":"dishonest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"OT_extension_and_protocol_specific_precomputation","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-MIXED"],"value_encoding":["MPC-COMP-ENC-ADDITIVE","MPC-COMP-ENC-XOR","MPC-COMP-ENC-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER","MPC-COMP-EVAL-GMW","MPC-COMP-EVAL-YAO"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":["MPC-COMP-CONV-ABY"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable"},"complexity":{"online_rounds":"subprotocol_and_conversion_dependent","communication_driver":"selected_sharing_subprotocols_and_conversion_gates","preprocessing":"ot_extension_and_garbling_material"},"configuration_note":"Paper's passive two-party configuration across arithmetic, Boolean, and Yao sharings.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Full-stack identity","content":"ABY is compared as a mixed configuration, not as a fourth sharing type competing with its A/B/Y components."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-ABY-PASSIVE"},{"id":"MPC-PROTOCOL-BMR-SPDZ","type":"protocol","title":"BMR with SPDZ-secured preprocessing","subtitle":"active multiparty garbled circuit · 2015","status":"published","evidence":"primary_source_checked","year":2015,"venue":null,"primaryUrl":null,"summary":"The arithmetic protocol protects circuit preparation; the online phase is a multiparty garbled-circuit evaluation.","tags":["active-security","preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-BMR-SPDZ","title":"BMR with SPDZ-secured preprocessing","name":"BMR + SPDZ","paper_ids":["MPC-PAPER-1990-BMR","MPC-PAPER-2011-SPDZ","MPC-PAPER-2015-BMR-SPDZ"],"claim_ids":["MPC-CONTRIB-1990-BMR-CONSTANT","MPC-CONTRIB-2011-SPDZ-AUTH","MPC-CONTRIB-2015-BMR-SPDZ"],"year":2015,"protocol_family":"active_multiparty_garbled_circuit","research_lenses":["round-communication","active-security","preprocessing-correlation"],"tasks":["general_mpc","constant_round_online","dishonest_majority_active"],"properties":{"parties":"n","corruption_threshold":"t < n","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_authenticated_channels","setup":"SPDZ_style_offline_distributed_garbling","output_guarantee":"security_with_abort","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-MULTI-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BMR"],"correlation_source":["MPC-COMP-CORR-SHE"],"active_security_enforcement":["MPC-COMP-ACT-BMR-SPDZ"],"conversion_layer":["MPC-COMP-CONV-BMR-PREP"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{},"complexity":{"online_rounds":"two","communication_driver":"offline_distributed_garbling;_online_input_labels","preprocessing":"actively_secure_arithmetic_MPC_builds_BMR_tables"},"configuration_note":"Exact composition from the 2015 paper; it is neither plain BMR nor an arithmetic SPDZ online execution.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Composition","content":"The arithmetic protocol protects circuit preparation; the online phase is a multiparty garbled-circuit evaluation."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-BMR-SPDZ"},{"id":"MPC-PROTOCOL-YAO-PASSIVE","type":"protocol","title":"Yao / OT-extension passive 2PC","subtitle":"garbled circuit 2pc · 2015","status":"published","evidence":"primary_source_checked","year":2015,"venue":null,"primaryUrl":null,"summary":"This configuration makes the familiar optimized passive garbling stack explicit instead of attributing all later optimizations to “Yao.”","tags":["garbled-circuit-efficiency","preprocessing-correlation"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-YAO-PASSIVE","title":"Yao / OT-extension passive 2PC","name":"Yao passive 2PC","paper_ids":["MPC-PAPER-2003-IKNP","MPC-PAPER-2008-FREEXOR","MPC-PAPER-2009-PRACTICAL2PC","MPC-PAPER-2015-HALFGATES"],"claim_ids":["MPC-CONTRIB-2003-IKNP-OTEXT","MPC-CONTRIB-2008-FREEXOR","MPC-CONTRIB-2015-HALFGATES"],"year":2015,"protocol_family":"garbled_circuit_2pc","research_lenses":["garbled-circuit-efficiency","preprocessing-correlation"],"tasks":["general_2pc","boolean_circuit_evaluation"],"properties":{"parties":"2","corruption_threshold":"1 passive corruption","majority_regime":"dishonest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"base_OT_then_OT_extension","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-YAO"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"constant_after_ot_setup","communication_driver":"garbled_non_xor_gates_plus_input_ot","preprocessing":"base_ot_and_ot_extension"},"configuration_note":"Modernized passive Yao stack with Free-XOR, half-gates, and IKNP-style OT extension; it is not the literal 1982 protocol instance.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Why this row exists","content":"This configuration makes the familiar optimized passive garbling stack explicit instead of attributing all later optimizations to “Yao.”"}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-YAO-PASSIVE"},{"id":"MPC-CONTRIB-2016-MASCOT-TRIPLES","type":"contribution","title":"OT-based checks replace public-key-heavy SPDZ triple generation","subtitle":"MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious Transfer","status":"published","evidence":"primary_source_checked","year":2016,"venue":"CCS 2016","primaryUrl":"https://eprint.iacr.org/2016/505","summary":"MASCOT generates actively secure authenticated arithmetic triples from oblivious transfer, multiplication, and consistency checks, replacing SPDZ's somewhat-homomorphic-encryption preprocessing while preserving its online sharing protocol.","tags":["active-security","atomic-contribution","backbone","implementation-systems","mascot","ot-preprocessing","preprocessing-correlation","preprocessing_replacement","spdz","triples"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2016-MASCOT-TRIPLES","paper_id":"MPC-PAPER-2016-MASCOT","year":2016,"title":"OT-based checks replace public-key-heavy SPDZ triple generation","claim_slug":"mascot-ot-authenticated-triples","contribution_kind":"optimization","contribution_role":"preprocessing_replacement","statement":"MASCOT generates actively secure authenticated arithmetic triples from oblivious transfer, multiplication, and consistency checks, replacing SPDZ's somewhat-homomorphic-encryption preprocessing while preserving its online sharing protocol.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"The original SPDZ architecture had a light online phase but generated authenticated multiplication triples through expensive somewhat-homomorphic encryption.","technical_delta":"MASCOT derives candidate products from OT, authenticates them, and applies sacrifice and consistency checks to obtain maliciously secure triples without the original homomorphic-encryption generator.","significance_at_publication":"It showed that an MPC online architecture could remain stable while its correlation backend was independently replaced for better concrete performance.","narrative":"SPDZ had already isolated its expensive work in preprocessing, but the original somewhat-homomorphic-encryption machinery made that phase costly. MASCOT keeps the authenticated arithmetic shares and online protocol intact while replacing the triple generator. Oblivious-transfer-based multiplication creates candidate correlations, and authentication plus sacrifice-style checks remove malformed values under malicious behavior. The atomic contribution is this OT-based preprocessing replacement, not a new online arithmetic semantics. It mattered because it validated the modular promise of the SPDZ architecture: researchers and systems could optimize correlation generation as an independent technical thread while retaining the same actively secure dishonest-majority online interface."},"source_locator":{"dossier_section":"MPC-PAPER-2016-MASCOT § Atomic contribution","primary_source":"Abstract and preprocessing protocol","primary_source_url":"https://eprint.iacr.org/2016/505","status":"section_checked"},"qualifiers":["arithmetic triples","OT-based preprocessing","malicious security","SPDZ online compatibility"],"limitations":["preprocessing and checks remain nontrivial","performance depends on OT implementation and network context"],"facet_status":"normalized","facets":{"task":["preprocessing-efficiency"],"mechanism":["ot-multiplication","sacrifice-checks"],"correlation_type":["authenticated-triples"],"adversary_behavior":["malicious"],"majority_regime":["dishonest-majority"]},"status":"published","evidence":"primary_source_checked","research_lenses":["preprocessing-correlation","active-security","implementation-systems"],"keywords":["mascot","spdz","triples","ot-preprocessing"],"work_id":"MPC-PAPER-2016-MASCOT","role":"preprocessing_replacement","lens":"preprocessing-correlation","visibility":"backbone"},"sections":[{"heading":"Overview","content":"MASCOT triples The optimization is attached to the SPDZ preprocessing boundary rather than classified as an implementation."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2016-MASCOT-TRIPLES"},{"id":"MPC-PAPER-2016-MASCOT","type":"paper","title":"MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious Transfer","subtitle":"Marcel Keller, Emmanuela Orsini, Peter Scholl · 2016","status":"published","evidence":"primary_source_checked","year":2016,"venue":"CCS 2016","primaryUrl":"https://eprint.iacr.org/2016/505","summary":"MASCOT supplies preprocessing; the complete comparison row explicitly pairs it with the SPDZ online protocol.","tags":["active-security","preprocessing-correlation"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2016-MASCOT","title":"MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious Transfer","authors":["Marcel Keller","Emmanuela Orsini","Peter Scholl"],"year":2016,"venue":"CCS 2016","primary_url":"https://eprint.iacr.org/2016/505","status":"published","evidence":"primary_source_checked","keywords":["preprocessing-correlation","active-security"],"contribution_ids":["MPC-CONTRIB-2016-MASCOT-TRIPLES"]},"sections":[{"heading":"Configuration boundary","content":"MASCOT supplies preprocessing; the complete comparison row explicitly pairs it with the SPDZ online protocol."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2016-MASCOT"},{"id":"MPC-PROTOCOL-MASCOT-SPDZ","type":"protocol","title":"SPDZ online with MASCOT preprocessing","subtitle":"authenticated arithmetic preprocessing · 2016","status":"published","evidence":"primary_source_checked","year":2016,"venue":null,"primaryUrl":null,"summary":"The online layer is shared, but the correlation source and preprocessing checks are not.","tags":["active-security","preprocessing-correlation"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-MASCOT-SPDZ","title":"SPDZ online with MASCOT preprocessing","name":"MASCOT + SPDZ online","paper_ids":["MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ","MPC-PAPER-2016-MASCOT"],"claim_ids":["MPC-CONTRIB-2011-SPDZ-AUTH","MPC-CONTRIB-2016-MASCOT-TRIPLES"],"year":2016,"protocol_family":"authenticated_arithmetic_preprocessing","research_lenses":["preprocessing-correlation","active-security"],"tasks":["general_mpc","dishonest_majority_active_arithmetic"],"properties":{"parties":"n","corruption_threshold":"t < n","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_authenticated_channels","setup":"OT_based_input_independent_preprocessing","output_guarantee":"security_with_abort","privacy_basis":"computational_preprocessing_and_information_theoretic_online_checks"},"stack":{"representation":["MPC-COMP-REP-ARITH-FIELD"],"value_encoding":["MPC-COMP-ENC-AUTH-ADDITIVE"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER"],"correlation_source":["MPC-COMP-CORR-MASCOT"],"active_security_enforcement":["MPC-COMP-ACT-SPDZ-MAC"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_arithmetic_multiplicative_depth","communication_driver":"SPDZ_online_openings","preprocessing":"OT_based_authenticated_triples_with_consistency_checks"},"configuration_note":"MASCOT offline phase feeding the authenticated SPDZ arithmetic online phase.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Difference from SPDZ/SHE","content":"The online layer is shared, but the correlation source and preprocessing checks are not."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-MASCOT-SPDZ"},{"id":"MPC-CONTRIB-2017-EMP-M2PC","type":"contribution","title":"Single-execution malicious garbled 2PC reduces setup and circuit-processing cost","subtitle":"Faster Secure Two-Party Computation in the Single-Execution Setting","status":"published","evidence":"primary_source_checked","year":2017,"venue":"EUROCRYPT 2017","primaryUrl":"https://www.iacr.org/archive/eurocrypt2017/10210107/10210107.pdf","summary":"Wang, Ranellucci, and Katz optimize malicious garbled-circuit two-party computation for a single execution by reducing public-key work and improving oblivious-transfer and circuit-processing bottlenecks, with an open implementation supporting the evaluation.","tags":["active-security","atomic-contribution","emp","garbled-circuit-efficiency","implementation-systems","malicious-2pc","protocol_optimization","reviewed_related","single-execution","systems-codesign"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2017-EMP-M2PC","paper_id":"MPC-PAPER-2017-EMP-M2PC","year":2017,"title":"Single-execution malicious garbled 2PC reduces setup and circuit-processing cost","claim_slug":"emp-single-execution-malicious-2pc","contribution_kind":"optimization","contribution_role":"protocol_optimization","statement":"Wang, Ranellucci, and Katz optimize malicious garbled-circuit two-party computation for a single execution by reducing public-key work and improving oblivious-transfer and circuit-processing bottlenecks, with an open implementation supporting the evaluation.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Malicious 2PC protocols often amortized setup across repeated executions or paid substantial public-key and checking costs when evaluated as a single run.","technical_delta":"The protocol and implementation co-optimize base cryptography, OT handling, and garbled-circuit processing for the one-execution regime rather than assuming a long amortization horizon.","significance_at_publication":"It made the amortization unit explicit and supplied a concrete systems-security transition without confusing the protocol optimization with the released software version.","narrative":"Practical malicious two-party computation was frequently evaluated under amortization assumptions that spread setup and public-key operations across many executions. That model can hide the cost faced by an application that invokes the protocol only once. Wang, Ranellucci, and Katz redesign and implement the malicious garbled-circuit path around this single-execution boundary, reducing public-key work and streamlining OT and circuit processing. The atomic contribution is the implementation-aware protocol optimization for that amortization unit; the EMP codebase is a related artifact with its own identity. It mattered because later comparisons had to state whether costs were per run or amortized rather than treating all practical 2PC results as directly comparable."},"source_locator":{"dossier_section":"MPC-PAPER-2017-EMP-M2PC § Atomic contribution","primary_source":"Abstract and contribution summary","primary_source_url":"https://www.iacr.org/archive/eurocrypt2017/10210107/10210107.pdf","status":"section_checked"},"qualifiers":["two-party setting","malicious security","single-execution accounting","garbled circuits"],"limitations":["performance is tied to the reported implementation context","the contribution does not represent every protocol exposed by later EMP repositories"],"facet_status":"normalized","facets":{"task":["malicious-2pc-efficiency"],"mechanism":["garbled-circuit-codesign","ot-optimization"],"adversary_behavior":["malicious"],"party_model":["two-party"],"amortization_unit":["single-execution"]},"status":"published","evidence":"primary_source_checked","research_lenses":["active-security","garbled-circuit-efficiency","implementation-systems"],"keywords":["emp","malicious-2pc","single-execution","systems-codesign"],"work_id":"MPC-PAPER-2017-EMP-M2PC","role":"protocol_optimization","lens":"active-security","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"EMP single-execution 2PC The paper's protocol-and-systems delta is separated from any mutable repository head."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2017-EMP-M2PC"},{"id":"MPC-PAPER-2017-EMP-M2PC","type":"paper","title":"Faster Secure Two-Party Computation in the Single-Execution Setting","subtitle":"Xiao Wang, Samuel Ranellucci, Jonathan Katz · 2017","status":"published","evidence":"primary_source_checked","year":2017,"venue":"EUROCRYPT 2017","primaryUrl":"https://www.iacr.org/archive/eurocrypt2017/10210107/10210107.pdf","summary":"This card links the actively secure 2PC mechanism to the EMP practice track.","tags":["active-security","garbled-circuit-efficiency","implementation-systems"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2017-EMP-M2PC","title":"Faster Secure Two-Party Computation in the Single-Execution Setting","authors":["Xiao Wang","Samuel Ranellucci","Jonathan Katz"],"year":2017,"venue":"EUROCRYPT 2017","primary_url":"https://www.iacr.org/archive/eurocrypt2017/10210107/10210107.pdf","status":"published","evidence":"primary_source_checked","keywords":["active-security","implementation-systems","garbled-circuit-efficiency"],"contribution_ids":["MPC-CONTRIB-2017-EMP-M2PC"]},"sections":[{"heading":"Role","content":"This card links the actively secure 2PC mechanism to the EMP practice track."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2017-EMP-M2PC"},{"id":"MPC-CONTRIB-2018-ABY3-REPLICATED","type":"contribution","title":"Replicated ring sharing extends mixed-domain computation to three parties","subtitle":"ABY3: A Mixed Protocol Framework for Machine Learning","status":"published","evidence":"primary_source_checked","year":2018,"venue":"CCS 2018","primaryUrl":"https://eprint.iacr.org/2018/403","summary":"ABY3 constructs a three-party mixed-protocol framework from replicated ring sharing and explicit arithmetic, binary, and Yao-style conversions, with the passive configuration separated from stronger variants.","tags":["aby3","atomic-contribution","backbone","implementation-systems","mixed-protocol","mixed-protocol-compilation","protocol_framework","replicated-sharing","round-communication","three-party-mpc"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2018-ABY3-REPLICATED","paper_id":"MPC-PAPER-2018-ABY3","year":2018,"title":"Replicated ring sharing extends mixed-domain computation to three parties","claim_slug":"aby3-replicated-ring-mixed-protocol","contribution_kind":"construction","contribution_role":"protocol_framework","statement":"ABY3 constructs a three-party mixed-protocol framework from replicated ring sharing and explicit arithmetic, binary, and Yao-style conversions, with the passive configuration separated from stronger variants.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"ABY exposed mixed-domain conversion for two parties, while machine-learning workloads motivated efficient fixed-point arithmetic and bit-level operations in an honest-majority setting.","technical_delta":"ABY3 uses three-party replicated sharing over rings as the common architecture and supplies conversions among arithmetic, binary, and garbled representations tailored to that party model.","significance_at_publication":"It changed both the party/sharing model and the mixed-protocol stack, giving data-analysis workloads a distinct honest-majority design point.","narrative":"ABY showed how a two-party computation could cross arithmetic, Boolean, and garbled domains, but a three-party honest-majority setting offers different sharing and communication opportunities. ABY3 bases its core on replicated ring shares and defines conversions for arithmetic, binary, and Yao-style subcomputations, including operations needed by machine-learning workloads. The atomic contribution is this three-party mixed-domain architecture, not an unqualified claim about every active-security variant discussed by the paper. It mattered because protocol assignment and conversion could be studied under a new party and trust model, and later systems could optimize the replicated-sharing path while keeping its exact security configuration visible."},"source_locator":{"dossier_section":"MPC-PAPER-2018-ABY3 § Atomic contribution","primary_source":"Abstract and protocol overview","primary_source_url":"https://eprint.iacr.org/2018/403","status":"section_checked"},"qualifiers":["three-party setting","replicated ring sharing","mixed arithmetic/binary/Yao domains"],"limitations":["passive and stronger configurations must not be conflated","application-specific fixed-point semantics require separate accounting"],"facet_status":"normalized","facets":{"task":["mixed-protocol-computation"],"mechanism":["replicated-sharing","typed-conversions"],"representation":["ring-sharing","binary-sharing","yao-garbling"],"party_model":["three-party"],"majority_regime":["honest-majority"]},"status":"published","evidence":"primary_source_checked","research_lenses":["mixed-protocol-compilation","round-communication","implementation-systems"],"keywords":["aby3","replicated-sharing","mixed-protocol","three-party-mpc"],"work_id":"MPC-PAPER-2018-ABY3","role":"protocol_framework","lens":"mixed-protocol-compilation","visibility":"backbone"},"sections":[{"heading":"Overview","content":"ABY3 replicated sharing The contribution does not make the framework name stand in for every security configuration."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2018-ABY3-REPLICATED"},{"id":"MPC-PAPER-2018-ABY3","type":"paper","title":"ABY3: A Mixed Protocol Framework for Machine Learning","subtitle":"Payman Mohassel, Peter Rindal · 2018","status":"published","evidence":"primary_source_checked","year":2018,"venue":"CCS 2018","primaryUrl":"https://eprint.iacr.org/2018/403","summary":"The atlas displays the passive 3PC configuration. Security variants with different checks are not merged into this row.","tags":["implementation-systems","mixed-protocol-compilation","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2018-ABY3","title":"ABY3: A Mixed Protocol Framework for Machine Learning","authors":["Payman Mohassel","Peter Rindal"],"year":2018,"venue":"CCS 2018","primary_url":"https://eprint.iacr.org/2018/403","status":"published","evidence":"primary_source_checked","keywords":["mixed-protocol-compilation","implementation-systems","round-communication"],"contribution_ids":["MPC-CONTRIB-2018-ABY3-REPLICATED"]},"sections":[{"heading":"Boundary note","content":"The atlas displays the passive 3PC configuration. Security variants with different checks are not merged into this row."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2018-ABY3"},{"id":"MPC-PROTOCOL-ABY3-PASSIVE","type":"protocol","title":"ABY3 passive replicated-ring 3PC","subtitle":"honest majority mixed 3pc · 2018","status":"published","evidence":"primary_source_checked","year":2018,"venue":null,"primaryUrl":null,"summary":"“ABY3” does not imply malicious security in this row.","tags":["mixed-protocol-compilation","round-communication"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-ABY3-PASSIVE","title":"ABY3 passive replicated-ring 3PC","name":"ABY3 passive","paper_ids":["MPC-PAPER-2018-ABY3"],"claim_ids":["MPC-CONTRIB-2018-ABY3-REPLICATED"],"year":2018,"protocol_family":"honest_majority_mixed_3pc","research_lenses":["mixed-protocol-compilation","round-communication"],"tasks":["general_3pc","mixed_domain_computation","ring_arithmetic"],"properties":{"parties":"3","corruption_threshold":"1 passive corruption","majority_regime":"honest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_pairwise_channels","setup":"pairwise_PRG_seeds","output_guarantee":"abort_on_disconnect","privacy_basis":"information_theoretic_given_seeded_masks_except_PRG_expansion"},"stack":{"representation":["MPC-COMP-REP-MIXED","MPC-COMP-REP-ARITH-RING"],"value_encoding":["MPC-COMP-ENC-REPLICATED","MPC-COMP-ENC-ABY3-YAO"],"evaluation_protocol":["MPC-COMP-EVAL-REPLICATED","MPC-COMP-EVAL-ABY3-YAO"],"correlation_source":["MPC-COMP-CORR-PAIRWISE"],"active_security_enforcement":[],"conversion_layer":["MPC-COMP-CONV-ABY3"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable"},"complexity":{"online_rounds":"operation_and_conversion_dependent","communication_driver":"replicated_multiplications_and_domain_conversions","preprocessing":"pairwise_seed_expansion"},"configuration_note":"Passive three-party configuration; malicious ABY3-style variants require different enforcement and party assumptions.","visibility":"backbone","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Boundary","content":"“ABY3” does not imply malicious security in this row."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-ABY3-PASSIVE"},{"id":"MPC-CONTRIB-2019-PCG-SILENT","type":"contribution","title":"Pseudorandom correlation generators move large OT batches to local seed expansion","subtitle":"Efficient Pseudorandom Correlation Generators: Silent OT Extension and More","status":"published","evidence":"primary_source_checked","year":2019,"venue":"CRYPTO 2019","primaryUrl":"https://eprint.iacr.org/2019/448","summary":"Boyle, Couteau, Gilboa, Ishai, Kohl, and Scholl formalize pseudorandom correlation generators and construct silent OT-style expansion, replacing communication and stored correlated randomness with short seeds and local computation.","tags":["atomic-contribution","backbone","correlation-generation","correlation_generator","local-expansion","pcg","preprocessing-correlation","round-communication","silent-ot"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2019-PCG-SILENT","paper_id":"MPC-PAPER-2019-PCG","year":2019,"title":"Pseudorandom correlation generators move large OT batches to local seed expansion","claim_slug":"pcg-silent-correlation-expansion","contribution_kind":"mechanism","contribution_role":"correlation_generator","statement":"Boyle, Couteau, Gilboa, Ishai, Kohl, and Scholl formalize pseudorandom correlation generators and construct silent OT-style expansion, replacing communication and stored correlated randomness with short seeds and local computation.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"OT extension made each additional transfer cheap in public-key terms, but producing very large correlation batches still required communication and storage proportional to the batch.","technical_delta":"A PCG lets parties expand compact correlated seeds locally into a much larger structured correlation, including silent OT constructions under the paper's assumptions.","significance_at_publication":"It made communication-free expansion a reusable correlation primitive and shifted the bottleneck toward assumptions, local work, and seed setup.","narrative":"IKNP-style extension reduced public-key operations, yet the parties still exchanged data proportional to the number of expanded transfers. Pseudorandom correlation generators define a stronger interface: compact correlated seeds are established once, then each party expands locally to obtain a large correlated output. The paper gives efficient constructions including silent OT. The atomic contribution is this seed-to-correlation abstraction and its communication shift, not a claim that all preprocessing becomes free. It mattered because MPC designers could replace bandwidth-heavy correlation distribution with local computation and study PCGs independently across OT, vector OLE, and multiplication-preprocessing applications."},"source_locator":{"dossier_section":"MPC-PAPER-2019-PCG § Atomic contribution","primary_source":"Abstract; PCG definition and constructions","primary_source_url":"https://eprint.iacr.org/2019/448","status":"section_checked"},"qualifiers":["short correlated seeds","local pseudorandom expansion","silent OT constructions"],"limitations":["construction security depends on stated assumptions","local computation and seed-establishment costs remain"],"facet_status":"normalized","facets":{"task":["correlation-generation"],"mechanism":["pseudorandom-correlation-generator","silent-expansion"],"correlation_type":["oblivious-transfer"],"cost_coordinate":["communication","storage"]},"status":"published","evidence":"primary_source_checked","research_lenses":["preprocessing-correlation","round-communication"],"keywords":["pcg","silent-ot","correlation-generation","local-expansion"],"work_id":"MPC-PAPER-2019-PCG","role":"correlation_generator","lens":"preprocessing-correlation","visibility":"backbone"},"sections":[{"heading":"Overview","content":"Silent PCG correlations This mechanism is not equated with an entire preprocessing protocol or implementation."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2019-PCG-SILENT"},{"id":"MPC-PAPER-2019-PCG","type":"paper","title":"Efficient Pseudorandom Correlation Generators: Silent OT Extension and More","subtitle":"Elette Boyle, Geoffroy Couteau, Niv Gilboa et al. · 2019","status":"published","evidence":"primary_source_checked","year":2019,"venue":"CRYPTO 2019","primaryUrl":"https://eprint.iacr.org/2019/448","summary":"Each PCG construction has its own assumption and correlation type; “silent preprocessing” is not one universal drop-in object.","tags":["preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2019-PCG","title":"Efficient Pseudorandom Correlation Generators: Silent OT Extension and More","authors":["Elette Boyle","Geoffroy Couteau","Niv Gilboa","Yuval Ishai","Lisa Kohl","Peter Scholl"],"year":2019,"venue":"CRYPTO 2019","primary_url":"https://eprint.iacr.org/2019/448","status":"published","evidence":"primary_source_checked","keywords":["preprocessing-correlation","round-communication"],"contribution_ids":["MPC-CONTRIB-2019-PCG-SILENT"]},"sections":[{"heading":"Security boundary","content":"Each PCG construction has its own assumption and correlation type; “silent preprocessing” is not one universal drop-in object."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2019-PCG"},{"id":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","type":"contribution","title":"MOTION generalizes modular mixed-protocol execution beyond two parties","subtitle":"MOTION — A Framework for Mixed-Protocol Multi-Party Computation","status":"published","evidence":"primary_source_checked","year":2020,"venue":"IACR ePrint 2020/1137","primaryUrl":"https://eprint.iacr.org/2020/1137","summary":"MOTION provides an asynchronous modular software architecture that combines multiple sharing protocols and conversions for two or more parties under full-threshold passive security.","tags":["atomic-contribution","framework","implementation-systems","implementation_framework","mixed-protocol","mixed-protocol-compilation","motion","multiparty","reviewed_related"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","paper_id":"MPC-PAPER-2020-MOTION","year":2020,"title":"MOTION generalizes modular mixed-protocol execution beyond two parties","claim_slug":"motion-multiparty-mixed-protocol-framework","contribution_kind":"implementation_result","contribution_role":"implementation_framework","statement":"MOTION provides an asynchronous modular software architecture that combines multiple sharing protocols and conversions for two or more parties under full-threshold passive security.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"ABY provided a two-party mixed-protocol interface, while broader MPC frameworks often exposed protocol families without the same modular cross-domain execution model.","technical_delta":"MOTION organizes gates, wires, communication, and protocol providers behind an asynchronous runtime that supports multiple passive sharing types and party counts.","significance_at_publication":"It made framework architecture itself a reviewed realization contribution while leaving exact protocol configurations and immutable artifact versions independently inspectable.","narrative":"Mixed-protocol execution had a clear two-party framework in ABY, but extending the idea to more parties required new runtime abstractions for communication, scheduling, sharing types, and conversions. MOTION supplies a modular asynchronous software architecture in which protocol providers can coexist and computations can run for two or more parties under the documented passive full-threshold model. The atomic contribution is the multiparty framework architecture, not a new security theorem for every backend and not the identity of one repository commit. It mattered because mixed-domain MPC became an extensible systems surface: implementations could add providers or conversions while exact configurations and reproducible artifact versions remained separately accountable."},"source_locator":{"dossier_section":"MPC-PAPER-2020-MOTION § Atomic contribution","primary_source":"Abstract and framework architecture","primary_source_url":"https://eprint.iacr.org/2020/1137","status":"section_checked"},"qualifiers":["two or more parties","passive full-threshold security","asynchronous modular runtime"],"limitations":["active security is outside the normalized configuration","the paper contribution is distinct from later repository versions"],"facet_status":"normalized","facets":{"task":["framework-realization"],"mechanism":["modular-protocol-providers","asynchronous-runtime"],"adversary_behavior":["passive"],"party_model":["two-or-more"],"representation":["mixed-domain"]},"status":"published","evidence":"primary_source_checked","research_lenses":["implementation-systems","mixed-protocol-compilation"],"keywords":["motion","framework","mixed-protocol","multiparty"],"work_id":"MPC-PAPER-2020-MOTION","role":"implementation_framework","lens":"implementation-systems","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"MOTION framework architecture The contribution, exact protocol configurations, and pinned implementation version retain separate identities."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2020-MOTION-MULTIPARTY"},{"id":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","type":"contribution","title":"MP-SPDZ unifies many MPC backends behind one compiler and virtual machine","subtitle":"MP-SPDZ: A Versatile Framework for Multi-Party Computation","status":"published","evidence":"primary_source_checked","year":2020,"venue":"CCS 2020","primaryUrl":"https://eprint.iacr.org/2020/521","summary":"MP-SPDZ provides a high-level compiler and virtual-machine architecture that realizes multiple arithmetic and binary MPC protocol families while keeping backend selection and protocol-specific costs explicit.","tags":["active-security","atomic-contribution","backbone","compiler","implementation-systems","implementation_framework","mixed-protocol-compilation","mp-spdz","multi-backend","preprocessing-correlation","virtual-machine"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","paper_id":"MPC-PAPER-2020-MPSPDZ","year":2020,"title":"MP-SPDZ unifies many MPC backends behind one compiler and virtual machine","claim_slug":"mp-spdz-multi-backend-compiler-runtime","contribution_kind":"implementation_result","contribution_role":"implementation_framework","statement":"MP-SPDZ provides a high-level compiler and virtual-machine architecture that realizes multiple arithmetic and binary MPC protocol families while keeping backend selection and protocol-specific costs explicit.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"MPC implementations were often tied to one protocol family, representation, or security model, making programs and performance studies difficult to compare across backends.","technical_delta":"MP-SPDZ separates a high-level program and bytecode execution layer from a broad set of protocol runtimes, including several authenticated-sharing and binary alternatives.","significance_at_publication":"It created a common experimental surface without claiming that unlike protocol configurations share one security or performance contract.","narrative":"Practical MPC software commonly embodied one protocol architecture, so changing from an SPDZ variant to an honest-majority or binary backend could also require a different programming and runtime environment. MP-SPDZ introduces a compiler and virtual-machine surface that supports many protocol families beneath one high-level language. Backend selection remains explicit, and each protocol keeps its own setup, adversary, and cost profile. The atomic contribution is this multi-backend systems architecture, not a theorem that the supported protocols are interchangeable. It mattered because researchers could implement workloads once, inspect several exact configurations, and build more disciplined implementation and measurement comparisons around a shared toolchain."},"source_locator":{"dossier_section":"MPC-PAPER-2020-MPSPDZ § Atomic contribution","primary_source":"Abstract; architecture and supported-protocol sections","primary_source_url":"https://eprint.iacr.org/2020/521","status":"section_checked"},"qualifiers":["compiler and virtual machine","multiple arithmetic and binary backends","explicit protocol selection"],"limitations":["supported configurations have incompatible security and preprocessing contracts","measurements remain version and environment specific"],"facet_status":"normalized","facets":{"task":["framework-realization"],"mechanism":["compiler","virtual-machine","protocol-backends"],"representation":["arithmetic","binary"],"security_contract":["backend-specific"]},"status":"published","evidence":"primary_source_checked","research_lenses":["implementation-systems","active-security","preprocessing-correlation","mixed-protocol-compilation"],"keywords":["mp-spdz","compiler","virtual-machine","multi-backend"],"work_id":"MPC-PAPER-2020-MPSPDZ","role":"implementation_framework","lens":"implementation-systems","visibility":"backbone"},"sections":[{"heading":"Overview","content":"MP-SPDZ framework architecture The shared programming surface does not collapse the distinct configurations it can execute."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK"},{"id":"MPC-PAPER-2020-MOTION","type":"paper","title":"MOTION — A Framework for Mixed-Protocol Multi-Party Computation","subtitle":"Lennart Braun, Daniel Demmler, Thomas Schneider et al. · 2020","status":"published","evidence":"primary_source_checked","year":2020,"venue":"IACR ePrint 2020/1137","primaryUrl":"https://eprint.iacr.org/2020/1137","summary":"MOTION's asynchronous software architecture is distinct from an asynchronous-network security proof.","tags":["implementation-systems","mixed-protocol-compilation"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2020-MOTION","title":"MOTION — A Framework for Mixed-Protocol Multi-Party Computation","authors":["Lennart Braun","Daniel Demmler","Thomas Schneider","Oleksandr Tkachenko"],"year":2020,"venue":"IACR ePrint 2020/1137","primary_url":"https://eprint.iacr.org/2020/1137","status":"published","evidence":"primary_source_checked","keywords":["implementation-systems","mixed-protocol-compilation"],"contribution_ids":["MPC-CONTRIB-2020-MOTION-MULTIPARTY"]},"sections":[{"heading":"Boundary note","content":"MOTION's asynchronous software architecture is distinct from an asynchronous-network security proof."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2020-MOTION"},{"id":"MPC-PAPER-2020-MPSPDZ","type":"paper","title":"MP-SPDZ: A Versatile Framework for Multi-Party Computation","subtitle":"Marcel Keller · 2020","status":"published","evidence":"primary_source_checked","year":2020,"venue":"CCS 2020","primaryUrl":"https://eprint.iacr.org/2020/521","summary":"MP-SPDZ is an implementation framework, not a single security configuration. The UI lists realized configurations separately.","tags":["implementation-systems","mixed-protocol-compilation"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2020-MPSPDZ","title":"MP-SPDZ: A Versatile Framework for Multi-Party Computation","authors":["Marcel Keller"],"year":2020,"venue":"CCS 2020","primary_url":"https://eprint.iacr.org/2020/521","status":"published","evidence":"primary_source_checked","keywords":["implementation-systems","mixed-protocol-compilation"],"contribution_ids":["MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK"]},"sections":[{"heading":"Practice boundary","content":"MP-SPDZ is an implementation framework, not a single security configuration. The UI lists realized configurations separately."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2020-MPSPDZ"},{"id":"MPC-PROTOCOL-MOTION-PASSIVE","type":"protocol","title":"MOTION passive mixed multiparty configuration","subtitle":"mixed protocol framework · 2020","status":"published","evidence":"primary_source_checked","year":2020,"venue":null,"primaryUrl":null,"summary":"It binds the paper's stated security model to the mechanisms realized by the implementation, while the immutable repository remains a separate object.","tags":["implementation-systems","mixed-protocol-compilation"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-MOTION-PASSIVE","title":"MOTION passive mixed multiparty configuration","name":"MOTION passive","paper_ids":["MPC-PAPER-2020-MOTION"],"claim_ids":["MPC-CONTRIB-2020-MOTION-MULTIPARTY"],"year":2020,"protocol_family":"mixed_protocol_framework","research_lenses":["mixed-protocol-compilation","implementation-systems"],"tasks":["general_mpc","mixed_domain_computation"],"properties":{"parties":"2 or more","corruption_threshold":"up to n-1 passive corruptions","majority_regime":"dishonest_majority_passive","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_security_model_with_asynchronous_software_scheduling","setup":"protocol_specific_OT_and_precomputation","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-MIXED","MPC-COMP-REP-ARITH-RING","MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-ADDITIVE","MPC-COMP-ENC-XOR","MPC-COMP-ENC-MULTI-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER","MPC-COMP-EVAL-GMW","MPC-COMP-EVAL-BMR"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":["MPC-COMP-CONV-MOTION"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable"},"complexity":{"online_rounds":"selected_protocol_graph_dependent","communication_driver":"selected_protocols_and_conversions","preprocessing":"OT_and_provider_setup"},"configuration_note":"Framework-level passive configuration; asynchronous execution in the code is not an asynchronous-network adversarial guarantee.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Why include a framework row","content":"It binds the paper's stated security model to the mechanisms realized by the implementation, while the immutable repository remains a separate object."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-MOTION-PASSIVE"},{"id":"MPC-CONTRIB-2021-THREE-HALVES","type":"contribution","title":"Three-Halves garbles a Free-XOR-compatible AND gate in 1.5λ + 5 bits","subtitle":"Three Halves Make a Whole? Beating the Half-Gates Lower Bound for Garbled Circuits","status":"published","evidence":"fulltext_checked","year":2021,"venue":"CRYPTO 2021","primaryUrl":"https://eprint.iacr.org/2021/749","summary":"RR21 constructs garbling for general Boolean circuits with free XOR gates and 1.5λ + 5 bits per AND gate using slicing and dicing, under the RTCCR hash assumption in Theorem 3. A gate-hiding variant costs 1.5λ + 10 bits per non-free gate; both have leading coefficient 1.5.","tags":["atomic-contribution","catalog_only","free-xor","garbled-circuit-efficiency","garbling","gate_cost_reduction","three-halves"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2021-THREE-HALVES","paper_id":"MPC-PAPER-2021-THREE-HALVES","year":2021,"title":"Three-Halves garbles a Free-XOR-compatible AND gate in 1.5λ + 5 bits","claim_slug":"three-halves-composable-free-xor-and","contribution_kind":"optimization","contribution_role":"gate_cost_reduction","statement":"RR21 constructs garbling for general Boolean circuits with free XOR gates and 1.5λ + 5 bits per AND gate using slicing and dicing, under the RTCCR hash assumption in Theorem 3. A gate-hiding variant costs 1.5λ + 10 bits per non-free gate; both have leading coefficient 1.5.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Half-gates attained two ciphertexts per AND gate and was optimal in the earlier linear-garbling model; smaller isolated gates did not preserve the input/output correlation needed for composition.","technical_delta":"Slicing labels and randomizing control information escapes the linear model while preserving the global Free-XOR offset across gates.","significance_at_publication":"The result reduced composable AND-gate communication and sharpened the question of optimality in broader symmetric-key models.","narrative":"Half-gates reduced communication to two ciphertexts per AND gate while keeping XOR gates free. Its matching lower bound applied to a linear model, not every possible use of symmetric cryptography. Rosulek and Roy step outside that model by slicing wire labels and randomizing the evaluator's control information. Unlike earlier smaller isolated gates, their output labels retain the correlation needed to continue evaluating an arbitrary circuit. The result is a concrete gate-size improvement, not a universal reduction in local computation or complete protocol cost. Their optimality question subsequently motivated broader lower-bound models."},"source_locator":{"dossier_section":"MPC-PAPER-2021-THREE-HALVES § Atomic contribution","primary_source":"ePrint 2021/749, §1.1 (p. 2), §5.4 Theorem 3 (pp. 18–21), §6.1 (pp. 22–23), §8 (p. 25); PDF page numbers match printed pages","primary_source_url":"https://eprint.iacr.org/2021/749.pdf","status":"section_checked"},"qualifiers":["λ here is the manuscript's κ; XOR gates remain free and labels retain the common global offset.","The theorem uses randomized tweakable circular correlation robustness (RTCCR), not an arbitrary PRF assumption.","Gate-hiding and ordinary AND variants differ in their constant additive control cost."],"limitations":["The 1.5λ term is an upper bound achieved by this construction, not a universal lower bound.","Input encoding, output decoding, OT, and malicious-security enforcement are not included in a per-AND gate size."],"facet_status":"normalized","facets":{"task":["garbled-circuit-efficiency"],"mechanism":["slicing-and-dicing"],"cost_coordinate":["garbled-gate-bits"],"gate_type":["and"]},"status":"published","evidence":"fulltext_checked","research_lenses":["garbled-circuit-efficiency"],"keywords":["three-halves","free-xor","garbling"],"work_id":"MPC-PAPER-2021-THREE-HALVES","role":"gate_cost_reduction","lens":"garbled-circuit-efficiency","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Composable Three-Halves garbling The upper-bound reference point for MPC-OP-005 is 1.5λ + O(1), including the gate-hiding variant where needed. It is not an end-to-end MPC bandwidth bound."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2021-THREE-HALVES"},{"id":"MPC-PAPER-2021-THREE-HALVES","type":"paper","title":"Three Halves Make a Whole? Beating the Half-Gates Lower Bound for Garbled Circuits","subtitle":"Mike Rosulek, Lawrence Roy · 2021","status":"published","evidence":"fulltext_checked","year":2021,"venue":"CRYPTO 2021","primaryUrl":"https://eprint.iacr.org/2021/749","summary":"Three Halves Make a Whole?","tags":["free-xor","garbling","gate-size","slicing-and-dicing"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2021-THREE-HALVES","title":"Three Halves Make a Whole? Beating the Half-Gates Lower Bound for Garbled Circuits","authors":["Mike Rosulek","Lawrence Roy"],"year":2021,"venue":"CRYPTO 2021","citation_key":"RR21","versions":["IACR ePrint 2021/749 manuscript dated 2021-06-03","CRYPTO 2021"],"primary_url":"https://eprint.iacr.org/2021/749","status":"published","evidence":"fulltext_checked","keywords":["garbling","free-xor","slicing-and-dicing","gate-size"],"contribution_ids":["MPC-CONTRIB-2021-THREE-HALVES"]},"sections":[{"heading":"Overview","content":"Three Halves Make a Whole?"},{"heading":"Atomic contribution","content":"MPC-CONTRIB-2021-THREE-HALVES records the composable Free-XOR-compatible construction. The reviewed manuscript's §1.1 (p. 2), §5.4 Theorem 3 (pp. 18–21), and §6.1 (pp. 22–23) specify its size and hash assumption. Garbled-gate size does not include the entire 2PC protocol."},{"heading":"Open-question locators","content":"Section 8, “Optimality” (p. 25), asks whether the 1.5κ cost is optimal beyond the earlier linear model and identifies Minicrypt as a natural setting. MPC-OP-005 keeps a narrower residual after the JRR25 lower bound; it does not assert that every variant of RR21's question remains open. Its separate computation-cost and privacy-free questions are not automatically admitted by this intake."},{"heading":"Version boundary","content":"The publication year is 2021, not the 2022 date mistakenly used for RR21 in the JRR25 abstract. This review checks statements and model boundaries, not an independent verification of the complete security proof or implementation."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2021-THREE-HALVES"},{"id":"MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL","type":"contribution","title":"Four-round statistical MPC with GOD and exponential depth-dependent work","subtitle":"The Round Complexity of Statistical MPC with Optimal Resiliency","status":"published","evidence":"fulltext_checked","year":2023,"venue":"STOC 2023","primaryUrl":"https://eprint.iacr.org/2023/418","summary":"Every functionality represented by a Boolean circuit of size S and depth D has a four-round statistically secure MPC protocol with GOD against static active rushing unbounded corruption of t < n/2 parties, with error 2^(-κ) and running time polynomial in κ, 2^n, S and 2^D, in the source's secure-channel and broadcast model.","tags":["GOD","atomic-contribution","catalog_only","depth-dependence","four-round","generality-feasibility","network-delivery","round-communication","statistical-security","theorem"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL","paper_id":"MPC-PAPER-2023-AKP","year":2023,"title":"Four-round statistical MPC with GOD and exponential depth-dependent work","claim_slug":"four-round-statistical-mpc-depth-dependent-work","contribution_kind":"research_result","contribution_role":"theorem","statement":"Every functionality represented by a Boolean circuit of size S and depth D has a four-round statistically secure MPC protocol with GOD against static active rushing unbounded corruption of t < n/2 parties, with error 2^(-κ) and running time polynomial in κ, 2^n, S and 2^D, in the source's secure-channel and broadcast model.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"General statistical MPC at the honest-majority threshold was feasible, and four rounds were necessary, but the matching round upper bound was not known.","technical_delta":"The construction attains four rounds while retaining statistical security and GOD; its running time remains exponential in n and circuit depth.","significance_at_publication":"The exact interaction bound is separated from the still-open efficiency of constant-round information-theoretic general computation.","narrative":"Statistical MPC already allowed an honest majority to compute general functions with guaranteed output delivery, but its exact number of rounds remained unsettled. Applebaum, Kachlon and Patra achieve the four-round bound for general functionalities. The result is about interaction, not polynomial efficiency: its work is polynomial in the circuit size but exponential in circuit depth and the number of participants. Keeping those dependencies visible separates a resolved round-feasibility question from the remaining task of making constant-round information-theoretic computation efficient. The paper explicitly notes that eliminating the depth dependence is open even under much weaker, passive corruption conditions."},"source_locator":{"dossier_section":"MPC-PAPER-2023-AKP § Atomic contribution","primary_source":"ePrint 2023/418 revision 2025-06-17, §1 model (p. 5), §1.1.3 and Theorem 1.5 with following discussion and footnote 3 (p. 8)","primary_source_url":"https://eprint.iacr.org/2023/418.pdf","status":"theorem_checked"},"qualifiers":["Static active rushing computationally unbounded adversary; t < n/2.","Secure point-to-point channels and broadcast; four rounds in that model.","Running time poly(κ, 2^n, S, 2^D); statistical error 2^(-κ)."],"limitations":["This is not polynomial-time MPC for arbitrary polynomial-size circuits or growing n.","The NC¹ efficiency discussion has a qualified extension via secure reductions from log space; it is not a universal impossibility outside NC¹.","No adaptive-corruption or practical-performance claim is admitted."],"facet_status":"normalized","facets":{"task":["general-mpc"],"adversary_behavior":["malicious"],"corruption_timing":["static"],"majority_regime":["honest-majority"],"network_model":["synchronous-private-channels","broadcast"],"output_guarantee":["guaranteed-output-delivery"],"security":["statistical"]},"status":"published","evidence":"fulltext_checked","research_lenses":["generality-feasibility","round-communication","network-delivery"],"keywords":["four-round","statistical-security","GOD","depth-dependence"],"work_id":"MPC-PAPER-2023-AKP","role":"theorem","lens":"generality-feasibility","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Four-round statistical MPC with depth-dependent work The source's positive theorem settles the interaction count without settling the efficiency target in MPC-OP-001. This record does not create research-map membership or a technical lineage edge."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL"},{"id":"MPC-IMPL-2023-MOTION-FFA76F8","type":"implementation","title":"MOTION at ffa76f8","subtitle":"2023","status":"reported","evidence":"primary_source_checked","year":2023,"venue":null,"primaryUrl":"https://github.com/encryptogroup/MOTION/tree/ffa76f82ace55c7ba49c0c89d97246b8827c52a9","summary":"The code schedules work asynchronously; this does not upgrade the protocol to asynchronous-network security.","tags":["implementation","mixed-protocol","motion"],"metadata":{"dossier_type":"implementation","id":"MPC-IMPL-2023-MOTION-FFA76F8","title":"MOTION at ffa76f8","year":2023,"paper_ids":["MPC-PAPER-2020-MOTION"],"configuration_ids":["MPC-PROTOCOL-MOTION-PASSIVE"],"artifact":{"repository":"https://github.com/encryptogroup/MOTION","commit":"ffa76f82ace55c7ba49c0c89d97246b8827c52a9","commit_url":"https://github.com/encryptogroup/MOTION/tree/ffa76f82ace55c7ba49c0c89d97246b8827c52a9","version":"commit-ffa76f8"},"artifact_type":"open-source modular MPC framework","language":"C++","backend":"Boolean GMW, arithmetic GMW, BMR, and conversion providers in the pinned tree","availability":"public repository","maturity":"research framework","configuration_binding":"paper-aligned passive full-threshold framework configuration","realized_stack":{"representation":"mixed Boolean and arithmetic circuit graph","value_encoding":"protocol-provider-specific shares and garbled values","evaluation_protocol":"GMW and garbled providers","correlation_source":"OT extension and provider-specific setup","active_security_enforcement":"passive only in the paper configuration","conversion_layer":"explicit mixed-protocol conversion gates","output_recovery_layer":"reconstruction with failure/transport abort"},"benchmark_eligible":true,"benchmark_eligibility_note":"Requires a fixed provider graph, party count, build profile, host/network, workload, and setup accounting.","status":"reported","evidence":"primary_source_checked","evidence_status":"repository_revision_checked","source_locator":"pinned repository README and src/motioncore providers","primary_url":"https://github.com/encryptogroup/MOTION/tree/ffa76f82ace55c7ba49c0c89d97246b8827c52a9","tags":["implementation","motion","mixed-protocol"]},"sections":[{"heading":"Boundary","content":"The code schedules work asynchronously; this does not upgrade the protocol to asynchronous-network security."}],"sourcePath":"data/mpc-catalog.json#MPC-IMPL-2023-MOTION-FFA76F8"},{"id":"MPC-PAPER-2023-AKP","type":"paper","title":"The Round Complexity of Statistical MPC with Optimal Resiliency","subtitle":"Benny Applebaum, Eliran Kachlon, Arpita Patra · 2023","status":"published","evidence":"fulltext_checked","year":2023,"venue":"STOC 2023","primaryUrl":"https://eprint.iacr.org/2023/418","summary":"The Round Complexity of Statistical MPC with Optimal Resiliency","tags":["constant-round","guaranteed-output-delivery","statistical-security"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2023-AKP","title":"The Round Complexity of Statistical MPC with Optimal Resiliency","authors":["Benny Applebaum","Eliran Kachlon","Arpita Patra"],"year":2023,"venue":"STOC 2023","versions":["STOC 2023 conference paper","IACR ePrint 2023/418 full version revised 2025-06-17"],"primary_url":"https://eprint.iacr.org/2023/418","status":"published","evidence":"fulltext_checked","keywords":["statistical-security","constant-round","guaranteed-output-delivery"],"contribution_ids":["MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL"]},"sections":[{"heading":"Overview","content":"The Round Complexity of Statistical MPC with Optimal Resiliency"},{"heading":"Version and bibliographic notes","content":"The ePrint record identifies the STOC 2023 publication and a full-version revision dated 2025-06-17. This intake checks the introduction's model, §1.1.3 and Theorem 1.5, including the following efficiency limitation, on numbered PDF page 8. It does not constitute an independent audit of the entire security proof."},{"heading":"Atomic contribution","content":"MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL records four-round general MPC with statistical security and GOD, preserving the exponential dependence on circuit depth and number of parties. It is a catalog-only result supporting the distinction between round feasibility and polynomial efficiency in MPC-OP-001."},{"heading":"Limitations and unresolved review","content":"The paper contains separate signature, verifiable-sharing and single-input functionality contributions that this intake does not split into records. Its explicit residual question concerns eliminating exponential depth dependence; it is not a claim that four-round information-theoretic MPC remains impossible."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2023-AKP"},{"id":"MPC-BENCH-2024-HPMPC-AND","type":"benchmark_run","title":"HP-MPC reported batched AND-gate throughput","subtitle":"2024","status":"reported","evidence":"primary_source_checked","year":2024,"venue":null,"primaryUrl":"https://eprint.iacr.org/2024/386","summary":"This row preserves a striking source claim while refusing to turn it into a cross-framework leaderboard. The paper experiment and the later immutable repository revision are explicitly distinguished.","tags":["benchmark","hp-mpc","non-comparable","throughput"],"metadata":{"dossier_type":"benchmark_run","id":"MPC-BENCH-2024-HPMPC-AND","title":"HP-MPC reported batched AND-gate throughput","year":2024,"implementation_id":"MPC-IMPL-2026-HPMPC-155C935","configuration_id":"MPC-PROTOCOL-HPMPC-3PC","artifact_commit":"155c93572d747b527a6452c9ad8f24eb3b776667","compatibility_key":{"configuration":"paper's implemented honest-majority 3PC/4PC protocol set; this row is bound to the displayed 3PC configuration for navigation","implementation_version":"repository snapshot 155c935; paper experiments predate this snapshot","party_profile":"three-party passive row; paper throughput statement spans several implemented protocols","security_model":"honest-majority; protocol-specific passive or malicious setting","workload":"large batch of independent Boolean AND gates","circuit_domain":"Boolean circuit over F2","problem_size":"batch size and vector width are protocol/figure dependent; consult paper Section 5","hardware":"paper benchmark servers; exact normalized host profile not transcribed into this atlas","network":"25 Gbit/s LAN for the headline observation","thread_count":"paper configuration; not normalized here","software_toolchain":"HP-MPC paper artifact lineage; pinned repository is a later revision","compiler_flags":"protocol and vectorization macros are required; exact headline-run flags not normalized","preprocessing_accounting":"paper-specific; online and total measurements must not be conflated","metric_definition":"steady-state batched gate throughput reported by the paper","evidence_state":"paper_reported_not_reproduced_and_artifact_revision_mismatch"},"metrics":{"and_gate_throughput":"more than 25 billion AND gates per second for each of six reported protocols on the 25-Gbit/s setup","arithmetic_multiplication_throughput":"more than one billion 32-bit multiplications per second for five of six implementations"},"comparable":false,"comparison_group":"none","non_comparability_reasons":["The pinned repository revision postdates the paper experiment.","The headline statement aggregates several protocol and security configurations.","Exact host, thread, batch, vector-width, and phase-accounting coordinates are not normalized in this record."],"status":"reported","evidence":"primary_source_checked","evidence_status":"reported_not_reproduced","source_locator":"Paper abstract, Contributions, and Section 5; pinned repository README for later artifact identity","primary_url":"https://eprint.iacr.org/2024/386","tags":["benchmark","hp-mpc","throughput","non-comparable"]},"sections":[{"heading":"Interpretation","content":"This row preserves a striking source claim while refusing to turn it into a cross-framework leaderboard. The paper experiment and the later immutable repository revision are explicitly distinguished."}],"sourcePath":"data/mpc-catalog.json#MPC-BENCH-2024-HPMPC-AND"},{"id":"MPC-CONTRIB-2024-FOLEAGE-F4","type":"contribution","title":"F4-OLE PCGs give near-linear communication for multiparty Boolean triples","subtitle":"FOLEAGE: F4OLE-Based Multi-Party Computation for Boolean Circuits","status":"published","evidence":"primary_source_checked","year":2024,"venue":"ASIACRYPT 2024","primaryUrl":"https://eprint.iacr.org/2024/429","summary":"FOLEAGE constructs multiparty Boolean-triple preprocessing from an F4-OLE pseudorandom correlation generator, with communication near linear in the number of parties times the number of triples plus lower-order seed terms.","tags":["atomic-contribution","backbone","boolean-triples","correlation_generator","f4ole","foleage","implementation-systems","pcg","preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2024-FOLEAGE-F4","paper_id":"MPC-PAPER-2024-FOLEAGE","year":2024,"title":"F4-OLE PCGs give near-linear communication for multiparty Boolean triples","claim_slug":"foleage-f4ole-boolean-triple-preprocessing","contribution_kind":"optimization","contribution_role":"correlation_generator","statement":"FOLEAGE constructs multiparty Boolean-triple preprocessing from an F4-OLE pseudorandom correlation generator, with communication near linear in the number of parties times the number of triples plus lower-order seed terms.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Silent PCGs reduced communication for correlation expansion, but efficient actively secure multiparty preprocessing over the binary field retained costly party-scaling and correlation-conversion bottlenecks.","technical_delta":"FOLEAGE specializes PCG machinery to F4-OLE and derives Boolean multiplication triples with communication dominated by the party-by-triple term, supplemented by lower-order seed setup.","significance_at_publication":"It advanced the concrete and asymptotic preprocessing frontier for multiparty Boolean circuits without reclassifying the optimization as merely an implementation.","narrative":"Pseudorandom correlation generators showed how short seeds could replace large communicated correlation batches, but multiparty Boolean preprocessing still had to manage active security and unfavorable scaling across parties. FOLEAGE builds its preprocessing around a PCG for multiplication over the four-element field and converts that structure into Boolean multiplication triples. The normalized cost is near linear in parties times generated triples, with additional lower-order seed terms stated separately. The atomic contribution is this F4-OLE-based correlation protocol and its communication boundary, not the accompanying code alone. It mattered because the PCG line reached a sharper multiparty binary-MPC design point suitable for implementation study."},"source_locator":{"dossier_section":"MPC-PAPER-2024-FOLEAGE § Atomic contribution","primary_source":"Abstract and construction overview","primary_source_url":"https://eprint.iacr.org/2024/429","status":"section_checked"},"qualifiers":["multiparty Boolean triples","F4-OLE PCG","preprocessing communication"],"limitations":["lower-order seed costs and local work remain","exact concrete gains depend on party count and implementation context"],"facet_status":"normalized","facets":{"task":["boolean-preprocessing-efficiency"],"mechanism":["f4ole-pcg","triple-generation"],"correlation_type":["boolean-multiplication-triples"],"cost_coordinate":["communication"],"party_model":["multiparty"]},"status":"published","evidence":"primary_source_checked","research_lenses":["preprocessing-correlation","round-communication","implementation-systems"],"keywords":["foleage","f4ole","pcg","boolean-triples"],"work_id":"MPC-PAPER-2024-FOLEAGE","role":"correlation_generator","lens":"preprocessing-correlation","visibility":"backbone"},"sections":[{"heading":"Overview","content":"FOLEAGE preprocessing The systems venue and artifact presence do not change this object's role as a protocol optimization contribution."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2024-FOLEAGE-F4"},{"id":"MPC-CONTRIB-2024-HPMPC-NETWORK","type":"contribution","title":"Topology-aware Trio and Quad tolerate all but two low-bandwidth links","subtitle":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","status":"published","evidence":"primary_source_checked","year":2024,"venue":"USENIX Security 2024","primaryUrl":"https://eprint.iacr.org/2024/386","summary":"HP-MPC redistributes Trio and Quad communication so all but two links may have arbitrarily low bandwidth and all but one may have arbitrarily high latency, without increasing the protocols' total per-multiplication communication.","tags":["active-security","atomic-contribution","heterogeneous-network","honest-majority","hp-mpc","implementation-systems","network-delivery","protocol_and_system_optimization","reviewed_related","round-communication","topology-aware-scheduling"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2024-HPMPC-NETWORK","paper_id":"MPC-PAPER-2024-HPMPC","year":2024,"title":"Topology-aware Trio and Quad tolerate all but two low-bandwidth links","claim_slug":"hpmc-heterogeneous-link-protocol-codesign","contribution_kind":"optimization","contribution_role":"protocol_and_system_optimization","statement":"HP-MPC redistributes Trio and Quad communication so all but two links may have arbitrarily low bandwidth and all but one may have arbitrarily high latency, without increasing the protocols' total per-multiplication communication.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Honest-majority protocols usually optimized total communication or assumed comparable links, so one weak path could throttle an otherwise low-bandwidth multiplication protocol.","technical_delta":"The paper gives communication variants that route latency-critical and bulk messages over different links while retaining the three- and five-element totals of Trio and Quad.","significance_at_publication":"It made link topology an explicit protocol-design coordinate rather than leaving heterogeneous-network handling to an implementation after the security protocol was fixed.","narrative":"Low total communication does not guarantee high throughput when a protocol puts latency-critical or bulk traffic on the weakest links. HP-MPC treats that placement as part of protocol design. Its Trio and Quad variants redirect messages so that all but two links may be arbitrarily bandwidth-limited and all but one may have arbitrarily high latency, while retaining the paper's total communication per multiplication. The mapped contribution is this topology-aware scheduling boundary across the exact passive three-party and malicious four-party configurations. Vectorized local work, the complete masked-sharing protocols, the repository revision, and reported throughput are recorded separately rather than folded into one generic claim of speed."},"source_locator":{"dossier_section":"MPC-PAPER-2024-HPMPC § Atomic contribution","primary_source":"Abstract; Contributions; heterogeneous-network protocol variants","primary_source_url":"https://eprint.iacr.org/2024/386","status":"section_checked"},"qualifiers":["three-party passive Trio","four-party one-corruption malicious Quad","ring arithmetic","all but two low-bandwidth links","all but one high-latency link"],"limitations":["security and message schedules differ between Trio and Quad","the weak-link claim is protocol-structural rather than a portable throughput number","disconnection and availability are not implied"],"facet_status":"normalized","facets":{"task":["heterogeneous-network-efficiency"],"mechanism":["topology-aware-communication-scheduling"],"network_model":["heterogeneous-links"],"party_model":["three-party","four-party"],"adversary_behavior":["passive-3pc","malicious-4pc"],"contribution_stage":["implementation-aware-protocol-codesign"]},"status":"published","evidence":"primary_source_checked","research_lenses":["round-communication","network-delivery","active-security","implementation-systems"],"keywords":["hp-mpc","heterogeneous-network","topology-aware-scheduling","honest-majority"],"work_id":"MPC-PAPER-2024-HPMPC","role":"protocol_and_system_optimization","lens":"round-communication","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"HP-MPC network-aware scheduling The contribution is linked to, but not identified with, the implementation version and benchmark observation."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2024-HPMPC-NETWORK"},{"id":"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK","type":"contribution","title":"Trio and Quad reduce per-gate local arithmetic without extra communication","subtitle":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","status":"published","evidence":"primary_source_checked","year":2024,"venue":"USENIX Security 2024","primaryUrl":"https://eprint.iacr.org/2024/386","summary":"By reducing correlations among party shares, Trio and Quad require up to half as many basic local instructions per gate as the paper's related baselines while retaining total communication of three and five ring elements per multiplication.","tags":["atomic-contribution","implementation-systems","implementation_aware_protocol_optimization","local-computation","protocol-optimization","quad","reviewed_related","round-communication","trio"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK","paper_id":"MPC-PAPER-2024-HPMPC","year":2024,"title":"Trio and Quad reduce per-gate local arithmetic without extra communication","claim_slug":"trio-quad-reduced-local-instructions","contribution_kind":"optimization","contribution_role":"implementation_aware_protocol_optimization","statement":"By reducing correlations among party shares, Trio and Quad require up to half as many basic local instructions per gate as the paper's related baselines while retaining total communication of three and five ring elements per multiplication.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Communication-efficient honest-majority protocols could still become computation-bound because each secure gate expanded into many local additions, multiplications, hashes, or pseudorandom values.","technical_delta":"The revised masked-sharing correlations remove local arithmetic from the multiplication path without paying additional communicated ring elements in the three- or four-party configuration.","significance_at_publication":"It made per-gate instruction count a protocol-level optimization target alongside rounds and communication, before any compiler or hardware measurement was considered.","narrative":"Honest-majority MPC papers often compared communicated elements while treating local share arithmetic as negligible. At the throughput reached by batched ring and Boolean evaluation, however, those additions and multiplications can become the bottleneck. HP-MPC changes the correlations in Trio and Quad's masked shares so their gate protocols require up to half the basic local instructions of the related baselines discussed in the paper, without increasing the three- and five-element communication totals. This is a protocol-level efficiency result. Vectorization helps realize it, but the pinned implementation and the billion-gate measurements are separate evidence objects with their own version, hardware, network, and batch boundaries."},"source_locator":{"dossier_section":"MPC-PAPER-2024-HPMPC § Atomic contributions","primary_source":"Abstract; Contributions; protocol operation counts in Tables 1 and 13","primary_source_url":"https://eprint.iacr.org/2024/386","status":"section_checked"},"qualifiers":["basic local additions and multiplications per gate","comparison to the paper's related baselines","no added total per-multiplication communication","exact three- and four-party configurations"],"limitations":["the up-to-half comparison is operation- and baseline-specific","wall-clock gains depend on implementation and workload","Trio and Quad have different security contracts"],"facet_status":"normalized","facets":{"task":["local-computation-efficiency"],"mechanism":["masked-sharing-correlation-redesign"],"cost_coordinate":["basic-local-instructions"],"party_model":["three-party","four-party"],"contribution_stage":["implementation-aware-protocol-optimization"]},"status":"published","evidence":"primary_source_checked","research_lenses":["round-communication","implementation-systems"],"keywords":["trio","quad","local-computation","protocol-optimization"],"work_id":"MPC-PAPER-2024-HPMPC","role":"implementation_aware_protocol_optimization","lens":"round-communication","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"Local-work optimization The normalized resource is per-gate local arithmetic, not unqualified speed or a portable framework-wide throughput ranking."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK"},{"id":"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","type":"contribution","title":"Trio and Quad use masked sharing at three and four parties","subtitle":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","status":"published","evidence":"primary_source_checked","year":2024,"venue":"USENIX Security 2024","primaryUrl":"https://eprint.iacr.org/2024/386","summary":"HP-MPC constructs Trio, a three-party protocol with one passive corruption, and Quad, a four-party protocol with one malicious corruption, using paper-specific masked-sharing semantics and total communication of three and five ring elements per multiplication respectively.","tags":["active-security","atomic-contribution","honest-majority","implementation-systems","masked-sharing","protocol_construction","quad","reviewed_related","round-communication","trio"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","paper_id":"MPC-PAPER-2024-HPMPC","year":2024,"title":"Trio and Quad use masked sharing at three and four parties","claim_slug":"trio-quad-masked-sharing-protocols","contribution_kind":"construction","contribution_role":"protocol_construction","statement":"HP-MPC constructs Trio, a three-party protocol with one passive corruption, and Quad, a four-party protocol with one malicious corruption, using paper-specific masked-sharing semantics and total communication of three and five ring elements per multiplication respectively.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Existing high-throughput honest-majority protocols already reached low communication, but their sharing correlations and local arithmetic left distinct computation and topology bottlenecks.","technical_delta":"Trio changes the masked shares held by the two online parties, while Quad adds a fourth party and compare-view checks to verify the resulting messages against one malicious corruption.","significance_at_publication":"The paper introduced two complete security-specific protocol configurations whose sharing semantics support its later local-work and heterogeneous-link optimizations.","narrative":"Prior three- and four-party ring protocols already had attractive communication totals, so HP-MPC did not present another generic replicated-sharing row. Trio changes which masked values and mask shares the online parties retain, arranging multiplication so input-dependent and input-independent errors can be corrected with three communicated ring elements. Quad builds on that sharing layout with a fourth party and compare-view checks, tolerating one malicious corruption with five elements per multiplication. This card records the two complete, security-specific protocol constructions. Their local-instruction savings, weak-link schedules, software revision, and measured throughput remain separate research or engineering objects."},"source_locator":{"dossier_section":"MPC-PAPER-2024-HPMPC § Atomic contributions","primary_source":"Contributions; Sections 3–5; Trio and Quad multiplication protocols","primary_source_url":"https://eprint.iacr.org/2024/386","status":"section_checked"},"qualifiers":["Trio has three parties and one passive corruption","Quad has four parties and one malicious corruption","ring arithmetic and Boolean variants","three and five total elements per multiplication"],"limitations":["the two configurations do not share one adversary contract","setup uses shared-key pseudorandom generation","communication totals do not by themselves imply the reported throughput"],"facet_status":"normalized","facets":{"task":["honest-majority-mpc"],"mechanism":["masked-sharing","compare-view-checks","shared-random-value-generation"],"party_model":["three-party","four-party"],"adversary_behavior":["passive-3pc","malicious-4pc"],"representation":["ring-sharing"]},"status":"published","evidence":"primary_source_checked","research_lenses":["active-security","round-communication","implementation-systems"],"keywords":["trio","quad","masked-sharing","honest-majority"],"work_id":"MPC-PAPER-2024-HPMPC","role":"protocol_construction","lens":"active-security","visibility":"reviewed_related"},"sections":[{"heading":"Overview","content":"Trio and Quad construction This card identifies the protocol pair without treating its systems realization or benchmark as part of the construction theorem."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED"},{"id":"MPC-PAPER-2024-FOLEAGE","type":"paper","title":"FOLEAGE: F4OLE-Based Multi-Party Computation for Boolean Circuits","subtitle":"Maxime Bombar, Dung Bui, Geoffroy Couteau et al. · 2024","status":"published","evidence":"primary_source_checked","year":2024,"venue":"ASIACRYPT 2024","primaryUrl":"https://eprint.iacr.org/2024/429","summary":"The paper has an IACR Results Reproduced artifact at https://artifacts.iacr.org/asiacrypt/2024/a8/; its measurements remain context-bound.","tags":["preprocessing-correlation","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2024-FOLEAGE","title":"FOLEAGE: F4OLE-Based Multi-Party Computation for Boolean Circuits","authors":["Maxime Bombar","Dung Bui","Geoffroy Couteau","Alain Couvreur","Clement Ducros","Sacha Servan-Schreiber"],"year":2024,"venue":"ASIACRYPT 2024","primary_url":"https://eprint.iacr.org/2024/429","status":"published","evidence":"primary_source_checked","keywords":["preprocessing-correlation","round-communication"],"contribution_ids":["MPC-CONTRIB-2024-FOLEAGE-F4"]},"sections":[{"heading":"Artifact","content":"The paper has an IACR Results Reproduced artifact at https://artifacts.iacr.org/asiacrypt/2024/a8/; its measurements remain context-bound."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2024-FOLEAGE"},{"id":"MPC-PAPER-2024-HPMPC","type":"paper","title":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","subtitle":"Christopher Harth-Kitzerow, Ajith Suresh, Yongqin Wang et al. · 2024","status":"published","evidence":"primary_source_checked","year":2024,"venue":"USENIX Security 2024","primaryUrl":"https://eprint.iacr.org/2024/386","summary":"Reported billion-gate throughput depends on protocol, vectorization, batch size, 25-Gbit/s hardware, and phase accounting; it is not a portable property of honest-majority MPC.","tags":["implementation-systems","network-delivery","round-communication"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2024-HPMPC","title":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","authors":["Christopher Harth-Kitzerow","Ajith Suresh","Yongqin Wang","Hossein Yalame","Georg Carle","Murali Annavaram"],"year":2024,"venue":"USENIX Security 2024","primary_url":"https://eprint.iacr.org/2024/386","status":"published","evidence":"primary_source_checked","keywords":["round-communication","implementation-systems","network-delivery"],"contribution_ids":["MPC-CONTRIB-2024-HPMPC-NETWORK","MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK"]},"sections":[{"heading":"Measurement boundary","content":"Reported billion-gate throughput depends on protocol, vectorization, batch size, 25-Gbit/s hardware, and phase accounting; it is not a portable property of honest-majority MPC."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2024-HPMPC"},{"id":"MPC-PROTOCOL-HPMPC-3PC","type":"protocol","title":"HP-MPC semi-honest ring 3PC","subtitle":"high throughput honest majority · 2024","status":"published","evidence":"primary_source_checked","year":2024,"venue":null,"primaryUrl":null,"summary":"The protocol row stores the construction; the >billion-gate observations belong to a specific implementation and environment.","tags":["implementation-systems","network-delivery","round-communication"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-HPMPC-3PC","title":"HP-MPC semi-honest ring 3PC","name":"HP-MPC 3PC","paper_ids":["MPC-PAPER-2024-HPMPC"],"claim_ids":["MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","MPC-CONTRIB-2024-HPMPC-NETWORK","MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK"],"year":2024,"protocol_family":"high_throughput_honest_majority","research_lenses":["round-communication","network-delivery","implementation-systems"],"tasks":["general_3pc","high_throughput_ring_arithmetic","heterogeneous_networks"],"properties":{"parties":"3","corruption_threshold":"1 passive corruption","majority_regime":"honest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_channels_with_heterogeneous_link_performance","setup":"pairwise_correlated_randomness","output_guarantee":"abort_on_disconnect","privacy_basis":"computational_seed_expansion_with_information_theoretic_sharing"},"stack":{"representation":["MPC-COMP-REP-ARITH-RING","MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-HPMPC-MASKED"],"evaluation_protocol":["MPC-COMP-EVAL-HPMPC-MASKED"],"correlation_source":["MPC-COMP-CORR-PAIRWISE"],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"multiplicative_depth_dependent","communication_driver":"three_elements_per_arithmetic_multiplication_in_reported_variant","preprocessing":"optional_interleaved_or_offline_masks"},"configuration_note":"Paper's novel semi-honest 3PC family; benchmark identity additionally fixes the HP-MPC artifact and network.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Measurement boundary","content":"The protocol row stores the construction; the >billion-gate observations belong to a specific implementation and environment."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-HPMPC-3PC"},{"id":"MPC-PROTOCOL-HPMPC-4PC","type":"protocol","title":"HP-MPC malicious ring 4PC","subtitle":"high throughput honest majority · 2024","status":"published","evidence":"primary_source_checked","year":2024,"venue":null,"primaryUrl":null,"summary":"Party count and adversary behavior change together, so the 3PC and 4PC variants remain distinct configurations.","tags":["active-security","implementation-systems","round-communication"],"metadata":{"dossier_type":"construction","id":"MPC-PROTOCOL-HPMPC-4PC","title":"HP-MPC malicious ring 4PC","name":"HP-MPC 4PC","paper_ids":["MPC-PAPER-2024-HPMPC"],"claim_ids":["MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","MPC-CONTRIB-2024-HPMPC-NETWORK","MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK"],"year":2024,"protocol_family":"high_throughput_honest_majority","research_lenses":["active-security","round-communication","implementation-systems"],"tasks":["general_4pc","malicious_ring_arithmetic","heterogeneous_networks"],"properties":{"parties":"4","corruption_threshold":"1 active corruption","majority_regime":"honest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_channels_with_heterogeneous_link_performance","setup":"pairwise_correlated_randomness","output_guarantee":"security_with_abort","privacy_basis":"computational_seed_expansion_with_information_theoretic_sharing"},"stack":{"representation":["MPC-COMP-REP-ARITH-RING","MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-HPMPC-MASKED"],"evaluation_protocol":["MPC-COMP-EVAL-HPMPC-MASKED"],"correlation_source":["MPC-COMP-CORR-PAIRWISE"],"active_security_enforcement":["MPC-COMP-ACT-HPMPC4"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"multiplicative_depth_dependent","communication_driver":"five_elements_per_arithmetic_multiplication_in_reported_variant","preprocessing":"optional_interleaved_or_offline_masks"},"configuration_note":"Paper's malicious four-party, one-corruption configuration; it is not the same security row as the 3PC protocol.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked"},"sections":[{"heading":"Security note","content":"Party count and adversary behavior change together, so the 3PC and 4PC variants remain distinct configurations."}],"sourcePath":"data/mpc-catalog.json#MPC-PROTOCOL-HPMPC-4PC"},{"id":"MPC-CONTRIB-2025-CDPP-SIMD-GOD","type":"contribution","title":"Statistical GOD with constant communication overhead across Θ(n^7) SIMD evaluations","subtitle":"Statistical MPC with a Constant Communication Overhead","status":"preprint","evidence":"fulltext_checked","year":2025,"venue":"IACR ePrint 2025/1555","primaryUrl":"https://eprint.iacr.org/2025/1555","summary":"With n = 3t+1 and synchronous private authenticated channels, the current CDPP manuscript gives statistically secure MPC with GOD and O(D) expected rounds against malicious adaptive unbounded corruption; for Θ(n^7) parallel evaluations of a circuit with c_M multiplication gates, one field-element input per party and one common output, total communication is O(c_M n^7+n^8) field elements.","tags":["GOD","SIMD","atomic-contribution","catalog_only","constant-overhead","network-delivery","packing","preprocessing-correlation","round-communication","statistical-security","theorem"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2025-CDPP-SIMD-GOD","paper_id":"MPC-PAPER-2025-CDPP","year":2025,"title":"Statistical GOD with constant communication overhead across Θ(n^7) SIMD evaluations","claim_slug":"statistical-god-constant-overhead-large-simd","contribution_kind":"research_result","contribution_role":"theorem","statement":"With n = 3t+1 and synchronous private authenticated channels, the current CDPP manuscript gives statistically secure MPC with GOD and O(D) expected rounds against malicious adaptive unbounded corruption; for Θ(n^7) parallel evaluations of a circuit with c_M multiplication gates, one field-element input per party and one common output, total communication is O(c_M n^7+n^8) field elements.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Low-communication statistical protocols could use abort or incur additional round costs; combining robustness with O(D) rounds required more expensive primitives.","technical_delta":"Robust authenticated packed sharing, VSS and degree reduction support GOD with constant per-gate amortized communication across a large SIMD batch.","significance_at_publication":"Low amortized communication and guaranteed completion are obtained together, leaving general single-circuit computation and smaller batch sizes as explicit residuals.","narrative":"Detecting a malformed sharing can permit a protocol to abort, but guaranteed output delivery requires the computation to survive that behavior. Choudhury, Damgård, Patil and Patra build robust primitives for packed secret sharing and use them in statistical MPC. The current manuscript combines O(D) expected rounds with constant amortized communication at n = 3t+1. That amortization requires Θ(n^7) evaluations of the same circuit in parallel, and its theorem also includes an n^8 input/output term. The result therefore approaches the low-communication GOD target from the batching direction; removing the large SIMD requirement remains a separate question."},"source_locator":{"dossier_section":"MPC-PAPER-2025-CDPP § Atomic contribution","primary_source":"ePrint 2025/1555 revision 2026-05-22, §1 adversary model (p. 1), §1.1 Theorem 1.1 (p. 2), §3 field/network convention (p. 11), §7 Theorem 7.1 and footnotes 9–10 (pp. 23–24)","primary_source_url":"https://eprint.iacr.org/2025/1555.pdf","status":"theorem_checked"},"qualifiers":["n = 3t+1; malicious adaptive rushing computationally unbounded adversary; statistical security with GOD.","Synchronous private authenticated channels; broadcasts are included or emulated with constant expected round protocols.","Θ(n^7) independent SIMD evaluations; O(c_M n^7+n^8) field elements, not O(c_M) total for one execution.","Source field convention has |F| >= 2^κ and symbols of O(κ) bits for polynomial-size circuits and party counts; constant overhead is in field elements, not constant bits independent of security."],"limitations":["O(D) is an expected round bound, not a deterministic worst-case bound.","General-circuit-to-SIMD compilation introduces a log |C| size factor and potentially a depth-dependent additive term for irregular circuits.","The current revision is synchronous; an older abstract's asynchronous claims are not admitted.","No constant local-computation overhead or measured practicality claim is admitted."],"facet_status":"normalized","facets":{"task":["general-mpc"],"mechanism":["packed-secret-sharing","verifiable-secret-sharing","robust-degree-reduction"],"adversary_behavior":["malicious"],"corruption_timing":["adaptive"],"majority_regime":["honest-majority"],"network_model":["synchronous-private-channels"],"output_guarantee":["guaranteed-output-delivery"],"security":["statistical"]},"status":"preprint","evidence":"fulltext_checked","research_lenses":["round-communication","network-delivery","preprocessing-correlation"],"keywords":["statistical-security","GOD","SIMD","constant-overhead","packing"],"work_id":"MPC-PAPER-2025-CDPP","role":"theorem","lens":"round-communication","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Statistical GOD with large-batch amortization The unit of comparison is the full SIMD workload, including the n^8 term in Theorem 7.1, not just an online multiplication in isolation. The source's §1.3 asks to reduce that batch or handle a general circuit without its cost."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2025-CDPP-SIMD-GOD"},{"id":"MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND","type":"contribution","title":"A 1.5λ lower bound for strongly secure Free-XOR AND gates with restricted evaluator queries","subtitle":"Lower Bounds for Garbled Circuits from Shannon-Type Information Inequalities","status":"published","evidence":"fulltext_checked","year":2025,"venue":"CRYPTO 2025","primaryUrl":"https://eprint.iacr.org/2025/876","summary":"JRR25 Theorem 26 gives a 1.5λ − negl(λ) garbled-gate size lower bound for the class of AND gates with input/output bit flips, under Definition 12 input-to-output syntax, λ-bit labels with the common Free-XOR offset, Definition 16 strong security, and non-adaptive coordinated evaluator queries to the random oracle.","tags":["atomic-contribution","catalog_only","free-xor","garbled-circuit-efficiency","garbling","lower-bound","minicrypt","theorem"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND","paper_id":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","year":2025,"title":"A 1.5λ lower bound for strongly secure Free-XOR AND gates with restricted evaluator queries","claim_slug":"free-xor-and-lower-bound-coordinated-nonadaptive","contribution_kind":"research_result","contribution_role":"theorem","statement":"JRR25 Theorem 26 gives a 1.5λ − negl(λ) garbled-gate size lower bound for the class of AND gates with input/output bit flips, under Definition 12 input-to-output syntax, λ-bit labels with the common Free-XOR offset, Definition 16 strong security, and non-adaptive coordinated evaluator queries to the random oracle.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Three-Halves escaped the earlier linear-garbling bound; later lower bounds still imposed restrictions on algebraic representations.","technical_delta":"Model the joint distribution of labels, gate data and oracle responses using Shannon-type information inequalities, restricting oracle-query behavior rather than the internal algebra.","significance_at_publication":"The result matches the leading Three-Halves cost in a broader but still explicitly bounded single-gate model.","narrative":"Three-Halves showed why optimality in a fixed algebraic template need not imply optimality for garbling generally. Januzelli, Rosulek and Roy instead derive information inequalities from a single gate's security and oracle behavior. Their theorem matches the Three-Halves leading cost without prescribing the internal algebra of the algorithms. It still requires non-adaptive evaluator queries and knowledge of which input evaluations share each query, together with a stronger security game and composable label correlations. Those conditions are part of the result, not technical details that can be dropped when comparing a different construction."},"source_locator":{"dossier_section":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS § Atomic contribution","primary_source":"ePrint 2025/876, §1.1 (pp. 3–4), Definitions 12–14 (pp. 9–10), §3.3 and Definition 16 (pp. 11–12), Theorem 26 and Corollary 27 (p. 23); PDF page numbers match printed pages","primary_source_url":"https://eprint.iacr.org/2025/876.pdf","status":"theorem_checked"},"qualifiers":["Minicrypt adversaries are computationally unbounded with polynomially many random-oracle queries.","The garbler receives input labels and chooses output labels; all labels have λ bits and the same Free-XOR correlation.","Strong security reveals complementary labels only after the adversary loses oracle access.","Non-adaptivity and coordination restrict Ev, not Gb."],"limitations":["Does not cover adaptive or uncoordinated evaluator oracle queries.","Does not establish a whole-circuit lower bound for non-projective or layer-batched encodings.","Strong security is not silently replaced by ordinary garbling security."],"facet_status":"normalized","facets":{"task":["garbled-circuit-efficiency"],"mechanism":["information-inequalities"],"cost_coordinate":["garbled-gate-bits"],"gate_type":["and"],"query_model":["non-adaptive","coordinated"]},"status":"published","evidence":"fulltext_checked","research_lenses":["garbled-circuit-efficiency"],"keywords":["lower-bound","free-xor","minicrypt","garbling"],"work_id":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","role":"theorem","lens":"garbled-circuit-efficiency","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Model-scoped garbled-gate lower bound This is the partial lower-bound answer to MPC-OP-005. It rules out improvements inside its query model, not the relaxations asked about in that problem."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND"},{"id":"MPC-PAPER-2025-CDPP","type":"paper","title":"Statistical MPC with a Constant Communication Overhead","subtitle":"Ashish Choudhury, Ivan Damgård, Shravani Patil et al. · 2025","status":"preprint","evidence":"fulltext_checked","year":2025,"venue":"IACR ePrint 2025/1555","primaryUrl":"https://eprint.iacr.org/2025/1555","summary":"Statistical MPC with a Constant Communication Overhead","tags":["SIMD","constant-overhead","guaranteed-output-delivery","statistical-security"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2025-CDPP","title":"Statistical MPC with a Constant Communication Overhead","authors":["Ashish Choudhury","Ivan Damgård","Shravani Patil","Arpita Patra"],"year":2025,"venue":"IACR ePrint 2025/1555","versions":["IACR ePrint 2025/1555 received 2025-08-29","current manuscript revised 2026-05-22"],"primary_url":"https://eprint.iacr.org/2025/1555","status":"preprint","evidence":"fulltext_checked","keywords":["statistical-security","SIMD","guaranteed-output-delivery","constant-overhead"],"contribution_ids":["MPC-CONTRIB-2025-CDPP-SIMD-GOD"]},"sections":[{"heading":"Overview","content":"Statistical MPC with a Constant Communication Overhead"},{"heading":"Version and bibliographic notes","content":"The admitted source is the manuscript revised 2026-05-22, not an earlier abstract or mirror that also described asynchronous results. The current title, abstract, §1 and §3 use the synchronous model. The bibliographic year remains 2025, while all admitted theorem and open-question claims are tied to the 2026 revision."},{"heading":"Atomic contribution","content":"MPC-CONTRIB-2025-CDPP-SIMD-GOD records the batched statistical MPC theorem. The checked locators are §1.1, Theorem 1.1 (page 2), §1.2–§1.3 (page 3), the model and field convention in §3 (page 11), and §7, Theorem 7.1 (pages 23–24). Its Θ(n^7) parallel evaluations are essential to the admitted amortization, not a hidden implementation detail."},{"heading":"Open-question provenance and limitations","content":"Section 1.3 explicitly asks for a general-circuit protocol retaining constant communication overhead, O(D) rounds and GOD, and separately asks to reduce the SIMD requirement. These support MPC-OP-004. The paper's VSS and degree-reduction mechanisms are not separately admitted in this bounded intake. Fulltext checking covers the cited claims and limitations, not an independent proof or implementation verification."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2025-CDPP"},{"id":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","type":"paper","title":"Lower Bounds for Garbled Circuits from Shannon-Type Information Inequalities","subtitle":"Jake Januzelli, Mike Rosulek, Lawrence Roy · 2025","status":"published","evidence":"fulltext_checked","year":2025,"venue":"CRYPTO 2025","primaryUrl":"https://eprint.iacr.org/2025/876","summary":"MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND records Theorem 26 and Corollary 27 (p. 23), with the retained syntax, label distribution and security definition from §§3.1–3.4 (pp. 9–12). The paper's non-Free-XOR theorems are separate results, not bundled into this atom.","tags":["garbling","information-inequalities","lower-bounds","minicrypt"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","title":"Lower Bounds for Garbled Circuits from Shannon-Type Information Inequalities","authors":["Jake Januzelli","Mike Rosulek","Lawrence Roy"],"year":2025,"venue":"CRYPTO 2025","citation_key":"JRR25","versions":["IACR ePrint 2025/876 received 2025-05-16","CRYPTO 2025"],"primary_url":"https://eprint.iacr.org/2025/876","status":"published","evidence":"fulltext_checked","keywords":["garbling","lower-bounds","information-inequalities","minicrypt"],"contribution_ids":["MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND"]},"sections":[{"heading":"Atomic contribution","content":"MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND records Theorem 26 and Corollary 27 (p. 23), with the retained syntax, label distribution and security definition from §§3.1–3.4 (pp. 9–12). The paper's non-Free-XOR theorems are separate results, not bundled into this atom."},{"heading":"Open-question provenance","content":"Section 1.1 (pp. 3–4) identifies non-adaptive and coordinated evaluator queries as potentially limiting assumptions. This supplies the remaining model gap for MPC-OP-005, following RR21's original question. The exact relaxation in that card is a curator normalization, not a quotation of a JRR conjecture."},{"heading":"Evidence boundary","content":"The theorem statement and definitions were checked in the full manuscript, including the rendered page containing Theorem 26. The automated entropy-proof artifact was not rerun. A lower bound for this single-gate interface must not be extrapolated to arbitrary whole-circuit encodings."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2025-JRR-GARBLING-BOUNDS"},{"id":"MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT","type":"contribution","title":"Active CRT-based MPC keeps leading computation and communication linear with abort","subtitle":"Actively Secure MPC with O(|C|) Computation and Communication via CRT","status":"published","evidence":"fulltext_checked","year":2026,"venue":"CRYPTO 2026","primaryUrl":"https://eprint.iacr.org/2026/1270","summary":"For any fixed 0 < ε < 1/2 and fields with log |F| = Ω(n² log n), BEP gives statistically secure MPC with abort for general arithmetic circuits against t < (1/2−ε)n active corruptions, with O(|C| log |F|) leading communication and bit-computation cost under the source convention suppressing statistical-security, log n and log log |F| factors.","tags":["CRT","abort","active-security","atomic-contribution","catalog_only","communication","computation","network-delivery","round-communication","theorem"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT","paper_id":"MPC-PAPER-2026-BEP","year":2026,"title":"Active CRT-based MPC keeps leading computation and communication linear with abort","claim_slug":"active-crt-mpc-linear-leading-cost-abort","contribution_kind":"research_result","contribution_role":"theorem","statement":"For any fixed 0 < ε < 1/2 and fields with log |F| = Ω(n² log n), BEP gives statistically secure MPC with abort for general arithmetic circuits against t < (1/2−ε)n active corruptions, with O(|C| log |F|) leading communication and bit-computation cost under the source convention suppressing statistical-security, log n and log log |F| factors.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Leading linear communication was known for active security with abort, while jointly leading linear communication and computation was available for passive CRT-based MPC.","technical_delta":"Active consistency mechanisms extend CRT-based computation to active security with abort while preserving its leading cost dependence.","significance_at_publication":"The source separates the cost of active checking from the further problem of continuing to guaranteed output delivery.","narrative":"Constant-leading communication does not automatically give low local work: previous active protocols could still pay a factor proportional to the number of participants in computation. CRT-based secret sharing had reduced both leading costs for passive security. Bienstock, Escudero and Polychroniadou extend that approach to active security with abort. Their arithmetic-circuit theorem preserves the large-field restriction and suppresses statistical-security and logarithmic factors in its cost notation. It does not guarantee that honest parties receive an output after detected cheating. Accordingly, the result is a neighboring cost benchmark for guaranteed-delivery research, not a solution to the GOD target."},"source_locator":{"dossier_section":"MPC-PAPER-2026-BEP § Atomic contribution","primary_source":"ePrint 2026/1270, §1.1 Theorem 1 and footnotes 3–4 (p. 2), preceding GOD discussion (p. 2) and §1.2 (p. 3)","primary_source_url":"https://eprint.iacr.org/2026/1270.pdf","status":"theorem_checked"},"qualifiers":["Active corruption t < (1/2−ε)n for any fixed positive ε; statistical security with abort.","Large fields with log |F| = Ω(n² log n).","The source explicitly suppresses λ, log n and log log |F| factors; the leading O(|C| log |F|) expression is not a bound uniform in all parameters.","The circuit-cost discussion counts multiplication gates; additions can be local."],"limitations":["Guaranteed output delivery is not provided.","No small-field, adaptive-corruption or exact O(D)-round claim is normalized from this introductory theorem.","The comparison does not assert that this is the uniquely closest result for every coordinate of MPC-OP-004."],"facet_status":"normalized","facets":{"task":["general-mpc"],"mechanism":["CRT-secret-sharing","active-consistency-checking"],"adversary_behavior":["malicious"],"corruption_timing":["not_normalized"],"majority_regime":["honest-majority"],"output_guarantee":["security-with-abort"],"security":["statistical"]},"status":"published","evidence":"fulltext_checked","research_lenses":["active-security","round-communication","network-delivery"],"keywords":["CRT","active-security","abort","communication","computation"],"work_id":"MPC-PAPER-2026-BEP","role":"theorem","lens":"active-security","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Active CRT-based computation with abort The admissible closest-result comparison preserves both a model gap (abort versus GOD) and accounting qualifications. It does not attach the missing GOD guarantee by association with other honest-majority results."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT"},{"id":"MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF","type":"contribution","title":"PRF-based multiparty scalar-vector triples with exponential party-dependent key cost","subtitle":"Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography","status":"published","evidence":"fulltext_checked","year":2026,"venue":"ITC 2026","primaryUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7","summary":"IKR construct a k-party PCF for additive shares of a scalar x, vector a, and xa using only PRFs; if each scalar share lies in a common support S, each party holds k|S|^(k−1)−(k−1)|S|^(k−2)+2k−2 PRF keys and evaluates each key once per coordinate.","tags":["atomic-contribution","catalog_only","correlation_generator","party-scaling","pcf","preprocessing-correlation","round-communication","secret-replication","svmt"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF","paper_id":"MPC-PAPER-2026-IKR-PCF","year":2026,"title":"PRF-based multiparty scalar-vector triples with exponential party-dependent key cost","claim_slug":"prf-multiparty-svmt-pcf","contribution_kind":"mechanism","contribution_role":"correlation_generator","statement":"IKR construct a k-party PCF for additive shares of a scalar x, vector a, and xa using only PRFs; if each scalar share lies in a common support S, each party holds k|S|^(k−1)−(k−1)|S|^(k−2)+2k−2 PRF keys and evaluates each key once per coordinate.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Two-party VOLE does not immediately supply consistently programmable cross-terms with privacy against colluding receivers.","technical_delta":"Secret projection of several lines with shared slopes and independent intercepts supplies the multiparty scalar-vector correlation.","significance_at_publication":"The construction establishes symmetric-only feasibility while making party-dependent local work and storage explicit.","narrative":"Moving from two-party VOLE to multiparty scalar-vector products requires compatible cross-terms without exposing a sender's vector to colluding receivers. Reusing a single line is unsafe because receivers can combine evaluations to recover its slope. IKR instead use several lines with a shared slope and independent intercepts, together with secret projection and replicated PRF keys. The resulting correlation provides additive shares of a scalar, a vector, and their product, with local indexed evaluation and privacy against any strict coalition. This extends symmetric-only correlation generation to a multiparty setting, but the key count grows exponentially with the participants. That construction cost motivates a scaling problem rather than establishing a universal lower bound or a complete malicious MPC protocol."},"source_locator":{"dossier_section":"MPC-PAPER-2026-IKR-PCF § Atomic contributions","primary_source":"ITC 2026 proceedings, Theorem 2, p. 7:6; Definition 6, pp. 7:8–7:9; §4.2 and Corollary 27, pp. 7:14–7:17; Definitions 12–13, pp. 7:10–7:11","primary_source_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol385-itc2026/LIPIcs.ITC.2026.7/LIPIcs.ITC.2026.7.pdf","status":"section_checked"},"qualifiers":["The correlation shares one scalar across all vector coordinates and offers indexed random access.","Insider security concerns every fixed strict coalition, including k−1 exposed keys, relative to the corruptible ideal correlation.","Formal Corollary 27 uses a joint scalar-share support X subset F^k and its union S of marginal supports."],"limitations":["Exponential dependence on k remains even when F=S=F2.","Adaptive evaluation indices do not establish adaptive party corruption, malicious distributed key generation, or UC composition.","This atom is unauthenticated SVMT; authenticated variants have additional parameters and are not folded into its guarantee."],"facet_status":"normalized","facets":{"task":["correlation-generation"],"mechanism":["secret-projection","pseudorandom-correlation-function"],"party_model":["multi-party"],"correlation_type":["scalar-vector-multiplication-triple"],"assumption":["pseudorandom-function"],"cost_coordinate":["local-computation","storage","party-scaling"]},"status":"published","evidence":"fulltext_checked","research_lenses":["preprocessing-correlation","round-communication"],"keywords":["pcf","svmt","secret-replication","party-scaling"],"work_id":"MPC-PAPER-2026-IKR-PCF","role":"correlation_generator","lens":"preprocessing-correlation","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Multiparty scalar-vector correlation Catalogue-only inclusion records the exact partial result used by MPC-OP-003. The source proves a correlation mechanism; it does not establish that the mechanism's exponential cost is necessary for every symmetric construction."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF"},{"id":"MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF","type":"contribution","title":"Secret projection recovers small-scalar VOLE PCFs from PRFs","subtitle":"Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography","status":"published","evidence":"fulltext_checked","year":2026,"venue":"ITC 2026","primaryUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7","summary":"IKR derive a two-party PCF for VOLE over a finite field F with scalar in X subset F from any PRF; the direct construction assigns |X| keys to the sender and |X|−1 to the receiver, with one PRF call per held key per evaluated coordinate.","tags":["atomic-contribution","catalog_only","correlation_generator","pcf","preprocessing-correlation","secret-replication","small-domain-vole"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF","paper_id":"MPC-PAPER-2026-IKR-PCF","year":2026,"title":"Secret projection recovers small-scalar VOLE PCFs from PRFs","claim_slug":"secret-projection-small-scalar-vole-pcf","contribution_kind":"mechanism","contribution_role":"correlation_generator","statement":"IKR derive a two-party PCF for VOLE over a finite field F with scalar in X subset F from any PRF; the direct construction assigns |X| keys to the sender and |X|−1 to the receiver, with one PRF call per held key per evaluated coordinate.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Small-domain VOLE PCFs from symmetric primitives were already known from Roy and subsequent work.","technical_delta":"A secret projection of a linear correlation gives a common explanation of this two-party construction and the later multiparty construction.","significance_at_publication":"The mechanism separates attainable correlation types from the stronger assumptions used in general OT and OLE expansion.","narrative":"Small-domain VOLE already admitted constructions from symmetric primitives. IKR revisit that result by viewing a line's evaluations as a linear correlation: the sender receives enough evaluations to recover the line, while the receiver receives one secretly selected evaluation. Replicated PRF keys compress these correlations and provide local access to vector coordinates. This perspective explains an existing construction within the same framework used for the paper's multiparty results. It also exposes the remaining parameter boundary: evaluation work grows with the scalar domain, even when keys can be compressed. The contribution is this unifying mechanism, not first VOLE feasibility or a construction of independent random OT correlations from arbitrary one-way functions."},"source_locator":{"dossier_section":"MPC-PAPER-2026-IKR-PCF § Atomic contributions","primary_source":"ITC 2026 proceedings, Theorem 1, p. 7:5; Corollary 22 and Remarks 24–25, p. 7:14; Definitions 12–13, pp. 7:10–7:11","primary_source_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol385-itc2026/LIPIcs.ITC.2026.7/LIPIcs.ITC.2026.7.pdf","status":"section_checked"},"qualifiers":["VOLE shares one scalar across the vector; it is not a batch of independent random OTs.","The finite field and scalar domain are distinct parameters; the stated evaluation cost is linear in |X|.","The result concerns correlated keys and local evaluation, not a free distributed setup."],"limitations":["Large scalar domains make the direct evaluation expensive; key compression alone does not remove this evaluation cost.","No generic OWF-based random-OT PCG or complete malicious MPC protocol is established by this contribution."],"facet_status":"normalized","facets":{"task":["correlation-generation"],"mechanism":["secret-projection","pseudorandom-correlation-function"],"party_model":["two-party"],"correlation_type":["small-domain-vole"],"assumption":["pseudorandom-function"]},"status":"published","evidence":"fulltext_checked","research_lenses":["preprocessing-correlation"],"keywords":["pcf","small-domain-vole","secret-replication"],"work_id":"MPC-PAPER-2026-IKR-PCF","role":"correlation_generator","lens":"preprocessing-correlation","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Small-scalar VOLE via secret projection The sender holds vectors a,b; the receiver holds one scalar x and ax+b. The scalar persists across evaluated vector coordinates. Catalogue-only inclusion supports the open-question comparison without adding a research-map node."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF"},{"id":"MPC-CONTRIB-2026-LS-BATCHED-GARBLING","type":"contribution","title":"Layer-batched ROM garbling separates circuit-size cost from statistical error","subtitle":"Breaking the Ω(|C|κ) Barrier on Garbled Circuit Size in the Random Oracle Model","status":"published","evidence":"fulltext_checked","year":2026,"venue":"CRYPTO 2026","primaryUrl":"https://eprint.iacr.org/2026/1297","summary":"LS26 Theorem 1 gives Boolean-circuit garbling of size O(|C| log T + Dκ² log T) bits and input encoding O(WI log T) bits in the programmable random-oracle model, with error 2^(−κ) against a computationally unbounded T-query adversary; D is depth and WI is the number of input wires.","tags":["atomic-contribution","batching","catalog_only","garbled-circuit-efficiency","garbling","random-oracle","statistical-error","theorem"],"metadata":{"dossier_type":"contribution","id":"MPC-CONTRIB-2026-LS-BATCHED-GARBLING","paper_id":"MPC-PAPER-2026-LS-GARBLING","year":2026,"title":"Layer-batched ROM garbling separates circuit-size cost from statistical error","claim_slug":"layer-batched-rom-garbling-bounded-query-size","contribution_kind":"research_result","contribution_role":"theorem","statement":"LS26 Theorem 1 gives Boolean-circuit garbling of size O(|C| log T + Dκ² log T) bits and input encoding O(WI log T) bits in the programmable random-oracle model, with error 2^(−κ) against a computationally unbounded T-query adversary; D is depth and WI is the number of input wires.","statement_status":"source_normalized_statement","historical_context_status":"curator_synthesis","historical_context":{"prior_boundary":"Practical gatewise constructions paid a security-parameter factor per AND gate, while finer lower bounds addressed restricted single-gate interfaces.","technical_delta":"Encode inputs non-projectively and garble batches of gates within a layer rather than independently preserving the earlier gate interface.","significance_at_publication":"The construction separates whole-circuit amortization from single-gate optimality and exposes a remaining depth-dependent overhead.","narrative":"Lower bounds for an isolated gate do not automatically constrain a construction that encodes inputs and layers jointly. Li and Song exploit that distinction in the random-oracle model, separating the adversary's query budget from the requested statistical error. Their garbled-circuit size has a circuit-linear term depending on log T and an additional depth-dependent term. The improvement is asymptotic and depends on the parameter regime; it is not an unconditional concrete-speed claim. This gives an important boundary when reading the single-gate optimality question: the new construction avoids that interface rather than disproving a theorem within it."},"source_locator":{"dossier_section":"MPC-PAPER-2026-LS-GARBLING § Atomic contribution","primary_source":"ePrint 2026/1297, §1.1 Theorem 1 and Corollary 1 (pp. 4–5), §1.2 (pp. 7–8), §3.4 Definition 1 (pp. 16–17); PDF page numbers match printed pages","primary_source_url":"https://eprint.iacr.org/2026/1297.pdf","status":"theorem_checked"},"qualifiers":["T bounds adversary oracle queries; κ specifies statistical error. They are different coordinates.","The stated upper bound yields o(|C|κ) when log T = o(κ) and Dκ log T = o(|C|); these are sufficient conditions, not a lower bound excluding other regimes.","Input encoding is non-projective; the bound is not a per-single-AND-gate claim or a Free-XOR guarantee.","The random oracle is programmable, not a global or non-programmable oracle."],"limitations":["The work explicitly defers improved concrete size; no measured implementation advantage is claimed here.","The input-encoding term remains separate and is not omitted from full communication accounting.","This different interface is not an APPROACHES edge to the single-gate target MPC-OP-005."],"facet_status":"normalized","facets":{"task":["garbled-circuit-efficiency"],"mechanism":["layer-batching","non-projective-encoding"],"cost_coordinate":["garbled-circuit-bits"],"oracle_model":["programmable-random-oracle"]},"status":"published","evidence":"fulltext_checked","research_lenses":["garbled-circuit-efficiency"],"keywords":["garbling","batching","random-oracle","statistical-error"],"work_id":"MPC-PAPER-2026-LS-GARBLING","role":"theorem","lens":"garbled-circuit-efficiency","visibility":"catalog_only"},"sections":[{"heading":"Overview","content":"Whole-circuit cost, not single-gate cost The depth term and the separation of T from κ are essential to this result. Taking log T = Θ(κ) does not give a sub-κ leading cost per gate."}],"sourcePath":"data/mpc-catalog.json#MPC-CONTRIB-2026-LS-BATCHED-GARBLING"},{"id":"MPC-IMPL-2026-ABY-88FED3E","type":"implementation","title":"ABY at 88fed3e","subtitle":"2026","status":"reported","evidence":"primary_source_checked","year":2026,"venue":null,"primaryUrl":"https://github.com/encryptogroup/ABY/tree/88fed3ef6789580cac342201e135a358a083ca36","summary":"This is the moving framework pinned to a concrete revision; it is separate from the 2015 paper configuration and later ABY-family papers.","tags":["2pc","aby","implementation","mixed-protocol"],"metadata":{"dossier_type":"implementation","id":"MPC-IMPL-2026-ABY-88FED3E","title":"ABY at 88fed3e","year":2026,"paper_ids":["MPC-PAPER-2015-ABY"],"configuration_ids":["MPC-PROTOCOL-ABY-PASSIVE"],"artifact":{"repository":"https://github.com/encryptogroup/ABY","commit":"88fed3ef6789580cac342201e135a358a083ca36","commit_url":"https://github.com/encryptogroup/ABY/tree/88fed3ef6789580cac342201e135a358a083ca36","version":"commit-88fed3e"},"artifact_type":"open-source mixed-protocol 2PC framework","language":"C++","backend":"arithmetic, Boolean GMW, and Yao circuits","availability":"public repository","maturity":"research framework","configuration_binding":"paper-aligned passive ABY configuration","realized_stack":{"representation":"mixed arithmetic and Boolean circuit graph","value_encoding":"arithmetic, Boolean, and Yao shares","evaluation_protocol":"arithmetic sharing, Boolean GMW, and Yao garbling","correlation_source":"OT extension and circuit-specific preprocessing","active_security_enforcement":"passive configuration","conversion_layer":"A2B, B2A, A2Y, Y2A, B2Y, and Y2B-style conversion surface","output_recovery_layer":"output gates with connection-failure abort"},"benchmark_eligible":true,"benchmark_eligibility_note":"Requires a fixed circuit, sharing assignment, cryptographic parameters, build flags, host/network, and phase accounting.","status":"reported","evidence":"primary_source_checked","evidence_status":"repository_revision_checked","source_locator":"pinned README and src/abycore circuit/share providers","primary_url":"https://github.com/encryptogroup/ABY/tree/88fed3ef6789580cac342201e135a358a083ca36","tags":["implementation","aby","2pc","mixed-protocol"]},"sections":[{"heading":"Identity","content":"This is the moving framework pinned to a concrete revision; it is separate from the 2015 paper configuration and later ABY-family papers."}],"sourcePath":"data/mpc-catalog.json#MPC-IMPL-2026-ABY-88FED3E"},{"id":"MPC-IMPL-2026-HPMPC-155C935","type":"implementation","title":"HP-MPC at 155c935","subtitle":"2026","status":"reported","evidence":"primary_source_checked","year":2026,"venue":null,"primaryUrl":"https://github.com/chart21/hpmpc/tree/155c93572d747b527a6452c9ad8f24eb3b776667","summary":"The pinned README warns that one 4PC workload requires a later fix option for recently reported attacks. The atlas therefore does not treat the repository name as a blanket malicious-security badge.","tags":["3pc","4pc","high-throughput","hp-mpc","implementation"],"metadata":{"dossier_type":"implementation","id":"MPC-IMPL-2026-HPMPC-155C935","title":"HP-MPC at 155c935","year":2026,"paper_ids":["MPC-PAPER-2024-HPMPC"],"configuration_ids":["MPC-PROTOCOL-HPMPC-3PC","MPC-PROTOCOL-HPMPC-4PC"],"artifact":{"repository":"https://github.com/chart21/hpmpc","commit":"155c93572d747b527a6452c9ad8f24eb3b776667","commit_url":"https://github.com/chart21/hpmpc/tree/155c93572d747b527a6452c9ad8f24eb3b776667","version":"commit-155c935"},"artifact_type":"open-source high-throughput MPC runtime","language":"C and C++","backend":"vectorized 3PC and 4PC protocol implementations","availability":"public repository","maturity":"research implementation","configuration_binding":"protocol compile-time options select the exact 3PC/4PC configuration","realized_stack":{"representation":"batched Boolean or 2-power-ring circuits","value_encoding":"replicated and protocol-specific honest-majority shares","evaluation_protocol":"vectorized 3PC/4PC gate protocols","correlation_source":"pairwise seeded masks with optional preprocessing","active_security_enforcement":"protocol-selected passive or malicious checks","conversion_layer":"workload and protocol dependent","output_recovery_layer":"protocol reconstruction with abort behavior"},"benchmark_eligible":true,"benchmark_eligibility_note":"Paper observations are retained as non-comparable until protocol macro, hardware, vector width, workload, parties, topology, and accounting all match.","status":"reported","evidence":"primary_source_checked","evidence_status":"repository_revision_checked","source_locator":"pinned README, config.h options, protocols directory, and paper Section 5","primary_url":"https://github.com/chart21/hpmpc/tree/155c93572d747b527a6452c9ad8f24eb3b776667","tags":["implementation","hp-mpc","high-throughput","3pc","4pc"]},"sections":[{"heading":"Security caveat","content":"The pinned README warns that one 4PC workload requires a later fix option for recently reported attacks. The atlas therefore does not treat the repository name as a blanket malicious-security badge."}],"sourcePath":"data/mpc-catalog.json#MPC-IMPL-2026-HPMPC-155C935"},{"id":"MPC-IMPL-2026-MPSPDZ-9D80959","type":"implementation","title":"MP-SPDZ at 9d80959","subtitle":"2026","status":"reported","evidence":"primary_source_checked","year":2026,"venue":null,"primaryUrl":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9","summary":"The commit is the implementation object. “MP-SPDZ performance” without a protocol flag and benchmark context is not an admissible measurement claim.","tags":["implementation","mp-spdz","multi-backend"],"metadata":{"dossier_type":"implementation","id":"MPC-IMPL-2026-MPSPDZ-9D80959","title":"MP-SPDZ at 9d80959","year":2026,"paper_ids":["MPC-PAPER-2020-MPSPDZ"],"configuration_ids":["MPC-PROTOCOL-SPDZ-SHE","MPC-PROTOCOL-MASCOT-SPDZ","MPC-PROTOCOL-TINYOT","MPC-PROTOCOL-BMR-SPDZ"],"artifact":{"repository":"https://github.com/data61/MP-SPDZ","commit":"9d809599ea6ce627216a389ca7d984fbb75d0cb9","commit_url":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9","version":"commit-9d80959"},"artifact_type":"open-source compiler and multi-backend runtime","language":"C++, Python, assembly-like bytecode","backend":"arithmetic and binary protocol families selected at runtime","availability":"public repository","maturity":"research framework with broad protocol coverage","configuration_binding":"multi_configuration_framework; exact runtime flag selects the protocol","realized_stack":{"representation":"high-level programs compiled to arithmetic or binary bytecode","value_encoding":"protocol-selected Shamir, replicated, authenticated additive, or binary shares","evaluation_protocol":"protocol-selected arithmetic, binary, garbled, or replicated evaluation","correlation_source":"protocol-selected OT, HE, dealer, or no separate preprocessing","active_security_enforcement":"protocol-selected MAC, sacrifice, consistency, or passive execution","conversion_layer":"documented mixed-domain types and conversion subprotocols","output_recovery_layer":"protocol-selected reconstruction and abort semantics"},"benchmark_eligible":true,"benchmark_eligibility_note":"Eligible only after a command fixes protocol, field/ring, security parameter, parties, compile flags, workload, network, and phase accounting.","status":"reported","evidence":"primary_source_checked","evidence_status":"repository_revision_checked","source_locator":"pinned README, documentation protocol table, and source tree","primary_url":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9","tags":["implementation","mp-spdz","multi-backend"]},"sections":[{"heading":"Identity","content":"The commit is the implementation object. “MP-SPDZ performance” without a protocol flag and benchmark context is not an admissible measurement claim."}],"sourcePath":"data/mpc-catalog.json#MPC-IMPL-2026-MPSPDZ-9D80959"},{"id":"MPC-PAPER-2026-BEP","type":"paper","title":"Actively Secure MPC with O(|C|) Computation and Communication via CRT","subtitle":"Alexander Bienstock, Daniel Escudero, Antigoni Polychroniadou · 2026","status":"published","evidence":"fulltext_checked","year":2026,"venue":"CRYPTO 2026","primaryUrl":"https://eprint.iacr.org/2026/1270","summary":"Actively Secure MPC with O(|C|) Computation and Communication via CRT","tags":["CRT-secret-sharing","communication-complexity","security-with-abort","statistical-security"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2026-BEP","title":"Actively Secure MPC with O(|C|) Computation and Communication via CRT","authors":["Alexander Bienstock","Daniel Escudero","Antigoni Polychroniadou"],"year":2026,"venue":"CRYPTO 2026","versions":["CRYPTO 2026 paper","IACR ePrint 2026/1270 received 2026-06-17"],"primary_url":"https://eprint.iacr.org/2026/1270","status":"published","evidence":"fulltext_checked","keywords":["CRT-secret-sharing","statistical-security","security-with-abort","communication-complexity"],"contribution_ids":["MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT"]},"sections":[{"heading":"Overview","content":"Actively Secure MPC with O(|C|) Computation and Communication via CRT"},{"heading":"Version and bibliographic notes","content":"The ePrint record identifies the CRYPTO 2026 publication. This intake uses the ePrint manuscript's §1.1, Theorem 1 and footnotes 3–4 on page 2, with the preceding discussion and §1.2 on page 3 for the GOD boundary."},{"heading":"Atomic contribution","content":"MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT preserves the active-security-with-abort guarantee, the restriction log |F| = Ω(n² log n), and the theorem convention suppressing statistical-security, log n and log log |F| factors. The title's O(|C|) shorthand is not a universal all-parameter cost bound. The manuscript explicitly distinguishes its abort result from guaranteed output delivery."},{"heading":"Limitations and unresolved review","content":"This is a catalog-only closest-result intake for MPC-OP-004, not an exact configuration or measured implementation. Corruption timing and concrete round costs are not normalized from the introductory theorem. The checked statements do not establish a GOD upgrade; the complete protocol proofs were not independently verified."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2026-BEP"},{"id":"MPC-PAPER-2026-IKR-PCF","type":"paper","title":"Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography","subtitle":"Yuval Ishai, Hugo Krawczyk, Tal Rabin · 2026","status":"published","evidence":"fulltext_checked","year":2026,"venue":"ITC 2026","primaryUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7","summary":"Claims use the ITC proceedings version, not an assumed later ePrint revision. The proceedings identify ePrint 2026/1355 as the full version.","tags":["pseudorandom-correlation-function","scalar-vector-multiplication","small-domain-vole","symmetric-cryptography"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2026-IKR-PCF","title":"Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography","authors":["Yuval Ishai","Hugo Krawczyk","Tal Rabin"],"year":2026,"venue":"ITC 2026","versions":["IACR ePrint 2026/1355, received 2026-07-01 and approved 2026-07-03","ITC 2026, LIPIcs 385, article 7, pp. 7:1–7:22, published 2026-08-12"],"primary_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7","status":"published","evidence":"fulltext_checked","keywords":["pseudorandom-correlation-function","symmetric-cryptography","small-domain-vole","scalar-vector-multiplication"],"contribution_ids":["MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF","MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF"]},"sections":[{"heading":"Version and bibliographic notes","content":"Claims use the ITC proceedings version, not an assumed later ePrint revision. The proceedings identify ePrint 2026/1355 as the full version."},{"heading":"Atomic contributions","content":"MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF: secret-projection derivation of the small-scalar VOLE PCF; Theorem 1, p. 7:5, and Corollary 22, p. 7:14. This revisits Roy's construction rather than claiming first feasibility. MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF: multiparty scalar-vector multiplication correlations from PRFs; Theorem 2, p. 7:6, and Corollary 27, pp. 7:16–7:17."},{"heading":"Open-question locators","content":"Section 1.4, p. 7:7, explicitly leaves OT PCGs from symmetric cryptography open. Section 6, p. 7:19, asks whether the scalar-size and party-count blowups of these VOLE-style constructions are inherent. The cards MPC-OP-002 and MPC-OP-003 normalize separate targets from these passages."},{"heading":"Security boundary","content":"Definitions 12–13, pp. 7:10–7:11, use corruptible ideal correlations and insider security after seed exposure. The PCF supports adaptively chosen evaluation indices; that is not a claim of adaptive party corruption. Correlated seed distribution remains a distinct setup task. These atoms do not assert an end-to-end malicious or UC MPC protocol, nor negligible-error authentication from a small authentication-key domain."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2026-IKR-PCF"},{"id":"MPC-PAPER-2026-IT-CONSTANT-ROUND","type":"paper","title":"Constant-round MPC protocols with Fall-back Security","subtitle":"Anasuya Acharya, Aditya Patankar, Arpita Patra et al. · 2026","status":"preprint","evidence":"fulltext_checked","year":2026,"venue":"IACR ePrint 2026/1768","primaryUrl":"https://eprint.iacr.org/2026/1768","summary":"Constant-round MPC protocols with Fall-back Security","tags":["constant-round","fall-back-security","information-theoretic-security"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2026-IT-CONSTANT-ROUND","title":"Constant-round MPC protocols with Fall-back Security","authors":["Anasuya Acharya","Aditya Patankar","Arpita Patra","Divya Ravi","Raghavendra Vernekar"],"year":2026,"venue":"IACR ePrint 2026/1768","versions":["IACR ePrint 2026/1768 received 2026-08-21"],"primary_url":"https://eprint.iacr.org/2026/1768","status":"preprint","evidence":"fulltext_checked","review_scope":"ePrint manuscript received 2026-08-21, §1.1 and §1.2 (numbered PDF pp. 3–5), checked for the general-circuit efficiency question and the NC¹ qualification; no independent audit of its positive security proofs.","keywords":["fall-back-security","information-theoretic-security","constant-round"],"contribution_ids":[]},"sections":[{"heading":"Overview","content":"Constant-round MPC protocols with Fall-back Security"},{"heading":"Version and bibliographic notes","content":"The source is the ePrint manuscript received 2026-08-21. Its ePrint metadata describes it as a major revision of a TCC 2026 publication; this card uses the available manuscript identity and does not assign an unverified proceedings date."},{"heading":"Open-question provenance","content":"Section 1.1, numbered PDF page 3, explicitly identifies extending efficient constant-round information-theoretic computation to general circuits as an open question. The fall-back protocols there instantiate an information-theoretic base protocol for NC¹ and add guarantees under computational assumptions at higher corruption levels. The source's abstract alone does not make the NC¹ efficiency restriction visible, so the full section is the evidence used for MPC-OP-001."},{"heading":"Limitations and unresolved review","content":"This is a source/provenance-only intake: no atomic positive result, protocol configuration, map membership or lineage edge is admitted. The relevant introduction and theorem statements were checked; security proofs were not independently verified. Its phrase about extending beyond NC¹ is not interpreted as excluding all log-space functionalities, which AKP23 footnote 3 discusses via secure reductions to NC¹."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2026-IT-CONSTANT-ROUND"},{"id":"MPC-PAPER-2026-LS-GARBLING","type":"paper","title":"Breaking the Ω(|C|κ) Barrier on Garbled Circuit Size in the Random Oracle Model","subtitle":"Junru Li, Yifan Song · 2026","status":"published","evidence":"fulltext_checked","year":2026,"venue":"CRYPTO 2026","primaryUrl":"https://eprint.iacr.org/2026/1297","summary":"MPC-CONTRIB-2026-LS-BATCHED-GARBLING records Theorem 1 and Corollary 1 (pp. 4–5). Section 1.2 (pp. 7–8) explains why the layer-batched construction lies outside earlier single-gate lower bounds. The separate malicious 2PC and NISC theorems are not included in this atom.","tags":["batching","circuit-size","garbling","random-oracle"],"metadata":{"dossier_type":"paper","id":"MPC-PAPER-2026-LS-GARBLING","title":"Breaking the Ω(|C|κ) Barrier on Garbled Circuit Size in the Random Oracle Model","authors":["Junru Li","Yifan Song"],"year":2026,"venue":"CRYPTO 2026","citation_key":"LS26","versions":["IACR ePrint 2026/1297 received 2026-06-21","CRYPTO 2026"],"primary_url":"https://eprint.iacr.org/2026/1297","status":"published","evidence":"fulltext_checked","keywords":["garbling","random-oracle","batching","circuit-size"],"contribution_ids":["MPC-CONTRIB-2026-LS-BATCHED-GARBLING"]},"sections":[{"heading":"Atomic contribution","content":"MPC-CONTRIB-2026-LS-BATCHED-GARBLING records Theorem 1 and Corollary 1 (pp. 4–5). Section 1.2 (pp. 7–8) explains why the layer-batched construction lies outside earlier single-gate lower bounds. The separate malicious 2PC and NISC theorems are not included in this atom."},{"heading":"Boundary","content":"This result prevents describing Ω(|C|κ) as an unrestricted ROM impossibility. It does not resolve MPC-OP-005's retained single-gate interface. Section 1.1 (p. 5) explicitly leaves improvement of concrete garbled-circuit size for future work; that sentence does not itself pose a depth-independent asymptotic target."}],"sourcePath":"data/mpc-catalog.json#MPC-PAPER-2026-LS-GARBLING"},{"id":"MPC-COMP-ACT-BGW-VSS","type":"component","title":"Verifiable sharing and degree-consistency checks","subtitle":"active security enforcement","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Enforces polynomial consistency and reconstructability against Byzantine deviations under the BGW honest-majority threshold.","tags":["active","honest-majority","vss"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ACT-BGW-VSS","title":"Verifiable sharing and degree-consistency checks","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-1988-BGW"],"status":"published","evidence":"primary_source_checked","tags":["vss","honest-majority","active"]},"sections":[{"heading":"Role","content":"Enforces polynomial consistency and reconstructability against Byzantine deviations under the BGW honest-majority threshold."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ACT-BGW-VSS"},{"id":"MPC-COMP-ACT-BMR-SPDZ","type":"component","title":"SPDZ-secured distributed garbling","subtitle":"active security enforcement","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Constructs and checks the BMR garbling inside an actively secure arithmetic MPC before the fast online evaluation.","tags":["active","bmr","spdz"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ACT-BMR-SPDZ","title":"SPDZ-secured distributed garbling","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2015-BMR-SPDZ"],"status":"published","evidence":"primary_source_checked","tags":["bmr","spdz","active"]},"sections":[{"heading":"Role","content":"Constructs and checks the BMR garbling inside an actively secure arithmetic MPC before the fast online evaluation."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ACT-BMR-SPDZ"},{"id":"MPC-COMP-ACT-HPMPC4","type":"component","title":"HP-MPC four-party malicious checks","subtitle":"active security enforcement","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"The protocol-specific verification layer for the paper's four-party, one-corruption malicious configuration.","tags":["4pc","active","honest-majority"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ACT-HPMPC4","title":"HP-MPC four-party malicious checks","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2024-HPMPC"],"status":"published","evidence":"primary_source_checked","tags":["4pc","active","honest-majority"]},"sections":[{"heading":"Role","content":"The protocol-specific verification layer for the paper's four-party, one-corruption malicious configuration."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ACT-HPMPC4"},{"id":"MPC-COMP-ACT-SPDZ-MAC","type":"component","title":"SPDZ global-MAC checks and sacrifice","subtitle":"active security enforcement","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Checks opened authenticated shares against a hidden global MAC key and sacrifices preprocessing candidates to detect malformed correlations.","tags":["active","mac","sacrifice","spdz"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ACT-SPDZ-MAC","title":"SPDZ global-MAC checks and sacrifice","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2011-SPDZ","MPC-PAPER-2016-MASCOT"],"status":"published","evidence":"primary_source_checked","tags":["spdz","mac","sacrifice","active"]},"sections":[{"heading":"Role","content":"Checks opened authenticated shares against a hidden global MAC key and sacrifices preprocessing candidates to detect malformed correlations."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ACT-SPDZ-MAC"},{"id":"MPC-COMP-ACT-TINYOT","type":"component","title":"TinyOT authenticated-bit checks","subtitle":"active security enforcement","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Uses global-key bit MACs and batch checks to detect malicious deviations in Boolean two-party computation.","tags":["active","authenticated-bits","tinyot"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ACT-TINYOT","title":"TinyOT authenticated-bit checks","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2012-TINYOT"],"status":"published","evidence":"primary_source_checked","tags":["tinyot","authenticated-bits","active"]},"sections":[{"heading":"Role","content":"Uses global-key bit MACs and batch checks to detect malicious deviations in Boolean two-party computation."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ACT-TINYOT"},{"id":"MPC-COMP-CONV-ABY","type":"component","title":"ABY A/B/Y conversion gates","subtitle":"conversion layer","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Converts values among arithmetic sharing, Boolean sharing, and Yao labels within one passive 2PC execution.","tags":["aby","conversion","mixed-protocol"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CONV-ABY","title":"ABY A/B/Y conversion gates","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2015-ABY"],"status":"published","evidence":"primary_source_checked","tags":["aby","conversion","mixed-protocol"]},"sections":[{"heading":"Role","content":"Converts values among arithmetic sharing, Boolean sharing, and Yao labels within one passive 2PC execution."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CONV-ABY"},{"id":"MPC-COMP-CONV-ABY3","type":"component","title":"ABY3 arithmetic/binary/Yao conversion","subtitle":"conversion layer","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Switches replicated ring shares among arithmetic, binary, and garbled subprotocols in the three-party setting.","tags":["3pc","aby3","conversion"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CONV-ABY3","title":"ABY3 arithmetic/binary/Yao conversion","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2018-ABY3"],"status":"published","evidence":"primary_source_checked","tags":["aby3","conversion","3pc"]},"sections":[{"heading":"Role","content":"Switches replicated ring shares among arithmetic, binary, and garbled subprotocols in the three-party setting."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CONV-ABY3"},{"id":"MPC-COMP-CONV-BMR-PREP","type":"component","title":"Arithmetic-to-BMR preprocessing bridge","subtitle":"conversion layer","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Maps arithmetic MPC outputs used during preprocessing into the seeds and tables required by the BMR garbling.","tags":["bmr","composition","spdz"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CONV-BMR-PREP","title":"Arithmetic-to-BMR preprocessing bridge","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2015-BMR-SPDZ"],"status":"published","evidence":"primary_source_checked","tags":["bmr","spdz","composition"]},"sections":[{"heading":"Role","content":"Maps arithmetic MPC outputs used during preprocessing into the seeds and tables required by the BMR garbling."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CONV-BMR-PREP"},{"id":"MPC-COMP-CONV-MOTION","type":"component","title":"MOTION mixed-protocol conversions","subtitle":"conversion layer","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Implements modular conversions among supported passive sharing protocols for two or more parties.","tags":["conversion","framework","motion"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CONV-MOTION","title":"MOTION mixed-protocol conversions","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2020-MOTION"],"status":"published","evidence":"primary_source_checked","tags":["motion","conversion","framework"]},"sections":[{"heading":"Role","content":"Implements modular conversions among supported passive sharing protocols for two or more parties."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CONV-MOTION"},{"id":"MPC-COMP-CORR-BASEOT","type":"component","title":"Oblivious transfer for input and AND correlations","subtitle":"correlation source","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Provides receiver-selective transfer used for garbled inputs or shared AND evaluation.","tags":["correlation","ot"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CORR-BASEOT","title":"Oblivious transfer for input and AND correlations","component_kind":"correlation_source","paper_ids":["MPC-PAPER-1982-YAO","MPC-PAPER-1987-GMW"],"status":"published","evidence":"primary_source_checked","tags":["ot","correlation"]},"sections":[{"heading":"Role","content":"Provides receiver-selective transfer used for garbled inputs or shared AND evaluation."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CORR-BASEOT"},{"id":"MPC-COMP-CORR-F4OLE","type":"component","title":"FOLEAGE F4-OLE Boolean-triple generator","subtitle":"correlation source","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Specializes PCG techniques over F4 to generate F2 multiplication triples with near-linear circuit-dependent communication in party count.","tags":["boolean-triples","f4ole","pcg"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CORR-F4OLE","title":"FOLEAGE F4-OLE Boolean-triple generator","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2024-FOLEAGE"],"status":"published","evidence":"primary_source_checked","tags":["f4ole","pcg","boolean-triples"]},"sections":[{"heading":"Role","content":"Specializes PCG techniques over F4 to generate F2 multiplication triples with near-linear circuit-dependent communication in party count."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CORR-F4OLE"},{"id":"MPC-COMP-CORR-MASCOT","type":"component","title":"MASCOT OT-based arithmetic preprocessing","subtitle":"correlation source","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Generates authenticated arithmetic multiplication triples from OT with consistency checks, replacing the original SPDZ SHE preprocessing.","tags":["mascot","ot","triples"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CORR-MASCOT","title":"MASCOT OT-based arithmetic preprocessing","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2016-MASCOT"],"status":"published","evidence":"primary_source_checked","tags":["mascot","ot","triples"]},"sections":[{"heading":"Role","content":"Generates authenticated arithmetic multiplication triples from OT with consistency checks, replacing the original SPDZ SHE preprocessing."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CORR-MASCOT"},{"id":"MPC-COMP-CORR-OTEXT","type":"component","title":"IKNP OT extension","subtitle":"correlation source","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Amortizes many OTs from a small base-OT seed using symmetric primitives.","tags":["iknp","ot-extension"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CORR-OTEXT","title":"IKNP OT extension","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2003-IKNP"],"status":"published","evidence":"primary_source_checked","tags":["iknp","ot-extension"]},"sections":[{"heading":"Role","content":"Amortizes many OTs from a small base-OT seed using symmetric primitives."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CORR-OTEXT"},{"id":"MPC-COMP-CORR-PAIRWISE","type":"component","title":"Pairwise-seed correlated randomness","subtitle":"correlation source","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Uses seeds shared between party pairs to derive masks locally and reduce communication in replicated-sharing protocols.","tags":["honest-majority","pairwise-prg"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CORR-PAIRWISE","title":"Pairwise-seed correlated randomness","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2018-ABY3","MPC-PAPER-2024-HPMPC"],"status":"published","evidence":"primary_source_checked","tags":["pairwise-prg","honest-majority"]},"sections":[{"heading":"Role","content":"Uses seeds shared between party pairs to derive masks locally and reduce communication in replicated-sharing protocols."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CORR-PAIRWISE"},{"id":"MPC-COMP-CORR-PCG","type":"component","title":"Pseudorandom correlation generator","subtitle":"correlation source","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Expands short correlated seeds locally into long protocol-specific correlations with no interaction during expansion.","tags":["pcg","silent-preprocessing"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CORR-PCG","title":"Pseudorandom correlation generator","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2019-PCG"],"status":"published","evidence":"primary_source_checked","tags":["pcg","silent-preprocessing"]},"sections":[{"heading":"Role","content":"Expands short correlated seeds locally into long protocol-specific correlations with no interaction during expansion."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CORR-PCG"},{"id":"MPC-COMP-CORR-SHE","type":"component","title":"SHE-generated SPDZ preprocessing","subtitle":"correlation source","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Uses somewhat homomorphic encryption plus proofs/checks to create authenticated arithmetic preprocessing before inputs are known.","tags":["homomorphic-encryption","spdz","triples"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-CORR-SHE","title":"SHE-generated SPDZ preprocessing","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2011-SPDZ"],"status":"published","evidence":"primary_source_checked","tags":["spdz","homomorphic-encryption","triples"]},"sections":[{"heading":"Role","content":"Uses somewhat homomorphic encryption plus proofs/checks to create authenticated arithmetic preprocessing before inputs are known."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-CORR-SHE"},{"id":"MPC-COMP-ENC-ABY3-YAO","type":"component","title":"ABY3 three-party Yao sharing","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Stores a Boolean value in the paper's three-party Yao domain, with one evaluator holding the active wire key and two garblers holding the label material needed to construct matching garbled circuits.","tags":["aby3","three-party-garbling","yao-sharing"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-ABY3-YAO","title":"ABY3 three-party Yao sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2018-ABY3"],"status":"published","evidence":"primary_source_checked","tags":["aby3","yao-sharing","three-party-garbling"]},"sections":[{"heading":"Role","content":"Stores a Boolean value in the paper's three-party Yao domain, with one evaluator holding the active wire key and two garblers holding the label material needed to construct matching garbled circuits."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-ABY3-YAO"},{"id":"MPC-COMP-ENC-ADDITIVE","type":"component","title":"Unauthenticated additive sharing","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Represents a value as additive shares without the global-MAC relation of SPDZ authenticated sharing. The surrounding passive protocol and correlation source supply privacy and multiplication.","tags":["additive-sharing","arithmetic","passive-security"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-ADDITIVE","title":"Unauthenticated additive sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2015-ABY","MPC-PAPER-2020-MOTION"],"status":"published","evidence":"primary_source_checked","tags":["additive-sharing","passive-security","arithmetic"]},"sections":[{"heading":"Role","content":"Represents a value as additive shares without the global-MAC relation of SPDZ authenticated sharing. The surrounding passive protocol and correlation source supply privacy and multiplication."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-ADDITIVE"},{"id":"MPC-COMP-ENC-AUTH-ADDITIVE","type":"component","title":"SPDZ authenticated additive sharing","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Associates additive shares with shares of a global-MAC relation so openings can be checked against active deviation.","tags":["authenticated-sharing","spdz"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-AUTH-ADDITIVE","title":"SPDZ authenticated additive sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2011-SPDZ","MPC-PAPER-2016-MASCOT"],"status":"published","evidence":"primary_source_checked","tags":["authenticated-sharing","spdz"]},"sections":[{"heading":"Role","content":"Associates additive shares with shares of a global-MAC relation so openings can be checked against active deviation."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-AUTH-ADDITIVE"},{"id":"MPC-COMP-ENC-AUTH-BITS","type":"component","title":"TinyOT authenticated bits","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Authenticates XOR shares with global-key MAC relations tailored to Boolean computation.","tags":["authenticated-bits","tinyot"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-AUTH-BITS","title":"TinyOT authenticated bits","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2012-TINYOT"],"status":"published","evidence":"primary_source_checked","tags":["authenticated-bits","tinyot"]},"sections":[{"heading":"Role","content":"Authenticates XOR shares with global-key MAC relations tailored to Boolean computation."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-AUTH-BITS"},{"id":"MPC-COMP-ENC-GARBLED","type":"component","title":"Two-party garbled wire labels","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Encodes each Boolean wire value as one of two cryptographic labels held asymmetrically by garbler and evaluator.","tags":["garbling","labels"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-GARBLED","title":"Two-party garbled wire labels","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2008-FREEXOR","MPC-PAPER-2009-PRACTICAL2PC"],"status":"published","evidence":"primary_source_checked","tags":["garbling","labels"]},"sections":[{"heading":"Role","content":"Encodes each Boolean wire value as one of two cryptographic labels held asymmetrically by garbler and evaluator."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-GARBLED"},{"id":"MPC-COMP-ENC-HPMPC-MASKED","type":"component","title":"Trio and Quad masked sharing","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Encodes Trio and Quad values as input-dependent masked values plus differently distributed mask shares. The exact holdings differ between the three- and four-party configurations and are not ABY3 replicated sharing.","tags":["honest-majority","hp-mpc","masked-sharing","ring"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-HPMPC-MASKED","title":"Trio and Quad masked sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2024-HPMPC"],"status":"published","evidence":"primary_source_checked","tags":["hp-mpc","masked-sharing","ring","honest-majority"]},"sections":[{"heading":"Role","content":"Encodes Trio and Quad values as input-dependent masked values plus differently distributed mask shares. The exact holdings differ between the three- and four-party configurations and are not ABY3 replicated sharing."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-HPMPC-MASKED"},{"id":"MPC-COMP-ENC-MULTI-GARBLED","type":"component","title":"Multiparty BMR superseed labels","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Distributes each wire label across parties so no single party controls the multiparty garbling.","tags":["bmr","multiparty-garbling"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-MULTI-GARBLED","title":"Multiparty BMR superseed labels","component_kind":"value_encoding","paper_ids":["MPC-PAPER-1990-BMR","MPC-PAPER-2015-BMR-SPDZ","MPC-PAPER-2020-MOTION"],"status":"published","evidence":"primary_source_checked","tags":["bmr","multiparty-garbling"]},"sections":[{"heading":"Role","content":"Distributes each wire label across parties so no single party controls the multiparty garbling."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-MULTI-GARBLED"},{"id":"MPC-COMP-ENC-REPLICATED","type":"component","title":"Replicated three-party sharing","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Replicates additive share pieces across adjacent parties so one corruption leaves enough overlap for low-communication honest-majority evaluation.","tags":["3pc","replicated-sharing"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-REPLICATED","title":"Replicated three-party sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2018-ABY3"],"status":"published","evidence":"primary_source_checked","tags":["replicated-sharing","3pc"]},"sections":[{"heading":"Role","content":"Replicates additive share pieces across adjacent parties so one corruption leaves enough overlap for low-communication honest-majority evaluation."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-REPLICATED"},{"id":"MPC-COMP-ENC-SHAMIR","type":"component","title":"Shamir polynomial sharing","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Represents a field value as evaluations of a low-degree polynomial, enabling local linear gates and threshold reconstruction.","tags":["honest-majority","shamir"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-SHAMIR","title":"Shamir polynomial sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-1988-BGW"],"status":"published","evidence":"primary_source_checked","tags":["shamir","honest-majority"]},"sections":[{"heading":"Role","content":"Represents a field value as evaluations of a low-degree polynomial, enabling local linear gates and threshold reconstruction."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-SHAMIR"},{"id":"MPC-COMP-ENC-XOR","type":"component","title":"XOR/additive Boolean sharing","subtitle":"value encoding","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Represents a bit as the XOR of party shares, making XOR gates local and pushing interaction to AND gates.","tags":["boolean-sharing","xor"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-ENC-XOR","title":"XOR/additive Boolean sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-1987-GMW","MPC-PAPER-2012-TINYOT"],"status":"published","evidence":"primary_source_checked","tags":["boolean-sharing","xor"]},"sections":[{"heading":"Role","content":"Represents a bit as the XOR of party shares, making XOR gates local and pushing interaction to AND gates."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-ENC-XOR"},{"id":"MPC-COMP-EVAL-ABY3-YAO","type":"component","title":"ABY3 three-party garbled evaluation","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Evaluates ABY3's Yao-domain subcomputations using the paper's two-garbler, one-evaluator three-party garbling path; it is distinct from two-party Yao evaluation and BMR distributed garbling.","tags":["aby3","three-party-garbling","yao-sharing"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-ABY3-YAO","title":"ABY3 three-party garbled evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2018-ABY3"],"status":"published","evidence":"primary_source_checked","tags":["aby3","yao-sharing","three-party-garbling"]},"sections":[{"heading":"Role","content":"Evaluates ABY3's Yao-domain subcomputations using the paper's two-garbler, one-evaluator three-party garbling path; it is distinct from two-party Yao evaluation and BMR distributed garbling."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-ABY3-YAO"},{"id":"MPC-COMP-EVAL-BEAVER","type":"component","title":"Beaver-triple online multiplication","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Opens masked differences against a preprocessed multiplication triple, leaving only local arithmetic and a small online exchange per multiplication layer.","tags":["beaver-triples","online"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-BEAVER","title":"Beaver-triple online multiplication","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ"],"status":"published","evidence":"primary_source_checked","tags":["beaver-triples","online"]},"sections":[{"heading":"Role","content":"Opens masked differences against a preprocessed multiplication triple, leaving only local arithmetic and a small online exchange per multiplication layer."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-BEAVER"},{"id":"MPC-COMP-EVAL-BGW","type":"component","title":"BGW polynomial gate evaluation","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Uses local polynomial-share arithmetic plus interactive degree reduction and verifiable sharing under honest-majority thresholds.","tags":["bgw","degree-reduction"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-BGW","title":"BGW polynomial gate evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1988-BGW"],"status":"published","evidence":"primary_source_checked","tags":["bgw","degree-reduction"]},"sections":[{"heading":"Role","content":"Uses local polynomial-share arithmetic plus interactive degree reduction and verifiable sharing under honest-majority thresholds."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-BGW"},{"id":"MPC-COMP-EVAL-BMR","type":"component","title":"BMR distributed garbling and local evaluation","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Parties jointly create a multiparty garbled circuit; once labels are delivered, each party evaluates locally in a constant-round online phase.","tags":["bmr","constant-round"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-BMR","title":"BMR distributed garbling and local evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1990-BMR","MPC-PAPER-2015-BMR-SPDZ","MPC-PAPER-2020-MOTION"],"status":"published","evidence":"primary_source_checked","tags":["bmr","constant-round"]},"sections":[{"heading":"Role","content":"Parties jointly create a multiparty garbled circuit; once labels are delivered, each party evaluates locally in a constant-round online phase."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-BMR"},{"id":"MPC-COMP-EVAL-GMW","type":"component","title":"GMW Boolean gate evaluation","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Evaluates XOR gates locally and interactive AND gates from oblivious-transfer-style correlations, with rounds tied to multiplicative depth.","tags":["boolean-sharing","gmw"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-GMW","title":"GMW Boolean gate evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1987-GMW","MPC-PAPER-2003-IKNP"],"status":"published","evidence":"primary_source_checked","tags":["gmw","boolean-sharing"]},"sections":[{"heading":"Role","content":"Evaluates XOR gates locally and interactive AND gates from oblivious-transfer-style correlations, with rounds tied to multiplicative depth."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-GMW"},{"id":"MPC-COMP-EVAL-HPMPC-MASKED","type":"component","title":"Trio and Quad masked multiplication","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Multiplies Trio and Quad masked values by distributing input-dependent and input-independent correction work so the paper's three- and four-party configurations retain their stated communication while reducing local instructions.","tags":["hp-mpc","masked-sharing","multiplication","vectorization"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-HPMPC-MASKED","title":"Trio and Quad masked multiplication","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2024-HPMPC"],"status":"published","evidence":"primary_source_checked","tags":["hp-mpc","masked-sharing","multiplication","vectorization"]},"sections":[{"heading":"Role","content":"Multiplies Trio and Quad masked values by distributing input-dependent and input-independent correction work so the paper's three- and four-party configurations retain their stated communication while reducing local instructions."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-HPMPC-MASKED"},{"id":"MPC-COMP-EVAL-REPLICATED","type":"component","title":"Replicated-sharing ring multiplication","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Combines overlapping share products with pairwise randomness to multiply ring-shared values with low bandwidth in 3PC/4PC settings.","tags":["high-throughput","replicated-sharing","ring"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-REPLICATED","title":"Replicated-sharing ring multiplication","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2018-ABY3"],"status":"published","evidence":"primary_source_checked","tags":["replicated-sharing","ring","high-throughput"]},"sections":[{"heading":"Role","content":"Combines overlapping share products with pairwise randomness to multiply ring-shared values with low bandwidth in 3PC/4PC settings."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-REPLICATED"},{"id":"MPC-COMP-EVAL-YAO","type":"component","title":"Yao garble-and-evaluate","subtitle":"evaluation protocol","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"One party garbles a Boolean circuit and the other evaluates it on obliviously transferred input labels.","tags":["2pc","yao"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-EVAL-YAO","title":"Yao garble-and-evaluate","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2009-PRACTICAL2PC"],"status":"published","evidence":"primary_source_checked","tags":["yao","2pc"]},"sections":[{"heading":"Role","content":"One party garbles a Boolean circuit and the other evaluates it on obliviously transferred input labels."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-EVAL-YAO"},{"id":"MPC-COMP-OUT-ABORT","type":"component","title":"Reconstruction with abort on failure","subtitle":"output recovery layer","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Honest parties either accept a reconstructed output or detect failure and abort; fairness and guaranteed delivery are not implied.","tags":["abort","output"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-OUT-ABORT","title":"Reconstruction with abort on failure","component_kind":"output_recovery_layer","paper_ids":["MPC-PAPER-2011-SPDZ","MPC-PAPER-2012-TINYOT"],"status":"published","evidence":"primary_source_checked","tags":["abort","output"]},"sections":[{"heading":"Role","content":"Honest parties either accept a reconstructed output or detect failure and abort; fairness and guaranteed delivery are not implied."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-OUT-ABORT"},{"id":"MPC-COMP-OUT-ASYNC","type":"component","title":"Asynchronous agreement and reconstruction","subtitle":"output recovery layer","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Coordinates progress and reconstruction without timing bounds while tolerating the asynchronous honest-majority corruption threshold.","tags":["agreement","asynchronous","output"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-OUT-ASYNC","title":"Asynchronous agreement and reconstruction","component_kind":"output_recovery_layer","paper_ids":["MPC-PAPER-1993-ASYNC"],"status":"published","evidence":"primary_source_checked","tags":["asynchronous","agreement","output"]},"sections":[{"heading":"Role","content":"Coordinates progress and reconstruction without timing bounds while tolerating the asynchronous honest-majority corruption threshold."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-OUT-ASYNC"},{"id":"MPC-COMP-OUT-HONEST-MAJORITY","type":"component","title":"Honest-majority robust reconstruction","subtitle":"output recovery layer","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Uses honest-majority error correction and verifiable sharing so qualified honest parties can reconstruct despite Byzantine shares.","tags":["guaranteed-output","honest-majority","robustness"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-OUT-HONEST-MAJORITY","title":"Honest-majority robust reconstruction","component_kind":"output_recovery_layer","paper_ids":["MPC-PAPER-1988-BGW"],"status":"published","evidence":"primary_source_checked","tags":["robustness","guaranteed-output","honest-majority"]},"sections":[{"heading":"Role","content":"Uses honest-majority error correction and verifiable sharing so qualified honest parties can reconstruct despite Byzantine shares."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-OUT-HONEST-MAJORITY"},{"id":"MPC-COMP-REP-ARITH-FIELD","type":"component","title":"Arithmetic circuit over a field","subtitle":"representation","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Expresses computation with field additions and multiplications, supporting polynomial sharing and triple-based multiplication.","tags":["arithmetic","field"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-REP-ARITH-FIELD","title":"Arithmetic circuit over a field","component_kind":"representation","paper_ids":["MPC-PAPER-1988-BGW","MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ"],"status":"published","evidence":"primary_source_checked","tags":["arithmetic","field"]},"sections":[{"heading":"Role","content":"Expresses computation with field additions and multiplications, supporting polynomial sharing and triple-based multiplication."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-REP-ARITH-FIELD"},{"id":"MPC-COMP-REP-ARITH-RING","type":"component","title":"Arithmetic circuit over a 2-power ring","subtitle":"representation","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Uses native fixed-width integer arithmetic over a ring such as Z/2^kZ; field-only checks and proofs do not transfer automatically.","tags":["arithmetic","ring"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-REP-ARITH-RING","title":"Arithmetic circuit over a 2-power ring","component_kind":"representation","paper_ids":["MPC-PAPER-2018-ABY3","MPC-PAPER-2024-HPMPC"],"status":"published","evidence":"primary_source_checked","tags":["arithmetic","ring"]},"sections":[{"heading":"Role","content":"Uses native fixed-width integer arithmetic over a ring such as Z/2^kZ; field-only checks and proofs do not transfer automatically."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-REP-ARITH-RING"},{"id":"MPC-COMP-REP-BOOLEAN","type":"component","title":"Boolean circuit representation","subtitle":"representation","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Represents a functionality as XOR/AND or general Boolean gates; depth and non-XOR count drive different protocols differently.","tags":["boolean","circuit"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-REP-BOOLEAN","title":"Boolean circuit representation","component_kind":"representation","paper_ids":["MPC-PAPER-1982-YAO","MPC-PAPER-1987-GMW"],"status":"published","evidence":"primary_source_checked","tags":["boolean","circuit"]},"sections":[{"heading":"Role","content":"Represents a functionality as XOR/AND or general Boolean gates; depth and non-XOR count drive different protocols differently."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-REP-BOOLEAN"},{"id":"MPC-COMP-REP-MIXED","type":"component","title":"Mixed arithmetic/Boolean/garbled representation","subtitle":"representation","status":"published","evidence":"primary_source_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Partitions one computation across domains and makes conversion gates explicit rather than forcing every operation into one circuit type.","tags":["conversion","mixed-protocol"],"metadata":{"dossier_type":"technique","id":"MPC-COMP-REP-MIXED","title":"Mixed arithmetic/Boolean/garbled representation","component_kind":"representation","paper_ids":["MPC-PAPER-2015-ABY","MPC-PAPER-2018-ABY3","MPC-PAPER-2020-MOTION"],"status":"published","evidence":"primary_source_checked","tags":["mixed-protocol","conversion"]},"sections":[{"heading":"Role","content":"Partitions one computation across domains and makes conversion gates explicit rather than forcing every operation into one circuit type."}],"sourcePath":"data/mpc-catalog.json#MPC-COMP-REP-MIXED"},{"id":"MPC-OP-001","type":"open_problem","title":"Efficient constant-round information-theoretic MPC for general circuits","subtitle":"","status":"open","evidence":"fulltext_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Can general computation have information-theoretic privacy, a constant number of interaction rounds, and polynomial communication and computation at the same time? Fix static passive corruption of fewer than half of the parties, with synchronous private authenticated channels and broadcast. For arbitrary polynomial-size Boolean circuits, require statistical simulation security with negligible error and an absolute constant…","tags":[],"metadata":{"dossier_type":"open_problem","id":"MPC-OP-001","title":"Efficient constant-round information-theoretic MPC for general circuits","origin_type":"explicit_open_question","origin_evidence":[{"paper":"MPC-PAPER-2023-AKP","relation":"explicit_open_question","locator":"§1.1.3, paragraph following Theorem 1.5 and footnote 3, numbered PDF p. 8"},{"paper":"MPC-PAPER-2026-IT-CONSTANT-ROUND","relation":"explicit_open_question","locator":"§1.1, opening and semi-honest-security paragraphs, numbered PDF p. 3"}],"faithful_source_statement":"AKP23 states that removing the exponential dependence on circuit depth from constant-round information-theoretic MPC is open even for a passive adversary corrupting one party. The 2026 fall-back-security manuscript again identifies extending efficient constant-round information-theoretic computation to general circuits as open.","normalization_delta":"The historical depth-dependence question is made into a polynomial-efficiency target for general Boolean circuits with static passive honest-majority corruption. This intentionally does not additionally require active security, an optimal exact round count, adaptive corruption, or fall-back security. Polynomial dependence on the number of participants is required for the full target; the fixed three-party one-corruption case is recorded as a weaker milestone, not silently equated with the full target.","target_profile":{"task":"general_circuit_mpc","functionality":"arbitrary_polynomial_size_Boolean_circuits","parties":"n_growing_polynomially_with_security_parameter","threshold":"t_less_than_n_over_2","adversary_behavior":"passive","corruption_timing":"static","security":"statistical_simulation_against_computationally_unbounded_adversaries","network":"synchronous_private_authenticated_point_to_point_and_broadcast","setup":"no_trusted_correlated_setup_beyond_declared_channels","assumptions":"none","rounds":"absolute_constant_independent_of_circuit_depth_size_and_party_count","local_work_and_total_communication":"polynomial_in_security_parameter_party_count_and_circuit_size","error":"negligible_in_statistical_security_parameter"},"resolution_condition":"Give a uniform protocol family and statistical simulation proof for arbitrary polynomial-size Boolean circuits under the stated passive honest-majority model, with an absolute constant number of rounds and polynomial local work and total communication in κ, n and circuit size. All setup, preprocessing and expansion costs must be included; no depth-exponential work, circuit-size-dependent number of rounds, or cryptographic hardness assumption may be hidden in preprocessing.","hierarchy_role":null,"hierarchy_links":[],"status":"open","evidence":"fulltext_checked","provenance":["MPC-PAPER-2023-AKP","MPC-PAPER-2026-IT-CONSTANT-ROUND"],"closest_results":["MPC-CONTRIB-1988-BGW-THRESHOLDS","MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL"],"routes":[],"barriers":[],"milestones":["Achieve constant rounds and polynomial overhead for arbitrary circuits with three parties and one static passive corruption, explicitly counting all preprocessing.","Remove exponential participant-count dependence from the four-round statistical GOD construction without conflating that improvement with eliminating depth dependence.","Extend a precisely stated information-theoretic encoding or secure-reduction class while preserving polynomial size and a constant number of interactive rounds."],"milestone_tracks":["weak_model","participant_scaling","encoding"]},"sections":[{"heading":"Exact normalized target","content":"Can general computation have information-theoretic privacy, a constant number of interaction rounds, and polynomial communication and computation at the same time? Fix static passive corruption of fewer than half of the parties, with synchronous private authenticated channels and broadcast. For arbitrary polynomial-size Boolean circuits, require statistical simulation security with negligible error and an absolute constant round count independent of circuit depth, size and number of parties. All work and communication, including preprocessing, must be polynomial in those parameters and the security parameter. Computational hardness assumptions and trusted correlated preprocessing are not part of this target."},{"heading":"Research history","content":"The classical honest-majority protocols establish general information-theoretic computation, but evaluating the circuit layer by layer retains depth-dependent interaction. Constant-round constructions approach the problem from the other direction: compress interaction while paying for a low-depth encoding of the function. MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL settles four-round statistical MPC with GOD at the honest-majority threshold, yet its work is polynomial in κ, 2^n, circuit size and 2^D. The paragraph after its Theorem 1.5 explicitly distinguishes the remaining efficiency question from this round-feasibility theorem."},{"heading":"Closest known results","content":"MPC-CONTRIB-1988-BGW-THRESHOLDS provides the general-computation, information-theoretic starting point; it does not remove circuit depth from interaction. MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL gives four rounds with a stronger active-security and output-delivery guarantee than this target, but does not achieve polynomial overhead for arbitrary depths or participant counts. MPC-PAPER-2026-IT-CONSTANT-ROUND still instantiates efficient information-theoretic base protocols for NC¹ and explicitly leaves the general extension open. These are complementary boundaries, not a ranking of protocols with identical guarantees."},{"heading":"Known obstacles","content":"The reviewed constant-round route encodes computation in a form whose size can grow exponentially with depth. Removing this cost without replacing statistical privacy by computational indistinguishability is the unresolved step. This is a limitation of available constructions, not a lower bound ruling out every information-theoretic method. Likewise, the NC¹ description is not an absolute class boundary: MPC-PAPER-2023-AKP notes secure reductions from log-space functions."},{"heading":"What would not resolve it","content":"A constant-round protocol using a random oracle or cryptographic hardness, a protocol with depth-exponential preprocessing, or an efficient protocol only for an expressly restricted function class does not settle the general target. Solving the fixed three-party passive case would be substantial progress, but would not by itself prove the full participant-scaling statement."}],"sourcePath":"data/mpc-catalog.json#MPC-OP-001"},{"id":"MPC-OP-002","type":"open_problem","title":"Random-OT correlation generators from general one-way functions","subtitle":"","status":"open","evidence":"claim_audited","year":null,"venue":null,"primaryUrl":null,"summary":"Can two parties expand short correlated seeds into a polynomially larger batch of random oblivious transfers, with no communication during expansion, assuming only the existence of one-way functions? For each random bit OT, the sender obtains two random bits and the receiver obtains a random choice bit and its selected sender bit. Revealing either party's seed must not reveal the other party's outputs beyond the standard…","tags":[],"metadata":{"dossier_type":"open_problem","id":"MPC-OP-002","title":"Random-OT correlation generators from general one-way functions","origin_type":"explicit_open_question","origin_evidence":[{"paper":"MPC-PAPER-2026-IKR-PCF","relation":"explicit_open_question","locator":"ITC 2026 proceedings, §1.4, p. 7:7; PCG model in §2.3, pp. 7:10–7:11"}],"faithful_source_statement":"IKR explicitly leave open PCGs for oblivious transfer based only on symmetric cryptography, meaning assumptions equivalent to general one-way functions.","normalization_delta":"The card selects random bit OT, specifies genuine polynomial seed expansion and standard insider security for corruptible correlations, and permits correlated seed setup. It does not require a PCF, public-key setup, quantum security, or a plain-model OT protocol from OWF.","target_profile":{"task":"random_bit_OT_pseudorandom_correlation_generator","parties":2,"assumptions":"general_OWF_or_equivalent_general_PRG_PRF_only","excluded_extra_assumptions":["LPN_variant","lattice_assumption","group_assumption","random_oracle"],"setup":"correlated_seed_sampler_allowed_distribution_protocol_cost_separate","expansion":"local_noninteractive_from_compact_correlated_seeds","compression":"N_at_least_m_power_1_plus_epsilon_for_some_fixed_positive_epsilon_where_m_is_total_seed_bits","security":"computational_insider_security_relative_to_corruptible_random_OT_with_one_exposed_seed","correctness_error":"negligible_in_lambda","security_error":"negligible_in_lambda","computational_model":"classical_probabilistic_polynomial_time"},"resolution_condition":"Give a PCG construction and reduction from arbitrary OWF (or a general PRG/PRF) for polynomially many random bit OTs, with polynomial-time Gen and Expand, total seed length m and N at least m^(1+epsilon) outputs for some fixed epsilon>0, negligible correctness and distinguishing error, and standard one-party insider security relative to the corruptible ideal OT correlation. Correlated seeds may be sampled centrally; securely distributing them is a separate task, not a required OWF-only protocol.","hierarchy_links":[],"status":"open","evidence":"claim_audited","provenance":["MPC-PAPER-2026-IKR-PCF","MPC-PAPER-2019-PCG"],"closest_results":["MPC-CONTRIB-2019-PCG-SILENT","MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF"],"routes":[],"barriers":[]},"sections":[{"heading":"Exact normalized target","content":"Can two parties expand short correlated seeds into a polynomially larger batch of random oblivious transfers, with no communication during expansion, assuming only the existence of one-way functions? For each random bit OT, the sender obtains two random bits and the receiver obtains a random choice bit and its selected sender bit. Revealing either party's seed must not reveal the other party's outputs beyond the standard corruptible ideal correlation. Both generation and expansion must be polynomial time, with negligible error. With m total seed bits, the batch contains at least m^(1+ε) bit OTs for some fixed ε > 0: this makes the polynomial expansion requirement explicit rather than allowing the seeds to store the output batch. Correlated seed setup is allowed and its cost is accounted for separately; this question does not ask for base OT from OWF without setup."},{"heading":"Research history","content":"MPC-CONTRIB-2019-PCG-SILENT makes compact correlated seeds and local expansion a reusable interface. It supplies silent OT under its stated construction assumptions. MPC-PAPER-2026-IKR-PCF, §1.4, then isolates the remaining assumption question: can general symmetric primitives support OT correlations, beyond the restricted correlation types already known?"},{"heading":"Closest known results","content":"The 2019 silent-OT contribution achieves the desired expansion interface using a binary-LPN variant and correlation-robust hashing, not a generic reduction from arbitrary OWF. IKR's PRF-based small-scalar VOLE meets the weak-assumption goal for a different correlation: one scalar is shared across a vector, rather than providing independently chosen random OTs. Neither closes the conjunction in this question."},{"heading":"Known obstacles","content":"The reviewed sources do not give a general impossibility theorem for this target. The current gap is a construction gap between the supported correlation and the permitted assumptions. A reduction from VOLE to OT must preserve compression, seed privacy, and the no-communication expansion interface; a low-communication OT extension protocol alone does not establish those properties."},{"heading":"What would not resolve it","content":"An LPN-, lattice-, or group-based silent OT construction changes the assumption coordinate. An OT extension with communication during expansion changes the interface. Storing the entire OT batch in the seeds is not compression. Requiring setup-free base OT would instead be a different question."}],"sourcePath":"data/mpc-catalog.json#MPC-OP-002"},{"id":"MPC-OP-003","type":"open_problem","title":"Polynomial-party-cost scalar-vector correlation functions from symmetric cryptography","subtitle":"","status":"open","evidence":"claim_audited","year":null,"venue":null,"primaryUrl":null,"summary":"Can many parties generate scalar-vector multiplication correlations from compact PRF-based keys without a cost exponential in the number of parties? Fix the field to F2. The parties hold additive shares of one random scalar x, a random vector a, and x·a. A PCF must let each party evaluate a chosen vector coordinate locally. Setup computation, key size, and each local evaluation should be polynomial in party count k, security…","tags":[],"metadata":{"dossier_type":"open_problem","id":"MPC-OP-003","title":"Polynomial-party-cost scalar-vector correlation functions from symmetric cryptography","origin_type":"explicit_open_question","origin_evidence":[{"paper":"MPC-PAPER-2026-IKR-PCF","relation":"explicit_open_question","locator":"ITC 2026 proceedings, §6, p. 7:19; Theorem 2, p. 7:6; Corollary 27, pp. 7:16–7:17"}],"faithful_source_statement":"IKR ask whether the exponential dependence on scalar bit-length and number of parties in their VOLE-style PCF computation and storage costs is inherent.","normalization_delta":"Isolate party scaling by fixing both the vector field and every scalar-share domain to F2. Require polynomial rather than merely improved exponential cost, preserve full k−1 insider-coalition security and PCF indexed access, and do not add authenticated triples or a complete MPC protocol. The polynomial target is a positive resolution of this specialized source question, not a quotation of the source's entire broader question.","target_profile":{"task":"k_party_scalar_vector_multiplication_PCF","vector_field":"F2","scalar_share_distribution":"uniform_independent_F2_shares_joint_support_F2_power_k","target_correlation":"additive_shares_of_x_a_and_xa_with_one_scalar_across_vector_coordinates","assumptions":"general_PRF_or_equivalent_OWF_only","coalition":"every_fixed_strict_subset_including_k_minus_1_exposed_keys","security":"computational_insider_security_relative_to_corruptible_SVMT","evaluation_access":"adaptively_chosen_indices_in_domain_of_size_N","total_setup_work":"polynomial_in_k_lambda_logN","per_party_key_bits":"polynomial_in_k_lambda_logN","per_party_per_coordinate_work":"polynomial_in_k_lambda_logN","errors":"negligible_in_lambda_for_polynomially_bounded_k_and_query_count","distribution_phase":"correlated_key_sampling_allowed_secure_distribution_accounted_separately"},"resolution_condition":"Construct a PRF-based PCF for k-party SVMT over F2 with polynomial(k,lambda,log N) key generation, key size, and per-coordinate evaluation, negligible correctness and distinguishing error, and insider security for any fixed coalition of up to k−1 exposed keys under adaptive index queries. The result must not hide exponential party dependence in a field, security parameter, setup phase, or weakened corruption threshold.","hierarchy_links":[],"status":"open","evidence":"claim_audited","provenance":["MPC-PAPER-2026-IKR-PCF"],"closest_results":["MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF"],"routes":[],"barriers":[]},"sections":[{"heading":"Exact normalized target","content":"Can many parties generate scalar-vector multiplication correlations from compact PRF-based keys without a cost exponential in the number of parties? Fix the field to F2. The parties hold additive shares of one random scalar x, a random vector a, and x·a. A PCF must let each party evaluate a chosen vector coordinate locally. Setup computation, key size, and each local evaluation should be polynomial in party count k, security parameter λ, and index length log N, while remaining secure against any fixed coalition of up to k−1 exposed keys. Evaluation indices may be chosen adaptively; party corruptions are not being upgraded to adaptive corruption. All errors remain negligible."},{"heading":"Research history","content":"MPC-PAPER-2026-IKR-PCF extends the secret-projection approach from two-party small-scalar VOLE to multiparty scalar-vector triples. Its construction supplies consistent cross-terms without leaking a sender's vector to colluding receivers. Section 6 asks whether the resulting dependence on party count is necessary. Fixing F2 separates this question from the independent cost of large scalar domains."},{"heading":"Closest known results","content":"IKR's construction already has the required PRF assumption and coalition threshold. For F2, each party holds k·2^(k−1) − (k−1)·2^(k−2) + 2k−2 PRF keys and evaluates each key once per coordinate. It therefore establishes feasibility, but not the polynomial-party cost target. Correlated key distribution must still be costed separately from local evaluation."},{"heading":"Known obstacles","content":"Simply reusing the same line for multiple VOLE receivers lets colluding receivers recover its slope. IKR avoid that specific leakage using independent intercepts, but their replicated-key construction then has combinatorial growth. This rules out that naive reuse, not all polynomial-cost constructions. IKR's footnote 2 discusses a multiparty-DPF improvement with polynomially many keys and inverse-polynomial error before application-level amplification. The source explicitly leaves unclear how that amplification would preserve the SVMT PCF interface. A negligible-error proof is therefore a substantive remaining obligation, not an automatic consequence of the DPF result."},{"heading":"What would not resolve it","content":"Reducing only a constant in the exponential cost, fixing k to a small constant, weakening to bounded-size coalitions, or retaining inverse-polynomial error does not meet this target. A PCG with only sequential expansion is a useful weaker object, not the required random-access PCF. Extra LPN or public-key assumptions change the question rather than settling the symmetric-only target."}],"sourcePath":"data/mpc-catalog.json#MPC-OP-003"},{"id":"MPC-OP-004","type":"open_problem","title":"Constant-overhead statistical MPC with GOD for a general circuit","subtitle":"","status":"open","evidence":"fulltext_checked","year":null,"venue":null,"primaryUrl":null,"summary":"Can a single general arithmetic circuit be evaluated with constant communication overhead and guaranteed output delivery, without a huge batch of identical computations? Fix n = 3t+1, synchronous private authenticated channels, statistical security against an adaptive malicious unbounded adversary, and O(D) expected rounds, where D is multiplicative depth. Require a constant number of field elements per multiplication gate…","tags":[],"metadata":{"dossier_type":"open_problem","id":"MPC-OP-004","title":"Constant-overhead statistical MPC with GOD for a general circuit","origin_type":"explicit_open_question","origin_evidence":[{"paper":"MPC-PAPER-2025-CDPP","relation":"explicit_open_question","locator":"Current 2026-05-22 revision, §1.3 Open Problems, fourth question, numbered PDF p. 3; model in §3 p. 11"},{"paper":"MPC-PAPER-2026-BEP","relation":"stated_limitation","locator":"§1 discussion before §1.1, numbered PDF p. 2, and §1.2, p. 3, distinguishing abort from GOD"}],"faithful_source_statement":"CDPP explicitly asks for a general-circuit MPC protocol simultaneously providing constant communication overhead, O(D) rounds and GOD, and separately asks to reduce its Θ(n^7) SIMD requirement. BEP states that its low-communication active result has abort rather than GOD and identifies guaranteed delivery at the corresponding communication level as still open.","normalization_delta":"The general-circuit question is fixed to CDPP's synchronous n=3t+1 model with adaptive malicious unbounded corruption and expected O(D) rounds. A single arbitrary circuit replaces the Θ(n^7)-copy SIMD workload. Constant overhead means a constant number of field elements per multiplication gate, not constant bits independent of security; setup and input/output terms must be explicit and cannot conceal a per-gate n factor or a required batch of independent evaluations. Constant local-computation overhead is not added to the source question.","target_profile":{"task":"general_arithmetic_circuit_mpc","functionality":"single_arbitrary_circuit_with_one_field_input_per_party_and_one_common_output","threshold":"n_equals_3t_plus_1","adversary_behavior":"malicious_rushing_computationally_unbounded","corruption_timing":"adaptive","security":"statistical_simulation_with_negligible_error","output_guarantee":"guaranteed_output_delivery","network":"synchronous_private_authenticated_point_to_point","broadcast_accounting":"count_broadcast_emulation_in_total_communication_and_expected_rounds","setup":"no_trusted_preprocessing_all_correlations_generated_and_charged","assumptions":"none","field":"finite_field_with_log_size_Theta_kappa_and_size_at_least_circuit_size_plus_n","rounds":"O_multiplicative_depth_expected_including_preprocessing","communication":"O_1_field_elements_per_multiplication_gate_with_explicit_input_output_and_circuit_independent_setup_terms","batch_requirement":"none_for_independent_circuit_evaluations","local_work":"polynomial_not_required_constant_overhead"},"resolution_condition":"Construct and prove a statistically secure protocol with GOD against the stated adaptive malicious adversary for one arbitrary arithmetic circuit, with O(D) expected rounds and a total communication bound whose circuit-dependent multiplication term is O(c_M) field elements with coefficient independent of n and c_M. State field size, statistical error, broadcast emulation, correlation generation, input/output costs and any circuit-independent setup term explicitly. The bound must not require Θ(n^7) or another growing number of independent evaluations and must not hide an n or log |C| multiplier on the circuit term in preprocessing or setup.","hierarchy_role":null,"hierarchy_links":[],"status":"open","evidence":"fulltext_checked","provenance":["MPC-PAPER-2025-CDPP","MPC-PAPER-2026-BEP"],"closest_results":["MPC-CONTRIB-2025-CDPP-SIMD-GOD","MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT"],"routes":[],"barriers":[],"milestones":["Reduce the Θ(n^7) SIMD requirement while retaining the current statistical security, GOD, and expected O(D) round guarantees, and give the full new cost formula.","Handle single general circuits at the target communication level with a stated relaxation such as static corruption or O(D)+poly(n) rounds; label the relaxation instead of declaring the full target resolved.","Replace one explicitly identified abort-only consistency primitive by a robust primitive and prove that its recovery cost preserves the desired total circuit-dependent overhead."],"milestone_tracks":["batch_size","relaxed_model","robust_primitives"]},"sections":[{"heading":"Exact normalized target","content":"Can a single general arithmetic circuit be evaluated with constant communication overhead and guaranteed output delivery, without a huge batch of identical computations? Fix n = 3t+1, synchronous private authenticated channels, statistical security against an adaptive malicious unbounded adversary, and O(D) expected rounds, where D is multiplicative depth. Require a constant number of field elements per multiplication gate in the total cost, including preprocessing. Field size, input/output costs, broadcast emulation and any circuit-independent setup term must be shown separately. No computational assumption or trusted supply of free correlated randomness is allowed. Use the source convention of Θ(κ)-bit field elements with |F| at least the circuit size plus n; the party count and circuit size are polynomially bounded in κ. The target therefore does not conceal a growing field word behind a claim of constant bit cost."},{"heading":"Research history","content":"Secret-sharing protocols make linear gates local and use interaction for multiplication. Packing many values together reduces communication, but active behavior creates a further choice: detect inconsistency and abort, or repair enough state to guarantee completion. The 2026 revision of CDPP approaches the second option with robust packed-sharing primitives and large-scale batching (MPC-PAPER-2025-CDPP). MPC-PAPER-2026-BEP improves the leading computation and communication costs of active CRT-based evaluation, but remains on the with-abort side. These are different ways of approaching the conjunction, not two versions of the same theorem."},{"heading":"Closest known results","content":"MPC-CONTRIB-2025-CDPP-SIMD-GOD, in its 2026 revision, attains statistical GOD and O(D) expected rounds, but Theorem 7.1 evaluates Θ(n^7) copies of the circuit. Its total communication is O(c_M n^7+n^8) field elements, with symbols of O(κ) bits under the source's field convention. General-circuit-to-SIMD compilation can add a log |C| factor and, for irregular deep circuits, a further additive cost. MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT handles general arithmetic circuits with active security with abort and leading O(|C| log |F|) bit costs. Its theorem assumes log |F| = Ω(n² log n) and suppresses statistical-security, log n and log log |F| factors. Neither GOD, an adaptive-corruption upgrade, nor the exact round target is inferred from that statement. It is a neighboring cost result, not a theorem missing only one parameter."},{"heading":"Known obstacles","content":"An abort-only check detects cheating but does not supply a way to continue with consistent state. Highly packed sharing also leaves less redundancy for correction: MPC-PAPER-2025-CDPP explains why a prior Reed–Solomon correction route does not directly extend to its packed degrees. Robust primitives restore the delivery guarantee, but their fixed costs currently require a large batch to amortize. These are stated construction bottlenecks, not an impossibility theorem excluding all robust low-communication protocols."},{"heading":"What would not resolve it","content":"An online-only cost bound with uncharged preprocessing, a protocol that may abort, or constant overhead obtained only by evaluating many independent copies does not meet this target. A result for n = 3t+1 also does not imply the same bound at every honest-majority threshold. Constant overhead here means field elements, with their security-dependent bit length disclosed; it does not mean a constant number of bits per gate."}],"sourcePath":"data/mpc-catalog.json#MPC-OP-004"},{"id":"MPC-OP-005","type":"open_problem","title":"Does the 1.5λ AND-gate lower bound survive unrestricted evaluator queries?","subtitle":"","status":"open","evidence":"claim_audited","year":null,"venue":null,"primaryUrl":null,"summary":"Can a Free-XOR-compatible AND gate use fewer bits by allowing its evaluator to choose hash queries adaptively, or without knowing which other input evaluations share each query? Or does the 1.5λ − negl(λ) lower bound still hold? Keep JRR25's single-gate interface: the garbler receives the input labels and chooses output labels; all labels have λ bits and the same global Free-XOR offset. Keep its Definition 16 strong…","tags":[],"metadata":{"dossier_type":"open_problem","id":"MPC-OP-005","title":"Does the 1.5λ AND-gate lower bound survive unrestricted evaluator queries?","origin_type":"normalized_lineage_gap","origin_evidence":[{"paper":"MPC-PAPER-2021-THREE-HALVES","relation":"explicit_open_question","locator":"ePrint 2021/749, §8 “Optimality”, p. 25"},{"paper":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","relation":"stated_limitation","locator":"ePrint 2025/876, §1.1 pp. 3–4; Definitions 12–16 pp. 9–12; Theorem 26 and Corollary 27 p. 23"}],"faithful_source_statement":"RR21 asks whether the 1.5κ cost for garbled AND gates is optimal in a more inclusive model, suggesting Minicrypt. JRR25 proves a matching bound under non-adaptive coordinated evaluator queries and explicitly describes those query restrictions as potentially limiting.","normalization_delta":"Isolate one residual of the broader optimality question by removing only JRR25's two evaluator-query restrictions. Retain its single-gate syntax, Free-XOR label distribution and Definition 16 strong security. Ask about the stated 1.5λ − negl(λ) lower bound, not merely its leading coefficient, and allow either a proof or an in-model counterexample. This exact relaxation is curator-normalized, not an author-stated conjecture that the bound must hold.","target_profile":{"task":"single_AND_gate_lower_bound_extension","gate_class":"JRR25_Gand_with_input_and_output_bit_flips","syntax":"JRR25_Definition_12_input_to_output_gate_garbling","wire_labels":"lambda_bits_with_JRR25_CompLbl_free_xor_common_offset_on_inputs_and_outputs","security":"JRR25_Definition_16_strong_security","adversary":"computationally_unbounded_with_polynomially_many_random_oracle_queries","evaluator_queries":"polynomially_many_adaptive_or_uncoordinated_queries_allowed","garbler_queries":"unchanged_from_JRR25_no_new_query_restrictions","cost":"same_garbled_gate_size_measure_as_JRR25_Theorem_26","target_bound":"1.5_lambda_minus_negligible_in_lambda","accounting":"single_gate_not_whole_circuit_amortization"},"resolution_condition":"Prove the 1.5λ − negl(λ) size lower bound for all schemes in this retained model without either evaluator-query restriction, or exhibit a strongly secure scheme family in precisely that model that refutes the bound. Merely dropping one restriction proves a partial extension; changes of label distribution, security definition, primitive model or gatewise interface do not settle this target.","hierarchy_links":[],"status":"open","evidence":"claim_audited","provenance":["MPC-PAPER-2021-THREE-HALVES","MPC-PAPER-2025-JRR-GARBLING-BOUNDS","MPC-PAPER-2026-LS-GARBLING"],"closest_results":["MPC-CONTRIB-2021-THREE-HALVES","MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND"],"routes":[],"barriers":[]},"sections":[{"heading":"Exact normalized target","content":"Can a Free-XOR-compatible AND gate use fewer bits by allowing its evaluator to choose hash queries adaptively, or without knowing which other input evaluations share each query? Or does the 1.5λ − negl(λ) lower bound still hold? Keep JRR25's single-gate interface: the garbler receives the input labels and chooses output labels; all labels have λ bits and the same global Free-XOR offset. Keep its Definition 16 strong security, which reveals complementary labels only after oracle access is revoked. Remove only the non-adaptive and coordinated-query requirements. “Adaptive” concerns the evaluator's dependence on earlier oracle answers, not adaptive inputs or corruptions. This is a precisely scoped residual of the broader optimality question. Either an extended lower-bound proof or a counterexample under these retained conditions would answer it. No assertion is made that the extension must be true."},{"heading":"Research history","content":"Half-gates achieved two ciphertexts per AND gate within its linear model. MPC-PAPER-2021-THREE-HALVES escaped that model with slicing and dicing while retaining Free-XOR compatibility, then explicitly asked about optimality in more inclusive models (§8, p. 25). MPC-PAPER-2025-JRR-GARBLING-BOUNDS answered part of that question: information inequalities give a matching single-gate lower bound under two evaluator-query restrictions. Its §1.1 identifies those restrictions as potentially limiting. Removing them while fixing the other coordinates is the residual here."},{"heading":"Closest known results","content":"MPC-CONTRIB-2021-THREE-HALVES supplies the upper reference point: 1.5λ + O(1) bits with Free-XOR compatibility, including a gate-hiding variant. MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND proves 1.5λ − negl(λ) when evaluator queries are non-adaptive and coordinated (Theorem 26 and Corollary 27, p. 23). The remaining difference is the permitted query behavior, not a missing better construction within that restricted model. MPC-CONTRIB-2026-LS-BATCHED-GARBLING gives a different whole-circuit tradeoff: O(|C| log T + Dκ² log T) bits with error 2^(−κ) against a T-query adversary. Its layer batching and non-projective input encoding bypass the single-gate interface (§1.2, pp. 7–8). It is relevant context, not a counterexample or a closest-result edge to this target."},{"heading":"Known obstacles","content":"Within JRR25's existing query model, its lower bound already prevents smaller gates. A construction must escape at least one of the two query restrictions; an extended proof must justify information constraints without relying on both. Proving an extension after removing only one restriction is useful partial progress. Changing input/output label correlations can produce smaller isolated gates, but loses the retained composable Free-XOR interface. Likewise, whole-circuit amortization is a different problem. Neither is evidence of impossibility for the query relaxation itself."},{"heading":"What would not resolve it","content":"Beating the old half-gates 2λ cost is already accomplished. Reducing label security, requiring only authenticity without privacy, replacing strong security with a weaker game, or adding public-key primitives changes the target. The question also does not assert an Ω(|C|κ) lower bound for general garbled circuits: LS26 has already improved that cost in its stated parameter regimes."}],"sourcePath":"data/mpc-catalog.json#MPC-OP-005"}],"edges":[{"id":"MPC-REL-003744DF9B0B55","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0126561756AF52","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-ENC-GARBLED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-019E3F65E50ABA","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-REP-ARITH-RING","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-030A78A777D97E","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-COMP-ENC-GARBLED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-030F9BBB5EE298","source":"MPC-PAPER-2023-AKP","target":"MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-03A1842D2030B2","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-PAPER-2015-BMR-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-07F81FD0326651","source":"MPC-CONTRIB-2011-SPDZ-AUTH","target":"MPC-CONTRIB-2015-BMR-SPDZ","type":"INSTANTIATES_OFFLINE_PHASE","note":"The BMR+SPDZ construction uses SPDZ as the actively secure arithmetic engine that prepares and checks the distributed garbling.","reviewStatus":"primary_source_checked","evidenceLocator":"BMR+SPDZ abstract and Section 4","evidenceUrl":"https://eprint.iacr.org/2015/523"},{"id":"MPC-REL-095508E65633E4","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-09DF193FA8533A","source":"MPC-COMP-EVAL-YAO","target":"MPC-PAPER-2009-PRACTICAL2PC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0AA2C25F841803","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-CONTRIB-2024-HPMPC-NETWORK","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0AF939A0595BF0","source":"MPC-PAPER-2010-FAIR","target":"MPC-CONTRIB-2010-FAIR-FUNCTIONS","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0BAA7B32F13A2A","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-PAPER-2015-ABY","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0D2636F2D3BE0B","source":"MPC-PROTOCOL-BMR-PASSIVE","target":"MPC-COMP-ENC-MULTI-GARBLED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0D725148AACE7B","source":"MPC-OP-002","target":"MPC-PAPER-2019-PCG","type":"GROUNDED_IN","note":"","reviewStatus":"claim_audited","evidenceLocator":"","evidenceUrl":"https://eprint.iacr.org/2019/448"},{"id":"MPC-REL-0E2B2652EEA49F","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0E9B4AA052EC44","source":"MPC-COMP-ACT-BGW-VSS","target":"MPC-PAPER-1988-BGW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-0F3896350FFFE1","source":"MPC-IMPL-2026-MPSPDZ-9D80959","target":"MPC-PROTOCOL-MASCOT-SPDZ","type":"IMPLEMENTS","note":"multi_configuration_framework; exact runtime flag selects the protocol","reviewStatus":"source_declared","evidenceLocator":"pinned README, documentation protocol table, and source tree","evidenceUrl":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9"},{"id":"MPC-REL-0F59571D8F995E","source":"MPC-PAPER-2021-THREE-HALVES","target":"MPC-CONTRIB-2021-THREE-HALVES","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-10D6B1C24B509B","source":"MPC-COMP-EVAL-GMW","target":"MPC-PAPER-1987-GMW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-122D3BAB8B2EE6","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-CONV-ABY3","type":"USES_COMPONENT","note":"conversion_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-134A79086FBF1B","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-149059E9723854","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-COMP-CORR-OTEXT","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-1674164475C608","source":"MPC-CONTRIB-2025-CDPP-SIMD-GOD","target":"MPC-OP-004","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"fulltext_checked","evidenceLocator":"ePrint 2025/1555 revision 2026-05-22, §1 adversary model (p. 1), §1.1 Theorem 1.1 (p. 2), §3 field/network convention (p. 11), §7 Theorem 7.1 and footnotes 9–10 (pp. 23–24)","evidenceUrl":"https://eprint.iacr.org/2025/1555"},{"id":"MPC-REL-16893B5F9FAB19","source":"MPC-CONTRIB-2008-FREEXOR","target":"MPC-CONTRIB-2015-HALFGATES","type":"BUILDS_ON_MECHANISM","note":"Half-gates retains Free-XOR compatibility while reducing each AND gate to two ciphertexts.","reviewStatus":"primary_source_checked","evidenceLocator":"Half-gates abstract and comparison with Free-XOR garbling","evidenceUrl":"https://www.cs.virginia.edu/~evans/pubs/ec2015/"},{"id":"MPC-REL-185715F5DD100A","source":"MPC-IMPL-2026-ABY-88FED3E","target":"MPC-PROTOCOL-ABY-PASSIVE","type":"IMPLEMENTS","note":"paper-aligned passive ABY configuration","reviewStatus":"source_declared","evidenceLocator":"pinned README and src/abycore circuit/share providers","evidenceUrl":"https://github.com/encryptogroup/ABY/tree/88fed3ef6789580cac342201e135a358a083ca36"},{"id":"MPC-REL-19A7E5A21079DF","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-CORR-OTEXT","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-1B6C2ED29BF325","source":"MPC-PROTOCOL-TINYOT","target":"MPC-COMP-ENC-AUTH-BITS","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-1B7B9F5ED3DBCF","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-EVAL-GMW","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-1BC40FA9891081","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-COMP-ENC-AUTH-ADDITIVE","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-1C088835F1A084","source":"MPC-CONTRIB-2011-SPDZ-AUTH","target":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","type":"IMPLEMENTS_AS_BACKEND","note":"MP-SPDZ realizes the SPDZ lineage alongside alternative offline phases and protocol families behind a common compiler/runtime.","reviewStatus":"primary_source_checked","evidenceLocator":"MP-SPDZ architecture and supported-protocol table","evidenceUrl":"https://eprint.iacr.org/2020/521"},{"id":"MPC-REL-1FA47EBB2B17F3","source":"MPC-IMPL-2026-MPSPDZ-9D80959","target":"MPC-PROTOCOL-SPDZ-SHE","type":"IMPLEMENTS","note":"multi_configuration_framework; exact runtime flag selects the protocol","reviewStatus":"source_declared","evidenceLocator":"pinned README, documentation protocol table, and source tree","evidenceUrl":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9"},{"id":"MPC-REL-2018950C717784","source":"MPC-COMP-CORR-BASEOT","target":"MPC-PAPER-1987-GMW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-20854AFDD2B3B6","source":"MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF","target":"MPC-OP-003","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"claim_audited","evidenceLocator":"ITC 2026 proceedings, Theorem 2, p. 7:6; Definition 6, pp. 7:8–7:9; §4.2 and Corollary 27, pp. 7:14–7:17; Definitions 12–13, pp. 7:10–7:11","evidenceUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7"},{"id":"MPC-REL-20A6506C6ACCD8","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-20BC28F9BA4226","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-CONTRIB-2011-SPDZ-AUTH","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-21024191D26F3C","source":"MPC-COMP-ENC-MULTI-GARBLED","target":"MPC-PAPER-2015-BMR-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2114BB76D6C167","source":"MPC-COMP-ENC-MULTI-GARBLED","target":"MPC-PAPER-2020-MOTION","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2173E49E0D7C3C","source":"MPC-COMP-EVAL-HPMPC-MASKED","target":"MPC-PAPER-2024-HPMPC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-24169C32A05747","source":"MPC-PROTOCOL-TINYOT","target":"MPC-PAPER-2003-IKNP","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-245EAF61C8BE0F","source":"MPC-PAPER-2016-MASCOT","target":"MPC-CONTRIB-2016-MASCOT-TRIPLES","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-24847DCD38C5C0","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-COMP-REP-ARITH-FIELD","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-252FD1BC5948DC","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-COMP-EVAL-YAO","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-257725DA5330A6","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-25FC1E9FCE4A36","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-COMP-ACT-SPDZ-MAC","type":"USES_COMPONENT","note":"active_security_enforcement","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-269921244F9CB1","source":"MPC-COMP-ENC-XOR","target":"MPC-PAPER-2012-TINYOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-269DB15A0DC61D","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-PAPER-2024-HPMPC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-274FBA8D1E021D","source":"MPC-COMP-ENC-XOR","target":"MPC-PAPER-1987-GMW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2828B0200FAA3B","source":"MPC-PAPER-1982-YAO","target":"MPC-CONTRIB-1982-YAO-2PC","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-28433BB69BB95B","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-COMP-REP-ARITH-RING","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2A786B678D77F6","source":"MPC-PAPER-2018-ABY3","target":"MPC-CONTRIB-2018-ABY3-REPLICATED","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2D600DD23E8A91","source":"MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT","target":"MPC-OP-004","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"fulltext_checked","evidenceLocator":"ePrint 2026/1270, §1.1 Theorem 1 and footnotes 3–4 (p. 2), preceding GOD discussion (p. 2) and §1.2 (p. 3)","evidenceUrl":"https://eprint.iacr.org/2026/1270"},{"id":"MPC-REL-2DF35EFA205049","source":"MPC-PROTOCOL-BGW-ACTIVE","target":"MPC-COMP-ENC-SHAMIR","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2E2E1DB6B695AC","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2E5F7C185CAC90","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-PAPER-2008-FREEXOR","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2FCA8FA9E80A26","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-COMP-EVAL-BEAVER","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-2FDA0B802F0AD0","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-ENC-ADDITIVE","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3016229D3A24B4","source":"MPC-PAPER-2026-IKR-PCF","target":"MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-307643416CEE1E","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-EVAL-BMR","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3155406FD17647","source":"MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND","target":"MPC-OP-005","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"claim_audited","evidenceLocator":"ePrint 2025/876, §1.1 (pp. 3–4), Definitions 12–14 (pp. 9–10), §3.3 and Definition 16 (pp. 11–12), Theorem 26 and Corollary 27 (p. 23); PDF page numbers match printed pages","evidenceUrl":"https://eprint.iacr.org/2025/876"},{"id":"MPC-REL-31F63DB02FB196","source":"MPC-PAPER-1990-BMR","target":"MPC-CONTRIB-1990-BMR-CONSTANT","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-33AD78CCA0EE2D","source":"MPC-OP-004","target":"MPC-PAPER-2026-BEP","type":"GROUNDED_IN","note":"","reviewStatus":"fulltext_checked","evidenceLocator":"§1 discussion before §1.1, numbered PDF p. 2, and §1.2, p. 3, distinguishing abort from GOD","evidenceUrl":"https://eprint.iacr.org/2026/1270"},{"id":"MPC-REL-33D8A10C556355","source":"MPC-COMP-CORR-MASCOT","target":"MPC-PAPER-2016-MASCOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-356372ABF2EB23","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-ENC-REPLICATED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3690221768385F","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-CONTRIB-2015-BMR-SPDZ","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3711992ABEC3A7","source":"MPC-COMP-EVAL-ABY3-YAO","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-379BD05850F63C","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-COMP-ACT-HPMPC4","type":"USES_COMPONENT","note":"active_security_enforcement","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3B82ABFE0C3941","source":"MPC-COMP-EVAL-BMR","target":"MPC-PAPER-2020-MOTION","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3C4599563F607A","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-CONTRIB-2018-ABY3-REPLICATED","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3D86473A3D4475","source":"MPC-COMP-ENC-HPMPC-MASKED","target":"MPC-PAPER-2024-HPMPC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3E6B993C7BA1C1","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-CONTRIB-1987-GMW-COMPILER","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-3F4ABA459CF790","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-PAPER-2009-PRACTICAL2PC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-43BC8B3DFE5792","source":"MPC-PAPER-2001-UC","target":"MPC-CONTRIB-2001-UC-COMPOSITION","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4554630F4868C2","source":"MPC-COMP-REP-ARITH-RING","target":"MPC-PAPER-2024-HPMPC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-46A71FA2E8B880","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-CORR-PAIRWISE","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-46B808C29BF284","source":"MPC-PAPER-1987-GMW","target":"MPC-CONTRIB-1987-GMW-COMPILER","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-489CB7F907BE7C","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-PAPER-2003-IKNP","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-48B43D7837F453","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-494A31489DD22B","source":"MPC-PAPER-2019-PCG","target":"MPC-CONTRIB-2019-PCG-SILENT","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4A638540DCF4F0","source":"MPC-PROTOCOL-BGW-ACTIVE","target":"MPC-COMP-ACT-BGW-VSS","type":"USES_COMPONENT","note":"active_security_enforcement","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4B3BC6FA967E86","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-COMP-CORR-SHE","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4B534D7A6596D6","source":"MPC-PAPER-2014-KSS","target":"MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4CB5F8F9A86A65","source":"MPC-COMP-EVAL-REPLICATED","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4CC19C082C2FC8","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4D42B19AC83F85","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-PAPER-2015-HALFGATES","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4D946D86F0D695","source":"MPC-PAPER-2000-CDM","target":"MPC-CONTRIB-2000-CDM-LSSS","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4E0773FAF44F1F","source":"MPC-COMP-CORR-F4OLE","target":"MPC-PAPER-2024-FOLEAGE","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4E107E36688502","source":"MPC-PAPER-2020-MOTION","target":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-4FE1038A40A875","source":"MPC-COMP-CONV-ABY","target":"MPC-PAPER-2015-ABY","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-50050C3775A65F","source":"MPC-COMP-REP-MIXED","target":"MPC-PAPER-2020-MOTION","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-51759D0D8FDF72","source":"MPC-CONTRIB-1990-BMR-CONSTANT","target":"MPC-CONTRIB-2015-BMR-SPDZ","type":"ACTIVELY_SECURES","note":"The 2015 protocol retains BMR local garbled-circuit evaluation and changes its distributed preparation to an actively secure SPDZ-backed computation.","reviewStatus":"primary_source_checked","evidenceLocator":"BMR+SPDZ abstract and Sections 2–4","evidenceUrl":"https://eprint.iacr.org/2015/523"},{"id":"MPC-REL-534EF0EB16D444","source":"MPC-PROTOCOL-TINYOT","target":"MPC-CONTRIB-2003-IKNP-OTEXT","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-53B40132119BCA","source":"MPC-CONTRIB-2015-ABY-MIXED","target":"MPC-CONTRIB-2018-ABY3-REPLICATED","type":"CHANGES_PARTY_AND_SHARING_MODEL","note":"ABY3 adapts ABY's mixed arithmetic, Boolean, and Yao-domain interface to a three-party replicated-sharing design with new conversions, changing the party and trust contract rather than subsuming the two-party setting.","reviewStatus":"primary_source_checked","evidenceLocator":"ABY3 introduction and comparison with ABY","evidenceUrl":"https://eprint.iacr.org/2018/403"},{"id":"MPC-REL-557F715A1921F7","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-EVAL-BEAVER","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-55A9956A7EFF34","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-56A94A8D0B93BB","source":"MPC-COMP-REP-MIXED","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-56F6A0F5D9BE2E","source":"MPC-COMP-CORR-OTEXT","target":"MPC-PAPER-2003-IKNP","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-57D01EFF7539E1","source":"MPC-PROTOCOL-BMR-PASSIVE","target":"MPC-CONTRIB-1990-BMR-CONSTANT","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-582C204BAA6024","source":"MPC-COMP-ENC-REPLICATED","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-588B86533AA442","source":"MPC-CONTRIB-2015-ABY-MIXED","target":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","type":"CHANGES_FRAMEWORK_SCOPE","note":"MOTION supplies a modular runtime for mixed-protocol computation with two or more passively secure parties, compared with ABY's two-party framework; the recorded evidence does not establish inclusion of every ABY protocol or configuration.","reviewStatus":"primary_source_checked","evidenceLocator":"MOTION abstract and related-work comparison","evidenceUrl":"https://eprint.iacr.org/2020/1137"},{"id":"MPC-REL-59B3C55D448214","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-5C264E684A4256","source":"MPC-COMP-ACT-BMR-SPDZ","target":"MPC-PAPER-2015-BMR-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-5DF70E13162D9D","source":"MPC-PAPER-2024-HPMPC","target":"MPC-CONTRIB-2024-HPMPC-NETWORK","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-5E14000BFEE597","source":"MPC-COMP-ENC-AUTH-ADDITIVE","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-5E7CBBB63F2BB2","source":"MPC-PAPER-2024-HPMPC","target":"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-5EEE5E869AA80A","source":"MPC-COMP-REP-ARITH-FIELD","target":"MPC-PAPER-1988-BGW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-601BED8A93CDFB","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-EVAL-GMW","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-6116756F1B8F60","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-PAPER-1991-BEAVER","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-61A0B7640D37A6","source":"MPC-PROTOCOL-TINYOT","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-62D3A6D03ED738","source":"MPC-COMP-REP-ARITH-FIELD","target":"MPC-PAPER-1991-BEAVER","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-643DD00FB2F544","source":"MPC-PROTOCOL-BMR-PASSIVE","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-64CC4E65D5FF51","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-CONTRIB-2003-IKNP-OTEXT","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-657A8F05EDD1BE","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-COMP-EVAL-HPMPC-MASKED","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-66655E3B793EEA","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-669F5C41A3EED9","source":"MPC-COMP-ENC-AUTH-BITS","target":"MPC-PAPER-2012-TINYOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-66A924F30EE1B8","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-EVAL-REPLICATED","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-67E9BF60B1E9E1","source":"MPC-OP-001","target":"MPC-PAPER-2023-AKP","type":"GROUNDED_IN","note":"","reviewStatus":"fulltext_checked","evidenceLocator":"§1.1.3, paragraph following Theorem 1.5 and footnote 3, numbered PDF p. 8","evidenceUrl":"https://eprint.iacr.org/2023/418"},{"id":"MPC-REL-6A267FEFBEA43C","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-PAPER-2003-IKNP","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-6A8953E811F956","source":"MPC-PAPER-2015-ABY","target":"MPC-CONTRIB-2015-ABY-MIXED","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-6B54EF76E0A5DD","source":"MPC-PROTOCOL-BGW-ACTIVE","target":"MPC-COMP-OUT-HONEST-MAJORITY","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-6B8009F4CB8089","source":"MPC-COMP-ACT-SPDZ-MAC","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-6BA45AEECF696D","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-CONV-MOTION","type":"USES_COMPONENT","note":"conversion_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-6F468A915C082F","source":"MPC-PAPER-2024-FOLEAGE","target":"MPC-CONTRIB-2024-FOLEAGE-F4","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7032726985BCC2","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-COMP-EVAL-HPMPC-MASKED","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7043FAC890ED2C","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-PAPER-1991-BEAVER","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7072F16DF0C399","source":"MPC-PROTOCOL-BMR-PASSIVE","target":"MPC-PAPER-1990-BMR","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-717C45D8394D90","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-ENC-MULTI-GARBLED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-722141992ACD07","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7247881850DF34","source":"MPC-PAPER-2024-HPMPC","target":"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-728943C5B41035","source":"MPC-COMP-REP-ARITH-FIELD","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-728C802BED28A5","source":"MPC-OP-005","target":"MPC-PAPER-2026-LS-GARBLING","type":"GROUNDED_IN","note":"","reviewStatus":"claim_audited","evidenceLocator":"","evidenceUrl":"https://eprint.iacr.org/2026/1297"},{"id":"MPC-REL-72BE75F840FAFD","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-CONTRIB-1990-BMR-CONSTANT","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-72F4721B90D119","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-REP-MIXED","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7570947554127E","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-PAPER-2024-HPMPC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-76C87D385F73CA","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-COMP-ENC-AUTH-ADDITIVE","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-78765BD72DCFF5","source":"MPC-COMP-ENC-ABY3-YAO","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7A2B0273896FBB","source":"MPC-CONTRIB-1991-BEAVER-TRIPLES","target":"MPC-CONTRIB-2011-SPDZ-AUTH","type":"ACTIVELY_AUTHENTICATES","note":"SPDZ instantiates the preprocessing model with authenticated arithmetic triples and global-MAC checks that tolerate a dishonest majority.","reviewStatus":"primary_source_checked","evidenceLocator":"SPDZ online protocol and preprocessing overview","evidenceUrl":"https://eprint.iacr.org/2011/535"},{"id":"MPC-REL-7C56F989F80105","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-PAPER-1990-BMR","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7E2DB18FB16177","source":"MPC-IMPL-2023-MOTION-FFA76F8","target":"MPC-PROTOCOL-MOTION-PASSIVE","type":"IMPLEMENTS","note":"paper-aligned passive full-threshold framework configuration","reviewStatus":"source_declared","evidenceLocator":"pinned repository README and src/motioncore providers","evidenceUrl":"https://github.com/encryptogroup/MOTION/tree/ffa76f82ace55c7ba49c0c89d97246b8827c52a9"},{"id":"MPC-REL-7E2E9CEE95DEBF","source":"MPC-PAPER-1988-BGW","target":"MPC-CONTRIB-1988-BGW-THRESHOLDS","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-7E6862A2B93A34","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-EVAL-BEAVER","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-81A0D6E682FD8C","source":"MPC-PAPER-2010-TASTY","target":"MPC-CONTRIB-2010-TASTY-MIXED-COMPILER","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-81A99B61C50CA3","source":"MPC-OP-005","target":"MPC-PAPER-2021-THREE-HALVES","type":"GROUNDED_IN","note":"","reviewStatus":"claim_audited","evidenceLocator":"ePrint 2021/749, §8 “Optimality”, p. 25","evidenceUrl":"https://eprint.iacr.org/2021/749"},{"id":"MPC-REL-824B556BBB4C87","source":"MPC-COMP-EVAL-BMR","target":"MPC-PAPER-1990-BMR","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-833FD899E646B9","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-COMP-CORR-SHE","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-83B6BD61491341","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-COMP-CORR-OTEXT","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-83E25BF051C56F","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-COMP-ENC-XOR","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-84DCEB04ACC162","source":"MPC-OP-005","target":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","type":"GROUNDED_IN","note":"","reviewStatus":"claim_audited","evidenceLocator":"ePrint 2025/876, §1.1 pp. 3–4; Definitions 12–16 pp. 9–12; Theorem 26 and Corollary 27 p. 23","evidenceUrl":"https://eprint.iacr.org/2025/876"},{"id":"MPC-REL-872A911B35CBF5","source":"MPC-PAPER-2026-LS-GARBLING","target":"MPC-CONTRIB-2026-LS-BATCHED-GARBLING","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-8917D6F89E3296","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-8AE6C4D457A77B","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-CONTRIB-2003-IKNP-OTEXT","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-8AEBF332CB8F00","source":"MPC-PAPER-2015-HALFGATES","target":"MPC-CONTRIB-2015-HALFGATES","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-8AEF876AB75121","source":"MPC-PROTOCOL-BMR-PASSIVE","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-8B0C575755A66F","source":"MPC-OP-003","target":"MPC-PAPER-2026-IKR-PCF","type":"GROUNDED_IN","note":"","reviewStatus":"claim_audited","evidenceLocator":"ITC 2026 proceedings, §6, p. 7:19; Theorem 2, p. 7:6; Corollary 27, pp. 7:16–7:17","evidenceUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7"},{"id":"MPC-REL-8CDE14C2E1086A","source":"MPC-IMPL-2026-MPSPDZ-9D80959","target":"MPC-PROTOCOL-TINYOT","type":"IMPLEMENTS","note":"multi_configuration_framework; exact runtime flag selects the protocol","reviewStatus":"source_declared","evidenceLocator":"pinned README, documentation protocol table, and source tree","evidenceUrl":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9"},{"id":"MPC-REL-8E3773FCBA6F5D","source":"MPC-COMP-ENC-GARBLED","target":"MPC-PAPER-2008-FREEXOR","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-90249374E01C9E","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-ENC-ADDITIVE","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-912192BBBC81A0","source":"MPC-COMP-CORR-BASEOT","target":"MPC-PAPER-1982-YAO","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-92045D42BEDAB6","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-93FA66F7F58CA1","source":"MPC-PAPER-2003-IKNP","target":"MPC-CONTRIB-2003-IKNP-OTEXT","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-94A3961A16FA26","source":"MPC-COMP-OUT-ABORT","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9527D2AB45DFC3","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-PAPER-1987-GMW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-95479115AF457B","source":"MPC-COMP-CONV-MOTION","target":"MPC-PAPER-2020-MOTION","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9664AADA07237B","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9797DBC8BBBA4B","source":"MPC-PAPER-2015-BMR-SPDZ","target":"MPC-CONTRIB-2015-BMR-SPDZ","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-993E36E1A238C4","source":"MPC-COMP-ACT-HPMPC4","target":"MPC-PAPER-2024-HPMPC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-99BB474E0ADFEA","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-COMP-EVAL-GMW","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-99FAAD2C46255B","source":"MPC-COMP-EVAL-BGW","target":"MPC-PAPER-1988-BGW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9A356C5AF67214","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-COMP-CORR-PAIRWISE","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9A4FF9274CA75E","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-ENC-XOR","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9AB1D3A5FEBD1F","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-CONTRIB-2015-ABY-MIXED","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9AF6167904E08C","source":"MPC-COMP-CONV-BMR-PREP","target":"MPC-PAPER-2015-BMR-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9B9D8A7C3850A0","source":"MPC-COMP-ENC-GARBLED","target":"MPC-PAPER-2009-PRACTICAL2PC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9C0A2094735946","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-REP-MIXED","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9DFD43C6B41D59","source":"MPC-PROTOCOL-BGW-ACTIVE","target":"MPC-PAPER-1988-BGW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9E7CA1465E4CA6","source":"MPC-PAPER-2008-FREEXOR","target":"MPC-CONTRIB-2008-FREEXOR","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-9F31E027D2BF90","source":"MPC-COMP-EVAL-GMW","target":"MPC-PAPER-2003-IKNP","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-A0643939A45195","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-COMP-CORR-PAIRWISE","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-A197F44A23C6BE","source":"MPC-PAPER-2020-MPSPDZ","target":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-A3BCEB4841E798","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-CONTRIB-2016-MASCOT-TRIPLES","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-A3BF84E12FC284","source":"MPC-CONTRIB-2016-MASCOT-TRIPLES","target":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","type":"IMPLEMENTS_AS_BACKEND","note":"MP-SPDZ exposes MASCOT-style OT preprocessing as one backend for authenticated arithmetic online computation.","reviewStatus":"primary_source_checked","evidenceLocator":"MP-SPDZ supported-protocol table and documentation","evidenceUrl":"https://eprint.iacr.org/2020/521"},{"id":"MPC-REL-A405F7FB1256D4","source":"MPC-CONTRIB-1988-BGW-THRESHOLDS","target":"MPC-CONTRIB-2000-CDM-LSSS","type":"GENERALIZES_REPRESENTATION","note":"CDM generalizes the polynomial secret-sharing approach to multiplicative linear secret-sharing schemes and general access structures.","reviewStatus":"primary_source_checked","evidenceLocator":"CDM abstract and introduction","evidenceUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070321-new.pdf"},{"id":"MPC-REL-A44FDFCD770A40","source":"MPC-PAPER-2017-EMP-M2PC","target":"MPC-CONTRIB-2017-EMP-M2PC","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-A4546757DCECB8","source":"MPC-CONTRIB-2011-SPDZ-AUTH","target":"MPC-CONTRIB-2016-MASCOT-TRIPLES","type":"REPLACES_PREPROCESSING","note":"MASCOT preserves the SPDZ authenticated-sharing online phase but replaces SHE-based triple generation with OT-based multiplication and consistency checks.","reviewStatus":"primary_source_checked","evidenceLocator":"MASCOT abstract and comparison to SPDZ preprocessing","evidenceUrl":"https://eprint.iacr.org/2016/505"},{"id":"MPC-REL-A5E7F88A4B633C","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-CONTRIB-2015-HALFGATES","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-A8F174068A06F2","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-COMP-CONV-BMR-PREP","type":"USES_COMPONENT","note":"conversion_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-A96887C127F14B","source":"MPC-PROTOCOL-TINYOT","target":"MPC-PAPER-2012-TINYOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-AC860D8CABC010","source":"MPC-COMP-OUT-ASYNC","target":"MPC-PAPER-1993-ASYNC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-ACA02C53A27C7B","source":"MPC-PROTOCOL-TINYOT","target":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-AD6BED854587AC","source":"MPC-COMP-ACT-TINYOT","target":"MPC-PAPER-2012-TINYOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-ADCD137B86B7D7","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-PAPER-2016-MASCOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-AF55404ED4B8A7","source":"MPC-COMP-CORR-PAIRWISE","target":"MPC-PAPER-2024-HPMPC","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B017CE7369B2B5","source":"MPC-CONTRIB-1988-BGW-THRESHOLDS","target":"MPC-OP-001","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"fulltext_checked","evidenceLocator":"Abstract; completeness and impossibility theorems","evidenceUrl":"https://mit6875.github.io/PAPERS/BGW.pdf"},{"id":"MPC-REL-B0586E717FCF52","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B12993D61FFE86","source":"MPC-OP-004","target":"MPC-PAPER-2025-CDPP","type":"GROUNDED_IN","note":"","reviewStatus":"fulltext_checked","evidenceLocator":"Current 2026-05-22 revision, §1.3 Open Problems, fourth question, numbered PDF p. 3; model in §3 p. 11","evidenceUrl":"https://eprint.iacr.org/2025/1555"},{"id":"MPC-REL-B15CB2197E0A9C","source":"MPC-BENCH-2024-HPMPC-AND","target":"MPC-IMPL-2026-HPMPC-155C935","type":"BENCHMARKS","note":"","reviewStatus":"source_declared","evidenceLocator":"Paper abstract, Contributions, and Section 5; pinned repository README for later artifact identity","evidenceUrl":"https://eprint.iacr.org/2024/386"},{"id":"MPC-REL-B193FF655A173F","source":"MPC-PROTOCOL-YAO-PASSIVE","target":"MPC-CONTRIB-2008-FREEXOR","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B2AA1A0E8BD2EB","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B335ACF2BA2622","source":"MPC-PROTOCOL-TINYOT","target":"MPC-COMP-CORR-OTEXT","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B40BE6499C8A30","source":"MPC-COMP-ENC-AUTH-ADDITIVE","target":"MPC-PAPER-2016-MASCOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B484E6B4F2431F","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-COMP-ENC-HPMPC-MASKED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B52CD907BFD95E","source":"MPC-COMP-ENC-ADDITIVE","target":"MPC-PAPER-2015-ABY","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B680D663E59BB0","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-EVAL-ABY3-YAO","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-B9D86D3119DD1C","source":"MPC-PROTOCOL-BGW-ACTIVE","target":"MPC-COMP-EVAL-BGW","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-BA65AE384AF90C","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-BB70E58B500998","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-PAPER-2020-MOTION","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-BC66EBA255FB9F","source":"MPC-PAPER-2025-CDPP","target":"MPC-CONTRIB-2025-CDPP-SIMD-GOD","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-BC9D95A13D4C02","source":"MPC-PAPER-2009-PRACTICAL2PC","target":"MPC-CONTRIB-2009-PRACTICAL2PC","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-BED994351315A5","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-BFF0BBD15A0EB9","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-COMP-REP-ARITH-RING","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C0C3D63539F41F","source":"MPC-COMP-OUT-HONEST-MAJORITY","target":"MPC-PAPER-1988-BGW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C4BB2210EF7A77","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-CONV-ABY","type":"USES_COMPONENT","note":"conversion_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C4BCA835DFFAC6","source":"MPC-COMP-CONV-ABY3","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C56875EF88F3F8","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-COMP-EVAL-BEAVER","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C5F017ADB694D0","source":"MPC-COMP-REP-BOOLEAN","target":"MPC-PAPER-1987-GMW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C651FA3120A4AE","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-COMP-ENC-HPMPC-MASKED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C67988D770CB5D","source":"MPC-PROTOCOL-BGW-ACTIVE","target":"MPC-CONTRIB-1988-BGW-THRESHOLDS","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C6B7EE16634487","source":"MPC-COMP-ENC-ADDITIVE","target":"MPC-PAPER-2020-MOTION","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C7184A1EEED507","source":"MPC-COMP-OUT-ABORT","target":"MPC-PAPER-2012-TINYOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C898A0631B1750","source":"MPC-COMP-REP-BOOLEAN","target":"MPC-PAPER-1982-YAO","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-C97DCA9DDCE4F0","source":"MPC-COMP-CORR-PAIRWISE","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-CA561673154459","source":"MPC-PROTOCOL-TINYOT","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-CAB130C310E78C","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-REP-MIXED","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-CB059E7FD13872","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-CONTRIB-2011-SPDZ-AUTH","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-CC540C635DA4A5","source":"MPC-COMP-REP-ARITH-RING","target":"MPC-PAPER-2018-ABY3","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-CCDCA8A772C4B2","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-ENC-XOR","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-CFC192B1C62A06","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D0B1E1A14CDDDD","source":"MPC-OP-002","target":"MPC-PAPER-2026-IKR-PCF","type":"GROUNDED_IN","note":"","reviewStatus":"claim_audited","evidenceLocator":"ITC 2026 proceedings, §1.4, p. 7:7; PCG model in §2.3, pp. 7:10–7:11","evidenceUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7"},{"id":"MPC-REL-D0B48CFA3588B0","source":"MPC-CONTRIB-1987-GMW-COMPILER","target":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","type":"CHANGES_SECURITY_MECHANISM","note":"TinyOT keeps Boolean shared-circuit evaluation but replaces a generic malicious compiler with OT-generated authenticated bits and specialized checks.","reviewStatus":"primary_source_checked","evidenceLocator":"TinyOT introduction and authenticated-bit protocol","evidenceUrl":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf"},{"id":"MPC-REL-D115E83CEC2C7A","source":"MPC-CONTRIB-2003-IKNP-OTEXT","target":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","type":"SUPPLIES_CORRELATION","note":"TinyOT's practical preprocessing relies on extending OTs so authenticated Boolean correlations can be generated at scale.","reviewStatus":"primary_source_checked","evidenceLocator":"TinyOT introduction and preprocessing analysis","evidenceUrl":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf"},{"id":"MPC-REL-D1267C26C42D1C","source":"MPC-PROTOCOL-ABY3-PASSIVE","target":"MPC-COMP-ENC-ABY3-YAO","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D19738039FF319","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-COMP-REP-ARITH-FIELD","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D3356A661B47FA","source":"MPC-COMP-ENC-SHAMIR","target":"MPC-PAPER-1988-BGW","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D3C563EC9B30EB","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-COMP-ENC-MULTI-GARBLED","type":"USES_COMPONENT","note":"value_encoding","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D6284AE8AAFF3C","source":"MPC-PROTOCOL-BMR-PASSIVE","target":"MPC-COMP-EVAL-BMR","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D67643741DEC0D","source":"MPC-BENCH-2024-HPMPC-AND","target":"MPC-PROTOCOL-HPMPC-3PC","type":"MEASURES_CONFIGURATION","note":"","reviewStatus":"source_declared","evidenceLocator":"Paper abstract, Contributions, and Section 5; pinned repository README for later artifact identity","evidenceUrl":"https://eprint.iacr.org/2024/386"},{"id":"MPC-REL-D73AAB821663EB","source":"MPC-COMP-EVAL-BEAVER","target":"MPC-PAPER-1991-BEAVER","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D8EB74F491875B","source":"MPC-PAPER-1991-BEAVER","target":"MPC-CONTRIB-1991-BEAVER-TRIPLES","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D93D4112FE9258","source":"MPC-COMP-ENC-MULTI-GARBLED","target":"MPC-PAPER-1990-BMR","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D95A9BA560498E","source":"MPC-COMP-CORR-SHE","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-D9D62466754BB9","source":"MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF","target":"MPC-OP-002","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"claim_audited","evidenceLocator":"ITC 2026 proceedings, Theorem 1, p. 7:5; Corollary 22 and Remarks 24–25, p. 7:14; Definitions 12–13, pp. 7:10–7:11","evidenceUrl":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7"},{"id":"MPC-REL-D9F11C10D2164C","source":"MPC-PAPER-2026-BEP","target":"MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-DA2D742E6B256E","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-REP-ARITH-RING","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-DA8F5B5DBBEC24","source":"MPC-PROTOCOL-BGW-ACTIVE","target":"MPC-COMP-REP-ARITH-FIELD","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-DB8AE6DD05BDEE","source":"MPC-PROTOCOL-ABY-PASSIVE","target":"MPC-COMP-EVAL-YAO","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-DB8AEA72F0ED6D","source":"MPC-PROTOCOL-HPMPC-4PC","target":"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-DED56AD56C69E3","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-COMP-ACT-SPDZ-MAC","type":"USES_COMPONENT","note":"active_security_enforcement","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-DF7EA270C4FD49","source":"MPC-PROTOCOL-GMW-PASSIVE","target":"MPC-COMP-REP-BOOLEAN","type":"USES_COMPONENT","note":"representation","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-DFD5E38C14B278","source":"MPC-COMP-EVAL-BEAVER","target":"MPC-PAPER-2011-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E0DA083025CCD2","source":"MPC-COMP-REP-MIXED","target":"MPC-PAPER-2015-ABY","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E0E34C9DB6D076","source":"MPC-PROTOCOL-HPMPC-3PC","target":"MPC-CONTRIB-2024-HPMPC-NETWORK","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E18A4A490B17C6","source":"MPC-PAPER-1993-ASYNC","target":"MPC-CONTRIB-1993-ASYNC-FEASIBILITY","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E2294170DE5492","source":"MPC-CONTRIB-2021-THREE-HALVES","target":"MPC-OP-005","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"claim_audited","evidenceLocator":"ePrint 2021/749, §1.1 (p. 2), §5.4 Theorem 3 (pp. 18–21), §6.1 (pp. 22–23), §8 (p. 25); PDF page numbers match printed pages","evidenceUrl":"https://eprint.iacr.org/2021/749"},{"id":"MPC-REL-E41B89E89B8CF2","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-COMP-OUT-ABORT","type":"USES_COMPONENT","note":"output_recovery_layer","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E4AED96EA20C71","source":"MPC-PAPER-1995-PROACTIVE","target":"MPC-CONTRIB-1995-PROACTIVE-REFRESH","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E59F091FA10940","source":"MPC-COMP-EVAL-BMR","target":"MPC-PAPER-2015-BMR-SPDZ","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E6CA4C7E81FFE3","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-CONTRIB-1991-BEAVER-TRIPLES","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-E8E8B8A9E1F9CC","source":"MPC-IMPL-2026-HPMPC-155C935","target":"MPC-PROTOCOL-HPMPC-3PC","type":"IMPLEMENTS","note":"protocol compile-time options select the exact 3PC/4PC configuration","reviewStatus":"source_declared","evidenceLocator":"pinned README, config.h options, protocols directory, and paper Section 5","evidenceUrl":"https://github.com/chart21/hpmpc/tree/155c93572d747b527a6452c9ad8f24eb3b776667"},{"id":"MPC-REL-EA7A56C0B3841E","source":"MPC-COMP-ACT-SPDZ-MAC","target":"MPC-PAPER-2016-MASCOT","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-EAC05044FFF177","source":"MPC-PAPER-1996-ADAPTIVE","target":"MPC-CONTRIB-1996-ADAPTIVE-NCE","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F05833119F685E","source":"MPC-COMP-CORR-PCG","target":"MPC-PAPER-2019-PCG","type":"DESCRIBED_IN","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F134FAD9B7E3F8","source":"MPC-PROTOCOL-MASCOT-SPDZ","target":"MPC-COMP-CORR-MASCOT","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F242AD5F3F1356","source":"MPC-IMPL-2026-HPMPC-155C935","target":"MPC-PROTOCOL-HPMPC-4PC","type":"IMPLEMENTS","note":"protocol compile-time options select the exact 3PC/4PC configuration","reviewStatus":"source_declared","evidenceLocator":"pinned README, config.h options, protocols directory, and paper Section 5","evidenceUrl":"https://github.com/chart21/hpmpc/tree/155c93572d747b527a6452c9ad8f24eb3b776667"},{"id":"MPC-REL-F64A5F31541F80","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-COMP-EVAL-BMR","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F680104F386F75","source":"MPC-PROTOCOL-BMR-SPDZ","target":"MPC-COMP-ACT-BMR-SPDZ","type":"USES_COMPONENT","note":"active_security_enforcement","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F6858F4EA971ED","source":"MPC-PAPER-2012-TINYOT","target":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F71AD1DA51E197","source":"MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL","target":"MPC-OP-001","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"fulltext_checked","evidenceLocator":"ePrint 2023/418 revision 2025-06-17, §1 model (p. 5), §1.1.3 and Theorem 1.5 with following discussion and footnote 3 (p. 8)","evidenceUrl":"https://eprint.iacr.org/2023/418"},{"id":"MPC-REL-F85209A11D8E1A","source":"MPC-PROTOCOL-SPDZ-SHE","target":"MPC-CONTRIB-2011-SPDZ-AUTH","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F8DD1888D607C4","source":"MPC-CONTRIB-2019-PCG-SILENT","target":"MPC-OP-002","type":"APPROACHES","note":"Explicitly selected partial result; not a resolution or a technical-lineage edge.","reviewStatus":"claim_audited","evidenceLocator":"Abstract; PCG definition and constructions","evidenceUrl":"https://eprint.iacr.org/2019/448"},{"id":"MPC-REL-F96028B5A69B0E","source":"MPC-OP-001","target":"MPC-PAPER-2026-IT-CONSTANT-ROUND","type":"GROUNDED_IN","note":"","reviewStatus":"fulltext_checked","evidenceLocator":"§1.1, opening and semi-honest-security paragraphs, numbered PDF p. 3","evidenceUrl":"https://eprint.iacr.org/2026/1768"},{"id":"MPC-REL-F97EA4C1BC904C","source":"MPC-PROTOCOL-TINYOT","target":"MPC-COMP-EVAL-GMW","type":"USES_COMPONENT","note":"evaluation_protocol","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-F9BCF27B54709B","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-COMP-CORR-OTEXT","type":"USES_COMPONENT","note":"correlation_source","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-FA403D8391D3FF","source":"MPC-PROTOCOL-MOTION-PASSIVE","target":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","type":"SUPPORTED_BY_CLAIM","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-FCDE8C650E1AE2","source":"MPC-PAPER-2026-IKR-PCF","target":"MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-FD463A6123F443","source":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","target":"MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-FE73DB72B6CDFB","source":"MPC-IMPL-2026-MPSPDZ-9D80959","target":"MPC-PROTOCOL-BMR-SPDZ","type":"IMPLEMENTS","note":"multi_configuration_framework; exact runtime flag selects the protocol","reviewStatus":"source_declared","evidenceLocator":"pinned README, documentation protocol table, and source tree","evidenceUrl":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9"},{"id":"MPC-REL-FFC96AE83049E8","source":"MPC-PAPER-2011-SPDZ","target":"MPC-CONTRIB-2011-SPDZ-AUTH","type":"HAS_CONTRIBUTION","note":"","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""},{"id":"MPC-REL-FFDD744C0085AB","source":"MPC-PROTOCOL-TINYOT","target":"MPC-COMP-ACT-TINYOT","type":"USES_COMPONENT","note":"active_security_enforcement","reviewStatus":"source_declared","evidenceLocator":"","evidenceUrl":""}],"protocols":[{"id":"MPC-PROTOCOL-BGW-ACTIVE","name":"BGW active MPC","title":"BGW active honest-majority field MPC","year":1988,"protocol_family":"polynomial_secret_sharing","paper_ids":["MPC-PAPER-1988-BGW"],"claim_ids":["MPC-CONTRIB-1988-BGW-THRESHOLDS"],"research_lenses":["generality-feasibility","active-security","network-delivery"],"tasks":["general_mpc","arithmetic_circuit_evaluation","guaranteed_output"],"properties":{"parties":"n","corruption_threshold":"t < n/3 active","majority_regime":"honest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_information_theoretic","network_model":"synchronous_private_channels_with_broadcast","setup":"no_cryptographic_preprocessing","output_guarantee":"robust_reconstruction_and_delivery_in_model","privacy_basis":"information_theoretic"},"stack":{"representation":["MPC-COMP-REP-ARITH-FIELD"],"value_encoding":["MPC-COMP-ENC-SHAMIR"],"evaluation_protocol":["MPC-COMP-EVAL-BGW"],"correlation_source":[],"active_security_enforcement":["MPC-COMP-ACT-BGW-VSS"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-HONEST-MAJORITY"]},"stack_status":{"correlation_source":"not_separate","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_arithmetic_multiplicative_depth","communication_driver":"verifiable_sharing_and_degree_reduction","preprocessing":"not_separate"},"configuration_note":"Active, synchronous BGW field configuration; the passive t<n/2 result is a different model profile.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"Private channels and broadcast are part of this row's model; removing or emulating them changes the construction."},{"id":"MPC-PROTOCOL-BMR-PASSIVE","name":"BMR passive MPC","title":"BMR constant-round multiparty garbling","year":1990,"protocol_family":"multiparty_garbled_circuit","paper_ids":["MPC-PAPER-1990-BMR"],"claim_ids":["MPC-CONTRIB-1990-BMR-CONSTANT"],"research_lenses":["garbled-circuit-efficiency","round-communication"],"tasks":["general_mpc","constant_round_online"],"properties":{"parties":"n","corruption_threshold":"paper configurations vary; displayed row is passive","majority_regime":"configuration_specific","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"distributed_garbling_phase","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-MULTI-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BMR"],"correlation_source":[],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"correlation_source":"not_separate","active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"constant","communication_driver":"distributed_garbling_tables_and_input_labels","preprocessing":"distributed_garbling"},"configuration_note":"Passive BMR core shown separately from the later actively secure BMR+SPDZ composition.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"The original mechanism establishes the constant-round line; BMR+SPDZ changes its enforcement and preprocessing layers."},{"id":"MPC-PROTOCOL-GMW-PASSIVE","name":"GMW passive Boolean MPC","title":"GMW / OT-extension passive Boolean MPC","year":2003,"protocol_family":"boolean_secret_sharing","paper_ids":["MPC-PAPER-1987-GMW","MPC-PAPER-2003-IKNP"],"claim_ids":["MPC-CONTRIB-1987-GMW-COMPILER","MPC-CONTRIB-2003-IKNP-OTEXT"],"research_lenses":["generality-feasibility","preprocessing-correlation","round-communication"],"tasks":["general_mpc","boolean_circuit_evaluation"],"properties":{"parties":"2 or more","corruption_threshold":"configuration-dependent passive threshold","majority_regime":"supports_dishonest_majority_passive","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"base_OT_then_OT_extension","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-XOR"],"evaluation_protocol":["MPC-COMP-EVAL-GMW"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_boolean_multiplicative_depth","communication_driver":"pairwise_ot_correlations_per_and_gate","preprocessing":"ot_extension"},"configuration_note":"A normalized passive GMW configuration using OT extension; stronger-security compilers require separate rows.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"GMW typically favors low AND depth; Yao typically favors constant rounds with cost per non-XOR gate."},{"id":"MPC-PROTOCOL-SPDZ-SHE","name":"SPDZ · SHE preprocessing","title":"SPDZ with SHE preprocessing","year":2012,"protocol_family":"authenticated_arithmetic_preprocessing","paper_ids":["MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ"],"claim_ids":["MPC-CONTRIB-1991-BEAVER-TRIPLES","MPC-CONTRIB-2011-SPDZ-AUTH"],"research_lenses":["active-security","preprocessing-correlation"],"tasks":["general_mpc","dishonest_majority_active_arithmetic"],"properties":{"parties":"n","corruption_threshold":"t < n","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"adaptive","security_framework":"statistical_UC_with_abort","network_model":"synchronous_secure_point_to_point_channels","setup":"input_independent_SHE_preprocessing","output_guarantee":"security_with_abort","privacy_basis":"computational_preprocessing_and_information_theoretic_online_checks"},"stack":{"representation":["MPC-COMP-REP-ARITH-FIELD"],"value_encoding":["MPC-COMP-ENC-AUTH-ADDITIVE"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER"],"correlation_source":["MPC-COMP-CORR-SHE"],"active_security_enforcement":["MPC-COMP-ACT-SPDZ-MAC"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_arithmetic_multiplicative_depth","communication_driver":"openings_per_multiplication_layer","preprocessing":"expensive_SHE_based_authenticated_triples"},"configuration_note":"Original SPDZ configuration; MASCOT changes only the preprocessing source and its consistency machinery, so it receives a separate row.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"The name “SPDZ” alone is insufficient for implementation or benchmark comparison because several offline phases can feed the online protocol."},{"id":"MPC-PROTOCOL-TINYOT","name":"TinyOT","title":"TinyOT active Boolean 2PC","year":2012,"protocol_family":"authenticated_boolean_preprocessing","paper_ids":["MPC-PAPER-2003-IKNP","MPC-PAPER-2012-TINYOT"],"claim_ids":["MPC-CONTRIB-2003-IKNP-OTEXT","MPC-CONTRIB-2012-TINYOT-AUTHBITS"],"research_lenses":["active-security","preprocessing-correlation"],"tasks":["general_2pc","malicious_boolean_computation"],"properties":{"parties":"2","corruption_threshold":"1 active corruption","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_authenticated_channels","setup":"base_OT_and_OT_extension","output_guarantee":"security_with_abort","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-AUTH-BITS"],"evaluation_protocol":["MPC-COMP-EVAL-GMW"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":["MPC-COMP-ACT-TINYOT"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_and_depth","communication_driver":"authenticated_and_evaluation_and_openings","preprocessing":"OT_generated_authenticated_bits"},"configuration_note":"OT-based authenticated-sharing design, distinct from malicious Yao cut-and-choose protocols.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"TinyOT is placed in the Boolean-sharing and authenticated-preprocessing threads, not in the garbled-circuit thread."},{"id":"MPC-PROTOCOL-ABY-PASSIVE","name":"ABY","title":"ABY passive mixed-protocol 2PC","year":2015,"protocol_family":"mixed_protocol_2pc","paper_ids":["MPC-PAPER-2015-ABY"],"claim_ids":["MPC-CONTRIB-2015-ABY-MIXED"],"research_lenses":["mixed-protocol-compilation","implementation-systems"],"tasks":["general_2pc","mixed_domain_computation"],"properties":{"parties":"2","corruption_threshold":"1 passive corruption","majority_regime":"dishonest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"OT_extension_and_protocol_specific_precomputation","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-MIXED"],"value_encoding":["MPC-COMP-ENC-ADDITIVE","MPC-COMP-ENC-XOR","MPC-COMP-ENC-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER","MPC-COMP-EVAL-GMW","MPC-COMP-EVAL-YAO"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":["MPC-COMP-CONV-ABY"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable"},"complexity":{"online_rounds":"subprotocol_and_conversion_dependent","communication_driver":"selected_sharing_subprotocols_and_conversion_gates","preprocessing":"ot_extension_and_garbling_material"},"configuration_note":"Paper's passive two-party configuration across arithmetic, Boolean, and Yao sharings.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"ABY is compared as a mixed configuration, not as a fourth sharing type competing with its A/B/Y components."},{"id":"MPC-PROTOCOL-BMR-SPDZ","name":"BMR + SPDZ","title":"BMR with SPDZ-secured preprocessing","year":2015,"protocol_family":"active_multiparty_garbled_circuit","paper_ids":["MPC-PAPER-1990-BMR","MPC-PAPER-2011-SPDZ","MPC-PAPER-2015-BMR-SPDZ"],"claim_ids":["MPC-CONTRIB-1990-BMR-CONSTANT","MPC-CONTRIB-2011-SPDZ-AUTH","MPC-CONTRIB-2015-BMR-SPDZ"],"research_lenses":["round-communication","active-security","preprocessing-correlation"],"tasks":["general_mpc","constant_round_online","dishonest_majority_active"],"properties":{"parties":"n","corruption_threshold":"t < n","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_authenticated_channels","setup":"SPDZ_style_offline_distributed_garbling","output_guarantee":"security_with_abort","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-MULTI-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BMR"],"correlation_source":["MPC-COMP-CORR-SHE"],"active_security_enforcement":["MPC-COMP-ACT-BMR-SPDZ"],"conversion_layer":["MPC-COMP-CONV-BMR-PREP"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{},"complexity":{"online_rounds":"two","communication_driver":"offline_distributed_garbling;_online_input_labels","preprocessing":"actively_secure_arithmetic_MPC_builds_BMR_tables"},"configuration_note":"Exact composition from the 2015 paper; it is neither plain BMR nor an arithmetic SPDZ online execution.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked","summary":"The arithmetic protocol protects circuit preparation; the online phase is a multiparty garbled-circuit evaluation."},{"id":"MPC-PROTOCOL-YAO-PASSIVE","name":"Yao passive 2PC","title":"Yao / OT-extension passive 2PC","year":2015,"protocol_family":"garbled_circuit_2pc","paper_ids":["MPC-PAPER-2003-IKNP","MPC-PAPER-2008-FREEXOR","MPC-PAPER-2009-PRACTICAL2PC","MPC-PAPER-2015-HALFGATES"],"claim_ids":["MPC-CONTRIB-2003-IKNP-OTEXT","MPC-CONTRIB-2008-FREEXOR","MPC-CONTRIB-2015-HALFGATES"],"research_lenses":["garbled-circuit-efficiency","preprocessing-correlation"],"tasks":["general_2pc","boolean_circuit_evaluation"],"properties":{"parties":"2","corruption_threshold":"1 passive corruption","majority_regime":"dishonest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_authenticated_channels","setup":"base_OT_then_OT_extension","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-YAO"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"constant_after_ot_setup","communication_driver":"garbled_non_xor_gates_plus_input_ot","preprocessing":"base_ot_and_ot_extension"},"configuration_note":"Modernized passive Yao stack with Free-XOR, half-gates, and IKNP-style OT extension; it is not the literal 1982 protocol instance.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"This configuration makes the familiar optimized passive garbling stack explicit instead of attributing all later optimizations to “Yao.”"},{"id":"MPC-PROTOCOL-MASCOT-SPDZ","name":"MASCOT + SPDZ online","title":"SPDZ online with MASCOT preprocessing","year":2016,"protocol_family":"authenticated_arithmetic_preprocessing","paper_ids":["MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ","MPC-PAPER-2016-MASCOT"],"claim_ids":["MPC-CONTRIB-2011-SPDZ-AUTH","MPC-CONTRIB-2016-MASCOT-TRIPLES"],"research_lenses":["preprocessing-correlation","active-security"],"tasks":["general_mpc","dishonest_majority_active_arithmetic"],"properties":{"parties":"n","corruption_threshold":"t < n","majority_regime":"dishonest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_authenticated_channels","setup":"OT_based_input_independent_preprocessing","output_guarantee":"security_with_abort","privacy_basis":"computational_preprocessing_and_information_theoretic_online_checks"},"stack":{"representation":["MPC-COMP-REP-ARITH-FIELD"],"value_encoding":["MPC-COMP-ENC-AUTH-ADDITIVE"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER"],"correlation_source":["MPC-COMP-CORR-MASCOT"],"active_security_enforcement":["MPC-COMP-ACT-SPDZ-MAC"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"proportional_to_arithmetic_multiplicative_depth","communication_driver":"SPDZ_online_openings","preprocessing":"OT_based_authenticated_triples_with_consistency_checks"},"configuration_note":"MASCOT offline phase feeding the authenticated SPDZ arithmetic online phase.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"The online layer is shared, but the correlation source and preprocessing checks are not."},{"id":"MPC-PROTOCOL-ABY3-PASSIVE","name":"ABY3 passive","title":"ABY3 passive replicated-ring 3PC","year":2018,"protocol_family":"honest_majority_mixed_3pc","paper_ids":["MPC-PAPER-2018-ABY3"],"claim_ids":["MPC-CONTRIB-2018-ABY3-REPLICATED"],"research_lenses":["mixed-protocol-compilation","round-communication"],"tasks":["general_3pc","mixed_domain_computation","ring_arithmetic"],"properties":{"parties":"3","corruption_threshold":"1 passive corruption","majority_regime":"honest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_pairwise_channels","setup":"pairwise_PRG_seeds","output_guarantee":"abort_on_disconnect","privacy_basis":"information_theoretic_given_seeded_masks_except_PRG_expansion"},"stack":{"representation":["MPC-COMP-REP-MIXED","MPC-COMP-REP-ARITH-RING"],"value_encoding":["MPC-COMP-ENC-REPLICATED","MPC-COMP-ENC-ABY3-YAO"],"evaluation_protocol":["MPC-COMP-EVAL-REPLICATED","MPC-COMP-EVAL-ABY3-YAO"],"correlation_source":["MPC-COMP-CORR-PAIRWISE"],"active_security_enforcement":[],"conversion_layer":["MPC-COMP-CONV-ABY3"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable"},"complexity":{"online_rounds":"operation_and_conversion_dependent","communication_driver":"replicated_multiplications_and_domain_conversions","preprocessing":"pairwise_seed_expansion"},"configuration_note":"Passive three-party configuration; malicious ABY3-style variants require different enforcement and party assumptions.","visibility":"backbone","status":"published","evidence":"primary_source_checked","summary":"“ABY3” does not imply malicious security in this row."},{"id":"MPC-PROTOCOL-MOTION-PASSIVE","name":"MOTION passive","title":"MOTION passive mixed multiparty configuration","year":2020,"protocol_family":"mixed_protocol_framework","paper_ids":["MPC-PAPER-2020-MOTION"],"claim_ids":["MPC-CONTRIB-2020-MOTION-MULTIPARTY"],"research_lenses":["mixed-protocol-compilation","implementation-systems"],"tasks":["general_mpc","mixed_domain_computation"],"properties":{"parties":"2 or more","corruption_threshold":"up to n-1 passive corruptions","majority_regime":"dishonest_majority_passive","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_security_model_with_asynchronous_software_scheduling","setup":"protocol_specific_OT_and_precomputation","output_guarantee":"abort_on_disconnect","privacy_basis":"computational"},"stack":{"representation":["MPC-COMP-REP-MIXED","MPC-COMP-REP-ARITH-RING","MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-ADDITIVE","MPC-COMP-ENC-XOR","MPC-COMP-ENC-MULTI-GARBLED"],"evaluation_protocol":["MPC-COMP-EVAL-BEAVER","MPC-COMP-EVAL-GMW","MPC-COMP-EVAL-BMR"],"correlation_source":["MPC-COMP-CORR-OTEXT"],"active_security_enforcement":[],"conversion_layer":["MPC-COMP-CONV-MOTION"],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable"},"complexity":{"online_rounds":"selected_protocol_graph_dependent","communication_driver":"selected_protocols_and_conversions","preprocessing":"OT_and_provider_setup"},"configuration_note":"Framework-level passive configuration; asynchronous execution in the code is not an asynchronous-network adversarial guarantee.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked","summary":"It binds the paper's stated security model to the mechanisms realized by the implementation, while the immutable repository remains a separate object."},{"id":"MPC-PROTOCOL-HPMPC-3PC","name":"HP-MPC 3PC","title":"HP-MPC semi-honest ring 3PC","year":2024,"protocol_family":"high_throughput_honest_majority","paper_ids":["MPC-PAPER-2024-HPMPC"],"claim_ids":["MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","MPC-CONTRIB-2024-HPMPC-NETWORK","MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK"],"research_lenses":["round-communication","network-delivery","implementation-systems"],"tasks":["general_3pc","high_throughput_ring_arithmetic","heterogeneous_networks"],"properties":{"parties":"3","corruption_threshold":"1 passive corruption","majority_regime":"honest_majority","adversary_behavior":"passive","corruption_timing":"static","security_framework":"standalone","network_model":"synchronous_channels_with_heterogeneous_link_performance","setup":"pairwise_correlated_randomness","output_guarantee":"abort_on_disconnect","privacy_basis":"computational_seed_expansion_with_information_theoretic_sharing"},"stack":{"representation":["MPC-COMP-REP-ARITH-RING","MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-HPMPC-MASKED"],"evaluation_protocol":["MPC-COMP-EVAL-HPMPC-MASKED"],"correlation_source":["MPC-COMP-CORR-PAIRWISE"],"active_security_enforcement":[],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"active_security_enforcement":"not_applicable","conversion_layer":"not_applicable"},"complexity":{"online_rounds":"multiplicative_depth_dependent","communication_driver":"three_elements_per_arithmetic_multiplication_in_reported_variant","preprocessing":"optional_interleaved_or_offline_masks"},"configuration_note":"Paper's novel semi-honest 3PC family; benchmark identity additionally fixes the HP-MPC artifact and network.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked","summary":"The protocol row stores the construction; the >billion-gate observations belong to a specific implementation and environment."},{"id":"MPC-PROTOCOL-HPMPC-4PC","name":"HP-MPC 4PC","title":"HP-MPC malicious ring 4PC","year":2024,"protocol_family":"high_throughput_honest_majority","paper_ids":["MPC-PAPER-2024-HPMPC"],"claim_ids":["MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","MPC-CONTRIB-2024-HPMPC-NETWORK","MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK"],"research_lenses":["active-security","round-communication","implementation-systems"],"tasks":["general_4pc","malicious_ring_arithmetic","heterogeneous_networks"],"properties":{"parties":"4","corruption_threshold":"1 active corruption","majority_regime":"honest_majority","adversary_behavior":"active","corruption_timing":"static","security_framework":"standalone_with_abort","network_model":"synchronous_channels_with_heterogeneous_link_performance","setup":"pairwise_correlated_randomness","output_guarantee":"security_with_abort","privacy_basis":"computational_seed_expansion_with_information_theoretic_sharing"},"stack":{"representation":["MPC-COMP-REP-ARITH-RING","MPC-COMP-REP-BOOLEAN"],"value_encoding":["MPC-COMP-ENC-HPMPC-MASKED"],"evaluation_protocol":["MPC-COMP-EVAL-HPMPC-MASKED"],"correlation_source":["MPC-COMP-CORR-PAIRWISE"],"active_security_enforcement":["MPC-COMP-ACT-HPMPC4"],"conversion_layer":[],"output_recovery_layer":["MPC-COMP-OUT-ABORT"]},"stack_status":{"conversion_layer":"not_applicable"},"complexity":{"online_rounds":"multiplicative_depth_dependent","communication_driver":"five_elements_per_arithmetic_multiplication_in_reported_variant","preprocessing":"optional_interleaved_or_offline_masks"},"configuration_note":"Paper's malicious four-party, one-corruption configuration; it is not the same security row as the 3PC protocol.","visibility":"reviewed_related","status":"published","evidence":"primary_source_checked","summary":"Party count and adversary behavior change together, so the 3PC and 4PC variants remain distinct configurations."}],"components":[{"id":"MPC-COMP-ACT-HPMPC4","title":"HP-MPC four-party malicious checks","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2024-HPMPC"],"summary":"The protocol-specific verification layer for the paper's four-party, one-corruption malicious configuration.","tags":["4pc","active","honest-majority"]},{"id":"MPC-COMP-ACT-SPDZ-MAC","title":"SPDZ global-MAC checks and sacrifice","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2011-SPDZ","MPC-PAPER-2016-MASCOT"],"summary":"Checks opened authenticated shares against a hidden global MAC key and sacrifices preprocessing candidates to detect malformed correlations.","tags":["active","mac","sacrifice","spdz"]},{"id":"MPC-COMP-ACT-BMR-SPDZ","title":"SPDZ-secured distributed garbling","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2015-BMR-SPDZ"],"summary":"Constructs and checks the BMR garbling inside an actively secure arithmetic MPC before the fast online evaluation.","tags":["active","bmr","spdz"]},{"id":"MPC-COMP-ACT-TINYOT","title":"TinyOT authenticated-bit checks","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-2012-TINYOT"],"summary":"Uses global-key bit MACs and batch checks to detect malicious deviations in Boolean two-party computation.","tags":["active","authenticated-bits","tinyot"]},{"id":"MPC-COMP-ACT-BGW-VSS","title":"Verifiable sharing and degree-consistency checks","component_kind":"active_security_enforcement","paper_ids":["MPC-PAPER-1988-BGW"],"summary":"Enforces polynomial consistency and reconstructability against Byzantine deviations under the BGW honest-majority threshold.","tags":["active","honest-majority","vss"]},{"id":"MPC-COMP-CONV-ABY","title":"ABY A/B/Y conversion gates","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2015-ABY"],"summary":"Converts values among arithmetic sharing, Boolean sharing, and Yao labels within one passive 2PC execution.","tags":["aby","conversion","mixed-protocol"]},{"id":"MPC-COMP-CONV-ABY3","title":"ABY3 arithmetic/binary/Yao conversion","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2018-ABY3"],"summary":"Switches replicated ring shares among arithmetic, binary, and garbled subprotocols in the three-party setting.","tags":["3pc","aby3","conversion"]},{"id":"MPC-COMP-CONV-BMR-PREP","title":"Arithmetic-to-BMR preprocessing bridge","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2015-BMR-SPDZ"],"summary":"Maps arithmetic MPC outputs used during preprocessing into the seeds and tables required by the BMR garbling.","tags":["bmr","composition","spdz"]},{"id":"MPC-COMP-CONV-MOTION","title":"MOTION mixed-protocol conversions","component_kind":"conversion_layer","paper_ids":["MPC-PAPER-2020-MOTION"],"summary":"Implements modular conversions among supported passive sharing protocols for two or more parties.","tags":["conversion","framework","motion"]},{"id":"MPC-COMP-CORR-F4OLE","title":"FOLEAGE F4-OLE Boolean-triple generator","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2024-FOLEAGE"],"summary":"Specializes PCG techniques over F4 to generate F2 multiplication triples with near-linear circuit-dependent communication in party count.","tags":["boolean-triples","f4ole","pcg"]},{"id":"MPC-COMP-CORR-OTEXT","title":"IKNP OT extension","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2003-IKNP"],"summary":"Amortizes many OTs from a small base-OT seed using symmetric primitives.","tags":["iknp","ot-extension"]},{"id":"MPC-COMP-CORR-MASCOT","title":"MASCOT OT-based arithmetic preprocessing","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2016-MASCOT"],"summary":"Generates authenticated arithmetic multiplication triples from OT with consistency checks, replacing the original SPDZ SHE preprocessing.","tags":["mascot","ot","triples"]},{"id":"MPC-COMP-CORR-BASEOT","title":"Oblivious transfer for input and AND correlations","component_kind":"correlation_source","paper_ids":["MPC-PAPER-1982-YAO","MPC-PAPER-1987-GMW"],"summary":"Provides receiver-selective transfer used for garbled inputs or shared AND evaluation.","tags":["correlation","ot"]},{"id":"MPC-COMP-CORR-PAIRWISE","title":"Pairwise-seed correlated randomness","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2018-ABY3","MPC-PAPER-2024-HPMPC"],"summary":"Uses seeds shared between party pairs to derive masks locally and reduce communication in replicated-sharing protocols.","tags":["honest-majority","pairwise-prg"]},{"id":"MPC-COMP-CORR-PCG","title":"Pseudorandom correlation generator","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2019-PCG"],"summary":"Expands short correlated seeds locally into long protocol-specific correlations with no interaction during expansion.","tags":["pcg","silent-preprocessing"]},{"id":"MPC-COMP-CORR-SHE","title":"SHE-generated SPDZ preprocessing","component_kind":"correlation_source","paper_ids":["MPC-PAPER-2011-SPDZ"],"summary":"Uses somewhat homomorphic encryption plus proofs/checks to create authenticated arithmetic preprocessing before inputs are known.","tags":["homomorphic-encryption","spdz","triples"]},{"id":"MPC-COMP-EVAL-ABY3-YAO","title":"ABY3 three-party garbled evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2018-ABY3"],"summary":"Evaluates ABY3's Yao-domain subcomputations using the paper's two-garbler, one-evaluator three-party garbling path; it is distinct from two-party Yao evaluation and BMR distributed garbling.","tags":["aby3","three-party-garbling","yao-sharing"]},{"id":"MPC-COMP-EVAL-BGW","title":"BGW polynomial gate evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1988-BGW"],"summary":"Uses local polynomial-share arithmetic plus interactive degree reduction and verifiable sharing under honest-majority thresholds.","tags":["bgw","degree-reduction"]},{"id":"MPC-COMP-EVAL-BMR","title":"BMR distributed garbling and local evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1990-BMR","MPC-PAPER-2015-BMR-SPDZ","MPC-PAPER-2020-MOTION"],"summary":"Parties jointly create a multiparty garbled circuit; once labels are delivered, each party evaluates locally in a constant-round online phase.","tags":["bmr","constant-round"]},{"id":"MPC-COMP-EVAL-BEAVER","title":"Beaver-triple online multiplication","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ"],"summary":"Opens masked differences against a preprocessed multiplication triple, leaving only local arithmetic and a small online exchange per multiplication layer.","tags":["beaver-triples","online"]},{"id":"MPC-COMP-EVAL-GMW","title":"GMW Boolean gate evaluation","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-1987-GMW","MPC-PAPER-2003-IKNP"],"summary":"Evaluates XOR gates locally and interactive AND gates from oblivious-transfer-style correlations, with rounds tied to multiplicative depth.","tags":["boolean-sharing","gmw"]},{"id":"MPC-COMP-EVAL-REPLICATED","title":"Replicated-sharing ring multiplication","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2018-ABY3"],"summary":"Combines overlapping share products with pairwise randomness to multiply ring-shared values with low bandwidth in 3PC/4PC settings.","tags":["high-throughput","replicated-sharing","ring"]},{"id":"MPC-COMP-EVAL-HPMPC-MASKED","title":"Trio and Quad masked multiplication","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2024-HPMPC"],"summary":"Multiplies Trio and Quad masked values by distributing input-dependent and input-independent correction work so the paper's three- and four-party configurations retain their stated communication while reducing local instructions.","tags":["hp-mpc","masked-sharing","multiplication","vectorization"]},{"id":"MPC-COMP-EVAL-YAO","title":"Yao garble-and-evaluate","component_kind":"evaluation_protocol","paper_ids":["MPC-PAPER-2009-PRACTICAL2PC"],"summary":"One party garbles a Boolean circuit and the other evaluates it on obliviously transferred input labels.","tags":["2pc","yao"]},{"id":"MPC-COMP-OUT-ASYNC","title":"Asynchronous agreement and reconstruction","component_kind":"output_recovery_layer","paper_ids":["MPC-PAPER-1993-ASYNC"],"summary":"Coordinates progress and reconstruction without timing bounds while tolerating the asynchronous honest-majority corruption threshold.","tags":["agreement","asynchronous","output"]},{"id":"MPC-COMP-OUT-HONEST-MAJORITY","title":"Honest-majority robust reconstruction","component_kind":"output_recovery_layer","paper_ids":["MPC-PAPER-1988-BGW"],"summary":"Uses honest-majority error correction and verifiable sharing so qualified honest parties can reconstruct despite Byzantine shares.","tags":["guaranteed-output","honest-majority","robustness"]},{"id":"MPC-COMP-OUT-ABORT","title":"Reconstruction with abort on failure","component_kind":"output_recovery_layer","paper_ids":["MPC-PAPER-2011-SPDZ","MPC-PAPER-2012-TINYOT"],"summary":"Honest parties either accept a reconstructed output or detect failure and abort; fairness and guaranteed delivery are not implied.","tags":["abort","output"]},{"id":"MPC-COMP-REP-ARITH-RING","title":"Arithmetic circuit over a 2-power ring","component_kind":"representation","paper_ids":["MPC-PAPER-2018-ABY3","MPC-PAPER-2024-HPMPC"],"summary":"Uses native fixed-width integer arithmetic over a ring such as Z/2^kZ; field-only checks and proofs do not transfer automatically.","tags":["arithmetic","ring"]},{"id":"MPC-COMP-REP-ARITH-FIELD","title":"Arithmetic circuit over a field","component_kind":"representation","paper_ids":["MPC-PAPER-1988-BGW","MPC-PAPER-1991-BEAVER","MPC-PAPER-2011-SPDZ"],"summary":"Expresses computation with field additions and multiplications, supporting polynomial sharing and triple-based multiplication.","tags":["arithmetic","field"]},{"id":"MPC-COMP-REP-BOOLEAN","title":"Boolean circuit representation","component_kind":"representation","paper_ids":["MPC-PAPER-1982-YAO","MPC-PAPER-1987-GMW"],"summary":"Represents a functionality as XOR/AND or general Boolean gates; depth and non-XOR count drive different protocols differently.","tags":["boolean","circuit"]},{"id":"MPC-COMP-REP-MIXED","title":"Mixed arithmetic/Boolean/garbled representation","component_kind":"representation","paper_ids":["MPC-PAPER-2015-ABY","MPC-PAPER-2018-ABY3","MPC-PAPER-2020-MOTION"],"summary":"Partitions one computation across domains and makes conversion gates explicit rather than forcing every operation into one circuit type.","tags":["conversion","mixed-protocol"]},{"id":"MPC-COMP-ENC-ABY3-YAO","title":"ABY3 three-party Yao sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2018-ABY3"],"summary":"Stores a Boolean value in the paper's three-party Yao domain, with one evaluator holding the active wire key and two garblers holding the label material needed to construct matching garbled circuits.","tags":["aby3","three-party-garbling","yao-sharing"]},{"id":"MPC-COMP-ENC-MULTI-GARBLED","title":"Multiparty BMR superseed labels","component_kind":"value_encoding","paper_ids":["MPC-PAPER-1990-BMR","MPC-PAPER-2015-BMR-SPDZ","MPC-PAPER-2020-MOTION"],"summary":"Distributes each wire label across parties so no single party controls the multiparty garbling.","tags":["bmr","multiparty-garbling"]},{"id":"MPC-COMP-ENC-REPLICATED","title":"Replicated three-party sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2018-ABY3"],"summary":"Replicates additive share pieces across adjacent parties so one corruption leaves enough overlap for low-communication honest-majority evaluation.","tags":["3pc","replicated-sharing"]},{"id":"MPC-COMP-ENC-AUTH-ADDITIVE","title":"SPDZ authenticated additive sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2011-SPDZ","MPC-PAPER-2016-MASCOT"],"summary":"Associates additive shares with shares of a global-MAC relation so openings can be checked against active deviation.","tags":["authenticated-sharing","spdz"]},{"id":"MPC-COMP-ENC-SHAMIR","title":"Shamir polynomial sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-1988-BGW"],"summary":"Represents a field value as evaluations of a low-degree polynomial, enabling local linear gates and threshold reconstruction.","tags":["honest-majority","shamir"]},{"id":"MPC-COMP-ENC-AUTH-BITS","title":"TinyOT authenticated bits","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2012-TINYOT"],"summary":"Authenticates XOR shares with global-key MAC relations tailored to Boolean computation.","tags":["authenticated-bits","tinyot"]},{"id":"MPC-COMP-ENC-HPMPC-MASKED","title":"Trio and Quad masked sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2024-HPMPC"],"summary":"Encodes Trio and Quad values as input-dependent masked values plus differently distributed mask shares. The exact holdings differ between the three- and four-party configurations and are not ABY3 replicated sharing.","tags":["honest-majority","hp-mpc","masked-sharing","ring"]},{"id":"MPC-COMP-ENC-GARBLED","title":"Two-party garbled wire labels","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2008-FREEXOR","MPC-PAPER-2009-PRACTICAL2PC"],"summary":"Encodes each Boolean wire value as one of two cryptographic labels held asymmetrically by garbler and evaluator.","tags":["garbling","labels"]},{"id":"MPC-COMP-ENC-ADDITIVE","title":"Unauthenticated additive sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-2015-ABY","MPC-PAPER-2020-MOTION"],"summary":"Represents a value as additive shares without the global-MAC relation of SPDZ authenticated sharing. The surrounding passive protocol and correlation source supply privacy and multiplication.","tags":["additive-sharing","arithmetic","passive-security"]},{"id":"MPC-COMP-ENC-XOR","title":"XOR/additive Boolean sharing","component_kind":"value_encoding","paper_ids":["MPC-PAPER-1987-GMW","MPC-PAPER-2012-TINYOT"],"summary":"Represents a bit as the XOR of party shares, making XOR gates local and pushing interaction to AND gates.","tags":["boolean-sharing","xor"]}],"claims":[{"id":"MPC-CONTRIB-1982-YAO-2PC","paper_id":"MPC-PAPER-1982-YAO","paper_title":"Protocols for Secure Computations","paper_url":"https://research.cs.wisc.edu/areas/sec/yao1982-ocr.pdf","year":1982,"title":"Two-party private computation becomes a general protocol problem","role":"feasibility_and_construction","statement":"Yao formulates and gives protocols for two parties to compute functions of private inputs while limiting what each party learns, establishing secure two-party computation as a general cryptographic task.","source_locator":"Abstract and protocol constructions","lens":"generality-feasibility","visibility":"backbone","limitations":"the record does not attribute every modern garbled-circuit formalization to this paper; the exact security formulation predates contemporary simulation frameworks","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-1987-GMW-COMPILER","paper_id":"MPC-PAPER-1987-GMW","paper_title":"How to Play ANY Mental Game","paper_url":"https://www.math.ias.edu/~avi/PUBLICATIONS/MYPAPERS/GMW87/GMW87.pdf","year":1987,"title":"Circuit compilation gives general MPC with explicit adversary upgrades","role":"feasibility_and_compiler","statement":"Goldreich, Micali, and Wigderson give a general circuit-based method for secure multiparty computation and separate passive evaluation from compilation techniques that enforce security against stronger adversarial behavior.","source_locator":"Introduction and general protocol construction","lens":"generality-feasibility","visibility":"backbone","limitations":"round and communication costs depend on the circuit and subprotocols; later frameworks refine the security and composition contract","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-1988-BGW-THRESHOLDS","paper_id":"MPC-PAPER-1988-BGW","paper_title":"Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation","paper_url":"https://mit6875.github.io/PAPERS/BGW.pdf","year":1988,"title":"Honest-majority thresholds characterize information-theoretic general MPC","role":"feasibility_boundary","statement":"BGW establishes unconditional general MPC over private channels for passive corruption below one half and Byzantine corruption below one third, together with matching threshold limitations in its model.","source_locator":"Abstract; completeness and impossibility theorems","lens":"generality-feasibility","visibility":"backbone","limitations":"thresholds are model-dependent; dishonest-majority feasibility requires different assumptions or guarantees","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-1990-BMR-CONSTANT","paper_id":"MPC-PAPER-1990-BMR","paper_title":"The Round Complexity of Secure Protocols","paper_url":"https://web.cs.ucdavis.edu/~rogaway/papers/bmr90","year":1990,"title":"Distributed garbling removes circuit depth from MPC round complexity","role":"round_reduction","statement":"Beaver, Micali, and Rogaway construct constant-round multiparty computation by distributing garbled-circuit preparation so that the online interaction does not grow with circuit depth.","source_locator":"Abstract and constant-round protocol construction","lens":"garbled-circuit-efficiency","visibility":"backbone","limitations":"constant rounds do not imply constant communication; concrete costs depend on distributed garbling and cryptographic subprotocols","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-1991-BEAVER-TRIPLES","paper_id":"MPC-PAPER-1991-BEAVER","paper_title":"Efficient Multiparty Protocols Using Circuit Randomization","paper_url":"https://doi.org/10.1007/3-540-46766-1_34","year":1991,"title":"Input-independent multiplication triples separate MPC preprocessing from online work","role":"reusable_mechanism","statement":"Beaver's circuit-randomization method uses input-independent correlated multiplication values so arithmetic products can be opened and completed online with lightweight interaction once the correlations are available.","source_locator":"Circuit-randomization construction for multiplication","lens":"preprocessing-correlation","visibility":"backbone","limitations":"the mechanism assumes correctly generated correlations; security and cost depend on the surrounding protocol and triple generator","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-1993-ASYNC-FEASIBILITY","paper_id":"MPC-PAPER-1993-ASYNC","paper_title":"Asynchronous Secure Computation","paper_url":"https://doi.org/10.1145/167088.167109","year":1993,"title":"General MPC remains feasible with arbitrarily delayed messages","role":"model_transformation","statement":"Ben-Or, Canetti, and Goldreich establish general secure computation in a completely asynchronous private-channel network with optimal resilience below one third for fail-stop faults and below one fourth for Byzantine faults.","source_locator":"Abstract and main asynchronous secure-computation construction","lens":"network-delivery","visibility":"backbone","limitations":"the two fault types have different optimal resilience bounds; later probabilistic-error protocols reach different Byzantine thresholds; the result is not a claim for arbitrary dishonest majorities","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-1995-PROACTIVE-REFRESH","paper_id":"MPC-PAPER-1995-PROACTIVE","paper_title":"Proactive Secret Sharing or: How to Cope With Perpetual Leakage","paper_url":"https://research.google/pubs/proactive-secret-sharing-or-how-to-cope-with-perpetual-leakage/","year":1995,"title":"Periodic share refresh prevents mobile corruptions from accumulating secrets","role":"security_transformation","statement":"Proactive secret sharing periodically rerandomizes distributed shares without changing the protected secret, preventing an adversary that compromises different parties in different epochs from accumulating a reconstructing set.","source_locator":"Abstract and share-renewal protocol","lens":"adaptive-proactive","visibility":"reviewed_related","limitations":"requires the per-epoch corruption threshold and refresh assumptions; does not itself provide a complete MPC protocol","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-1996-ADAPTIVE-NCE","paper_id":"MPC-PAPER-1996-ADAPTIVE","paper_title":"Adaptively Secure Multi-party Computation","paper_url":"https://www.wisdom.weizmann.ac.il/~oded/PSX/dynamic.pdf","year":1996,"title":"Non-committing techniques secure MPC against execution-dependent corruptions","role":"security_transformation","statement":"Canetti, Feige, Goldreich, and Naor use non-committing encryption to obtain computational MPC over insecure channels against adaptive corruptions of non-erasing parties under the paper's threshold and trapdoor assumptions.","source_locator":"Abstract and main adaptive-security construction","lens":"adaptive-proactive","visibility":"reviewed_related","limitations":"the principal theorem handles fewer than one-third corruptions and notes a modification below one half; the compiler inherits its secure-channel protocol and trapdoor assumptions; proactive mobile corruption is a distinct contract","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2000-CDM-LSSS","paper_id":"MPC-PAPER-2000-CDM","paper_title":"General Secure Multi-party Computation from any Linear Secret-Sharing Scheme","paper_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070321-new.pdf","year":2000,"title":"Multiplicative linear secret sharing extends general MPC beyond thresholds","role":"abstraction_and_construction","statement":"Cramer, Damgård, and Maurer construct general MPC from multiplicative linear secret-sharing schemes, extending polynomial-threshold sharing to access structures whose multiplication and robustness conditions are stated algebraically.","source_locator":"Abstract, introduction, and main protocol theorem","lens":"generality-feasibility","visibility":"backbone","limitations":"security and robustness depend on the access structure and sharing properties; not every LSSS automatically satisfies the required multiplication condition","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2001-UC-COMPOSITION","paper_id":"MPC-PAPER-2001-UC","paper_title":"Universally Composable Security: A New Paradigm for Cryptographic Protocols","paper_url":"https://eprint.iacr.org/2000/067","year":2001,"title":"Environment-based simulation makes concurrent protocol composition explicit","role":"security_definition","statement":"Canetti defines universally composable security through an external environment and proves a composition theorem that preserves protocol security when secure subroutines are replaced inside arbitrary surrounding executions.","source_locator":"Framework definition and universal composition theorem","lens":"generality-feasibility","visibility":"reviewed_related","limitations":"composition guarantees inherit the framework and setup assumptions; stand-alone security does not imply UC security","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2003-IKNP-OTEXT","paper_id":"MPC-PAPER-2003-IKNP","paper_title":"Extending Oblivious Transfers Efficiently","paper_url":"https://www.iacr.org/archive/crypto2003/27290145/27290145.pdf","year":2003,"title":"Symmetric-key OT extension expands a small public-key seed into many transfers","role":"correlation_amplification","statement":"IKNP extends a small number of base oblivious transfers into a large batch using primarily symmetric-key operations, reducing the public-key cost of OT-intensive secure computation.","source_locator":"Abstract and OT-extension protocol","lens":"preprocessing-correlation","visibility":"backbone","limitations":"security inherits the base OTs and extension model; malicious security requires additional consistency mechanisms","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2008-FREEXOR","paper_id":"MPC-PAPER-2008-FREEXOR","paper_title":"Improved Garbled Circuit: Free XOR Gates and Applications","paper_url":"https://www.thomaschneider.de/papers/KS08XOR.pdf","year":2008,"title":"A global wire-label offset makes XOR gates free in garbled circuits","role":"gate_cost_reduction","statement":"Free-XOR correlates the two labels on every wire through one global offset so XOR gates require neither garbled ciphertexts nor cryptographic operations, concentrating garbling cost on non-XOR gates.","source_locator":"Abstract and Free-XOR construction","lens":"garbled-circuit-efficiency","visibility":"backbone","limitations":"security requires the stated hash/correlation assumptions; nonlinear gates still incur garbling cost","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2009-PRACTICAL2PC","paper_id":"MPC-PAPER-2009-PRACTICAL2PC","paper_title":"Secure Two-Party Computation Is Practical","paper_url":"https://eprint.iacr.org/2009/314","year":2009,"title":"End-to-end co-design makes semi-honest garbled-circuit 2PC practical","role":"systems_integration","statement":"Pinkas, Schneider, Smart, and Williams integrate circuit design, garbling, oblivious transfer, and systems optimizations into an end-to-end semi-honest two-party computation implementation evaluated on representative functions.","source_locator":"Abstract; system design and evaluation sections","lens":"garbled-circuit-efficiency","visibility":"reviewed_related","limitations":"the security model is semi-honest; performance observations are bound to the paper's implementation and workloads","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2010-FAIR-FUNCTIONS","paper_id":"MPC-PAPER-2010-FAIR","paper_title":"Complete Fairness in Multi-Party Computation Without an Honest Majority","paper_url":"https://eprint.iacr.org/2008/458","year":2009,"title":"Boolean OR and three-party majority admit complete fairness without an honest majority","role":"feasibility_refinement","statement":"Gordon and Katz construct completely fair protocols tolerating any t<n corruptions for n-party Boolean OR and three-party majority under suitable cryptographic assumptions, while proving that the latter requires super-logarithmic rounds.","source_locator":"Abstract and main complete-fairness theorems","lens":"network-delivery","visibility":"reviewed_related","limitations":"does not overturn general fairness impossibility; results use suitable cryptographic assumptions; the three-party-majority protocol requires super-logarithmic rounds","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2010-TASTY-MIXED-COMPILER","paper_id":"MPC-PAPER-2010-TASTY","paper_title":"TASTY: Tool for Automating Secure Two-partY computations","paper_url":"https://eprint.iacr.org/2010/365","year":2010,"title":"Typed HE and garbled values support mixed-protocol description and generation","role":"mixed_protocol_framework","statement":"TASTY provides a typed protocol-description language and runtime that generate and execute semi-honest two-party computations combining additively homomorphic encryption and garbled circuits, with explicit conversions between their value representations within one computation.","source_locator":"IACR ePrint 2010/365 full version: §2 (model), PDF pp. 3–5; §2.3 and Figure 2, p. 5; §4–§4.1 and Figures 5–7, pp. 6–8; §6 (automatic-selection boundary), p. 12","lens":"mixed-protocol-compilation","visibility":"catalog_only","limitations":"The underlying modular conversion framework and cryptographic primitives are prior building blocks, not separately claimed inventions of this atom.; Automatic compilation from a function-description language and automatic HE/GC selection are future work in §6.; No malicious or UC security guarantee, universal performance optimum, or portable benchmark ranking is admitted.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2011-SPDZ-AUTH","paper_id":"MPC-PAPER-2011-SPDZ","paper_title":"Multiparty Computation from Somewhat Homomorphic Encryption","paper_url":"https://eprint.iacr.org/2011/535","year":2012,"title":"Authenticated arithmetic shares enable a light dishonest-majority online phase","role":"protocol_construction","statement":"SPDZ combines somewhat-homomorphic-encryption preprocessing with information-theoretic MACs on arithmetic shares, obtaining a light online phase that is statistically UC-secure against active, adaptive corruption of up to n-1 parties in its synchronous secure-channel model.","source_locator":"Abstract; preprocessing overview and online protocol","lens":"active-security","visibility":"backbone","limitations":"original preprocessing uses somewhat homomorphic encryption; successful termination is not guaranteed with a dishonest majority; the optimality statements are scoped to the paper's field-size and accounting conditions","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","paper_id":"MPC-PAPER-2012-TINYOT","paper_title":"A New Approach to Practical Active-Secure Two-Party Computation","paper_url":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf","year":2012,"title":"OT-generated authenticated bits give specialized malicious Boolean 2PC","role":"protocol_construction","statement":"TinyOT builds actively secure Boolean two-party computation from OT-generated authenticated bits and shares, making XOR local and using amortized consistency checks instead of a generic malicious compiler or garbled-circuit cut-and-choose.","source_locator":"Abstract and authenticated-bit protocol sections","lens":"active-security","visibility":"backbone","limitations":"relies on preprocessing and OT assumptions; the architecture is specialized to Boolean sharing","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION","paper_id":"MPC-PAPER-2014-KSS","paper_title":"Automatic Protocol Selection in Secure Two-Party Computations","paper_url":"https://eprint.iacr.org/2014/200","year":2014,"title":"Conversion-aware cost models drive automatic HE and garbled-circuit assignment","role":"mixed_protocol_assignment","statement":"For a specified single-static-assignment intermediate program and forecast cost model, Kerschbaum, Schneider, and Schröpfer formulate assignment of operations to HE-assisted arithmetic sharing or garbled circuits with conversion costs, and give a 0–1 integer-programming formulation and a cost-decreasing greedy heuristic for choosing the mixed protocol.","source_locator":"IACR ePrint 2014/200 full version: §3.2–§3.4, PDF pp. 3–4; §4–§4.2, pp. 4–5; §5 and Definition 1, pp. 5–6; §5.1–§5.2 and Algorithm 1, pp. 6–7; §6 and Tables 1–2 for forecast-only evaluation context","lens":"mixed-protocol-compilation","visibility":"catalog_only","limitations":"Integer-programming optimality is relative to the modeled objective; the source discusses approximation of execution costs, including neighboring-operation effects.; The greedy method starts with garbled-circuit assignments and accepts cost-decreasing changes to HE; no general approximation ratio is admitted.; Section 5 conjectures NP-hardness of the specific partitioning problem and explicitly does not prove it.; The use-case comparisons are forecast results in specified settings, not universal measured speedups or cross-system rankings.; This atom is not a general automatic compiler for all MPC representations, a new malicious or UC security theorem, or a separate garbling construction.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2015-ABY-MIXED","paper_id":"MPC-PAPER-2015-ABY","paper_title":"ABY — A Framework for Efficient Mixed-Protocol Secure Two-Party Computation","paper_url":"https://www.ndss-symposium.org/wp-content/uploads/2017/09/08_2_1.pdf","year":2015,"title":"Typed conversions compose arithmetic, Boolean, and garbled 2PC domains","role":"mixed_protocol_framework","statement":"ABY provides a two-party framework whose computation can move through explicit conversion gates among arithmetic sharing, Boolean sharing, and Yao garbling, allowing each subcomputation to use a domain-specific cost profile.","source_locator":"NDSS 2015 version: §I.A and Figure 1, PDF p. 2; §I.B (mixed protocols and automated generation), p. 3; references [35] and [44], p. 14","lens":"mixed-protocol-compilation","visibility":"backbone","limitations":"conversion costs can dominate a poor partition; security properties are configuration-specific rather than inherited by the framework name","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2015-BMR-SPDZ","paper_id":"MPC-PAPER-2015-BMR-SPDZ","paper_title":"Efficient Constant Round Multi-Party Computation Combining BMR and SPDZ","paper_url":"https://eprint.iacr.org/2015/523","year":2015,"title":"SPDZ preprocessing makes BMR garbling actively secure with a two-round online phase","role":"protocol_composition","statement":"Lindell, Pinkas, Smart, and Yanai use actively secure arithmetic MPC to prepare a BMR garbled circuit, obtaining malicious dishonest-majority MPC whose online phase takes two rounds and is dominated by local garbled-circuit evaluation.","source_locator":"Abstract and Sections 3–4","lens":"active-security","visibility":"reviewed_related","limitations":"offline preparation remains substantial; the two-round claim concerns the online phase rather than total execution","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2015-HALFGATES","paper_id":"MPC-PAPER-2015-HALFGATES","paper_title":"Two Halves Make a Whole: Reducing Data Transfer in Garbled Circuits Using Half Gates","paper_url":"https://www.cs.virginia.edu/~evans/pubs/ec2015/","year":2015,"title":"Half-gates reduce each Free-XOR-compatible AND gate to two ciphertexts","role":"gate_cost_reduction","statement":"Half-gates decomposes a garbled AND into evaluator and garbler halves, reaching two ciphertexts per AND gate while remaining compatible with the Free-XOR wire-label invariant.","source_locator":"Abstract and half-gates construction","lens":"garbled-circuit-efficiency","visibility":"backbone","limitations":"the bound is per AND gate rather than end-to-end cost; assumes the stated garbling and hash model","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2016-MASCOT-TRIPLES","paper_id":"MPC-PAPER-2016-MASCOT","paper_title":"MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious Transfer","paper_url":"https://eprint.iacr.org/2016/505","year":2016,"title":"OT-based checks replace public-key-heavy SPDZ triple generation","role":"preprocessing_replacement","statement":"MASCOT generates actively secure authenticated arithmetic triples from oblivious transfer, multiplication, and consistency checks, replacing SPDZ's somewhat-homomorphic-encryption preprocessing while preserving its online sharing protocol.","source_locator":"Abstract and preprocessing protocol","lens":"preprocessing-correlation","visibility":"backbone","limitations":"preprocessing and checks remain nontrivial; performance depends on OT implementation and network context","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2017-EMP-M2PC","paper_id":"MPC-PAPER-2017-EMP-M2PC","paper_title":"Faster Secure Two-Party Computation in the Single-Execution Setting","paper_url":"https://www.iacr.org/archive/eurocrypt2017/10210107/10210107.pdf","year":2017,"title":"Single-execution malicious garbled 2PC reduces setup and circuit-processing cost","role":"protocol_optimization","statement":"Wang, Ranellucci, and Katz optimize malicious garbled-circuit two-party computation for a single execution by reducing public-key work and improving oblivious-transfer and circuit-processing bottlenecks, with an open implementation supporting the evaluation.","source_locator":"Abstract and contribution summary","lens":"active-security","visibility":"reviewed_related","limitations":"performance is tied to the reported implementation context; the contribution does not represent every protocol exposed by later EMP repositories","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2018-ABY3-REPLICATED","paper_id":"MPC-PAPER-2018-ABY3","paper_title":"ABY3: A Mixed Protocol Framework for Machine Learning","paper_url":"https://eprint.iacr.org/2018/403","year":2018,"title":"Replicated ring sharing extends mixed-domain computation to three parties","role":"protocol_framework","statement":"ABY3 constructs a three-party mixed-protocol framework from replicated ring sharing and explicit arithmetic, binary, and Yao-style conversions, with the passive configuration separated from stronger variants.","source_locator":"Abstract and protocol overview","lens":"mixed-protocol-compilation","visibility":"backbone","limitations":"passive and stronger configurations must not be conflated; application-specific fixed-point semantics require separate accounting","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2019-PCG-SILENT","paper_id":"MPC-PAPER-2019-PCG","paper_title":"Efficient Pseudorandom Correlation Generators: Silent OT Extension and More","paper_url":"https://eprint.iacr.org/2019/448","year":2019,"title":"Pseudorandom correlation generators move large OT batches to local seed expansion","role":"correlation_generator","statement":"Boyle, Couteau, Gilboa, Ishai, Kohl, and Scholl formalize pseudorandom correlation generators and construct silent OT-style expansion, replacing communication and stored correlated randomness with short seeds and local computation.","source_locator":"Abstract; PCG definition and constructions","lens":"preprocessing-correlation","visibility":"backbone","limitations":"construction security depends on stated assumptions; local computation and seed-establishment costs remain","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","paper_id":"MPC-PAPER-2020-MOTION","paper_title":"MOTION — A Framework for Mixed-Protocol Multi-Party Computation","paper_url":"https://eprint.iacr.org/2020/1137","year":2020,"title":"MOTION generalizes modular mixed-protocol execution beyond two parties","role":"implementation_framework","statement":"MOTION provides an asynchronous modular software architecture that combines multiple sharing protocols and conversions for two or more parties under full-threshold passive security.","source_locator":"Abstract and framework architecture","lens":"implementation-systems","visibility":"reviewed_related","limitations":"active security is outside the normalized configuration; the paper contribution is distinct from later repository versions","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","paper_id":"MPC-PAPER-2020-MPSPDZ","paper_title":"MP-SPDZ: A Versatile Framework for Multi-Party Computation","paper_url":"https://eprint.iacr.org/2020/521","year":2020,"title":"MP-SPDZ unifies many MPC backends behind one compiler and virtual machine","role":"implementation_framework","statement":"MP-SPDZ provides a high-level compiler and virtual-machine architecture that realizes multiple arithmetic and binary MPC protocol families while keeping backend selection and protocol-specific costs explicit.","source_locator":"Abstract; architecture and supported-protocol sections","lens":"implementation-systems","visibility":"backbone","limitations":"supported configurations have incompatible security and preprocessing contracts; measurements remain version and environment specific","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2021-THREE-HALVES","paper_id":"MPC-PAPER-2021-THREE-HALVES","paper_title":"Three Halves Make a Whole? Beating the Half-Gates Lower Bound for Garbled Circuits","paper_url":"https://eprint.iacr.org/2021/749","year":2021,"title":"Three-Halves garbles a Free-XOR-compatible AND gate in 1.5λ + 5 bits","role":"gate_cost_reduction","statement":"RR21 constructs garbling for general Boolean circuits with free XOR gates and 1.5λ + 5 bits per AND gate using slicing and dicing, under the RTCCR hash assumption in Theorem 3. A gate-hiding variant costs 1.5λ + 10 bits per non-free gate; both have leading coefficient 1.5.","source_locator":"ePrint 2021/749, §1.1 (p. 2), §5.4 Theorem 3 (pp. 18–21), §6.1 (pp. 22–23), §8 (p. 25); PDF page numbers match printed pages","lens":"garbled-circuit-efficiency","visibility":"catalog_only","limitations":"The 1.5λ term is an upper bound achieved by this construction, not a universal lower bound.; Input encoding, output decoding, OT, and malicious-security enforcement are not included in a per-AND gate size.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2023-AKP-FOUR-ROUND-STATISTICAL","paper_id":"MPC-PAPER-2023-AKP","paper_title":"The Round Complexity of Statistical MPC with Optimal Resiliency","paper_url":"https://eprint.iacr.org/2023/418","year":2023,"title":"Four-round statistical MPC with GOD and exponential depth-dependent work","role":"theorem","statement":"Every functionality represented by a Boolean circuit of size S and depth D has a four-round statistically secure MPC protocol with GOD against static active rushing unbounded corruption of t < n/2 parties, with error 2^(-κ) and running time polynomial in κ, 2^n, S and 2^D, in the source's secure-channel and broadcast model.","source_locator":"ePrint 2023/418 revision 2025-06-17, §1 model (p. 5), §1.1.3 and Theorem 1.5 with following discussion and footnote 3 (p. 8)","lens":"generality-feasibility","visibility":"catalog_only","limitations":"This is not polynomial-time MPC for arbitrary polynomial-size circuits or growing n.; The NC¹ efficiency discussion has a qualified extension via secure reductions from log space; it is not a universal impossibility outside NC¹.; No adaptive-corruption or practical-performance claim is admitted.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2024-FOLEAGE-F4","paper_id":"MPC-PAPER-2024-FOLEAGE","paper_title":"FOLEAGE: F4OLE-Based Multi-Party Computation for Boolean Circuits","paper_url":"https://eprint.iacr.org/2024/429","year":2024,"title":"F4-OLE PCGs give near-linear communication for multiparty Boolean triples","role":"correlation_generator","statement":"FOLEAGE constructs multiparty Boolean-triple preprocessing from an F4-OLE pseudorandom correlation generator, with communication near linear in the number of parties times the number of triples plus lower-order seed terms.","source_locator":"Abstract and construction overview","lens":"preprocessing-correlation","visibility":"backbone","limitations":"lower-order seed costs and local work remain; exact concrete gains depend on party count and implementation context","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2024-HPMPC-NETWORK","paper_id":"MPC-PAPER-2024-HPMPC","paper_title":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","paper_url":"https://eprint.iacr.org/2024/386","year":2024,"title":"Topology-aware Trio and Quad tolerate all but two low-bandwidth links","role":"protocol_and_system_optimization","statement":"HP-MPC redistributes Trio and Quad communication so all but two links may have arbitrarily low bandwidth and all but one may have arbitrarily high latency, without increasing the protocols' total per-multiplication communication.","source_locator":"Abstract; Contributions; heterogeneous-network protocol variants","lens":"round-communication","visibility":"reviewed_related","limitations":"security and message schedules differ between Trio and Quad; the weak-link claim is protocol-structural rather than a portable throughput number; disconnection and availability are not implied","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK","paper_id":"MPC-PAPER-2024-HPMPC","paper_title":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","paper_url":"https://eprint.iacr.org/2024/386","year":2024,"title":"Trio and Quad reduce per-gate local arithmetic without extra communication","role":"implementation_aware_protocol_optimization","statement":"By reducing correlations among party shares, Trio and Quad require up to half as many basic local instructions per gate as the paper's related baselines while retaining total communication of three and five ring elements per multiplication.","source_locator":"Abstract; Contributions; protocol operation counts in Tables 1 and 13","lens":"round-communication","visibility":"reviewed_related","limitations":"the up-to-half comparison is operation- and baseline-specific; wall-clock gains depend on implementation and workload; Trio and Quad have different security contracts","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","paper_id":"MPC-PAPER-2024-HPMPC","paper_title":"High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network Settings","paper_url":"https://eprint.iacr.org/2024/386","year":2024,"title":"Trio and Quad use masked sharing at three and four parties","role":"protocol_construction","statement":"HP-MPC constructs Trio, a three-party protocol with one passive corruption, and Quad, a four-party protocol with one malicious corruption, using paper-specific masked-sharing semantics and total communication of three and five ring elements per multiplication respectively.","source_locator":"Contributions; Sections 3–5; Trio and Quad multiplication protocols","lens":"active-security","visibility":"reviewed_related","limitations":"the two configurations do not share one adversary contract; setup uses shared-key pseudorandom generation; communication totals do not by themselves imply the reported throughput","review_status":"primary_source_checked"},{"id":"MPC-CONTRIB-2025-CDPP-SIMD-GOD","paper_id":"MPC-PAPER-2025-CDPP","paper_title":"Statistical MPC with a Constant Communication Overhead","paper_url":"https://eprint.iacr.org/2025/1555","year":2025,"title":"Statistical GOD with constant communication overhead across Θ(n^7) SIMD evaluations","role":"theorem","statement":"With n = 3t+1 and synchronous private authenticated channels, the current CDPP manuscript gives statistically secure MPC with GOD and O(D) expected rounds against malicious adaptive unbounded corruption; for Θ(n^7) parallel evaluations of a circuit with c_M multiplication gates, one field-element input per party and one common output, total communication is O(c_M n^7+n^8) field elements.","source_locator":"ePrint 2025/1555 revision 2026-05-22, §1 adversary model (p. 1), §1.1 Theorem 1.1 (p. 2), §3 field/network convention (p. 11), §7 Theorem 7.1 and footnotes 9–10 (pp. 23–24)","lens":"round-communication","visibility":"catalog_only","limitations":"O(D) is an expected round bound, not a deterministic worst-case bound.; General-circuit-to-SIMD compilation introduces a log |C| size factor and potentially a depth-dependent additive term for irregular circuits.; The current revision is synchronous; an older abstract's asynchronous claims are not admitted.; No constant local-computation overhead or measured practicality claim is admitted.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2025-JRR-FREE-XOR-BOUND","paper_id":"MPC-PAPER-2025-JRR-GARBLING-BOUNDS","paper_title":"Lower Bounds for Garbled Circuits from Shannon-Type Information Inequalities","paper_url":"https://eprint.iacr.org/2025/876","year":2025,"title":"A 1.5λ lower bound for strongly secure Free-XOR AND gates with restricted evaluator queries","role":"theorem","statement":"JRR25 Theorem 26 gives a 1.5λ − negl(λ) garbled-gate size lower bound for the class of AND gates with input/output bit flips, under Definition 12 input-to-output syntax, λ-bit labels with the common Free-XOR offset, Definition 16 strong security, and non-adaptive coordinated evaluator queries to the random oracle.","source_locator":"ePrint 2025/876, §1.1 (pp. 3–4), Definitions 12–14 (pp. 9–10), §3.3 and Definition 16 (pp. 11–12), Theorem 26 and Corollary 27 (p. 23); PDF page numbers match printed pages","lens":"garbled-circuit-efficiency","visibility":"catalog_only","limitations":"Does not cover adaptive or uncoordinated evaluator oracle queries.; Does not establish a whole-circuit lower bound for non-projective or layer-batched encodings.; Strong security is not silently replaced by ordinary garbling security.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2026-BEP-CONSTANT-OVERHEAD-ABORT","paper_id":"MPC-PAPER-2026-BEP","paper_title":"Actively Secure MPC with O(|C|) Computation and Communication via CRT","paper_url":"https://eprint.iacr.org/2026/1270","year":2026,"title":"Active CRT-based MPC keeps leading computation and communication linear with abort","role":"theorem","statement":"For any fixed 0 < ε < 1/2 and fields with log |F| = Ω(n² log n), BEP gives statistically secure MPC with abort for general arithmetic circuits against t < (1/2−ε)n active corruptions, with O(|C| log |F|) leading communication and bit-computation cost under the source convention suppressing statistical-security, log n and log log |F| factors.","source_locator":"ePrint 2026/1270, §1.1 Theorem 1 and footnotes 3–4 (p. 2), preceding GOD discussion (p. 2) and §1.2 (p. 3)","lens":"active-security","visibility":"catalog_only","limitations":"Guaranteed output delivery is not provided.; No small-field, adaptive-corruption or exact O(D)-round claim is normalized from this introductory theorem.; The comparison does not assert that this is the uniquely closest result for every coordinate of MPC-OP-004.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2026-IKR-MULTIPARTY-SVMT-PCF","paper_id":"MPC-PAPER-2026-IKR-PCF","paper_title":"Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography","paper_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7","year":2026,"title":"PRF-based multiparty scalar-vector triples with exponential party-dependent key cost","role":"correlation_generator","statement":"IKR construct a k-party PCF for additive shares of a scalar x, vector a, and xa using only PRFs; if each scalar share lies in a common support S, each party holds k|S|^(k−1)−(k−1)|S|^(k−2)+2k−2 PRF keys and evaluates each key once per coordinate.","source_locator":"ITC 2026 proceedings, Theorem 2, p. 7:6; Definition 6, pp. 7:8–7:9; §4.2 and Corollary 27, pp. 7:14–7:17; Definitions 12–13, pp. 7:10–7:11","lens":"preprocessing-correlation","visibility":"catalog_only","limitations":"Exponential dependence on k remains even when F=S=F2.; Adaptive evaluation indices do not establish adaptive party corruption, malicious distributed key generation, or UC composition.; This atom is unauthenticated SVMT; authenticated variants have additional parameters and are not folded into its guarantee.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2026-IKR-SMALL-VOLE-PCF","paper_id":"MPC-PAPER-2026-IKR-PCF","paper_title":"Compressing Correlations via Secret Replication: PCFs from Symmetric Cryptography","paper_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ITC.2026.7","year":2026,"title":"Secret projection recovers small-scalar VOLE PCFs from PRFs","role":"correlation_generator","statement":"IKR derive a two-party PCF for VOLE over a finite field F with scalar in X subset F from any PRF; the direct construction assigns |X| keys to the sender and |X|−1 to the receiver, with one PRF call per held key per evaluated coordinate.","source_locator":"ITC 2026 proceedings, Theorem 1, p. 7:5; Corollary 22 and Remarks 24–25, p. 7:14; Definitions 12–13, pp. 7:10–7:11","lens":"preprocessing-correlation","visibility":"catalog_only","limitations":"Large scalar domains make the direct evaluation expensive; key compression alone does not remove this evaluation cost.; No generic OWF-based random-OT PCG or complete malicious MPC protocol is established by this contribution.","review_status":"fulltext_checked"},{"id":"MPC-CONTRIB-2026-LS-BATCHED-GARBLING","paper_id":"MPC-PAPER-2026-LS-GARBLING","paper_title":"Breaking the Ω(|C|κ) Barrier on Garbled Circuit Size in the Random Oracle Model","paper_url":"https://eprint.iacr.org/2026/1297","year":2026,"title":"Layer-batched ROM garbling separates circuit-size cost from statistical error","role":"theorem","statement":"LS26 Theorem 1 gives Boolean-circuit garbling of size O(|C| log T + Dκ² log T) bits and input encoding O(WI log T) bits in the programmable random-oracle model, with error 2^(−κ) against a computationally unbounded T-query adversary; D is depth and WI is the number of input wires.","source_locator":"ePrint 2026/1297, §1.1 Theorem 1 and Corollary 1 (pp. 4–5), §1.2 (pp. 7–8), §3.4 Definition 1 (pp. 16–17); PDF page numbers match printed pages","lens":"garbled-circuit-efficiency","visibility":"catalog_only","limitations":"The work explicitly defers improved concrete size; no measured implementation advantage is claimed here.; The input-encoding term remains separate and is not omitted from full communication accounting.; This different interface is not an APPROACHES edge to the single-gate target MPC-OP-005.","review_status":"fulltext_checked"}],"implementations":[{"id":"MPC-IMPL-2023-MOTION-FFA76F8","title":"MOTION at ffa76f8","year":2023,"artifact":{"repository":"https://github.com/encryptogroup/MOTION","commit":"ffa76f82ace55c7ba49c0c89d97246b8827c52a9","commit_url":"https://github.com/encryptogroup/MOTION/tree/ffa76f82ace55c7ba49c0c89d97246b8827c52a9","version":"commit-ffa76f8"},"artifact_type":"open-source modular MPC framework","configuration_ids":["MPC-PROTOCOL-MOTION-PASSIVE"],"configuration_binding":"paper-aligned passive full-threshold framework configuration","realized_stack":{"representation":"mixed Boolean and arithmetic circuit graph","value_encoding":"protocol-provider-specific shares and garbled values","evaluation_protocol":"GMW and garbled providers","correlation_source":"OT extension and provider-specific setup","active_security_enforcement":"passive only in the paper configuration","conversion_layer":"explicit mixed-protocol conversion gates","output_recovery_layer":"reconstruction with failure/transport abort"},"backend":"Boolean GMW, arithmetic GMW, BMR, and conversion providers in the pinned tree","language":"C++","maturity":"research framework","availability":"public repository","benchmark_eligible":true,"benchmark_eligibility_note":"Requires a fixed provider graph, party count, build profile, host/network, workload, and setup accounting.","evidence_status":"repository_revision_checked","source_locator":"pinned repository README and src/motioncore providers","primaryUrl":"https://github.com/encryptogroup/MOTION/tree/ffa76f82ace55c7ba49c0c89d97246b8827c52a9"},{"id":"MPC-IMPL-2026-ABY-88FED3E","title":"ABY at 88fed3e","year":2026,"artifact":{"repository":"https://github.com/encryptogroup/ABY","commit":"88fed3ef6789580cac342201e135a358a083ca36","commit_url":"https://github.com/encryptogroup/ABY/tree/88fed3ef6789580cac342201e135a358a083ca36","version":"commit-88fed3e"},"artifact_type":"open-source mixed-protocol 2PC framework","configuration_ids":["MPC-PROTOCOL-ABY-PASSIVE"],"configuration_binding":"paper-aligned passive ABY configuration","realized_stack":{"representation":"mixed arithmetic and Boolean circuit graph","value_encoding":"arithmetic, Boolean, and Yao shares","evaluation_protocol":"arithmetic sharing, Boolean GMW, and Yao garbling","correlation_source":"OT extension and circuit-specific preprocessing","active_security_enforcement":"passive configuration","conversion_layer":"A2B, B2A, A2Y, Y2A, B2Y, and Y2B-style conversion surface","output_recovery_layer":"output gates with connection-failure abort"},"backend":"arithmetic, Boolean GMW, and Yao circuits","language":"C++","maturity":"research framework","availability":"public repository","benchmark_eligible":true,"benchmark_eligibility_note":"Requires a fixed circuit, sharing assignment, cryptographic parameters, build flags, host/network, and phase accounting.","evidence_status":"repository_revision_checked","source_locator":"pinned README and src/abycore circuit/share providers","primaryUrl":"https://github.com/encryptogroup/ABY/tree/88fed3ef6789580cac342201e135a358a083ca36"},{"id":"MPC-IMPL-2026-HPMPC-155C935","title":"HP-MPC at 155c935","year":2026,"artifact":{"repository":"https://github.com/chart21/hpmpc","commit":"155c93572d747b527a6452c9ad8f24eb3b776667","commit_url":"https://github.com/chart21/hpmpc/tree/155c93572d747b527a6452c9ad8f24eb3b776667","version":"commit-155c935"},"artifact_type":"open-source high-throughput MPC runtime","configuration_ids":["MPC-PROTOCOL-HPMPC-3PC","MPC-PROTOCOL-HPMPC-4PC"],"configuration_binding":"protocol compile-time options select the exact 3PC/4PC configuration","realized_stack":{"representation":"batched Boolean or 2-power-ring circuits","value_encoding":"replicated and protocol-specific honest-majority shares","evaluation_protocol":"vectorized 3PC/4PC gate protocols","correlation_source":"pairwise seeded masks with optional preprocessing","active_security_enforcement":"protocol-selected passive or malicious checks","conversion_layer":"workload and protocol dependent","output_recovery_layer":"protocol reconstruction with abort behavior"},"backend":"vectorized 3PC and 4PC protocol implementations","language":"C and C++","maturity":"research implementation","availability":"public repository","benchmark_eligible":true,"benchmark_eligibility_note":"Paper observations are retained as non-comparable until protocol macro, hardware, vector width, workload, parties, topology, and accounting all match.","evidence_status":"repository_revision_checked","source_locator":"pinned README, config.h options, protocols directory, and paper Section 5","primaryUrl":"https://github.com/chart21/hpmpc/tree/155c93572d747b527a6452c9ad8f24eb3b776667"},{"id":"MPC-IMPL-2026-MPSPDZ-9D80959","title":"MP-SPDZ at 9d80959","year":2026,"artifact":{"repository":"https://github.com/data61/MP-SPDZ","commit":"9d809599ea6ce627216a389ca7d984fbb75d0cb9","commit_url":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9","version":"commit-9d80959"},"artifact_type":"open-source compiler and multi-backend runtime","configuration_ids":["MPC-PROTOCOL-SPDZ-SHE","MPC-PROTOCOL-MASCOT-SPDZ","MPC-PROTOCOL-TINYOT","MPC-PROTOCOL-BMR-SPDZ"],"configuration_binding":"multi_configuration_framework; exact runtime flag selects the protocol","realized_stack":{"representation":"high-level programs compiled to arithmetic or binary bytecode","value_encoding":"protocol-selected Shamir, replicated, authenticated additive, or binary shares","evaluation_protocol":"protocol-selected arithmetic, binary, garbled, or replicated evaluation","correlation_source":"protocol-selected OT, HE, dealer, or no separate preprocessing","active_security_enforcement":"protocol-selected MAC, sacrifice, consistency, or passive execution","conversion_layer":"documented mixed-domain types and conversion subprotocols","output_recovery_layer":"protocol-selected reconstruction and abort semantics"},"backend":"arithmetic and binary protocol families selected at runtime","language":"C++, Python, assembly-like bytecode","maturity":"research framework with broad protocol coverage","availability":"public repository","benchmark_eligible":true,"benchmark_eligibility_note":"Eligible only after a command fixes protocol, field/ring, security parameter, parties, compile flags, workload, network, and phase accounting.","evidence_status":"repository_revision_checked","source_locator":"pinned README, documentation protocol table, and source tree","primaryUrl":"https://github.com/data61/MP-SPDZ/tree/9d809599ea6ce627216a389ca7d984fbb75d0cb9"}],"benchmarkRuns":[{"id":"MPC-BENCH-2024-HPMPC-AND","title":"HP-MPC reported batched AND-gate throughput","year":2024,"implementation_id":"MPC-IMPL-2026-HPMPC-155C935","configuration_id":"MPC-PROTOCOL-HPMPC-3PC","artifact_commit":"155c93572d747b527a6452c9ad8f24eb3b776667","compatibility_key":{"configuration":"paper's implemented honest-majority 3PC/4PC protocol set; this row is bound to the displayed 3PC configuration for navigation","implementation_version":"repository snapshot 155c935; paper experiments predate this snapshot","party_profile":"three-party passive row; paper throughput statement spans several implemented protocols","security_model":"honest-majority; protocol-specific passive or malicious setting","workload":"large batch of independent Boolean AND gates","circuit_domain":"Boolean circuit over F2","problem_size":"batch size and vector width are protocol/figure dependent; consult paper Section 5","hardware":"paper benchmark servers; exact normalized host profile not transcribed into this atlas","network":"25 Gbit/s LAN for the headline observation","thread_count":"paper configuration; not normalized here","software_toolchain":"HP-MPC paper artifact lineage; pinned repository is a later revision","compiler_flags":"protocol and vectorization macros are required; exact headline-run flags not normalized","preprocessing_accounting":"paper-specific; online and total measurements must not be conflated","metric_definition":"steady-state batched gate throughput reported by the paper","evidence_state":"paper_reported_not_reproduced_and_artifact_revision_mismatch"},"metrics":{"and_gate_throughput":"more than 25 billion AND gates per second for each of six reported protocols on the 25-Gbit/s setup","arithmetic_multiplication_throughput":"more than one billion 32-bit multiplications per second for five of six implementations"},"comparable":false,"comparison_group":"none","non_comparability_reasons":["The pinned repository revision postdates the paper experiment.","The headline statement aggregates several protocol and security configurations.","Exact host, thread, batch, vector-width, and phase-accounting coordinates are not normalized in this record."],"evidence_status":"reported_not_reproduced","source_locator":"Paper abstract, Contributions, and Section 5; pinned repository README for later artifact identity","primaryUrl":"https://eprint.iacr.org/2024/386"}],"unresolved":[],"researchMap":{"schema_version":1,"rubric_version":1,"selection_policy":"semantic_contract_anchors","overview_focus_ids":["generality-feasibility","active-security","round-communication","network-delivery","adaptive-proactive","implementation-systems"],"threads":[{"id":"garbling_evaluation","label":"Garbling and distributed garbling","color":"#8b6340","description":"Garbled-circuit evaluation from two-party foundations through multiparty and gate optimizations."},{"id":"boolean_sharing_ot","label":"Boolean sharing and OT","color":"#2f718e","description":"Boolean secret sharing, oblivious transfer, and OT-amplified protocols."},{"id":"arithmetic_lsss","label":"Arithmetic sharing and LSSS","color":"#4f7b60","description":"Arithmetic secret sharing and multiplicative linear-secret-sharing architectures."},{"id":"authenticated_mpc","label":"Authenticated-share MPC","color":"#8e526e","description":"Authenticated shares, bits, and preprocessing for active security."},{"id":"correlation_generation","label":"Correlation generation","color":"#9a6c2d","description":"Triples, OT extension, PCGs, and other reusable offline correlations."},{"id":"mixed_domain_compilation","label":"Mixed-domain compilation","color":"#73549a","description":"Conversions and compilers across arithmetic, Boolean, and garbled representations."},{"id":"simulation_composition","label":"Security compilation and simulation","color":"#667784","description":"Security compilers, transcript-simulation mechanisms, and composition contracts across protocol environments."},{"id":"verifiable_sharing_coordination","label":"Verifiable sharing and coordination","color":"#2f7d77","description":"Verifiable sharing, asynchronous agreement, and share-refresh mechanisms that maintain distributed state."},{"id":"staged_output_protocols","label":"Staged output protocols","color":"#a34e48","description":"Protocol mechanisms that stage or condition output release to obtain function-specific fairness."}],"problems":[{"id":"generality-feasibility","label":"Generality and feasibility","question":"Which functionality, party, threshold, and network regimes admit secure computation?","reading_path":["MPC-CONTRIB-1982-YAO-2PC","MPC-CONTRIB-1987-GMW-COMPILER","MPC-CONTRIB-1988-BGW-THRESHOLDS","MPC-CONTRIB-1993-ASYNC-FEASIBILITY","MPC-CONTRIB-2000-CDM-LSSS"]},{"id":"garbled-circuit-efficiency","label":"Garbled-circuit efficiency","question":"Which invariants and encodings reduce garbled-circuit rounds, bandwidth, and gate cost?","reading_path":["MPC-CONTRIB-1982-YAO-2PC","MPC-CONTRIB-1990-BMR-CONSTANT","MPC-CONTRIB-2008-FREEXOR","MPC-CONTRIB-2015-HALFGATES","MPC-CONTRIB-2017-EMP-M2PC"]},{"id":"active-security","label":"Active security","question":"How are malicious deviations detected or tolerated across arithmetic, Boolean, and garbled protocols?","reading_path":["MPC-CONTRIB-1987-GMW-COMPILER","MPC-CONTRIB-1988-BGW-THRESHOLDS","MPC-CONTRIB-2011-SPDZ-AUTH","MPC-CONTRIB-2012-TINYOT-AUTHBITS","MPC-CONTRIB-2016-MASCOT-TRIPLES"]},{"id":"preprocessing-correlation","label":"Preprocessing and correlation","question":"Which correlations can be generated offline, cheaply expanded, or removed from online execution?","reading_path":["MPC-CONTRIB-1991-BEAVER-TRIPLES","MPC-CONTRIB-2003-IKNP-OTEXT","MPC-CONTRIB-2011-SPDZ-AUTH","MPC-CONTRIB-2016-MASCOT-TRIPLES","MPC-CONTRIB-2019-PCG-SILENT","MPC-CONTRIB-2024-FOLEAGE-F4"]},{"id":"round-communication","label":"Rounds and communication","question":"Which mechanisms reduce online rounds or communication without silently changing the security contract?","reading_path":["MPC-CONTRIB-1990-BMR-CONSTANT","MPC-CONTRIB-2008-FREEXOR","MPC-CONTRIB-2015-HALFGATES","MPC-CONTRIB-2019-PCG-SILENT","MPC-CONTRIB-2024-FOLEAGE-F4"]},{"id":"mixed-protocol-compilation","label":"Mixed-protocol compilation","question":"How can a computation cross arithmetic, Boolean, and garbled domains without flattening their cost models?","reading_path":["MPC-CONTRIB-2015-ABY-MIXED","MPC-CONTRIB-2018-ABY3-REPLICATED","MPC-CONTRIB-2020-MOTION-MULTIPARTY"]},{"id":"network-delivery","label":"Network and delivery","question":"Which network and fairness guarantees survive asynchrony, failure, and heterogeneous links?","reading_path":["MPC-CONTRIB-1988-BGW-THRESHOLDS","MPC-CONTRIB-1993-ASYNC-FEASIBILITY","MPC-CONTRIB-2010-FAIR-FUNCTIONS","MPC-CONTRIB-2024-HPMPC-NETWORK"]},{"id":"adaptive-proactive","label":"Adaptive and proactive security","question":"How can MPC remain secure when corruption timing changes or shares must be refreshed over time?","reading_path":["MPC-CONTRIB-1995-PROACTIVE-REFRESH","MPC-CONTRIB-1996-ADAPTIVE-NCE"]},{"id":"implementation-systems","label":"Practical realization","question":"Which protocol mechanisms became inspectable implementations or contextual measurements?","reading_path":["MPC-CONTRIB-2009-PRACTICAL2PC","MPC-CONTRIB-2017-EMP-M2PC","MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","MPC-CONTRIB-2024-HPMPC-NETWORK"]}],"overview_reading_path":["MPC-CONTRIB-1982-YAO-2PC","MPC-CONTRIB-1987-GMW-COMPILER","MPC-CONTRIB-1988-BGW-THRESHOLDS","MPC-CONTRIB-1991-BEAVER-TRIPLES","MPC-CONTRIB-2011-SPDZ-AUTH","MPC-CONTRIB-2015-ABY-MIXED","MPC-CONTRIB-2019-PCG-SILENT","MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK"],"nodes":{"MPC-CONTRIB-1982-YAO-2PC":{"group":"foundation","thread":"garbling_evaluation","lenses":["generality-feasibility","garbled-circuit-efficiency"],"visibility":"backbone","label":"Two-party SFE","primary":true,"anchor_roles":["model_definition","first_feasibility"],"selection_rationale":"Establishes secure two-party function evaluation as the task boundary needed to understand every later garbling and 2PC optimization without crediting it with all modern garbled-circuit details.","lane_rationale":"The card isolates private two-party function evaluation as a general research task and its feasibility boundary; it does not claim all later garbled-circuit machinery."},"MPC-CONTRIB-1987-GMW-COMPILER":{"group":"construction","thread":"boolean_sharing_ot","threads":["boolean_sharing_ot","simulation_composition"],"lenses":["generality-feasibility","active-security"],"visibility":"backbone","label":"General MPC compiler","primary":true,"anchor_roles":["first_feasibility","reusable_mechanism"],"selection_rationale":"Supplies the general circuit-to-MPC compiler and separates passive evaluation from adversary enforcement, a contract later sharing and authentication mechanisms deliberately instantiate.","lane_rationale":"The principal delta is the concrete circuit-to-MPC compilation architecture and adversary-enforcement transforms, not merely the historical fact of general feasibility."},"MPC-CONTRIB-1988-BGW-THRESHOLDS":{"group":"foundation","thread":"arithmetic_lsss","threads":["arithmetic_lsss","verifiable_sharing_coordination"],"lenses":["generality-feasibility","active-security","network-delivery"],"visibility":"backbone","label":"MPC threshold frontier","primary":true,"anchor_roles":["capability_boundary","lower_bound_or_barrier"],"selection_rationale":"Fixes the unconditional honest-majority corruption thresholds and the arithmetic-sharing architecture that later threshold, network, and access-structure results must qualify.","lane_rationale":"The mapped claim characterizes information-theoretic MPC feasibility and matching corruption-threshold limitations in the specified synchronous private-channel model."},"MPC-CONTRIB-1990-BMR-CONSTANT":{"group":"efficiency","thread":"garbling_evaluation","lenses":["garbled-circuit-efficiency","round-communication"],"visibility":"backbone","label":"Constant-round BMR","primary":true,"anchor_roles":["capability_boundary","reusable_mechanism"],"selection_rationale":"Shows that distributed garbling can remove circuit depth from online round complexity, anchoring the BMR line later combined with active arithmetic preprocessing.","lane_rationale":"The node's named delta removes circuit depth from communication-round complexity through distributed garbling; constant rounds do not mean constant communication."},"MPC-CONTRIB-1991-BEAVER-TRIPLES":{"group":"construction","thread":"correlation_generation","lenses":["preprocessing-correlation","round-communication"],"visibility":"backbone","label":"Beaver triples","primary":true,"anchor_roles":["reusable_mechanism"],"selection_rationale":"Isolates input-independent multiplication correlations as the online/offline interface reused by SPDZ and later preprocessing replacements.","lane_rationale":"The contribution supplies a reusable input-independent multiplication-correlation mechanism for masking online products; it is not a complete preprocessing implementation or a standalone benchmark."},"MPC-CONTRIB-1993-ASYNC-FEASIBILITY":{"group":"foundation","thread":"verifiable_sharing_coordination","lenses":["generality-feasibility","network-delivery"],"visibility":"backbone","label":"Asynchronous MPC","primary":true,"anchor_roles":["capability_boundary","first_feasibility"],"selection_rationale":"Introduces asynchronous verifiable sharing and agreement with distinct optimal fail-stop and Byzantine bounds; omitting the node would collapse two fault models into a generic honest-majority label.","lane_rationale":"The card establishes general asynchronous MPC feasibility with distinct optimal fail-stop and Byzantine resilience bounds; the fault models and errorless-computation conditions remain explicit."},"MPC-CONTRIB-1995-PROACTIVE-REFRESH":{"group":"construction","thread":"verifiable_sharing_coordination","lenses":["adaptive-proactive"],"visibility":"reviewed_related","label":"Proactive share refresh","primary":true,"selection_rationale":"Preserves the epoch-based refresh mechanism as a reviewed long-lived-security branch without presenting proactive secret sharing as a complete MPC configuration.","lane_rationale":"The node presents the concrete epoch-based share-renewal mechanism with erasure of obsolete state, rather than treating proactive security as an unqualified property of every MPC protocol."},"MPC-CONTRIB-1996-ADAPTIVE-NCE":{"group":"construction","thread":"simulation_composition","lenses":["adaptive-proactive"],"visibility":"reviewed_related","label":"Adaptive corruption security","primary":true,"selection_rationale":"Keeps non-committing encryption visible as the insecure-channel simulation mechanism for non-erasing adaptive corruption, preventing it from being conflated with epoch-based share refresh.","lane_rationale":"The claim is a non-committing-encryption transformation realizing adaptive security over insecure channels for non-erasing parties under stated thresholds, not an independent security analysis alone."},"MPC-CONTRIB-2000-CDM-LSSS":{"group":"construction","thread":"arithmetic_lsss","lenses":["generality-feasibility"],"visibility":"backbone","label":"Multiplicative LSSS MPC","primary":true,"anchor_roles":["capability_boundary","reusable_mechanism"],"selection_rationale":"Generalizes threshold polynomial sharing to multiplicative LSSS access structures, making the sharing representation an explicit compiler interface.","lane_rationale":"The contribution constructs MPC through a multiplicative-LSSS interface supporting qualified general access structures; its principal role is a reusable construction architecture."},"MPC-CONTRIB-2001-UC-COMPOSITION":{"group":"foundation","thread":"simulation_composition","lenses":["generality-feasibility","network-delivery"],"visibility":"reviewed_related","label":"UC composition contract","primary":true,"selection_rationale":"Keeps composability visible as a security-framework contribution so protocol rows do not silently inherit concurrent composition from stand-alone simulation.","lane_rationale":"The work defines environment-based universally composable security and establishes the composition theorem; protocol implementations do not inherit this framework without meeting its hypotheses."},"MPC-CONTRIB-2003-IKNP-OTEXT":{"group":"efficiency","thread":"correlation_generation","threads":["correlation_generation","boolean_sharing_ot"],"lenses":["preprocessing-correlation","garbled-circuit-efficiency"],"visibility":"backbone","label":"IKNP OT extension","primary":true,"anchor_roles":["reusable_mechanism","practice_transition"],"selection_rationale":"Establishes symmetric-key expansion of a small base-OT seed, the practical correlation mechanism consumed by later Boolean active-security protocols.","lane_rationale":"The source claim explicitly reduces public-key work for an OT batch to a small base-OT seed followed by symmetric-key expansion; the improved resource is public-key computation, not zero communication."},"MPC-CONTRIB-2008-FREEXOR":{"group":"efficiency","thread":"garbling_evaluation","lenses":["garbled-circuit-efficiency","round-communication"],"visibility":"backbone","label":"Free-XOR","primary":true,"anchor_roles":["reusable_mechanism","practice_transition"],"selection_rationale":"Changes the garbling invariant so XOR gates disappear from the ciphertext and cryptographic-operation budget, redefining the field's concrete circuit cost metric.","lane_rationale":"The global wire-label offset eliminates ciphertexts and cryptographic operations specifically for XOR gates while leaving nonlinear-gate cost and correlation assumptions intact."},"MPC-CONTRIB-2009-PRACTICAL2PC":{"group":"efficiency","thread":"garbling_evaluation","lenses":["garbled-circuit-efficiency","implementation-systems"],"visibility":"reviewed_related","label":"Practical 2PC codesign","primary":true,"selection_rationale":"Represents the whole-stack semi-honest 2PC co-design transition without confusing an implementation-aware research delta with a mutable artifact or one benchmark run.","lane_rationale":"The card records implementation-aware coordination of circuit generation, garbling, OT, memory, and networking for end-to-end semi-honest 2PC; performance remains tied to the paper's workloads and implementation."},"MPC-CONTRIB-2010-FAIR-FUNCTIONS":{"group":"foundation","thread":"staged_output_protocols","lenses":["network-delivery","generality-feasibility"],"visibility":"reviewed_related","label":"Fair OR and 3-party majority","primary":true,"selection_rationale":"Records the exact positive frontier—n-party OR and three-party majority—so a reader does not misread general fairness impossibility as ruling out every nontrivial functionality.","lane_rationale":"The mapped claim refines function-dependent fairness feasibility for n-party OR and three-party majority and includes the latter's round lower bound; it does not overturn general fairness impossibility."},"MPC-CONTRIB-2011-SPDZ-AUTH":{"group":"construction","thread":"authenticated_mpc","threads":["authenticated_mpc","correlation_generation"],"lenses":["active-security","preprocessing-correlation","round-communication"],"visibility":"backbone","label":"Authenticated-share MPC","primary":true,"anchor_roles":["capability_boundary","reusable_mechanism"],"selection_rationale":"Establishes authenticated arithmetic sharing with a light actively secure dishonest-majority online phase, the stable interface later preprocessing work deliberately preserves.","lane_rationale":"SPDZ supplies an authenticated-arithmetic-sharing architecture with global-MAC checks and an explicit preprocessing/online interface; stronger active-security guarantees qualify the construction rather than create a separate lane."},"MPC-CONTRIB-2012-TINYOT-AUTHBITS":{"group":"construction","thread":"authenticated_mpc","threads":["authenticated_mpc","boolean_sharing_ot"],"lenses":["active-security","preprocessing-correlation"],"visibility":"backbone","label":"TinyOT authenticated bits","primary":true,"anchor_roles":["capability_boundary","reusable_mechanism"],"selection_rationale":"Gives a Boolean-sharing active-security architecture based on authenticated bits and OT preprocessing rather than treating generic compilers or garbled cut-and-choose as the only route.","lane_rationale":"TinyOT gives a specialized actively secure Boolean 2PC protocol from authenticated bits, OT preprocessing, and consistency checks; the node identifies how that security contract is realized."},"MPC-CONTRIB-2015-ABY-MIXED":{"group":"construction","thread":"mixed_domain_compilation","lenses":["mixed-protocol-compilation","implementation-systems"],"visibility":"backbone","label":"ABY mixed protocols","primary":true,"anchor_roles":["capability_boundary","practice_transition"],"selection_rationale":"Makes arithmetic, Boolean, and garbled domains explicit typed choices connected by costed conversions, anchoring mixed-protocol compilation rather than a single sharing family.","lane_rationale":"The primary contribution is the mixed-domain framework and concrete conversion protocols among arithmetic sharing, Boolean sharing, and Yao garbling, not a single cross-work performance ranking."},"MPC-CONTRIB-2015-BMR-SPDZ":{"group":"construction","thread":"authenticated_mpc","threads":["authenticated_mpc","garbling_evaluation"],"lenses":["active-security","round-communication","preprocessing-correlation"],"visibility":"reviewed_related","label":"BMR + SPDZ","primary":true,"selection_rationale":"Preserves the cross-architecture composition of SPDZ preprocessing and BMR evaluation as reviewed-related, since it changes how components combine without starting a broader default thread.","lane_rationale":"The node composes an actively secure arithmetic preprocessing engine with distributed BMR garbling to realize a dishonest-majority protocol; the two-round claim is limited to its online phase."},"MPC-CONTRIB-2015-HALFGATES":{"group":"efficiency","thread":"garbling_evaluation","lenses":["garbled-circuit-efficiency","round-communication"],"visibility":"backbone","label":"Half-gates","primary":true,"anchor_roles":["practice_transition"],"selection_rationale":"Marks the two-ciphertext Free-XOR-compatible AND construction, the concrete nonlinear-gate communication point used by modern garbled-circuit implementations.","lane_rationale":"The principal delta is two ciphertexts per garbled AND while preserving the Free-XOR invariant; this is a specific nonlinear-gate communication improvement."},"MPC-CONTRIB-2016-MASCOT-TRIPLES":{"group":"construction","thread":"correlation_generation","threads":["correlation_generation","authenticated_mpc"],"lenses":["preprocessing-correlation","active-security","implementation-systems"],"visibility":"backbone","label":"MASCOT triples","primary":true,"anchor_roles":["practice_transition","reusable_mechanism"],"selection_rationale":"Replaces SPDZ's public-key-heavy offline generator with OT-based authenticated triples while preserving the online protocol, making backend modularity historically visible.","lane_rationale":"The mapped statement specifies an OT-based authenticated-triple generator replacing SHE preprocessing while retaining the SPDZ online interface; it does not normalize a context-independent performance advantage."},"MPC-CONTRIB-2017-EMP-M2PC":{"group":"efficiency","thread":"garbling_evaluation","lenses":["active-security","garbled-circuit-efficiency","implementation-systems"],"visibility":"reviewed_related","label":"EMP malicious 2PC","primary":true,"selection_rationale":"Captures the single-execution malicious-2PC optimization boundary and its implementation-aware accounting without making the released artifact itself the technical contribution.","lane_rationale":"The contribution optimizes public-key work, OT handling, and circuit processing for single-execution malicious 2PC; the accompanying artifact is evidence, not the reason for the lane."},"MPC-CONTRIB-2018-ABY3-REPLICATED":{"group":"construction","thread":"mixed_domain_compilation","threads":["mixed_domain_compilation","arithmetic_lsss"],"lenses":["mixed-protocol-compilation","round-communication","implementation-systems"],"visibility":"backbone","label":"ABY3 replicated sharing","primary":true,"anchor_roles":["capability_boundary","practice_transition"],"selection_rationale":"Moves mixed-domain computation to a three-party replicated-ring design, changing party model, sharing representation, and conversion costs together.","lane_rationale":"The claim gives a three-party replicated-ring architecture and domain conversions; changing the party/trust contract is not an unconditional improvement over two-party ABY."},"MPC-CONTRIB-2019-PCG-SILENT":{"group":"foundation","thread":"correlation_generation","lenses":["preprocessing-correlation","round-communication"],"visibility":"backbone","label":"Silent PCG correlations","primary":true,"anchor_roles":["reusable_mechanism","capability_boundary"],"selection_rationale":"Defines seed-expanded pseudorandom correlations and the silent-OT branch, changing large-batch correlation cost from communication and storage toward local computation.","lane_rationale":"The card explicitly isolates the new seed-to-correlation abstraction and its feasibility through silent expansion: compact correlated seeds define an independently reusable primitive, while local-work and setup costs remain."},"MPC-CONTRIB-2020-MOTION-MULTIPARTY":{"group":"construction","thread":"mixed_domain_compilation","lenses":["mixed-protocol-compilation","implementation-systems"],"visibility":"reviewed_related","label":"MOTION framework","primary":true,"selection_rationale":"Represents a modular multiparty mixed-protocol runtime as a systems-architecture contribution while leaving its pinned artifact and exact passive configurations separate.","lane_rationale":"The card contains a modular mixed-protocol execution architecture with explicit gate, wire, conversion, and runtime interfaces for passive multiparty computation; this is more than an artifact release and is not itself an asynchronous-network security theorem."},"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK":{"group":"construction","thread":"authenticated_mpc","lenses":["implementation-systems","active-security","preprocessing-correlation"],"visibility":"backbone","label":"MP-SPDZ framework","primary":true,"anchor_roles":["practice_transition"],"selection_rationale":"Establishes one compiler and virtual-machine surface across many explicit MPC backends, providing a practice anchor without implying that their security or cost contracts are interchangeable.","lane_rationale":"The contribution is a high-level compiler and virtual-machine architecture decoupling programs from explicit arithmetic and binary protocol backends; it is not merely repository availability or benchmark publication."},"MPC-CONTRIB-2024-FOLEAGE-F4":{"group":"efficiency","thread":"correlation_generation","lenses":["preprocessing-correlation","round-communication","implementation-systems"],"visibility":"backbone","label":"FOLEAGE preprocessing","primary":true,"anchor_roles":["current_frontier","practice_transition"],"selection_rationale":"Advances the PCG line to near-linear multiparty Boolean-triple communication through an F4-OLE construction, preserving its protocol optimization identity despite implementation evidence.","lane_rationale":"The mapped delta is near-linear party-by-triple preprocessing communication using F4-OLE PCG machinery, with seed terms and local computation explicitly retained."},"MPC-CONTRIB-2024-HPMPC-NETWORK":{"group":"efficiency","thread":"arithmetic_lsss","lenses":["round-communication","network-delivery","active-security","implementation-systems"],"visibility":"reviewed_related","label":"Weak-link-aware scheduling","primary":true,"selection_rationale":"Isolates the topology-aware message schedule and its exact weak-link tolerance; local instruction savings, masked protocol construction, software, and measurements are separate records.","lane_rationale":"The contribution changes the message schedule to tolerate specified weak links without increasing total per-multiplication communication; it is a topology-sensitive resource trade-off, not a universal throughput claim."},"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED":{"group":"construction","thread":"arithmetic_lsss","lenses":["active-security","round-communication","implementation-systems"],"visibility":"reviewed_related","label":"Trio and Quad masked sharing","primary":false,"selection_rationale":"Identifies the paper's complete three-party passive and four-party malicious masked-sharing protocols without crediting either configuration with the separate weak-link or implementation results.","lane_rationale":"The node isolates complete three-party passive Trio and four-party malicious Quad masked-sharing protocols with distinct security contracts, separate from local-work and network optimizations."},"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK":{"group":"efficiency","thread":"arithmetic_lsss","lenses":["round-communication","implementation-systems"],"visibility":"reviewed_related","label":"Lower per-gate local arithmetic","primary":false,"selection_rationale":"Makes the optimized resource explicit—basic local instructions per gate—so the paper's operation-count result is not flattened into an unqualified claim of high throughput.","lane_rationale":"The source contribution reduces basic local instructions per gate against named paper baselines without extra communicated ring elements; operation-count savings are not portable wall-clock measurements."}},"reading_collections":[{"id":"mpc_ot","label":"Oblivious transfer","question":"How are oblivious transfers constructed, extended, and generated, and which security and resource conditions govern those interfaces?","includes":"Definitions, constructions, extension mechanisms, and security or cost analyses that directly change the OT interface; named consumers and neighboring correlation interfaces may appear as context.","excludes":"Merely using OT in a complete MPC protocol does not make its contribution an OT advance; OLE, authenticated bits, and multiplication triples are not interchangeable names for OT.","coverage_note":"This pilot supports an OT-extension and silent-OT path, not a complete OT history. Foundational OT definitions, base constructions, and completeness results still need dedicated source contributions; component records do not fill that gap.","members":[{"contribution_id":"MPC-CONTRIB-2003-IKNP-OTEXT","role":"core","reason":"The atomic mechanism expands a small base-OT seed into many transfers through symmetric-key matrix expansion, directly changing the cost of the OT interface."},{"contribution_id":"MPC-CONTRIB-2019-PCG-SILENT","role":"core","reason":"The card explicitly includes silent OT constructions from compact correlated seeds; this OT-specific part directly changes communication and storage without eliminating seed setup or local work."},{"contribution_id":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","role":"context","reason":"OT-generated authenticated bits motivate an important consumer of OT, but the card's advance is actively secure Boolean sharing and its preprocessing rather than a new OT interface."},{"contribution_id":"MPC-CONTRIB-2016-MASCOT-TRIPLES","role":"context","reason":"The construction consumes OT to generate authenticated arithmetic triples; its direct resource result belongs to preprocessing and does not establish a new OT construction."},{"contribution_id":"MPC-CONTRIB-2024-FOLEAGE-F4","role":"context","reason":"F4-OLE-based Boolean-triple generation is a neighboring correlation interface that clarifies the boundary of OT; this context does not assert OT use or an OT improvement by FOLEAGE."}]},{"id":"mpc_preprocessing_resources","label":"Preprocessing and correlated resources","question":"Which input-independent correlated resources enable secure online computation, and how do their generation, authentication, storage, and communication costs change?","includes":"Direct advances in the offline-online resource abstraction, OT correlation expansion, authenticated bits and shares, OLE-based correlations, multiplication triples, and their generation or security checks.","excludes":"An offline phase or a correlation-source slot alone is insufficient for membership; consuming a sharing engine to prepare a garbled circuit does not by itself establish a new correlated-resource generator, and distinct resource interfaces retain their own contracts.","coverage_note":"Existing contributions support an initial path from circuit randomization through authenticated preprocessing and compact correlation expansion. OT overlaps intentionally with its independently readable collection; this pilot does not claim complete OT, OLE, VOLE, or preprocessing coverage.","members":[{"contribution_id":"MPC-CONTRIB-1991-BEAVER-TRIPLES","role":"core","reason":"The atomic mechanism uses input-independent multiplicative correlations to separate online arithmetic from offline preparation, directly defining the resource abstraction rather than a particular generator."},{"contribution_id":"MPC-CONTRIB-2003-IKNP-OTEXT","role":"core","reason":"Batch OT expansion directly improves generation of an explicit correlated resource; this intentional overlap with OT does not recast IKNP as an OLE or multiplication-triple generator."},{"contribution_id":"MPC-CONTRIB-2011-SPDZ-AUTH","role":"core","reason":"The contribution preprocesses authenticated multiplication correlations and establishes the global-MAC invariant used by online arithmetic, directly changing the authenticated-resource construction."},{"contribution_id":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","role":"core","reason":"The card constructs OT-generated authenticated bits and AND correlations with tailored consistency checks, directly advancing Boolean preprocessing resources."},{"contribution_id":"MPC-CONTRIB-2016-MASCOT-TRIPLES","role":"core","reason":"OT-based product generation, authentication, sacrifice, and consistency checks replace the original homomorphic-encryption triple generator while preserving the SPDZ online interface."},{"contribution_id":"MPC-CONTRIB-2019-PCG-SILENT","role":"core","reason":"The seed-to-correlation abstraction and local expansion directly change how structured correlated randomness is generated and stored, with assumptions, seed establishment, and local costs retained."},{"contribution_id":"MPC-CONTRIB-2024-FOLEAGE-F4","role":"core","reason":"The atomic delta specializes an F4-OLE PCG into multiparty Boolean-triple preprocessing and changes its communication accounting, without making seed costs or local work disappear."},{"contribution_id":"MPC-CONTRIB-2015-BMR-SPDZ","role":"context","reason":"The construction uses actively secure arithmetic MPC offline to prepare distributed garbling; it illustrates consumption and cross-phase composition rather than an independently claimed new OT, OLE, or triple generator."}]},{"id":"mpc_garbling","label":"Garbling","question":"How are garbled representations prepared, evaluated, and protected, and how can their protocol and execution costs be improved?","includes":"Direct advances in garbling encodings and evaluation, distributed garbling, maliciously secure execution, gate costs and round complexity, and protocol or systems co-design that changes these execution paths.","excludes":"Garbling is not synonymous with all two-party computation; independent OT generation, sharing mechanisms, mixed-domain conversion, backend support, or an artifact release alone does not establish a direct garbling contribution.","coverage_note":"This seed supports bounded paths through distributed garbling, gate optimization, semi-honest execution, and single-execution malicious protocols. Yao 1982 supplies conceptual context rather than an audited later garbling construction; later Yao formulations, formalization, and parts of the secure-execution literature still need dedicated source coverage. Gate types, threat models, and cost accounting remain distinct.","members":[{"contribution_id":"MPC-CONTRIB-1990-BMR-CONSTANT","role":"core","reason":"Distributed garbling changes the execution architecture so interaction rounds no longer grow with circuit depth; the contribution does not claim constant communication or computation."},{"contribution_id":"MPC-CONTRIB-2008-FREEXOR","role":"core","reason":"The global wire-label offset directly removes garbled ciphertexts and cryptographic operations for XOR gates under the stated correlation assumptions, without eliminating nonlinear-gate costs."},{"contribution_id":"MPC-CONTRIB-2009-PRACTICAL2PC","role":"core","reason":"End-to-end co-design coordinates circuit generation, garbling, OT handling, memory, and networking for semi-honest garbled two-party execution; this is a systems contribution to that path rather than merely an artifact release or invention of its components."},{"contribution_id":"MPC-CONTRIB-2015-BMR-SPDZ","role":"core","reason":"Authenticated arithmetic computation prepares and checks distributed BMR garbling, directly enabling the specified malicious dishonest-majority execution path; the two-round claim applies only to the online phase."},{"contribution_id":"MPC-CONTRIB-2015-HALFGATES","role":"core","reason":"The Free-XOR-compatible AND construction uses two correlated half-gates and two ciphertexts per AND; this directly changes garbling communication without asserting an end-to-end latency improvement."},{"contribution_id":"MPC-CONTRIB-2017-EMP-M2PC","role":"core","reason":"Protocol and implementation co-design reduces public-key work and circuit-processing costs for single-execution malicious garbled two-party computation; it does not stand for every backend in later EMP repositories."},{"contribution_id":"MPC-CONTRIB-1982-YAO-2PC","role":"context","reason":"The card establishes private two-party function evaluation as a general task, providing conceptual context without attributing a later complete garbled-circuit construction or modern formalization to this record."},{"contribution_id":"MPC-CONTRIB-2003-IKNP-OTEXT","role":"context","reason":"OT extension provides background on the cost of a distinct resource used in secure-computation execution; its atomic delta expands OT batches rather than changing garbling encodings or evaluation."}]},{"id":"mpc_secret_sharing","label":"Secret-sharing-based MPC","question":"How do MPC protocols represent, evaluate, and authenticate shared values, and maintain, refresh, or recover distributed state under explicit corruption and network models?","includes":"Directly MPC-related shared-value evaluation architectures, polynomial and linear sharing interfaces, verifiable sharing, authenticated shares, multiplication rules, refresh and recovery mechanisms, and protocol-level communication or local-work optimizations.","excludes":"This collection does not cover all independent secret-sharing theory; sharing only a decryption key in HE-based MPC, consuming an existing sharing engine, selecting among backends, or changing only resource generation while preserving the existing evaluation and authentication interface does not automatically establish a direct contribution.","coverage_note":"The current seed covers shared-value evaluation, authentication, refresh, asynchronous methods, replicated-ring architecture, and masked-sharing optimization, not a complete sharing, VSS, or MPC history. Early sharing and VSS sources, CCD, BDOZ, and Sharemind remain coverage gaps. Mechanisms and complete protocols are not interchangeable, and party, field or ring, corruption, network, and output conditions retain their separate meanings.","members":[{"contribution_id":"MPC-CONTRIB-1987-GMW-COMPILER","role":"core","reason":"The general compilation architecture evaluates circuit gates on distributed values and separates passive execution from stronger adversary enforcement; this membership does not add an optimized Boolean gate or OT-subprotocol claim absent from the atomic card."},{"contribution_id":"MPC-CONTRIB-1988-BGW-THRESHOLDS","role":"core","reason":"The contribution's own construction combines polynomial sharing, degree reduction, and verifiable sharing for general arithmetic evaluation, while preserving distinct model-specific passive and active threshold results."},{"contribution_id":"MPC-CONTRIB-1991-BEAVER-TRIPLES","role":"core","reason":"Opening masked differences and combining them with preprocessed correlations directly produces a sharing of a product, changing shared multiplication rules as well as the offline-online resource interface."},{"contribution_id":"MPC-CONTRIB-1993-ASYNC-FEASIBILITY","role":"core","reason":"The atomic construction combines asynchronous verifiable sharing, agreement, and online error correction rather than merely tagging a protocol as asynchronous; its fail-stop and Byzantine resilience bounds remain distinct."},{"contribution_id":"MPC-CONTRIB-1995-PROACTIVE-REFRESH","role":"core","reason":"Cross-epoch rerandomization and erasure directly change maintenance of distributed shares without changing the protected secret; the mechanism retains its per-epoch assumptions and is not a complete MPC protocol."},{"contribution_id":"MPC-CONTRIB-2000-CDM-LSSS","role":"core","reason":"Multiplicative linear secret sharing supplies a representation-level interface for shared evaluation beyond a single threshold, subject to the stated multiplication and robustness conditions rather than applying to every LSSS."},{"contribution_id":"MPC-CONTRIB-2011-SPDZ-AUTH","role":"core","reason":"The global-MAC invariant, authenticated arithmetic shares, and online openings and checks directly change shared evaluation and verification, not only the generation of preprocessing material."},{"contribution_id":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","role":"core","reason":"Authenticated bits, AND correlations, and amortized consistency checks define a specialized actively secure Boolean-sharing evaluation architecture rather than a garbling construction or OT extension alone."},{"contribution_id":"MPC-CONTRIB-2018-ABY3-REPLICATED","role":"core","reason":"The contribution changes the three-party replicated-ring common architecture and its arithmetic, binary, and Yao-style conversion interfaces; it does not claim invention of replicated sharing or one security guarantee for all variants."},{"contribution_id":"MPC-CONTRIB-2024-HPMPC-TRIO-QUAD-MASKED","role":"core","reason":"Trio and Quad change masked-share layouts, multiplication, and checking rules in their respective three- and four-party protocols, retaining their distinct passive and malicious security contracts."},{"contribution_id":"MPC-CONTRIB-2024-HPMPC-NETWORK","role":"core","reason":"Topology-aware message schedules directly change execution of the specified sharing protocols while retaining their per-multiplication communication totals; the result is not general asynchronous feasibility, availability, or portable throughput."},{"contribution_id":"MPC-CONTRIB-2024-HPMPC-REDUCED-LOCAL-WORK","role":"core","reason":"Revised masked-share correlations reduce local instructions on the multiplication path without extra communicated ring elements, a protocol-level efficiency delta rather than a new resource generator or universal benchmark ranking."},{"contribution_id":"MPC-CONTRIB-2016-MASCOT-TRIPLES","role":"context","reason":"MASCOT directly improves authenticated-triple generation while the card explicitly preserves the SPDZ online sharing protocol; it illustrates modular preprocessing rather than a new shared-value evaluation semantics."},{"contribution_id":"MPC-CONTRIB-2015-BMR-SPDZ","role":"context","reason":"The construction consumes an actively secure arithmetic-sharing engine to prepare distributed garbling, providing downstream composition context while its direct research target remains the garbled execution path."}]},{"id":"mpc_models_feasibility_composition","label":"Models, feasibility, and security composition","question":"Under which functionality, party, corruption, setup, network, and composition conditions can secure computation achieve its stated guarantees?","includes":"Definitions, feasibility and limitation results, independently attributable security analyses, and general constructions or transformations that directly establish or change those conditions; proactive state protection and function-specific output boundaries retain their exact scope.","excludes":"This collection is not the Foundation lane. A concrete protocol's malicious, adaptive, or UC security properties, ordinary cost improvements, and asynchronous runtime scheduling do not alone establish a new model or feasibility contribution.","coverage_note":"The seed covers early private computation, general compilation, threshold and access-structure boundaries, asynchronous and adaptive models, proactive state protection, composition, and selected fairness results. Independent impossibility sources, CCD attribution, and further model refinements remain incomplete; the results do not share one security or comparison contract.","members":[{"contribution_id":"MPC-CONTRIB-1982-YAO-2PC","role":"core","reason":"The contribution establishes private function evaluation as a general research task through early two-party protocols, without attributing modern simulation definitions or later garbled-circuit constructions to this atomic record."},{"contribution_id":"MPC-CONTRIB-1987-GMW-COMPILER","role":"core","reason":"General circuit compilation and the separation of passive evaluation from stronger adversary enforcement directly establish a generality and security-compilation boundary, rather than merely recording the security properties of one optimized gate protocol."},{"contribution_id":"MPC-CONTRIB-1988-BGW-THRESHOLDS","role":"core","reason":"The result establishes information-theoretic general MPC with passive corruption below one half and Byzantine corruption below one third, together with the corresponding limitations in its synchronous private-channel model."},{"contribution_id":"MPC-CONTRIB-1993-ASYNC-FEASIBILITY","role":"core","reason":"The contribution establishes errorless general computation in a completely asynchronous private-channel network, with separate optimal resilience bounds below one third for fail-stop faults and below one fourth for Byzantine faults."},{"contribution_id":"MPC-CONTRIB-1995-PROACTIVE-REFRESH","role":"core","reason":"Cross-epoch rerandomization directly changes the mobile-corruption security boundary for distributed state, retaining per-epoch thresholds, refresh assumptions, and secure erasure rather than claiming a complete general-purpose MPC protocol."},{"contribution_id":"MPC-CONTRIB-1996-ADAPTIVE-NCE","role":"core","reason":"Non-committing encryption supplies an adaptive-simulation transformation for non-erasing parties over insecure channels under the stated trapdoor assumptions; the principal construction handles fewer than one third corruptions and the card separately notes a modification below one half, not an epoch-based refresh guarantee."},{"contribution_id":"MPC-CONTRIB-2000-CDM-LSSS","role":"core","reason":"The abstraction and compiler extend general MPC beyond a single threshold to access structures satisfying the stated multiplicativity and robustness conditions; this is a direct generality change, not a claim that every LSSS suffices."},{"contribution_id":"MPC-CONTRIB-2001-UC-COMPOSITION","role":"core","reason":"Environment-based simulation, ideal-functionality replacement, and the universal composition theorem are the direct research objects, with the framework and setup assumptions retained rather than inferred from a protocol's UC label."},{"contribution_id":"MPC-CONTRIB-2010-FAIR-FUNCTIONS","role":"core","reason":"The result gives complete fairness for n-party Boolean OR and three-party majority with any t<n corruptions under the stated cryptographic and private-broadcast-or-PKI conditions, including a super-logarithmic round lower bound for majority; it is not a generic fairness or guaranteed-output-delivery upgrade."},{"contribution_id":"MPC-CONTRIB-2011-SPDZ-AUTH","role":"context","reason":"The concrete authenticated-sharing protocol illustrates explicitly scoped UC and adaptive-security conditions, but its atomic change is the sharing and preprocessing architecture rather than a new security model merely because those properties hold."}]},{"id":"mpc_mixed_domain_computation","label":"Mixed-domain computation and compilation","question":"How can one secure computation assign subcomputations to typed representations and evaluation protocols, convert between them, and account for conversion and execution costs?","includes":"Within-computation protocol assignment, typed domain conversions, cross-domain compilation, and execution architectures whose own contribution explicitly supports those interfaces.","excludes":"Security composition theorems, arbitrary assemblies of cryptographic components, different offline and online mechanisms, and selectable alternative backends do not by themselves establish mixed-domain execution.","coverage_note":"TASTY and KSS14 now precede ABY, ABY3, and MOTION in the reading collection, distinguishing typed mixed compilation from conversion-aware automatic assignment across distinct configurations. Earlier modular-design sources and other predecessors, later assignment methods, and wider conversion coverage remain gaps; neither TASTY nor ABY is presented as the beginning of all mixed-protocol work. The two newly reviewed contributions remain catalog-only pending a separate map-selection review.","members":[{"contribution_id":"MPC-CONTRIB-2010-TASTY-MIXED-COMPILER","role":"core","reason":"TASTYL explicitly describes homomorphic and garbled values and their conversions, and TASTY generates the corresponding semi-honest two-party execution. The programmer supplies the protocol representation choices; automatic protocol selection is explicitly left to future work, not claimed by this atom."},{"contribution_id":"MPC-CONTRIB-2014-KSS-PROTOCOL-SELECTION","role":"core","reason":"Conversion-aware assignment of operations between HE-based arithmetic and garbled circuits is the direct research target, with integer programming and a greedy heuristic evaluated against a specified forecast cost model. Model-relative optimization is not universal fastest execution or a proved hardness result for this partitioning problem."},{"contribution_id":"MPC-CONTRIB-2015-ABY-MIXED","role":"core","reason":"Explicit, costed conversions let a single computation move among arithmetic sharing, Boolean sharing, and Yao garbling, with the source card's passive two-party configuration conditions retained."},{"contribution_id":"MPC-CONTRIB-2018-ABY3-REPLICATED","role":"core","reason":"The three-party replicated-ring architecture supplies arithmetic, binary, and Yao-style conversions tailored to that party model, directly changing mixed-domain execution without combining the security claims of all variants."},{"contribution_id":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","role":"core","reason":"Modular protocol providers and conversions support mixed execution for two or more parties under the documented passive full-threshold model; asynchronous runtime scheduling does not establish security in an asynchronous network model."},{"contribution_id":"MPC-CONTRIB-2015-BMR-SPDZ","role":"context","reason":"Arithmetic preprocessing that prepares distributed garbling supplies a cross-phase composition contrast, not evidence of ABY-style typed conversion among subcomputations within the online computation."},{"contribution_id":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","role":"context","reason":"The multi-backend compiler and virtual machine clarify how selecting a protocol backend differs from within-computation typed conversion; this context preserves the card's systems-architecture contribution without asserting mixed execution absent from its atomic claim."}]}],"subfield_views":[{"collection_id":"mpc_ot","focus_ids":["round-communication"],"problem_ids":["MPC-OP-002"],"problem_note":"The random-OT correlation-compression target concerns OT itself, with correlated seed setup explicitly allowed. It is not an OWF-only base-OT claim.","comparison_groups":[{"id":"ot_extension","label":"OT extension","row_type":"component","record_ids":["MPC-COMP-CORR-OTEXT"],"reason":"The IKNP record describes OT expansion itself. Complete MPC consumers and generic correlation interfaces are not treated as alternative OT constructions."}],"comparison_note":"One OT-extension component is currently normalized; a comparison across base-OT and silent-OT constructions needs additional exact construction records."},{"collection_id":"mpc_preprocessing_resources","focus_ids":["active-security","round-communication","implementation-systems"],"problem_ids":["MPC-OP-002","MPC-OP-003"],"problem_note":"These targets concern the assumptions for expanding random OT and the party-scaling cost of symmetric-only multiparty scalar-vector triples. The OT target is the same canonical record used in the OT subfield.","comparison_groups":[{"id":"arithmetic_generators","label":"Authenticated arithmetic preprocessing","row_type":"component","record_ids":["MPC-COMP-CORR-SHE","MPC-COMP-CORR-MASCOT"],"reason":"These are distinct generators for authenticated arithmetic preprocessing; preserve their homomorphic-encryption versus OT mechanisms and their source-specific checks."},{"id":"boolean_generator","label":"Boolean-triple generation","row_type":"component","record_ids":["MPC-COMP-CORR-F4OLE"],"reason":"This record is an F4-OLE-based Boolean-triple generator, not a replacement name for arithmetic triples or OT."},{"id":"spdz_configurations","label":"SPDZ configurations with different preprocessing","row_type":"protocol","record_ids":["MPC-PROTOCOL-SPDZ-SHE","MPC-PROTOCOL-MASCOT-SPDZ"],"reason":"These complete configurations expose the effect of changing the preprocessing source while retaining the SPDZ online interface; they are not themselves generator-only rows."}],"comparison_note":"Generator interfaces and complete protocol configurations remain separate. These selected records do not cover every OT, OLE, PCG, or authenticated-resource construction, and membership alone establishes no benchmark comparability."},{"collection_id":"mpc_garbling","focus_ids":["garbled-circuit-efficiency","active-security","round-communication","implementation-systems"],"problem_ids":["MPC-OP-005"],"problem_note":"This target isolates the query-model gap in single-gate Free-XOR optimality. Whole-circuit batching and arithmetic garbling have different interfaces; this selected question is not a complete frontier for garbling.","comparison_groups":[{"id":"garbled_protocols","label":"Garbled protocol configurations","row_type":"protocol","record_ids":["MPC-PROTOCOL-YAO-PASSIVE","MPC-PROTOCOL-BMR-PASSIVE","MPC-PROTOCOL-BMR-SPDZ"],"reason":"The selected configurations directly execute two-party or distributed garbling. Their party counts, passive or active security, and offline versus online costs must remain explicit."}],"comparison_note":"These are distinct execution contracts, not a common-security performance ranking. Merely offering a garbling backend does not place a mixed framework in this selection."},{"collection_id":"mpc_secret_sharing","focus_ids":["generality-feasibility","active-security","round-communication","network-delivery","adaptive-proactive","implementation-systems"],"problem_ids":["MPC-OP-004"],"problem_note":"The general-circuit statistical GOD target concerns robust packed-sharing evaluation without relying on a large SIMD batch. It is also listed under models because the output guarantee is an essential target condition.","comparison_groups":[{"id":"sharing_protocols","label":"Shared-value protocol configurations","row_type":"protocol","record_ids":["MPC-PROTOCOL-GMW-PASSIVE","MPC-PROTOCOL-BGW-ACTIVE","MPC-PROTOCOL-SPDZ-SHE","MPC-PROTOCOL-MASCOT-SPDZ","MPC-PROTOCOL-TINYOT","MPC-PROTOCOL-ABY3-PASSIVE","MPC-PROTOCOL-HPMPC-3PC","MPC-PROTOCOL-HPMPC-4PC"],"reason":"These configurations specify Boolean, polynomial, authenticated, replicated, or masked shared-value evaluation. ABY3 is included for its replicated-sharing configuration; MASCOT-SPDZ is an online sharing configuration, not a claim that its generator introduced the online interface."}],"comparison_note":"Compare representation, party and corruption model, authentication, output, and cost coordinates separately. Different fields, rings, or threat models are not interchangeable benchmark settings."},{"collection_id":"mpc_models_feasibility_composition","focus_ids":["generality-feasibility","active-security","network-delivery","adaptive-proactive"],"problem_ids":["MPC-OP-001","MPC-OP-004"],"problem_note":"These targets ask for efficient constant-round information-theoretic general computation and low-overhead statistical computation with guaranteed output delivery. They have distinct adversary, round, and cost contracts; neither is inferred from map focus labels.","comparison_groups":[{"id":"model_contract_examples","label":"Configurations under different security contracts","row_type":"protocol","record_ids":["MPC-PROTOCOL-GMW-PASSIVE","MPC-PROTOCOL-BGW-ACTIVE","MPC-PROTOCOL-SPDZ-SHE","MPC-PROTOCOL-BMR-SPDZ","MPC-PROTOCOL-ABY3-PASSIVE","MPC-PROTOCOL-HPMPC-4PC"],"reason":"These explicit examples permit comparison of party count, corruption, setup, and output contracts. A configuration satisfying a model is not thereby an independent contribution to that model's feasibility or composition theory."}],"comparison_note":"This selection compares concrete contracts, not completeness theorems or universally ordered security levels. The subfield's independent models and bounds remain in its contribution map and reading list."},{"collection_id":"mpc_mixed_domain_computation","focus_ids":["round-communication","implementation-systems"],"problem_ids":[],"problem_note":"End-to-end compiler verification and robust cost prediction remain documented research directions, not admitted theorem-style residuals in this first batch. This empty scope does not mean mixed-domain computation has no open problems.","comparison_groups":[{"id":"mixed_configurations","label":"Mixed-domain configurations","row_type":"protocol","record_ids":["MPC-PROTOCOL-ABY-PASSIVE","MPC-PROTOCOL-ABY3-PASSIVE","MPC-PROTOCOL-MOTION-PASSIVE"],"reason":"Each source configuration explicitly supports typed execution and conversion within a computation. Their two-party, three-party, and multiparty contracts remain different."},{"id":"conversion_interfaces","label":"Conversion interfaces","row_type":"component","record_ids":["MPC-COMP-CONV-ABY","MPC-COMP-CONV-ABY3","MPC-COMP-CONV-MOTION"],"reason":"These components explicitly convert between value domains during mixed execution; the arithmetic-to-BMR offline bridge is not silently treated as the same interface."}],"comparison_note":"TASTY and KSS contributions are available in the reading list, but exact configuration rows have not yet been authored. Their absence here is not an assertion that ABY began mixed-protocol computation."}],"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"relations":[{"predecessor":"MPC-CONTRIB-2008-FREEXOR","successor":"MPC-CONTRIB-2015-HALFGATES","relation_type":"BUILDS_ON_MECHANISM","statement":"Half-gates retains Free-XOR compatibility while reducing each AND gate to two ciphertexts.","evidence_locator":"Half-gates abstract and comparison with Free-XOR garbling","evidence_url":"https://www.cs.virginia.edu/~evans/pubs/ec2015/","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","efficiency"],"map_relation":"lineage","id":"lineage-dcd52960b41d5829"},{"predecessor":"MPC-CONTRIB-1990-BMR-CONSTANT","successor":"MPC-CONTRIB-2015-BMR-SPDZ","relation_type":"ACTIVELY_SECURES","statement":"The 2015 protocol retains BMR local garbled-circuit evaluation and changes its distributed preparation to an actively secure SPDZ-backed computation.","evidence_locator":"BMR+SPDZ abstract and Sections 2–4","evidence_url":"https://eprint.iacr.org/2015/523","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","security"],"map_relation":"lineage","id":"lineage-9004cdb3341d3388"},{"predecessor":"MPC-CONTRIB-1987-GMW-COMPILER","successor":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","relation_type":"CHANGES_SECURITY_MECHANISM","statement":"TinyOT keeps Boolean shared-circuit evaluation but replaces a generic malicious compiler with OT-generated authenticated bits and specialized checks.","evidence_locator":"TinyOT introduction and authenticated-bit protocol","evidence_url":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf","review_status":"primary_source_checked","relation_basis":"result_progression","change_dimensions":["mechanism","security"],"map_relation":"related_work","id":"lineage-a66fa93d8a6aacdf"},{"predecessor":"MPC-CONTRIB-2003-IKNP-OTEXT","successor":"MPC-CONTRIB-2012-TINYOT-AUTHBITS","relation_type":"SUPPLIES_CORRELATION","statement":"TinyOT's practical preprocessing relies on extending OTs so authenticated Boolean correlations can be generated at scale.","evidence_locator":"TinyOT introduction and preprocessing analysis","evidence_url":"https://www.iacr.org/archive/crypto2012/74170674/74170674.pdf","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","efficiency"],"map_relation":"related_work","id":"lineage-df68959c3fb0dbeb"},{"predecessor":"MPC-CONTRIB-1988-BGW-THRESHOLDS","successor":"MPC-CONTRIB-2000-CDM-LSSS","relation_type":"GENERALIZES_REPRESENTATION","statement":"CDM generalizes the polynomial secret-sharing approach to multiplicative linear secret-sharing schemes and general access structures.","evidence_locator":"CDM abstract and introduction","evidence_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070321-new.pdf","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","model","functionality"],"map_relation":"lineage","id":"lineage-100ee4b0894d8ba8"},{"predecessor":"MPC-CONTRIB-1991-BEAVER-TRIPLES","successor":"MPC-CONTRIB-2011-SPDZ-AUTH","relation_type":"ACTIVELY_AUTHENTICATES","statement":"SPDZ instantiates the preprocessing model with authenticated arithmetic triples and global-MAC checks that tolerate a dishonest majority.","evidence_locator":"SPDZ online protocol and preprocessing overview","evidence_url":"https://eprint.iacr.org/2011/535","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","security"],"map_relation":"lineage","id":"lineage-9321183e9e751f5c"},{"predecessor":"MPC-CONTRIB-2011-SPDZ-AUTH","successor":"MPC-CONTRIB-2016-MASCOT-TRIPLES","relation_type":"REPLACES_PREPROCESSING","statement":"MASCOT preserves the SPDZ authenticated-sharing online phase but replaces SHE-based triple generation with OT-based multiplication and consistency checks.","evidence_locator":"MASCOT abstract and comparison to SPDZ preprocessing","evidence_url":"https://eprint.iacr.org/2016/505","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","assumption"],"map_relation":"lineage","id":"lineage-aadd882535698b65"},{"predecessor":"MPC-CONTRIB-2011-SPDZ-AUTH","successor":"MPC-CONTRIB-2015-BMR-SPDZ","relation_type":"INSTANTIATES_OFFLINE_PHASE","statement":"The BMR+SPDZ construction uses SPDZ as the actively secure arithmetic engine that prepares and checks the distributed garbling.","evidence_locator":"BMR+SPDZ abstract and Section 4","evidence_url":"https://eprint.iacr.org/2015/523","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","security"],"map_relation":"lineage","id":"lineage-ecb0ecd6084cc823"},{"predecessor":"MPC-CONTRIB-2015-ABY-MIXED","successor":"MPC-CONTRIB-2018-ABY3-REPLICATED","relation_type":"CHANGES_PARTY_AND_SHARING_MODEL","statement":"ABY3 adapts ABY's mixed arithmetic, Boolean, and Yao-domain interface to a three-party replicated-sharing design with new conversions, changing the party and trust contract rather than subsuming the two-party setting.","evidence_locator":"ABY3 introduction and comparison with ABY","evidence_url":"https://eprint.iacr.org/2018/403","review_status":"primary_source_checked","relation_basis":"model_relation","change_dimensions":["model","mechanism"],"map_relation":"lineage","id":"lineage-81a4cb87a23610c3"},{"predecessor":"MPC-CONTRIB-2015-ABY-MIXED","successor":"MPC-CONTRIB-2020-MOTION-MULTIPARTY","relation_type":"CHANGES_FRAMEWORK_SCOPE","statement":"MOTION supplies a modular runtime for mixed-protocol computation with two or more passively secure parties, compared with ABY's two-party framework; the recorded evidence does not establish inclusion of every ABY protocol or configuration.","evidence_locator":"MOTION abstract and related-work comparison","evidence_url":"https://eprint.iacr.org/2020/1137","review_status":"primary_source_checked","relation_basis":"model_relation","change_dimensions":["model","implementation"],"map_relation":"related_work","id":"lineage-aa96933689e91d90"},{"predecessor":"MPC-CONTRIB-2011-SPDZ-AUTH","successor":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","relation_type":"IMPLEMENTS_AS_BACKEND","statement":"MP-SPDZ realizes the SPDZ lineage alongside alternative offline phases and protocol families behind a common compiler/runtime.","evidence_locator":"MP-SPDZ architecture and supported-protocol table","evidence_url":"https://eprint.iacr.org/2020/521","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","implementation"],"map_relation":"lineage","id":"lineage-31c682a917f1b879"},{"predecessor":"MPC-CONTRIB-2016-MASCOT-TRIPLES","successor":"MPC-CONTRIB-2020-MPSPDZ-FRAMEWORK","relation_type":"IMPLEMENTS_AS_BACKEND","statement":"MP-SPDZ exposes MASCOT-style OT preprocessing as one backend for authenticated arithmetic online computation.","evidence_locator":"MP-SPDZ supported-protocol table and documentation","evidence_url":"https://eprint.iacr.org/2020/521","review_status":"primary_source_checked","relation_basis":"technical_dependency","change_dimensions":["mechanism","implementation"],"map_relation":"lineage","id":"lineage-8368f9e3dd8e48d4"}]},"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}