- The paper introduces dealer-assisted LTBits and MSB protocols for both Fp and Z2^k, using rich correlated randomness to reduce online comparison to one or tunably few communication rounds.
- The protocols achieve perfect security at the abstract protocol level and remain portable across MPC backends, adversary models, and party configurations through an extended arithmetic black-box interface.
- Experiments show speedups of up to 19.4× for small-batch prime-field comparisons over WAN and 1.79×–2.78× for ring-based comparisons across larger LAN and WAN workloads, while dealer trust and preprocessing costs remain limitations.
Overview and motivation
Secure comparison remains one of the dominant performance bottlenecks in practical multi-party computation (MPC). While arithmetic operations are efficiently supported via Beaver triples, comparison requires bit decomposition, prefix computations, or masked zero-testing, and its preprocessing phase—generating correlated randomness such as daBits, edaBits, and function secret sharing (FSS) material—can cost several to dozens of times more than the online phase. Recent dealer-assisted frameworks introduce a passive, non-colluding dealer that generates preprocessing data offline, but existing systems treat the dealer largely as a drop-in replacement for conventional preprocessing, producing the same triple- or edaBit-style randomness without redesigning the comparison protocol itself. Moreover, most prior comparison protocols are specialized to particular algebraic domains (Fp vs. Z2k), adversary models, or party configurations.
This paper addresses both issues by presenting the first dealer-assisted n-party LTBits (Less-Than-Bits) and MSB extraction protocols over both Fp and Z2k, achieving perfect security at the protocol level. The key design principle is to fully exploit the dealer's ability to generate rich correlated randomness—perfectly consistent arithmetic/bitwise decompositions of random masks, powers of random masks, and exponentially sized data for multi-input AND gates—in order to minimize the online phase.
Security model and black-box construction
The protocols are formulated entirely in terms of an extended Arithmetic Black-Box (ABB) model, an ideal functionality in the universal composability framework. The extension adds a multi-input multiplication gate Fm-Mult alongside the standard linear-combination, multiplication, opening, B2A conversion, daBit, and edaBit interfaces; the correctness of this extension is argued by composing the standard interfaces with multiplication tuples. Because all protocol steps are expressed solely through abstract ABB operations, any backend securely realizing the interface can instantiate them, with end-to-end security inherited via the UC composition theorem. Consequently, no standalone per-protocol security proofs are given—a deliberate consequence of the black-box design philosophy.
The adversary may be passive or active, with honest-majority ($2t < n$) or dishonest-majority (up to n−1 corruptions) configurations. The dealer participates only in preprocessing, learns nothing about online inputs, and does not affect online security. Concrete evaluation instantiates SPDZ-style authenticated sharing (SPDZ over Fp, SPDZ2k over Z2k0) and TinyOT-style Boolean sharing, using the optimized representation Z2k1 where only masked values are opened online.
Comparison over Z2k2: polynomial-based construction
The protocol Z2k3 compares a bitwise-shared secret Z2k4 against a public constant Z2k5 directly in Z2k6. During preprocessing, the dealer computes the polynomial Z2k7 together with the coefficient inverse Z2k8, and for each bit position samples a uniformly random mask Z2k9, distributing shares of all powers n0. Online, parties mask locally, open the masked values in a single round, and then evaluate the polynomial on the opened values using precomputed power shares via binomial expansion—all remaining work is local.
Two properties are notable. First, the online phase requires exactly one round of communication (two rounds for the derived MSB protocol), which is constant regardless of bit length n1. Second, the plaintext domain and sharing domain are independent: correctness holds whenever inputs fit in n2 bits and n3, so smaller plaintext domains yield proportionally cheaper execution. This construction eliminates the statistical errors inherent in edaBits-style conversions, since the dealer provides perfectly consistent arithmetic/bitwise decompositions.
The polynomial-based approach cannot be transplanted to n4: the final step requires multiplying by n5, but not every ring element is invertible. This motivates a separate ring-domain construction.
For the binary/ring setting, the paper introduces n7, an n8-input AND gate whose TinyOT-style instantiation achieves one-round online complexity. The dealer generates n9 shares—one for each non-empty subset product Fp0—so the online phase reduces to local masking, a subset-sum over shared values, and a single opening. This exponentially sized preprocessing material is precisely the kind of correlated randomness that would be prohibitively expensive without a dealer.
These gates feed a PrefixAND circuit Fp1 built as a balanced tree with tunable branching factor Fp2, yielding Fp3 online rounds and Fp4 communication for Fp5-bit inputs. Following Rabbit's LTBits methodology, this yields the comparison protocol Fp6, and a PrefixOR variant follows from De Morgan-style negation. The authors note that constant-round realizations of Fp7-input AND gates also exist across mainstream backends (Shamir, replicated sharing, SPDZ-style), so the gate design is not tied to TinyOT.
MSB extraction and perfect security
MSB extraction bridges LTBits to arithmetically shared inputs and enables a family of derived primitives: LTS (secret-vs-secret comparison), Select, Max, ReLU, and EQZ.
Over Fp8, Fp9 adopts Rabbit's Less-Than-Constant approach with the constant set to Z2k0, invoking two parallel LTBits instances on opened masked values Z2k1 and Z2k2. Unlike Rabbit's Z2k3 instantiation, which relies on edaBits and therefore achieves only statistical security due to potential wrap-around inconsistencies, the dealer here supplies a perfectly consistent decomposition of the mask Z2k4, so no statistical error arises.
Over Z2k5, Z2k6 uses the identity expressing Z2k7 through the MSB of the masked value Z2k8, the dealer-known Z2k9, and a single LTBits invocation comparing Fm-Mult0 against a dealer-provided bitwise-shared quantity. A notable advantage is that the dealer generates Fm-Mult1 during preprocessing, eliminating a recursive MSB invocation.
The paper argues perfect security at the protocol level for both constructions: since each mask Fm-Mult2 is information-theoretically uniform and used exactly once, every opened value is uniformly distributed and independent of the secret input, and all subsequent computation operates on public values or shares of input-independent randomness. The authors are careful to scope this claim: it applies to the abstract protocol description only, and concrete backends (e.g., SPDZFm-Mult3 or TinyOT) may themselves provide only statistical security, so end-to-end guarantees inherit the backend's level.
Experimental evaluation
Implementation is in C++20 following MD-ML's dealer-based architecture, evaluated on simulated WAN (100 ms delay, 1% loss, 100 Mbps) and LAN (1 ms delay, 0.01% loss, 10 Gbps) settings against Rabbit under identical conditions.
Performance of Fm-Mult4. Speedups concentrate in small-batch regimes (fewer than ~100 comparisons) and modest field sizes, and are largest in WAN where reduced rounds dominate:
| Prime |
Best speedup (LAN/WAN) |
Regime favoring protocol |
| Fm-Mult5 |
6.6× / 6.0× |
< 100 comparisons |
| Fm-Mult6 |
8.0× / 13.3× |
< 100–1000 comparisons |
| Fm-Mult7 |
— / 19.4× |
< 100 comparisons (WAN only) |
The peak result is a 19.4× WAN speedup at Fm-Mult8 for small batches. Importantly, the advantage reverses at scale: beyond roughly 100 comparisons, Rabbit's optimized circuit construction and better asymptotics dominate, particularly in LAN settings—for Fm-Mult9, Rabbit is faster in LAN across all tested batch sizes. The protocol is thus best suited to small batches of comparisons over modest fields in latency-constrained networks.
Performance of $2t < n$0. For 10,000 comparisons across $2t < n$1 and branching factors $2t < n$2, the protocol consistently outperforms Rabbit, with speedups of 1.79× to 2.78×:
| Config |
Network |
Optimal $2t < n$3 |
Runtime vs. Rabbit |
Speedup |
| $2t < n$4, passive |
LAN |
5 |
270 ms vs. 750 ms |
2.78× |
| $2t < n$5, passive |
WAN |
8 |
6.1 s vs. 13.3 s |
2.19× |
| $2t < n$6, active |
WAN |
6 |
11.4 s vs. 27.3 s |
2.40× |
| $2t < n$7, passive |
LAN |
7 |
752 ms vs. 1.7 s |
2.24× |
| $2t < n$8, active |
LAN |
5 |
3.1 s vs. 5.5 s |
1.79× |
Three trends emerge: WAN settings favor larger branching factors ($2t < n$9) because round reduction outweighs per-round overhead under high latency; optimal n−10 grows with bit length; and passive security tolerates slightly larger optimal n−11 than active security. Unlike the n−12 case, these gains hold even at large batch sizes.
Limitations and open questions
Several constraints bound the applicability of the results. The perfect-security claim is protocol-level only; concrete instantiations inherit whatever statistical gaps their backends introduce, so end-to-end perfect security is not established here. The trust model places significant weight on a passive, non-colluding dealer—the exponential n−13 preprocessing blow-up for n−14-input gates is acceptable only because the dealer produces it cheaply, and the paper does not address what happens if the dealer colludes or fails, nor quantify storage/bandwidth costs of distributing exponentially many shares for large n−15. On the n−16 side, the advantage evaporates for large batches and in LAN settings, meaning the protocol complements rather than replaces Rabbit. Finally, the evaluation covers MSB extraction in isolation; integration into end-to-end privacy-preserving machine learning pipelines—and extension to related primitives such as secure division and truncation—is left as future work by the authors.
Conclusion
This paper demonstrates that a passive dealer's capability to generate rich correlated randomness can be exploited for more than drop-in preprocessing substitution: it enables structurally redesigned comparison protocols with constant-round (n−17) or tunable n−18-round (n−19) online phases, perfect protocol-level security, and black-box portability across MPC backends and adversary models. Measured speedups of 1.79× to 19.4× over Rabbit—concentrated in small-batch/WAN regimes for Fp0 and consistent across configurations for Fp1—support the practicality of the approach for comparison-intensive MPC applications, while leaving dealer-failure resilience and end-to-end PPML integration as open problems.