Papers
Topics
Authors
Recent
Search
2000 character limit reached

Efficient Multi-Party Secure Comparison over Different Domains with Preprocessing Assistance

Published 23 Feb 2026 in cs.CR | (2602.19604v1)

Abstract: Secure comparison is a fundamental primitive in multi-party computation, supporting privacy-preserving applications such as machine learning and data analytics. A critical performance bottleneck in comparison protocols is their preprocessing phase, primarily due to the high cost of generating the necessary correlated randomness. Recent frameworks introduce a passive, non-colluding dealer to accelerate preprocessing. However, two key issues still remain. First, existing dealer-assisted approaches treat the dealer as a drop-in replacement for conventional preprocessing without redesigning the comparison protocol to optimize the online phase. Second, most protocols are specialized for particular algebraic domains, adversary models, or party configurations, lacking broad generality. In this work, we present the first dealer-assisted nn-party LTBits (Less-Than-Bits) and MSB (Most Significant Bit) extraction protocols over both F<em>p\mathbb{F}<em>p and Z</em>2<sup>k\mathbb{Z}</em>{2<sup>k}, achieving perfect security at the protocol level. By fully exploiting the dealer's capability to generate rich correlated randomness, our F<em>p\mathbb{F}<em>p construction achieves constant-round online complexity and our Z</em>2<sup>k\mathbb{Z}</em>{2<sup>k} construction achieves O(log⁡nk)O(\log_n k) rounds with tunable branching factor. All protocols are formulated as black-box constructions via an extended ABB model, ensuring portability across MPC backends and adversary models. Experimental results demonstrate 1.79×1.79\times to 19.4×19.4\times speedups over state-of-the-art MPC frameworks, highlighting the practicality of our protocols for comparison-intensive MPC applications.

Summary

  • The paper introduces dealer-assisted LTBits and MSB protocols for both Fp and Z2^k, using rich correlated randomness to reduce online comparison to one or tunably few communication rounds.
  • The protocols achieve perfect security at the abstract protocol level and remain portable across MPC backends, adversary models, and party configurations through an extended arithmetic black-box interface.
  • Experiments show speedups of up to 19.4× for small-batch prime-field comparisons over WAN and 1.79×–2.78× for ring-based comparisons across larger LAN and WAN workloads, while dealer trust and preprocessing costs remain limitations.

Overview and motivation

Secure comparison remains one of the dominant performance bottlenecks in practical multi-party computation (MPC). While arithmetic operations are efficiently supported via Beaver triples, comparison requires bit decomposition, prefix computations, or masked zero-testing, and its preprocessing phase—generating correlated randomness such as daBits, edaBits, and function secret sharing (FSS) material—can cost several to dozens of times more than the online phase. Recent dealer-assisted frameworks introduce a passive, non-colluding dealer that generates preprocessing data offline, but existing systems treat the dealer largely as a drop-in replacement for conventional preprocessing, producing the same triple- or edaBit-style randomness without redesigning the comparison protocol itself. Moreover, most prior comparison protocols are specialized to particular algebraic domains (Fp\mathbb{F}_p vs. Z2k\mathbb{Z}_{2^k}), adversary models, or party configurations.

This paper addresses both issues by presenting the first dealer-assisted nn-party LTBits (Less-Than-Bits) and MSB extraction protocols over both Fp\mathbb{F}_p and Z2k\mathbb{Z}_{2^k}, achieving perfect security at the protocol level. The key design principle is to fully exploit the dealer's ability to generate rich correlated randomness—perfectly consistent arithmetic/bitwise decompositions of random masks, powers of random masks, and exponentially sized data for multi-input AND gates—in order to minimize the online phase.

Security model and black-box construction

The protocols are formulated entirely in terms of an extended Arithmetic Black-Box (ABB) model, an ideal functionality in the universal composability framework. The extension adds a multi-input multiplication gate Fm-Mult\mathcal{F}_{\text{m-Mult}} alongside the standard linear-combination, multiplication, opening, B2A conversion, daBit, and edaBit interfaces; the correctness of this extension is argued by composing the standard interfaces with multiplication tuples. Because all protocol steps are expressed solely through abstract ABB operations, any backend securely realizing the interface can instantiate them, with end-to-end security inherited via the UC composition theorem. Consequently, no standalone per-protocol security proofs are given—a deliberate consequence of the black-box design philosophy.

The adversary may be passive or active, with honest-majority ($2t < n$) or dishonest-majority (up to n−1n-1 corruptions) configurations. The dealer participates only in preprocessing, learns nothing about online inputs, and does not affect online security. Concrete evaluation instantiates SPDZ-style authenticated sharing (SPDZ over Fp\mathbb{F}_p, SPDZ2k_{2^k} over Z2k\mathbb{Z}_{2^k}0) and TinyOT-style Boolean sharing, using the optimized representation Z2k\mathbb{Z}_{2^k}1 where only masked values are opened online.

Comparison over Z2k\mathbb{Z}_{2^k}2: polynomial-based construction

The protocol Z2k\mathbb{Z}_{2^k}3 compares a bitwise-shared secret Z2k\mathbb{Z}_{2^k}4 against a public constant Z2k\mathbb{Z}_{2^k}5 directly in Z2k\mathbb{Z}_{2^k}6. During preprocessing, the dealer computes the polynomial Z2k\mathbb{Z}_{2^k}7 together with the coefficient inverse Z2k\mathbb{Z}_{2^k}8, and for each bit position samples a uniformly random mask Z2k\mathbb{Z}_{2^k}9, distributing shares of all powers nn0. Online, parties mask locally, open the masked values in a single round, and then evaluate the polynomial on the opened values using precomputed power shares via binomial expansion—all remaining work is local.

Two properties are notable. First, the online phase requires exactly one round of communication (two rounds for the derived MSB protocol), which is constant regardless of bit length nn1. Second, the plaintext domain and sharing domain are independent: correctness holds whenever inputs fit in nn2 bits and nn3, so smaller plaintext domains yield proportionally cheaper execution. This construction eliminates the statistical errors inherent in edaBits-style conversions, since the dealer provides perfectly consistent arithmetic/bitwise decompositions.

The polynomial-based approach cannot be transplanted to nn4: the final step requires multiplying by nn5, but not every ring element is invertible. This motivates a separate ring-domain construction.

Comparison over nn6: multi-input AND gates

For the binary/ring setting, the paper introduces nn7, an nn8-input AND gate whose TinyOT-style instantiation achieves one-round online complexity. The dealer generates nn9 shares—one for each non-empty subset product Fp\mathbb{F}_p0—so the online phase reduces to local masking, a subset-sum over shared values, and a single opening. This exponentially sized preprocessing material is precisely the kind of correlated randomness that would be prohibitively expensive without a dealer.

These gates feed a PrefixAND circuit Fp\mathbb{F}_p1 built as a balanced tree with tunable branching factor Fp\mathbb{F}_p2, yielding Fp\mathbb{F}_p3 online rounds and Fp\mathbb{F}_p4 communication for Fp\mathbb{F}_p5-bit inputs. Following Rabbit's LTBits methodology, this yields the comparison protocol Fp\mathbb{F}_p6, and a PrefixOR variant follows from De Morgan-style negation. The authors note that constant-round realizations of Fp\mathbb{F}_p7-input AND gates also exist across mainstream backends (Shamir, replicated sharing, SPDZ-style), so the gate design is not tied to TinyOT.

MSB extraction and perfect security

MSB extraction bridges LTBits to arithmetically shared inputs and enables a family of derived primitives: LTS (secret-vs-secret comparison), Select, Max, ReLU, and EQZ.

Over Fp\mathbb{F}_p8, Fp\mathbb{F}_p9 adopts Rabbit's Less-Than-Constant approach with the constant set to Z2k\mathbb{Z}_{2^k}0, invoking two parallel LTBits instances on opened masked values Z2k\mathbb{Z}_{2^k}1 and Z2k\mathbb{Z}_{2^k}2. Unlike Rabbit's Z2k\mathbb{Z}_{2^k}3 instantiation, which relies on edaBits and therefore achieves only statistical security due to potential wrap-around inconsistencies, the dealer here supplies a perfectly consistent decomposition of the mask Z2k\mathbb{Z}_{2^k}4, so no statistical error arises.

Over Z2k\mathbb{Z}_{2^k}5, Z2k\mathbb{Z}_{2^k}6 uses the identity expressing Z2k\mathbb{Z}_{2^k}7 through the MSB of the masked value Z2k\mathbb{Z}_{2^k}8, the dealer-known Z2k\mathbb{Z}_{2^k}9, and a single LTBits invocation comparing Fm-Mult\mathcal{F}_{\text{m-Mult}}0 against a dealer-provided bitwise-shared quantity. A notable advantage is that the dealer generates Fm-Mult\mathcal{F}_{\text{m-Mult}}1 during preprocessing, eliminating a recursive MSB invocation.

The paper argues perfect security at the protocol level for both constructions: since each mask Fm-Mult\mathcal{F}_{\text{m-Mult}}2 is information-theoretically uniform and used exactly once, every opened value is uniformly distributed and independent of the secret input, and all subsequent computation operates on public values or shares of input-independent randomness. The authors are careful to scope this claim: it applies to the abstract protocol description only, and concrete backends (e.g., SPDZFm-Mult\mathcal{F}_{\text{m-Mult}}3 or TinyOT) may themselves provide only statistical security, so end-to-end guarantees inherit the backend's level.

Experimental evaluation

Implementation is in C++20 following MD-ML's dealer-based architecture, evaluated on simulated WAN (100 ms delay, 1% loss, 100 Mbps) and LAN (1 ms delay, 0.01% loss, 10 Gbps) settings against Rabbit under identical conditions.

Performance of Fm-Mult\mathcal{F}_{\text{m-Mult}}4. Speedups concentrate in small-batch regimes (fewer than ~100 comparisons) and modest field sizes, and are largest in WAN where reduced rounds dominate:

Prime Best speedup (LAN/WAN) Regime favoring protocol
Fm-Mult\mathcal{F}_{\text{m-Mult}}5 6.6× / 6.0× < 100 comparisons
Fm-Mult\mathcal{F}_{\text{m-Mult}}6 8.0× / 13.3× < 100–1000 comparisons
Fm-Mult\mathcal{F}_{\text{m-Mult}}7 — / 19.4× < 100 comparisons (WAN only)

The peak result is a 19.4× WAN speedup at Fm-Mult\mathcal{F}_{\text{m-Mult}}8 for small batches. Importantly, the advantage reverses at scale: beyond roughly 100 comparisons, Rabbit's optimized circuit construction and better asymptotics dominate, particularly in LAN settings—for Fm-Mult\mathcal{F}_{\text{m-Mult}}9, Rabbit is faster in LAN across all tested batch sizes. The protocol is thus best suited to small batches of comparisons over modest fields in latency-constrained networks.

Performance of $2t < n$0. For 10,000 comparisons across $2t < n$1 and branching factors $2t < n$2, the protocol consistently outperforms Rabbit, with speedups of 1.79× to 2.78×:

Config Network Optimal $2t < n$3 Runtime vs. Rabbit Speedup
$2t < n$4, passive LAN 5 270 ms vs. 750 ms 2.78×
$2t < n$5, passive WAN 8 6.1 s vs. 13.3 s 2.19×
$2t < n$6, active WAN 6 11.4 s vs. 27.3 s 2.40×
$2t < n$7, passive LAN 7 752 ms vs. 1.7 s 2.24×
$2t < n$8, active LAN 5 3.1 s vs. 5.5 s 1.79×

Three trends emerge: WAN settings favor larger branching factors ($2t < n$9) because round reduction outweighs per-round overhead under high latency; optimal n−1n-10 grows with bit length; and passive security tolerates slightly larger optimal n−1n-11 than active security. Unlike the n−1n-12 case, these gains hold even at large batch sizes.

Limitations and open questions

Several constraints bound the applicability of the results. The perfect-security claim is protocol-level only; concrete instantiations inherit whatever statistical gaps their backends introduce, so end-to-end perfect security is not established here. The trust model places significant weight on a passive, non-colluding dealer—the exponential n−1n-13 preprocessing blow-up for n−1n-14-input gates is acceptable only because the dealer produces it cheaply, and the paper does not address what happens if the dealer colludes or fails, nor quantify storage/bandwidth costs of distributing exponentially many shares for large n−1n-15. On the n−1n-16 side, the advantage evaporates for large batches and in LAN settings, meaning the protocol complements rather than replaces Rabbit. Finally, the evaluation covers MSB extraction in isolation; integration into end-to-end privacy-preserving machine learning pipelines—and extension to related primitives such as secure division and truncation—is left as future work by the authors.

Conclusion

This paper demonstrates that a passive dealer's capability to generate rich correlated randomness can be exploited for more than drop-in preprocessing substitution: it enables structurally redesigned comparison protocols with constant-round (n−1n-17) or tunable n−1n-18-round (n−1n-19) online phases, perfect protocol-level security, and black-box portability across MPC backends and adversary models. Measured speedups of 1.79× to 19.4× over Rabbit—concentrated in small-batch/WAN regimes for Fp\mathbb{F}_p0 and consistent across configurations for Fp\mathbb{F}_p1—support the practicality of the approach for comparison-intensive MPC applications, while leaving dealer-failure resilience and end-to-end PPML integration as open problems.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.