2

I am really new to cryptography and I have asked a similar question which is about Decisional Diffie-Hellman assumption (What's the meaning of asterisk and PPT in this paper?) and it is already kind of difficult to me.

But this paper Practical Secure Aggregation for Privacy-Preserving Machine Learning (https://eprint.iacr.org/2017/281.pdf) proposes a Two Oracle Diffie-Hellman assumption, which is even more difficult to understand.

enter image description here enter image description here

Could anyone please tell me bow the oracle function is used in the adversary M? I don't even really understand what the oracle is here.

user900476
  • 123
  • 3

1 Answers1

1

The oracles are giving the image by $H$ of $X^a$ (for $\mathcal{O}_a$) and $Y^b$ (for $\mathcal{O}_b$) for any $X\neq B$ and $Y\neq B$.

Notice there is a typo in the definition, because $b$ is used for the definition of the bit parameter, and the scalar challenge (Here I'm considering the scalar challenge).

Ievgeni
  • 2,653
  • 1
  • 13
  • 35