Check out the new USENIX Web site.

next up previous
Next: Error analysis Up: A scalable secret-bid second-price Previous: Anonymity

Passive attacks

Due to the use of verifiable secret sharing, no coalition of at most t auctioneers can determine any information about the bidding from their shares of the bids. Similarly, the degree reduction steps preserve secrecy against coalitions of at most t auctioneers. But what about the polynomials tex2html_wrap_inline1948 which are revealed in the course of determining the selling price? A single tex2html_wrap_inline1950 is uniformly random and independent of all other variables except for its free coefficient. If tex2html_wrap_inline1952 , then tex2html_wrap_inline1954 . If tex2html_wrap_inline1956 , then tex2html_wrap_inline1958 is an element uniformly distributed over tex2html_wrap_inline1960 . Note that tex2html_wrap_inline1962 exactly when there are at least two bids whose value is at least the speculative selling price (the previously determined digits of tex2html_wrap_inline1964 together with tex2html_wrap_inline1966 digit l).



Doug Tygar
Wed Jul 22 10:16:16 EDT 1998