LFCS Seminar: Tuesday 22 September: Sabine Oechsner


Title: Secure Computation in the Wild: When Cryptographic Protocols Meet the Real World
 
Abstract
 
Secure multiparty computation (MPC) allows mutually distrusting parties to jointly compute a public function of their private inputs, while hiding the inputs from each other. MPC protocols have been an object of study since the 1980s, and recent years have seen interest in deployment. However, protocol implementations frequently deviate from the original protocol design, for example for performance reasons or because of lack of specifications. While a formal security analysis is the standard for any new MPC protocol design, it is currently unclear how these security guarantees exactly translate into implementations.
In this talk I will discuss concurrency as new source of gaps between theory and practice of MPC security, and what we can learn about analyzing the security of practical MPC protocols. Specifically, I will be focusing on the SPDZ family of MPC protocols (Damgård et al., CRYPTO 2012, ESORICS 2013), which provides security against malicious adversaries when all-but-one of the participants may be corrupted. In a recent work, we identified a novel type of MAC key leakage in the MAC check protocol of SPDZ, which can be exploited in concurrent, multi-threaded settings, compromising output integrity and, in some cases, input privacy. In our analysis of three SPDZ implementations (MP-SPDZ, SCALE-MAMBA, and FRESCO), two are vulnerable to this attack, while we also uncover further issues and vulnerabilities with all three implementations. I will conclude by discussing mitigation strategies as well as recommendations for researchers, developers and users of MPC protocols.
 
Based on joint work with Alexander Kyster, Frederik Huss Nielsen, and Peter Scholl (IEEE S&P 2025).