<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wikidot="http://www.wikidot.com/rss-namespace">

	<channel>
		<title>Lecture 9 questions</title>
		<link>http://tau-foc-f19.wikidot.com/forum/t-12988998/lecture-9-questions</link>
		<description>Posts in the discussion thread &quot;Lecture 9 questions&quot;</description>
				<copyright></copyright>
		<lastBuildDate>Tue, 18 Aug 2026 05:01:31 +0000</lastBuildDate>
		
					<item>
				<guid>http://tau-foc-f19.wikidot.com/forum/t-12988998#post-4482058</guid>
				<title>Re: Lecture 9 questions</title>
				<link>http://tau-foc-f19.wikidot.com/forum/t-12988998/lecture-9-questions#post-4482058</link>
				<description></description>
				<pubDate>Tue, 28 Jan 2020 20:18:17 +0000</pubDate>
				<wikidot:authorName>nbitansky</wikidot:authorName>				<wikidot:authorUserId>1746223</wikidot:authorUserId>				<content:encoded>
					<![CDATA[
						 <p>1. To show that two pairs of joint distributions <span class="math-inline">$(X,Y)$</span> and <span class="math-inline">$(X',Y')$</span> are indistinguishable, it suffices to show:<br /> a. <span class="math-inline">$X$</span> is <span class="math-inline">$X'$</span> have the same distribution,<br /> b. for any <span class="math-inline">$x$</span>. <span class="math-inline">$Y|X=x$</span> is indistinguishable from <span class="math-inline">$Y|X'=x$</span>.<br /> In our case, <span class="math-inline">$X,X'$</span> represents the inputs, and <span class="math-inline">$Y,Y'$</span> the messages in the subprotocols.</p> <p>2. See reference solution for HW5.</p> <p>3. The same scheme, can be used to encode any function <span class="math-inline">$f$</span>. Naturally, to do so, it needs to know what is the function.</p> <p>4.<br /> - These are secret keys for symmetric encryption of long messages, they can't be one bit. As always, you can think about them as<span class="math-inline">$n$</span>-bit long.<br /> The ciphertext length is some polynomial in the length of the key and the message, nothing else is assumed (or implied by the table).</p> <p>- Not sure I understand the question. The mapping simply says for the two keys corresponding to the output wire, which corresponds to zero and which to one.</p> <p>- We don't explicitly learn <span class="math-inline">$v(w)$</span> (we actually learn nothing about it, which is the whole point). What the evaluator learns for each wire <span class="math-inline">$w$</span> is a single key, which is the key corresponding to <span class="math-inline">$v(w)$</span>. For the evaluator this looks as any random key, it has no idea that it corresponds to <span class="math-inline">$v(w)$</span> and not to <span class="math-inline">$1-v(w)$</span>.</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://tau-foc-f19.wikidot.com/forum/t-12988998#post-4481825</guid>
				<title>Lecture 9 questions</title>
				<link>http://tau-foc-f19.wikidot.com/forum/t-12988998/lecture-9-questions#post-4481825</link>
				<description></description>
				<pubDate>Tue, 28 Jan 2020 15:39:32 +0000</pubDate>
				<wikidot:authorName>AvivB</wikidot:authorName>				<wikidot:authorUserId>5908253</wikidot:authorUserId>				<content:encoded>
					<![CDATA[
						 <p>Hi,<br /> I have some question regarding Lecture 9:</p> <p>1. Page 4, Claim 2.4: I didn't understand your comment about fixing the inputs for g_hat protocols. By fixing you mean for specific bits of inputs?<br /> Why can we do that? how does it reduce the burden of prooving indistinguishability for the whole view?<br /> 2. Page 4, Remark about the original GMW construction: Can you please explain why it is sufficient to run the protocol only for MUL gates? (what is &quot;the protocol&quot; that we are supposed to run?).</p> <p>3. Page 5, Garbling Scheme definition: Why do we need to encode the description of f if the simulator also gets f? (we assume that f is public)<br /> 4. Page 6, Yao's Garbled Circuit:<br /> - In the first stage, each wire samples two secret keys. Are they one-bit? multiple-bits?<br /> Also, we assumed a secret-key encryption scheme. Does the cipher's length equal to the secret key's length? (The table T_g implies that).<br /> - In the second stage, we mentioned a mapping for the output wire. b can be either 0 or 1, and there is only one output wire. can't we turn it to two bits table? am I wrong somewhere?<br /> - In the fourth stage, we saw v(w). I don't understand how do we get this function, and what it does. I guess that it has to use the gate's table T_G somehow.</p> <p>Thanks, and sorry (again) for the long questions.</p> 
				 	]]>
				</content:encoded>							</item>
				</channel>
</rss>