Date:
12 May 2000
How to Break a Practical MIX and Design a New One
 Yvo Desmedt,
 Kaoru Kurosawa
Abstract
A MIX net takes a list of ciphertexts (c _{1}, ..., c _{N}) and outputs a permuted list of the plaintexts (m _{1}, ..., m _{N}) without revealing the relationship between (c _{1},..., c _{N}) and (m _{1}, ...,m _{N}). This paper first shows that the Jakobsson’s MIX net of Eurocrypt’98, which was believed to be resilient and very efficient, is broken. We next propose an efficient tresilient MIX net with O(t ^{2}) servers in which the cost of each MIX server is O(N). Two new concepts are introduced, existentialhonesty and limitedopenverification. They will be useful for distributed computation in general.
