The Approach of [ABOR00] [ Aiello-Bhatt-Ostrovsky-Rajogopalan 00] suggested to construct a delegation scheme by combining a Multi-Prover Interactive Proof-System with an FHE. Actually PIR suffices, but easier to describe with FHE
Multi Prover Interactive Proofs (MIP) [BenOr-Goldwasser-Kilian-Wigderson88]...... [Babai-Fortnow-Lund91]
Encrypt the queries and answer homomorphically.......
The [ABOR00] Protocol Simulate using a single prover.......
The [ABOR00] Protocol Simulate using a single prover.
The [ABOR00] Protocol Intuition: since encrypted under different keys, prover cannot use one query to answer a different query. [ Dwork-Landberg-Naor-Nissim-Reingold 01]: this intuition is false*! [Kalai-Raz09]: correct for single prover interactive proofs. We show: protocol works if MIP satisfies a stronger soundness condition called no-signaling soundness.
No-Signaling Prover Strategies Allow the provers a minimal form of communication. The answer of each prover may depend on the other queries as a function but must be independent as a RV.
Relation to Quantum MIP No-signaling strategies originally motivated by quantum MIPs – the (cheating) provers share an entangled quantum state. Entangled strategies are no-signaling. No-signaling soundness is likely to hold in future theories of physics (if information cannot travel faster than light).
The Provers Each prover generates the entire tableau of the computation. Output bit Input bits
The provers encode the computation via the [BFLS] PCP. The Provers
Each (honest) prover expects to be queried on a single point in the PCP and answers accordingly. The Provers
The verifier generates the PCP queries. Randomly permutes the queries and sends to the provers. Also explicitly checks input and output gates. Accepts the answers if PCP verifier accepts and input/output gates are correct. The Verifier
No-Signaling Soundness Challenges in NS setting: Each answer depends on other provers’ queries. No low degree test. No parallel repetition. Cheating provers are randomized.
[BFLS]: If the provers do not communicate, the MIP is sound. For no-signaling provers situation is more complicated. Classical Setting