CRYPTO NEWS

How to generate logn instances of 1 out of 2 OT from a single instance of 1 out of n OT?

I’m reading the paper Improved OT extension. The author said that in semi-honest model, a single instance of 1 out of n OT may be used to generate $log n$ instances of 1 out of 2 OT. More precisely, the cost of $text{OT}_{l}^m$ is exactly equal to the cost of 1 out of n $text{OT}_{llog n}^{m/log n}$.

I wonder why it is so. Are there any references about this?

How to generate logn instances of 1 out of 2 OT from a single instance of 1 out of n OT?

Shopping cart
There are no products in the cart!
Continue shopping
0