{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T08:54:04Z","timestamp":1766048044598,"version":"3.33.0"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2007,9,28]],"date-time":"2007-09-28T00:00:00Z","timestamp":1190937600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2008,4]]},"DOI":"10.1007\/s00145-007-9015-5","type":"journal-article","created":{"date-parts":[[2007,9,27]],"date-time":"2007-09-27T18:16:28Z","timestamp":1190916988000},"page":"200-249","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["Lower Bounds and Impossibility Results for\u00a0Concurrent Self Composition"],"prefix":"10.1007","volume":"21","author":[{"given":"Yehuda","family":"Lindell","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2007,9,28]]},"reference":[{"key":"9015_CR1","doi-asserted-by":"crossref","unstructured":"B. Barak, How to go beyond the black-box simulation barrier, in 42nd FOCS, pp.\u00a0106\u2013115, 2001","DOI":"10.1109\/SFCS.2001.959885"},{"key":"9015_CR2","series-title":"LNCS","first-page":"377","volume-title":"CRYPTO\u201991","author":"D. Beaver","year":"1991","unstructured":"D. Beaver, Foundations of secure interactive computing, in CRYPTO\u201991. LNCS, vol. 576 (Springer, Berlin, 1991), pp. 377\u2013391"},{"key":"9015_CR3","unstructured":"R. Canetti, Security and composition of multiparty cryptographic protocols, Theory of Cryptography Library, Record 98-18, version of June 4th, 1998 (later versions do not contain the referenced material)"},{"issue":"1","key":"9015_CR4","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1007\/s001459910006","volume":"13","author":"R. Canetti","year":"2000","unstructured":"R. Canetti, Security and composition of multiparty cryptographic protocols, J. Cryptol. 13(1), 143\u2013202 (2000)","journal-title":"J. Cryptol."},{"key":"9015_CR5","doi-asserted-by":"crossref","unstructured":"R. Canetti, Universally composable security: a new paradigm for cryptographic protocols, in 42nd FOCS, pp. 136\u2013145, 2001","DOI":"10.1109\/SFCS.2001.959888"},{"key":"9015_CR6","series-title":"LNCS","first-page":"19","volume-title":"CRYPTO\u201901","author":"R. Canetti","year":"2001","unstructured":"R. Canetti, M. Fischlin, Universally composable commitments, in CRYPTO\u201901. LNCS, vol. 2139 (Springer, Berlin, 2001), pp. 19\u201340."},{"key":"9015_CR7","doi-asserted-by":"crossref","unstructured":"R. Canetti, J. Kilian, E. Petrank, A. Rosen, Black-box concurrent zero-knowledge requires $\\tilde{\\Omega}(\\log n)$ rounds, in 33rd STOC, pp. 570\u2013579, 2001","DOI":"10.1145\/380752.380852"},{"key":"9015_CR8","doi-asserted-by":"crossref","unstructured":"R. Canetti, Y. Lindell, R. Ostrovsky, A. Sahai, Universally composable two-party and multi-party computation, in 34th STOC, pp. 494\u2013503, 2002","DOI":"10.1145\/509907.509980"},{"key":"9015_CR9","series-title":"LNCS","first-page":"68","volume-title":"EUROCRYPT\u201903","author":"R. Canetti","year":"2003","unstructured":"R. Canetti, E. Kushilevitz, Y. Lindell, On the limitations of universal composable two-party computation without set-up assumptions, in EUROCRYPT\u201903. LNCS, vol. 2656 (Springer, Berlin, 2003), pp. 68\u201386."},{"key":"9015_CR10","doi-asserted-by":"crossref","unstructured":"D. Chaum, Blind signatures for untraceable payments, in CRYPTO\u201982, pp.\u00a0199\u2013203, 1982","DOI":"10.1007\/978-1-4757-0602-4_18"},{"key":"9015_CR11","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1007\/3-540-44598-6_5","volume-title":"CRYPTO 2000","author":"Y. Dodis","year":"2000","unstructured":"Y. Dodis, S. Micali, Parallel reducibility for information-theoretically secure computation, in CRYPTO 2000. LNCS, vol. 1880 (Springer, Berlin, 2000), pp. 74\u201392"},{"key":"9015_CR12","doi-asserted-by":"crossref","unstructured":"C. Dwork, M. Naor, A. Sahai, Concurrent zero-knowledge, in 30th STOC, pp. 409\u2013418, 1998","DOI":"10.1145\/276698.276853"},{"issue":"6","key":"9015_CR13","doi-asserted-by":"publisher","first-page":"637","DOI":"10.1145\/3812.3818","volume":"28","author":"S. Even","year":"1985","unstructured":"S. Even, O. Goldreich, A. Lempel, A randomized protocol for signing contracts, Communications of the ACM 28(6), 637\u2013647 (1985)","journal-title":"Communications of the ACM"},{"key":"9015_CR14","doi-asserted-by":"crossref","unstructured":"U. Feige, A. Shamir, Witness indistinguishability and witness hiding protocols, in 22nd STOC, pp. 416\u2013426, 1990","DOI":"10.1145\/100216.100272"},{"key":"9015_CR15","doi-asserted-by":"crossref","unstructured":"J. Garay, P. Mackenzie, Concurrent oblivious transfer, in 41 st FOCS, pp. 314\u2013324, 2000","DOI":"10.1109\/SFCS.2000.892120"},{"key":"9015_CR16","series-title":"Foundations of Cryptography","volume-title":"Basic Tools","author":"O. Goldreich","year":"2001","unstructured":"O. Goldreich, Basic Tools. Foundations of Cryptography, vol. 1 (Cambridge University Press, Cambridge, 2001)."},{"issue":"3","key":"9015_CR17","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/s001459900010","volume":"9","author":"O. Goldreich","year":"1996","unstructured":"O. Goldreich, A. Kahan, How to construct constant-round zero-knowledge proof systems for NP, J. Cryptol. 9(3), 167\u2013190 (1996)","journal-title":"J. Cryptol."},{"issue":"4","key":"9015_CR18","doi-asserted-by":"publisher","first-page":"792","DOI":"10.1145\/6490.6503","volume":"33","author":"O. Goldreich","year":"1986","unstructured":"O. Goldreich, S. Goldwasser, S. Micali, How to construct random functions, J. ACM 33(4), 792\u2013807 (1986)","journal-title":"J. ACM"},{"key":"9015_CR19","doi-asserted-by":"crossref","unstructured":"O. Goldreich, S. Micali, A. Wigderson, How to play any mental game\u2014a completeness theorem for protocols with honest majority, in 19th STOC, pp. 218\u2013229, 1987. For details see O. Goldreich, Secure Multi-Party Computation. Manuscript, version 1.4, 2002. Available from http:\/\/www.wisdom.weizmann.ac.il\/~oded\/pp.html","DOI":"10.1145\/28395.28420"},{"key":"9015_CR20","series-title":"LNCS","first-page":"77","volume-title":"CRYPTO\u201990","author":"S. Goldwasser","year":"1990","unstructured":"S. Goldwasser, L. Levin, Fair computation of general functions in presence of immoral majority, in CRYPTO\u201990. LNCS, vol. 537 (Springer, Berlin, 1990), pp. 77\u201393."},{"issue":"2","key":"9015_CR21","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1137\/0217017","volume":"17","author":"S. Goldwasser","year":"1988","unstructured":"S. Goldwasser, S. Micali, R.L. Rivest, A digital signature scheme secure against adaptive chosen-message attacks, SIAM J. Comput. 17(2), 281\u2013308 (1988)","journal-title":"SIAM J. Comput."},{"key":"9015_CR22","doi-asserted-by":"crossref","unstructured":"R. Impagliazzo, M. Luby, One-way functions are essential for complexity based cryptography, in 30th FOCS, pp. 230\u2013235, 1989","DOI":"10.1109\/SFCS.1989.63483"},{"key":"9015_CR23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1007\/BFb0028162","volume-title":"5th International Workshop on Security Protocols","author":"J. Kelsey","year":"1997","unstructured":"J. Kelsey, B. Schneier, D. Wagner, Protocol interactions and the chosen protocol attack, in 5th International Workshop on Security Protocols. LNCS, vol. 1361 (Springer, Berlin, 1997), pp. 91\u2013104"},{"key":"9015_CR24","unstructured":"L. Lamport, Constructing digital signatures from one-way functions, SRI International, CSL-98, 1979"},{"key":"9015_CR25","doi-asserted-by":"crossref","unstructured":"Y. Lindell, Bounded-concurrent secure two-party computation without setup assumptions, in 35th STOC, pp. 683\u2013692, 2003. See [27] for a full version of the upper bound from this paper","DOI":"10.1145\/780542.780641"},{"key":"9015_CR26","doi-asserted-by":"crossref","unstructured":"Y. Lindell, Protocols for bounded-concurrent secure two-party computation without setup assumptions. Available from the Cryptology ePrint Archive, Report 2003\/100, 2003. http:\/\/eprint.iacr.org\/","DOI":"10.1145\/780542.780641"},{"key":"9015_CR27","doi-asserted-by":"crossref","unstructured":"Y. Lindell, General composition and universal composability in secure multi-party computation, in 44th FOCS, pp. 394\u2013403, 2003","DOI":"10.1109\/SFCS.2003.1238213"},{"key":"9015_CR28","series-title":"LNCS","first-page":"392","volume-title":"CRYPTO\u201991","author":"S. Micali","year":"1991","unstructured":"S. Micali, P. Rogaway, Secure computation. unpublished manuscript, 1992. Preliminary version, in CRYPTO\u201991. LNCS, vol. 576 (Springer, Berlin, 1991), pp. 392\u2013404"},{"key":"9015_CR29","doi-asserted-by":"crossref","unstructured":"R. Pass, Bounded-concurrent secure multi-party computation with a dishonest majority, in 36th STOC, pp. 232\u2013241, 2004","DOI":"10.1145\/1007352.1007393"},{"key":"9015_CR30","unstructured":"R. Pass, A. Rosen, Bounded-concurrent secure two-party computation in a constant number of rounds, in 44th FOCS, pp. 404\u2013413, 2003"},{"key":"9015_CR31","doi-asserted-by":"crossref","unstructured":"B. Pfitzmann, M. Waidner, Composition and integrity preservation of secure reactive systems, in 7th ACM Conference on Computer and Communication Security, pp. 245\u2013254, 2000","DOI":"10.1145\/352600.352639"},{"key":"9015_CR32","doi-asserted-by":"crossref","unstructured":"M. Prabhakaran, A. Rosen, A. Sahai, Concurrent zero knowledge with logarithmic round-complexity, in 33rd FOCS, pp. 366\u2013375, 2002","DOI":"10.1109\/SFCS.2002.1181961"},{"key":"9015_CR33","unstructured":"M. Rabin, How to exchange secrets by oblivious transfer. Tech. Memo TR-81, Aiken Computation Laboratory, Harvard U., 1981"},{"key":"9015_CR34","series-title":"LNCS","first-page":"415","volume-title":"EUROCRYPT\u201999","author":"R. Richardson","year":"1999","unstructured":"R. Richardson, J. Kilian, On the concurrent composition of zero-knowledge proofs, in EUROCRYPT\u201999. LNCS, vol. 1592 (Springer, Berlin, 1999), pp. 415\u2013431"},{"key":"9015_CR35","doi-asserted-by":"crossref","unstructured":"J. Rompel, One-way functions are necessary and sufficient for secure signatures, in 22nd STOC, pp. 387\u2013394, 1990","DOI":"10.1145\/100216.100269"},{"key":"9015_CR36","doi-asserted-by":"crossref","unstructured":"A. Yao, How to generate and exchange secrets, in 27th FOCS, pp. 162\u2013167, 1986","DOI":"10.1109\/SFCS.1986.25"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-007-9015-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-007-9015-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-007-9015-5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-007-9015-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,21]],"date-time":"2025-01-21T07:22:44Z","timestamp":1737444164000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-007-9015-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,9,28]]},"references-count":36,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2008,4]]}},"alternative-id":["9015"],"URL":"https:\/\/doi.org\/10.1007\/s00145-007-9015-5","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"type":"print","value":"0933-2790"},{"type":"electronic","value":"1432-1378"}],"subject":[],"published":{"date-parts":[[2007,9,28]]},"assertion":[{"value":"20 March 2005","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 August 2007","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 September 2007","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}