{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,8]],"date-time":"2025-05-08T12:43:03Z","timestamp":1746708183210},"reference-count":48,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"4","license":[{"start":{"date-parts":[[2021,7,23]],"date-time":"2021-07-23T00:00:00Z","timestamp":1626998400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,10,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Existing models for non-interactive MPC cannot provide full privacy for inputs, because they inherently leak the residual function (i.e., the output of the function on the honest parties\u2019 input together with all possible values of the adversarial inputs). For example, in any non-interactive sealed-bid auction, the last bidder can figure out what was the highest previous bid. We present a new MPC model which avoids this privacy leak. To achieve this, we utilize a blockchain in a novel way, incorporating smart contracts and arbitrary parties that can be incentivized to perform computation (\u201cbounty hunters,\u201d akin to miners). Security is maintained under a monetary assumption about the parties: an honest party can temporarily supply a recoverable collateral of value higher than the computational cost an adversary can expend. We thus construct non-interactive MPC protocols with strong security guarantees (full security, no residual leakage) in the short term. Over time, as the adversary can invest more and more computational resources, the security guarantee decays. Thus, our model, which we call Gage MPC, is suitable for secure computation with limited-time secrecy, such as auctions. A key ingredient in our protocols is a primitive we call \u201cGage Time Capsules\u201d (GaTC): a time capsule that allows a party to commit to a value that others are able to reveal but only at a designated computational cost. A GaTC allows a party to commit to a value together with a monetary collateral. If the original party properly opens the GaTC, it can recover the collateral. Otherwise, the collateral is used to incentivize bounty hunters to open the GaTC. This primitive is used to ensure completion of Gage MPC protocols on the desired inputs. As a requisite tool (of independent interest), we present a generalization of garbled circuit that are more robust: they can tolerate exposure of extra input labels. This is in contrast to Yao\u2019s garbled circuits, whose secrecy breaks down if even a single extra label is exposed. Finally, we present a proof-of-concept implementation of a special case of our construction, yielding an auction functionality over an Ethereum-like blockchain.<\/jats:p>","DOI":"10.2478\/popets-2021-0083","type":"journal-article","created":{"date-parts":[[2021,7,24]],"date-time":"2021-07-24T23:17:00Z","timestamp":1627168620000},"page":"528-548","source":"Crossref","is-referenced-by-count":10,"title":["Gage MPC: Bypassing Residual Function Leakage for Non-Interactive MPC"],"prefix":"10.56553","volume":"2021","author":[{"given":"Ghada","family":"Almashaqbeh","sequence":"first","affiliation":[{"name":"University of Connecticut"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabrice","family":"Benhamouda","sequence":"additional","affiliation":[{"name":"Algorand Foundation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seungwook","family":"Han","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Jaroslawicz","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tal","family":"Malkin","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alex","family":"Nicita","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tal","family":"Rabin","sequence":"additional","affiliation":[{"name":"University of Pennsylvania , Algorand Foundation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abhishek","family":"Shah","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eran","family":"Tromer","sequence":"additional","affiliation":[{"name":"Columbia University , Tel-Aviv University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2021,7,23]]},"reference":[{"key":"2022060519474638969_j_popets-2021-0083_ref_001","unstructured":"[1] Altcoin.io decentralized exchange. https:\/\/altcoin.io\/"},{"key":"2022060519474638969_j_popets-2021-0083_ref_002","unstructured":"[2] Etherdelta decentralized exchange. https:\/\/etherdelta.com\/"},{"key":"2022060519474638969_j_popets-2021-0083_ref_003","unstructured":"[3] Etheropt decentralized exchange (mirror of original software). https:\/\/github.com\/destenson\/etheropt--etheropt.github.io"},{"key":"2022060519474638969_j_popets-2021-0083_ref_004","unstructured":"[4] Intrinsically tradable tokens. https:\/\/github.com\/o0ragman0o\/ITT"},{"key":"2022060519474638969_j_popets-2021-0083_ref_005","unstructured":"[5] Ren: A privacy preserving virtual machine powering zero-knowledge financial applications. https:\/\/renproject.io\/litepaper.pdf"},{"key":"2022060519474638969_j_popets-2021-0083_ref_006","unstructured":"[6] Solidity by example: Blind auction. https:\/\/solidity.readthedocs.io\/en\/v0.5.3\/solidity-by-example.html#id2"},{"key":"2022060519474638969_j_popets-2021-0083_ref_007","doi-asserted-by":"crossref","unstructured":"[7] Almashaqbeh, G., Benhamouda, F., Han, S., Jaroslawicz, D., Malkin, T., Nicita, A., Rabin, T., Shah, A., Tromer, E.: Gage mpc: Bypassing residual function leakage for non-interactive mpc. Cryptology ePrint Archive, Report 2021\/256 (2021), https:\/\/eprint.iacr.org\/2021\/256","DOI":"10.2478\/popets-2021-0083"},{"key":"2022060519474638969_j_popets-2021-0083_ref_008","doi-asserted-by":"crossref","unstructured":"[8] Andrychowicz, M., Dziembowski, S., Malinowski, D., Mazurek, L.: Secure multiparty computations on bitcoin. In: 2014 IEEE Symposium on Security and Privacy. pp. 443\u2013458. IEEE Computer Society Press (May 2014)10.1109\/SP.2014.35","DOI":"10.1109\/SP.2014.35"},{"key":"2022060519474638969_j_popets-2021-0083_ref_009","doi-asserted-by":"crossref","unstructured":"[9] Beimel, A., Gabizon, A., Ishai, Y., Kushilevitz, E., Meldgaard, S., Paskin-Cherniavsky, A.: Non-interactive secure multiparty computation. In: Garay, J.A., Gennaro, R. (eds.) CRYPTO 2014, Part II. LNCS, vol. 8617, pp. 387\u2013404. Springer, Heidelberg (Aug 2014)10.1007\/978-3-662-44381-1_22","DOI":"10.1007\/978-3-662-44381-1_22"},{"key":"2022060519474638969_j_popets-2021-0083_ref_010","unstructured":"[10] Bellare, M., Goldwasser, S.: Encapsulated key escrow. Tech. rep., Cambridge, MA, USA (1996)"},{"key":"2022060519474638969_j_popets-2021-0083_ref_011","doi-asserted-by":"crossref","unstructured":"[11] Ben-Or, M., Goldwasser, S., Wigderson, A.: Completeness theorems for non-cryptographic fault-tolerant distributed computation (extended abstract). In: 20th ACM STOC. pp. 1\u201310. ACM Press (May 1988)10.1145\/62212.62213","DOI":"10.1145\/62212.62213"},{"key":"2022060519474638969_j_popets-2021-0083_ref_012","doi-asserted-by":"crossref","unstructured":"[12] Benhamouda, F., Krawczyk, H., Rabin, T.: Robust noninteractive multiparty computation against constant-size collusion. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017, Part I. LNCS, vol. 10401, pp. 391\u2013419. Springer, Heidelberg (Aug 2017)10.1007\/978-3-319-63688-7_13","DOI":"10.1007\/978-3-319-63688-7_13"},{"key":"2022060519474638969_j_popets-2021-0083_ref_013","doi-asserted-by":"crossref","unstructured":"[13] Bentov, I., Kumaresan, R.: How to use bitcoin to design fair protocols. In: Garay, J.A., Gennaro, R. (eds.) CRYPTO 2014, Part II. LNCS, vol. 8617, pp. 421\u2013439. Springer, Heidelberg (Aug 2014)10.1007\/978-3-662-44381-1_24","DOI":"10.1007\/978-3-662-44381-1_24"},{"key":"2022060519474638969_j_popets-2021-0083_ref_014","doi-asserted-by":"crossref","unstructured":"[14] Boneh, D., Bonneau, J., B\u00fcnz, B., Fisch, B.: Verifiable delay functions. In: Shacham, H., Boldyreva, A. (eds.) CRYPTO 2018, Part I. LNCS, vol. 10991, pp. 757\u2013788. Springer, Heidelberg (Aug 2018)10.1007\/978-3-319-96884-1_25","DOI":"10.1007\/978-3-319-96884-1_25"},{"key":"2022060519474638969_j_popets-2021-0083_ref_015","doi-asserted-by":"crossref","unstructured":"[15] Boneh, D., Naor, M.: Timed commitments. In: Bellare, M. (ed.) CRYPTO 2000. LNCS, vol. 1880, pp. 236\u2013254. Springer, Heidelberg (Aug 2000)10.1007\/3-540-44598-6_15","DOI":"10.1007\/3-540-44598-6_15"},{"key":"2022060519474638969_j_popets-2021-0083_ref_016","unstructured":"[16] Bowe, S., Chiesa, A., Green, M., Miers, I., Mishra, P., Wu, H.: Zexe: Enabling decentralized private computation. Cryptology ePrint Archive, Report 2018\/962 (2018), https:\/\/eprint.iacr.org\/2018\/962.pdf"},{"key":"2022060519474638969_j_popets-2021-0083_ref_017","doi-asserted-by":"crossref","unstructured":"[17] Brakerski, Z., D\u00f6ttling, N., Garg, S., Malavolta, G.: Leveraging linear decryption: Rate-1 fully-homomorphic encryption and time-lock puzzles. In: Hofheinz, D., Rosen, A. (eds.) TCC 2019, Part II. LNCS, vol. 11892, pp. 407\u2013437. Springer, Heidelberg (Dec 2019)10.1007\/978-3-030-36033-7_16","DOI":"10.1007\/978-3-030-36033-7_16"},{"key":"2022060519474638969_j_popets-2021-0083_ref_018","doi-asserted-by":"crossref","unstructured":"[18] Chaum, D., Cr\u00e9peau, C., Damg\u00e5rd, I.: Multiparty unconditionally secure protocols (extended abstract). In: 20th ACM STOC. pp. 11\u201319. ACM Press (May 1988)10.1145\/62212.62214","DOI":"10.1145\/62212.62214"},{"key":"2022060519474638969_j_popets-2021-0083_ref_019","doi-asserted-by":"crossref","unstructured":"[19] Choudhuri, A.R., Goyal, V., Jain, A.: Founding secure computation on blockchains. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019, Part II. LNCS, vol. 11477, pp. 351\u2013380. Springer, Heidelberg (May 2019)10.1007\/978-3-030-17656-3_13","DOI":"10.1007\/978-3-030-17656-3_13"},{"key":"2022060519474638969_j_popets-2021-0083_ref_020","doi-asserted-by":"crossref","unstructured":"[20] Choudhuri, A.R., Green, M., Jain, A., Kaptchuk, G., Miers, I.: Fairness in an unfair world: Fair multiparty computation from public bulletin boards. In: Thuraisingham, B.M., Evans, D., Malkin, T., Xu, D. (eds.) ACM CCS 2017. pp. 719\u2013728. ACM Press (Oct \/ Nov 2017)10.1145\/3133956.3134092","DOI":"10.1145\/3133956.3134092"},{"key":"2022060519474638969_j_popets-2021-0083_ref_021","doi-asserted-by":"crossref","unstructured":"[21] Cleve, R.: Limits on the security of coin flips when half the processors are faulty (extended abstract). In: 18th ACM STOC. pp. 364\u2013369. ACM Press (May 1986)10.1145\/12130.12168","DOI":"10.1145\/12130.12168"},{"key":"2022060519474638969_j_popets-2021-0083_ref_022","unstructured":"[22] DeFiprime.com: Dex tracker - decentralized exchanges trading volume. https:\/\/defiprime.com\/dex-volume"},{"key":"2022060519474638969_j_popets-2021-0083_ref_023","doi-asserted-by":"crossref","unstructured":"[23] Deuber, D., D\u00f6ttling, N., Magri, B., Malavolta, G., Thyagarajan, S.A.K.: Minting mechanism for proof of stake blockchains. In: International Conference on Applied Cryptography and Network Security. pp. 315\u2013334. Springer (2020)10.1007\/978-3-030-57808-4_16","DOI":"10.1007\/978-3-030-57808-4_16"},{"key":"2022060519474638969_j_popets-2021-0083_ref_024","doi-asserted-by":"crossref","unstructured":"[24] Dwork, C., Naor, M.: Pricing via processing or combatting junk mail. In: Brickell, E.F. (ed.) CRYPTO\u201992. LNCS, vol. 740, pp. 139\u2013147. Springer, Heidelberg (Aug 1993)10.1007\/3-540-48071-4_10","DOI":"10.1007\/3-540-48071-4_10"},{"key":"2022060519474638969_j_popets-2021-0083_ref_025","doi-asserted-by":"crossref","unstructured":"[25] Ephraim, N., Freitag, C., Komargodski, I., Pass, R.: Continuous verifiable delay functions. In: Annual International Conference on the Theory and Applications of Cryptographic Techniques. pp. 125\u2013154. Springer (2020)10.1007\/978-3-030-45727-3_5","DOI":"10.1007\/978-3-030-45727-3_5"},{"key":"2022060519474638969_j_popets-2021-0083_ref_026","doi-asserted-by":"crossref","unstructured":"[26] Feige, U., Kilian, J., Naor, M.: A minimal model for secure computation (extended abstract). In: 26th ACM STOC. pp. 554\u2013563. ACM Press (May 1994)10.1145\/195058.195408","DOI":"10.1145\/195058.195408"},{"key":"2022060519474638969_j_popets-2021-0083_ref_027","doi-asserted-by":"crossref","unstructured":"[27] Feige, U., Shamir, A.: Zero knowledge proofs of knowledge in two rounds. In: Brassard, G. (ed.) CRYPTO\u201989. LNCS, vol. 435, pp. 526\u2013544. Springer, Heidelberg (Aug 1990)10.1007\/0-387-34805-0_46","DOI":"10.1007\/0-387-34805-0_46"},{"key":"2022060519474638969_j_popets-2021-0083_ref_028","doi-asserted-by":"crossref","unstructured":"[28] Garay, J., Kiayias, A., Ostrovsky, R.M., Panagiotakos, G., Zikas, V.: Resource-restricted cryptography: Revisiting mpc bounds in the proof-of-work era. In: Annual International Conference on the Theory and Applications of Cryptographic Techniques. pp. 129\u2013158. Springer (2020)10.1007\/978-3-030-45724-2_5","DOI":"10.1007\/978-3-030-45724-2_5"},{"key":"2022060519474638969_j_popets-2021-0083_ref_029","doi-asserted-by":"crossref","unstructured":"[29] Garay, J.A., Kiayias, A., Leonardos, N.: The bitcoin backbone protocol: Analysis and applications. In: Oswald, E., Fischlin, M. (eds.) EUROCRYPT 2015, Part II. LNCS, vol. 9057, pp. 281\u2013310. Springer, Heidelberg (Apr 2015)10.1007\/978-3-662-46803-6_10","DOI":"10.1007\/978-3-662-46803-6_10"},{"key":"2022060519474638969_j_popets-2021-0083_ref_030","doi-asserted-by":"crossref","unstructured":"[30] Goldreich, O., Micali, S., Wigderson, A.: How to play any mental game or A completeness theorem for protocols with honest majority. In: Aho, A. (ed.) 19th ACM STOC. pp. 218\u2013229. ACM Press (May 1987)10.1145\/28395.28420","DOI":"10.1145\/28395.28420"},{"key":"2022060519474638969_j_popets-2021-0083_ref_031","doi-asserted-by":"crossref","unstructured":"[31] Gordon, S.D., Malkin, T., Rosulek, M., Wee, H.: Multi-party computation of polynomials and branching programs without simultaneous interaction. In: Johansson, T., Nguyen, P.Q. (eds.) EUROCRYPT 2013. LNCS, vol. 7881, pp. 575\u2013591. Springer, Heidelberg (May 2013)10.1007\/978-3-642-38348-9_34","DOI":"10.1007\/978-3-642-38348-9_34"},{"key":"2022060519474638969_j_popets-2021-0083_ref_032","doi-asserted-by":"crossref","unstructured":"[32] Goyal, R., Goyal, V.: Overcoming cryptographic impossibility results using blockchains. In: Kalai, Y., Reyzin, L. (eds.) TCC 2017, Part I. LNCS, vol. 10677, pp. 529\u2013561. Springer, Heidelberg (Nov 2017)10.1007\/978-3-319-70500-2_18","DOI":"10.1007\/978-3-319-70500-2_18"},{"key":"2022060519474638969_j_popets-2021-0083_ref_033","doi-asserted-by":"crossref","unstructured":"[33] Halevi, S., Ishai, Y., Jain, A., Komargodski, I., Sahai, A., Yogev, E.: Non-interactive multiparty computation without correlated randomness. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017, Part III. LNCS, vol. 10626, pp. 181\u2013211. Springer, Heidelberg (Dec 2017)10.1007\/978-3-319-70700-6_7","DOI":"10.1007\/978-3-319-70700-6_7"},{"key":"2022060519474638969_j_popets-2021-0083_ref_034","doi-asserted-by":"crossref","unstructured":"[34] Halevi, S., Lindell, Y., Pinkas, B.: Secure computation on the web: Computing without simultaneous interaction. In: Rogaway, P. (ed.) CRYPTO 2011. LNCS, vol. 6841, pp. 132\u2013150. Springer, Heidelberg (Aug 2011)10.1007\/978-3-642-22792-9_8","DOI":"10.1007\/978-3-642-22792-9_8"},{"key":"2022060519474638969_j_popets-2021-0083_ref_035","doi-asserted-by":"crossref","unstructured":"[35] Kaptchuk, G., Green, M., Miers, I.: Giving state to the stateless: Augmenting trustworthy computation with ledgers. In: NDSS 2019. The Internet Society (Feb 2019)10.14722\/ndss.2019.23060","DOI":"10.14722\/ndss.2019.23060"},{"key":"2022060519474638969_j_popets-2021-0083_ref_036","doi-asserted-by":"crossref","unstructured":"[36] Kiayias, A., Zhou, H.S., Zikas, V.: Fair and robust multi-party computation using a global transaction ledger. In: Fischlin, M., Coron, J.S. (eds.) EUROCRYPT 2016, Part II. LNCS, vol. 9666, pp. 705\u2013734. Springer, Heidelberg (May 2016)10.1007\/978-3-662-49896-5_25","DOI":"10.1007\/978-3-662-49896-5_25"},{"key":"2022060519474638969_j_popets-2021-0083_ref_037","doi-asserted-by":"crossref","unstructured":"[37] Kosba, A.E., Miller, A., Shi, E., Wen, Z., Papamanthou, C.: Hawk: The blockchain model of cryptography and privacy-preserving smart contracts. In: 2016 IEEE Symposium on Security and Privacy. pp. 839\u2013858. IEEE Computer Society Press (May 2016)10.1109\/SP.2016.55","DOI":"10.1109\/SP.2016.55"},{"key":"2022060519474638969_j_popets-2021-0083_ref_038","unstructured":"[38] Labs, A.: Idex: A real-time and high-throughput ethereum smart contract exchange. https:\/\/idex.market\/"},{"key":"2022060519474638969_j_popets-2021-0083_ref_039","doi-asserted-by":"crossref","unstructured":"[39] Malavolta, G., Thyagarajan, S.A.K.: Homomorphic time-lock puzzles and applications. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019, Part I. LNCS, vol. 11692, pp. 620\u2013649. Springer, Heidelberg (Aug 2019)10.1007\/978-3-030-26948-7_22","DOI":"10.1007\/978-3-030-26948-7_22"},{"key":"2022060519474638969_j_popets-2021-0083_ref_040","unstructured":"[40] Nakamoto, S.: Bitcoin: A peer-to-peer electronic cash system. White Paper, https:\/\/bitcoin.org\/bitcoin.pdf (2008)"},{"key":"2022060519474638969_j_popets-2021-0083_ref_041","doi-asserted-by":"crossref","unstructured":"[41] Naor, M.: Moderately hard functions: From complexity to spam fighting. In: International Conference on Foundations of Software Technology and Theoretical Computer Science. pp. 434\u2013442. Springer (2003)10.1007\/978-3-540-24597-1_37","DOI":"10.1007\/978-3-540-24597-1_37"},{"key":"2022060519474638969_j_popets-2021-0083_ref_042","doi-asserted-by":"crossref","unstructured":"[42] Pass, R., Seeman, L., shelat, a.: Analysis of the blockchain protocol in asynchronous networks. In: Coron, J., Nielsen, J.B. (eds.) EUROCRYPT 2017, Part II. LNCS, vol. 10211, pp. 643\u2013673. Springer, Heidelberg (Apr \/ May 2017)10.1007\/978-3-319-56614-6_22","DOI":"10.1007\/978-3-319-56614-6_22"},{"key":"2022060519474638969_j_popets-2021-0083_ref_043","unstructured":"[43] Peterson, J., Krug, J.: Augur: a decentralized, open-source platform for prediction markets. arXiv preprint arXiv:1501.01042 (2015)"},{"key":"2022060519474638969_j_popets-2021-0083_ref_044","doi-asserted-by":"crossref","unstructured":"[44] Rabin, T., Ben-Or, M.: Verifiable secret sharing and multi-party protocols with honest majority (extended abstract). In: 21st ACM STOC. pp. 73\u201385. ACM Press (May 1989)10.1145\/73007.73014","DOI":"10.1145\/73007.73014"},{"key":"2022060519474638969_j_popets-2021-0083_ref_045","unstructured":"[45] Rindal, P.: The ivory secure computation runtime. https:\/\/github.com\/ladnir\/Ivory-Runtime, [Online; accessed 2019-10-07]"},{"key":"2022060519474638969_j_popets-2021-0083_ref_046","unstructured":"[46] Rivest, R.L., Shamir, A., Wagner, D.A.: Time-lock puzzles and timed-release crypto. Tech. rep., Cambridge, MA, USA (1996)"},{"key":"2022060519474638969_j_popets-2021-0083_ref_047","unstructured":"[47] Warren, W., Bandeali, A.: 0x: An open protocol for decentralized exchange on the ethereum blockchain. https:\/\/github.com\/0xProject\/whitepaper\/blob\/master\/0x_white_paper.pdf"},{"key":"2022060519474638969_j_popets-2021-0083_ref_048","doi-asserted-by":"crossref","unstructured":"[48] Yao, A.C.C.: Protocols for secure computations (extended abstract). In: 23rd FOCS. pp. 160\u2013164. IEEE Computer Society Press (Nov 1982)10.1109\/SFCS.1982.38","DOI":"10.1109\/SFCS.1982.38"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0083","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:31:48Z","timestamp":1658334708000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0083.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,23]]},"references-count":48,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2021,7,23]]},"published-print":{"date-parts":[[2021,10,1]]}},"alternative-id":["10.2478\/popets-2021-0083"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0083","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,23]]}}}