how to delegate computations: the power of no-signaling proofs ron rothblum weizmann institute joint...
TRANSCRIPT
![Page 1: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/1.jpg)
How to Delegate Computations: The Power of No-Signaling Proofs
Ron RothblumWeizmann Institute
Joint work with Yael Kalai and Ran Raz
![Page 2: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/2.jpg)
Delegation
Motivation: allow a computationally weak device to outsource computation to the cloud.
![Page 3: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/3.jpg)
Delegation
A computationally weak device outsources its computation to the cloud.
![Page 4: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/4.jpg)
Delegation
The device does not trust the cloud and so it wants to verify the result super-efficiently (say in linear-time).
![Page 5: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/5.jpg)
Delegation
Focus of this talk: 1-round arguments.
𝑥 , 𝑞𝑢𝑒𝑟𝑦
𝑓 (𝑥) , 𝑝𝑟𝑜𝑜𝑓
![Page 6: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/6.jpg)
𝑥∈𝐿?
• Completeness: .
• Computational Soundness: and .
• Running time of :
• Running time of :
Prover Verifier
𝐿∈𝐷𝑇𝐼𝑀𝐸(𝑇 )
Delegation
![Page 7: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/7.jpg)
Prior Work
• 4-messages – [Kilian92]: For all of !– Assumes CRH.
• One-round (2-messages):– [Goldwasser-Kalai-Rothblum08, Kalai-Raz09]: for
bounded-depth computation. Assume sub-exponential PIR.
![Page 8: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/8.jpg)
Prior Work
• In other models: 1. Random oracle model [Micali94]2. Preprocessing [Gennaro-Gentry-Parno10, Chung-Kalai-
Vadhan10, Applebaum-Ishai-Kushilevitz10]
• Under non-falsifiable assumptions (e.g. KoE) [Groth10, Lipma12, Bitanski-Canetti-Chiesa-Tromer12a, Goldwasser-Lin-Rubinstein11, Damgard-Faust-Hazay12, Bitanski-
Canetti-Chiesa-Tromer12b, Gennaro-Gentry-Parno-Raykova12].
• Non-falsifiable necessary* for [Gentry-Wichs11]
![Page 9: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/9.jpg)
Main Result 1
Thm: Assuming sub-exponentially hard PIR Delegation for every language in with an time verifier and a time prover.
Communication is .
![Page 10: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/10.jpg)
Main Result 1
Thm: Assuming sub-exponentially hard PIR Delegation for every language in with an time verifier and a time prover.
Communication is .
quasi-polynomially
(for any ).
![Page 11: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/11.jpg)
Main Result 1 (General)
Thm: Assuming sub-exponentially hard PIR delegation for every language in with a time verifier and a prover.
𝑘=𝑠𝑒𝑐𝑢𝑟𝑖𝑡𝑦 𝑝𝑎𝑟𝑎𝑚𝑒𝑡𝑒𝑟
![Page 12: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/12.jpg)
The Approach of [ABOR00]
[Aiello-Bhatt-Ostrovsky-Rajogopalan00] suggested to construct a delegation scheme by combining a Multi-Prover Interactive Proof-System with an FHE.
Actually PIR suffices, but easier to describe
with FHE
![Page 13: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/13.jpg)
Multi Prover Interactive Proofs (MIP) [BenOr-Goldwasser-Kilian-Wigderson88]
𝑃1
𝑉𝑃2
𝑃 𝑙
.
.
.
• Completeness:
• Soundness:
𝑴𝑰𝑷=𝑵𝑬𝑿𝑷[Babai-Fortnow-Lund91]
![Page 14: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/14.jpg)
Fully Homomorphic Encryption𝐸𝑛𝑐𝑘(𝑚)
Eval
circuit
𝐸𝑛𝑐𝑘(𝐶 (𝑚 ))
For this talk think of the output as a fresh encryption of
![Page 15: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/15.jpg)
The [ABOR00] Protocol
𝑃1
𝑉𝑃 𝑙
.
.
.
𝑞1
𝑞𝑙
𝑎1
𝑎𝑙
Take an protocol.
![Page 16: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/16.jpg)
The [ABOR00] Protocol
𝑃1
𝑉𝑃 𝑙
𝐸𝑘1(𝑞1)
Encrypt the queries and answer homomorphically.
𝐸𝑘1(𝑎1)
𝐸𝑘𝑙(𝑞𝑙)
𝐸𝑘𝑙(𝑎𝑙)
.
.
.
![Page 17: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/17.jpg)
The [ABOR00] Protocol
𝑃1
𝑉𝑃 𝑙
𝐸𝑘1(𝑞1)
Simulate using a single prover.
𝐸𝑘1(𝑎1)
𝐸𝑘𝑙(𝑞𝑙)
𝐸𝑘𝑙(𝑎𝑙)
.
.
.
![Page 18: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/18.jpg)
𝑃The [ABOR00] Protocol
𝑉
Simulate using a single prover.
![Page 19: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/19.jpg)
The [ABOR00] Protocol
Intuition: since encrypted under different keys, prover cannot use one query to answer a different query.
[Dwork-Landberg-Naor-Nissim-Reingold01]: this intuition is false*!
[Kalai-Raz09]: correct for single prover interactive proofs.
We show: protocol works if MIP satisfies a stronger soundness condition called no-signaling soundness.
![Page 20: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/20.jpg)
No-Signaling Prover Strategies
• Allow the provers a minimal form of communication.
• The answer of each prover may depend on the other queries as a function but must be independent as a RV.
![Page 21: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/21.jpg)
No-Signaling Prover Strategies
A prover strategy for an MIP specifies for every a distribution .
Def: A prover strategy is no-signaling if for every and and
Def: A no-signaling MIP – for every no-signaling strategy the verifier rejects whp.
![Page 22: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/22.jpg)
Example
𝑞1
𝑞 2
𝑎1
𝑎2
𝑷 𝟏(𝑥 )
𝑷 𝟐(𝑥 )
𝑽 (𝑥)
Accept if
For some function
A no-signaling cheating strategy : and
Not contrived! Some PCP/MIP verifiers work this way.
![Page 23: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/23.jpg)
Relation to Quantum MIP
• No-signaling strategies originally motivated by quantum MIPs – the (cheating) provers share an entangled quantum state.
• Entangled strategies are no-signaling.
• No-signaling soundness is likely to hold in future theories of physics (if information cannot travel faster than light).
![Page 24: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/24.jpg)
The Power of No-Signaling Strategies
Def: is the class of languages with no-signaling MIPs with poly-time verifier.
• Known that:
[DLNNR01,Ito-Kobayashi-Matsumoto09,KR09, Ito10]
no-signaling strategies break the soundness of all known PCPs/MIPs.
![Page 25: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/25.jpg)
The Power of No-Signaling Strategies
Def: is the class of languages with no-signaling MIPs with poly-time verifier.
• Known that:
[DLNNR01,Ito-Kobayashi-Matsumoto09,KR09, Ito10]
no-signaling strategies break the soundness of all known PCPs/MIPs.
• We show:
![Page 26: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/26.jpg)
Main Technical Result
Suppose can be computed in time .
Thm: has no-signaling MIP with time verifier and time prover.
provers and total communication.
Corollary:
![Page 27: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/27.jpg)
Proof Outline
1. Information Theoretic Step Construct an efficient no-signaling MIP for any language in (and scaled up for ).
2. Cryptographic Step Apply a general transformation
No-signaling MIP + PIR Delegation
![Page 28: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/28.jpg)
Proof Outline
1. Information Theoretic Step Construct an efficient no-signaling MIP for any language in (and scaled up for ).
2. Cryptographic Step Apply a general transformation
No-signaling MIP + PIR Delegation
![Page 29: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/29.jpg)
Proof of Technical Result
(High Level Overview)
![Page 30: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/30.jpg)
Proof Sketch
Suppose that can be computed in time and in space .
Construct a no-signaling for .
Our starting point is the [BFLS] PCP.
This talk – we assume
![Page 31: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/31.jpg)
The Provers
Each prover generates the entire tableau of the computation.
Output bit
𝑇
𝑆
Input bits
Every layer is computed by applying gates to the
previous layer
![Page 32: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/32.jpg)
The provers encode the computation via the [BFLS] PCP.
The Provers
![Page 33: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/33.jpg)
Each (honest) prover expects to be queried on a single point in the PCP and answers accordingly.
The Provers
![Page 34: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/34.jpg)
• The verifier generates the PCP queries.
• Randomly permutes the queries and sends to the provers.
• Also explicitly checks input and output gates.
• Accepts the answers if PCP verifier accepts and input/output gates are correct.
The Verifier
![Page 35: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/35.jpg)
No-Signaling Soundness
Challenges in NS setting:
• Each answer depends on other provers’ queries.
• No low degree test.
• No parallel repetition.
• Cheating provers are randomized.
![Page 36: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/36.jpg)
• Assume that we have a no-signaling cheating prover strategy that succeeds with probability (think of as tiny).
• Once we fix the provers, their answers as RVs are defined can send “crazy” queries and see how they answer.
• Will derive a contradiction.
No-Signaling Soundness
![Page 37: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/37.jpg)
“Reading” a point = query provers on a random line that goes through the point and interpolate answers to get the value.
Reading a Point
![Page 38: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/38.jpg)
Fix some gate of the computation.
Reading a Point
𝑋𝑌 𝑍
![Page 39: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/39.jpg)
Lemma: Can “read a gate” in the tableau so that with probability the 3 values will be “consistent”.
Proof of lemma uses algebraic PCP-like techniques.
Lemma
![Page 40: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/40.jpg)
Simultaneously “read” all points in the tableau.
For every gate, wp by the lemma (and using no-signaling) we get a consistent value
By union bound, wp we get global consistency.
Since we check input/output gates, the verifier must reject.
First Attempt
![Page 41: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/41.jpg)
• Major problem: not enough provers!
• We wanted to query points but we do not have so many provers.
• Number of queries s verifier running time.
First Attempt
![Page 42: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/42.jpg)
Second Attempt
Inputs correct wp
Look at some gate in the second layer.
Consistent wp
![Page 43: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/43.jpg)
Second Attempt
Correct wp
Look at some gate in the second layer.
![Page 44: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/44.jpg)
Second Attempt
By no-signaling still correct wp
Look at some gate in the second layer.
![Page 45: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/45.jpg)
Second Attempt
Similarly ,correct wp
Look at neighbor of the gate.
![Page 46: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/46.jpg)
Second Attempt
Both inputs correct wp
Gate at 3rd layer.
Consistent wp
![Page 47: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/47.jpg)
Second Attempt
output correct wp
Gate at 3rd layer.
![Page 48: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/48.jpg)
Second Attempt
• Error grows exponentially in the depth.
• Gives delegation for low-depth computation (already known via [GKR08+KR09]).
![Page 49: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/49.jpg)
Third Attempt
Use provers!
Lower layer correct wp Upper layer consistent wp
![Page 50: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/50.jpg)
Third Attempt
Use provers!
Correct wp
![Page 51: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/51.jpg)
Third Attempt
By no-signalingstill correct wp
Use provers!
Consistent wp
![Page 52: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/52.jpg)
Third Attempt
upper layer is correct wp
Use provers!
![Page 53: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/53.jpg)
Third Attempt
Use provers!
![Page 54: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/54.jpg)
Third Attempt
Use provers!
![Page 55: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/55.jpg)
Third Attempt
Use provers!
![Page 56: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/56.jpg)
Third Attempt
Use provers!
![Page 57: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/57.jpg)
Third Attempt
top layer is correct wp
![Page 58: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/58.jpg)
• Number of provers so running time is roughly .
• Gives delegation for languages that can be computed in linear space.
• For construction is more complicated.
Third Attempt
![Page 59: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/59.jpg)
Missing Details…
• Construction for .• We assumed provers cheat wp (parallel rep. is
not known for no-signaling MIP).• Formalizing “reading” and proving the lemma.• …
![Page 60: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/60.jpg)
Summary
• Crypo result: Delegation for every language in with time verification (assuming PIR).
• Information-theoretic result: .
![Page 61: How to Delegate Computations: The Power of No-Signaling Proofs Ron Rothblum Weizmann Institute Joint work with Yael Kalai and Ran Raz](https://reader034.vdocuments.us/reader034/viewer/2022042608/56649ccb5503460f94994d10/html5/thumbnails/61.jpg)
Thanks!