Figure 4.


Structure of the PCG-based COT protocols. When κ = 128, we need to use public-key operations to compute 128 base ROT correlations based on the DDH, CDH, or LWE assumptions. We can use the IKNP-style OT extension protocol to generate COT correlations in an order of magnitude 103 − 104, and then extend them to COT correlations in an order of magnitude 105 − 107 (or even more) based on the LPN assumption

