Fully leakage-resilient signatures revisited: Graceful degradation, noisy leakage, and construction in the bounded-retrieval model

Fully leakage-resilient signatures revisited: Graceful degradation, noisy leakage, and construction in the bounded-retrieval model
复制标题

DOI:
10.1016/j.tcs.2016.11.016
复制
发表时间:
2017-01
期刊:
Theor. Comput. Sci.
影响因子:
--
通讯作者:
Antonio Faonio;J. Nielsen;D. Venturi
Antonio Faonio;J. Nielsen;D. Venturi
中科院分区:
其他
文献类型:
--
作者:
Antonio Faonio;J. Nielsen;D. Venturi

文献摘要

被引文献

相似文献

我们构造了新的防泄漏签名方案。我们的方案在攻击者泄露关于签名者整个状态的任意(但有限的)信息(有时称为完全泄漏弹性)时仍然是不可伪造的,包括签名算法的随机抛硬币。我们的结构的主要特点是,在标准的存在不可伪造性是不可能的情况下,它们提供了安全的优雅退化。这个属性是最近由Nielsen, Venturi和Zottarel (PKC 2014)提出的,用于处理秘钥比签名大小大得多的设置。其中一个显著的例子是所谓的有界检索模型(Bounded-Retrieval Model, BRM),在这种模型中,人们有意扩大密钥的大小,同时保持方案的签名大小和计算复杂度不变。我们的主要结构泄漏率为1−0(1),在标准模型中被证明是安全的。另外,我们还给出了一个基于随机oracle的BRM结构。我们所有的方案都是根据通用的构建块来描述的,但也允许在相当标准的数论假设下进行有效的实例化。最后,我们解释了如何将我们的一些方案扩展到噪声泄漏的设置,其中对泄漏函数的唯一限制是输出不会过多地减少密钥的最小熵。
We construct new leakage-resilient signature schemes. Our schemes remain unforgeable against an adversary leaking arbitrary (yet bounded) information on the entire state of the signer (sometimes known as fully leakage resilience), including the random coin tosses of the signing algorithm. The main feature of our constructions is that they offer a graceful degradation of security in situations where standard existential unforgeability is impossible. This property was recently put forward by Nielsen, Venturi, and Zottarel (PKC 2014)[19] to deal with settings in which the secret key is much larger than the size of a signature. One remarkable such case is the so-called Bounded-Retrieval Model (BRM), where one intentionally inflates the size of the secret key while keeping constant the signature size and the computational complexity of the scheme. Our main constructions have leakage rate 1− o (1), and are proven secure in the standard model. We additionally give a construction in the BRM, relying on a random oracle. All of our schemes are described in terms of generic building blocks, but also admit efficient instantiations under fairly standard number-theoretic assumptions. Finally, we explain how to extend some of our schemes to the setting of noisy leakage, where the only restriction on the leakage functions is that the output does not decrease the min-entropy of the secret key by too much.