Group Signatures with Time-bound Keys Revisited: A New Model and an Efficient Construction

Group Signatures with Time-bound Keys Revisited: A New Model and an Efficient Construction
复制标题

DOI:
10.1145/3052973.3052979
复制
发表时间:
2017-04
期刊:
Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
K. Emura;Takuya Hayashi;Ai Ishida
K. Emura;Takuya Hayashi;Ai Ishida
中科院分区:
其他
文献类型:
--
作者:
K. Emura;Takuya Hayashi;Ai Ishida

文献摘要

相似文献

楚等人。 (ASIACCS 2012) 提出了带有时间限制密钥的群签名 (GS-TBK),其中每个签名密钥都与到期时间 τ 相关联。除了证明该组的成员身份之外,签名者还需要证明到期时间尚未过去,即 t<τ,其中 t 是当前时间。超过到期时间的签名者将被自动撤销,这种撤销称为自然撤销。同时,由于凭证的泄露,签名者可以在过期时间之前被撤销。这种撤销称为提前撤销。楚等人的一个不错的财产。提议是,与验证者本地撤销(VLR)组签名方案相比,撤销列表的大小可以减小,假设自然撤销在实践中占签名者撤销的大部分,而过早撤销的签名者只占一小部分。在本文中,我们指出 Chu 等人对可追溯性的定义。没有捕获签名密钥到期时间的不可伪造性,这保证了拥有与到期时间 τ 相关的签名密钥的对手在 τ 过去后无法计算出有效的签名。我们引入了一种捕获不可伪造性的安全模型,并提出了一种在新模型中安全的 GS-TBK 方案。我们的方案还提供了恒定的签名成本,而之前的方案则取决于时间表示的位长度。最后,我们给出了实施结果,并表明我们的方案在实际环境中是可行的。
Chu et al. (ASIACCS 2012) proposed group signature with time-bound keys (GS-TBK) where each signing key is associated to an expiry time τ. In addition to prove the membership of the group, a signer needs to prove that the expiry time has not passed, i.e., t<τ where t is the current time. A signer whose expiry time has passed is automatically revoked, and this revocation is called natural revocation. Simultaneously, signers can be revoked before their expiry times have passed due to the compromise of the credential. This revocation is called premature revocation. A nice property of the Chu et al. proposal is that the size of revocation lists can be reduced compared to those of Verifier-Local Revocation (VLR) group signature schemes, by assuming that natural revocation accounts for most of signer revocations in practice, and prematurely revoked signers are only a small fraction. In this paper, we point out that the definition of traceability of Chu et al. did not capture unforgeability of expiry time of signing keys which guarantees that no adversary who has a signing key associated to an expiry time τ can compute a valid signature after τ has passed. We introduce a security model that captures unforgeability, and propose a GS-TBK scheme secure in the new model. Our scheme also provides the constant signing costs whereas those of the previous schemes depend on the bit-length of the time representation. Finally, we give implementation results, and show that our scheme is feasible in practical settings.