Sorting out signature schemes

Sorting out signature schemes
复制标题

整理签名方案

DOI:
10.1145/168588.168597
复制
发表时间:
1993
期刊:
--
影响因子:
--
通讯作者:
B. Pfitzmann
B. Pfitzmann
中科院分区:
--
文献类型:
--
作者:
B. Pfitzmann

文献摘要

被引文献

相似文献

数字签名方案是安全分布式系统的基本工具。对于什么是安全数字签名方案有一个正式的概念是很重要的,这样在这种方案的设计者和用户之间就有一个明确的接口。Goldwasser、Micali和Rivest在1988年给出了一个似乎是最终的定义,尽管实际上使用的大多数签名方案都不能证明其安全性,但它们都是为了满足它而构建的,例如,通过包括散列函数或冗余来对抗主动攻击。 然而,最近,一些新的安全特性的签名方案已被提出。它们中的大多数存在于几个变体中,其中一些在其他方面受到限制,其关系并不总是明确的。显然,这些新的性质需要定义和分类。然而,不幸的是,没有一个新计划被上述定义所涵盖。因此,新的属性不能被定义为添加,但是每种新类型的模式都需要从头开始一个新的定义,尽管这些定义之间有相似之处。这并不令人满意。 本文给出了数字签名方案的一般定义,它涵盖了所有已知的方案,并希望所有可能在未来发明的方案。特殊类型的计划,然后在一个正交的方式,使现有的计划可以系统地分类的额外的属性。 事实证明,签名方案最好由服务、结构和安全程度的分离来定义,并使用时序逻辑中的服务规范。这样的定义的几个部分可以很容易地重复用于其他类别的密码逻辑方案的一般定义。 讨论了与安全多方协议和认证逻辑的关系。
Digital signature schemes are a fundamental tool for secure distributed systems. It is important to have a formal notion of what a secure digital signature scheme is, so that there is a clear interface between designers and users of such schemes. A definition that seemed final was given by Goldwasser, Micali, and Rivest in 1988, and although most signature schemes used in practice cannot be proved secure with respect to it, they are all built so that they hopefully fulfil it, e.g., by the inclusion of hash functions or redundancy to counter active attacks. Recently, however, several signature schemes with new security properties have been presented. Most of them exist in several variants, and some of them pay for the new properties with restrictions in other respects, whose relation is not always clear. Obviously, these new properties need definitions and some classification. Unfortunately, however, none of the new schemes is covered by the definition mentioned above. Hence the new properties cannot be defined as additions, but each new type of scheme needs a new definition from scratch, although there are similarities between the definitions. This is unsatisfactory. This paper presents (an overview of) a general definition of digital signature schemes that covers all known schemes, and hopefully all that might be invented in future. Additional properties of special types of schemes are then presented in an orthogonal way, so that existing schemes can be classified systematically. It turns out that signature schemes are best defined by a separation of service, structure, and degree of security, with a service specification in temporal logic. Several parts of such a definition can easily be reused for general definitions of other classes of cryptologic schemes. Relations to secure multi-party protocols and logics of authentication are discussed.