Tightly secure signatures and public-key encryption

Tightly secure signatures and public-key encryption
复制标题

DOI:
10.1007/s10623-015-0062-x
复制
发表时间:
2016-07-01
影响因子:
1.6
通讯作者:
Jager, Tibor
Jager, Tibor
中科院分区:
数学3区
文献类型:
--
作者:
Hofheinz, Dennis;Jager, Tibor

文献摘要

被引文献

相似文献

我们构建了第一个公开加密(PKE)方案,该方案可以根据标准假设证明其选择的ciphertext(即Ind-CCA)安全性,并且不会在用户数量或密文的数量中降低。特别是,我们的方案可以安全部署在设置中,在这种设置中,无需限制加密和/或用户的数量。作为一个中央技术构建块,我们设计了第一个具有严格安全性的保存结构的签名方案。 (这种签名方案可能具有独立的兴趣。)将此方案与撒哈福的证明相结合,可以为组方程进行紧密模拟的非交互式零知识证明系统。如果我们在Naor-Yung双重加密方案中使用此证明系统,则从决策线性假设中获得紧密的Ind-CCA安全PKE方案。我们指出,我们的技术不是针对PKE安全性的。相反,我们将我们的签名方案和证明系统视为一般构件,可以帮助实现严格的安全性。
We construct the first public-key encryption (PKE) scheme whose chosen-ciphertext (i.e., IND-CCA) security can be proved under a standard assumption and does not degrade in either the number of users or the number of ciphertexts. In particular, our scheme can be safely deployed in settings in which no a-priori bound on the number of encryptions and/or users is known. As a central technical building block, we devise the first structure-preserving signature scheme with a tight security reduction. (This signature scheme may be of independent interest.) Combining this scheme with Groth-Sahai proofs yields a tightly simulation-sound non-interactive zero-knowledge proof system for group equations. If we use this proof system in the Naor-Yung double encryption scheme, we obtain a tightly IND-CCA secure PKE scheme from the decision linear assumption. We point out that our techniques are not specific to PKE security. Rather, we view our signature scheme and proof system as general building blocks that can help to achieve a tight security reduction.