Foundations of Fully Dynamic Group Signatures

Foundations of Fully Dynamic Group Signatures
复制标题

DOI:
10.1007/s00145-020-09357-w
复制
发表时间:
2016-06
影响因子:
3
通讯作者:
Jonathan Bootle;Andrea Cerulli;Pyrros Chaidos;Essam Ghadafi;Jens Groth
Jonathan Bootle;Andrea Cerulli;Pyrros Chaidos;Essam Ghadafi;Jens Groth
中科院分区:
计算机科学4区
文献类型:
--
作者:
Jonathan Bootle;Andrea Cerulli;Pyrros Chaidos;Essam Ghadafi;Jens Groth

文献摘要

被引文献

相似文献

组签名允许组成员代表组匿名签名。成员资格由指定的小组经理管理。如果需要,组管理员还可以在需要时透露签名者的身份,以加强问责和阻止滥用。为了使群签名在实践中得到应用,需要支持完全动态的群,即用户可以随时加入和离开。现有的完全动态群签名的安全定义是非正式的,存在缺陷,并且相互不兼容。我们通过为完全动态的群签名提供一个正式的严格的安全模型来填补这一空白。我们的模型是通用的,不是针对特定的设计范例量身定做的,因此,正如我们所展示的,可以用来讨论遵循不同设计范例的不同现有建筑的安全性。我们的定义是严格的,并在可能的情况下包括针对恶意选择的密钥的保护。我们既考虑了组管理和跟踪签名由同一授权机构管理的情况,即由单个组管理员管理的情况,也考虑了这些角色由两个单独的授权机构管理的情况,即组管理器和开放授权机构。我们还表明,我们的模型的专门化捕获了静态和部分动态方案的现有模型。在这个过程中,我们发现了使用撤销列表的群签名所实现的安全性中的一个细微差距。我们表明,在这样的方案中,新成员实现的可追溯性概念略弱。我们的安全模型的灵活性允许捕获这种可跟踪性的放松。
Group signatures allow members of a group to anonymously sign on behalf of the group. Membership is administered by a designated group manager. The group manager can also reveal the identity of a signer if and when needed to enforce accountability and deter abuse. For group signatures to be applicable in practice, they need to support fully dynamic groups, i.e., users may join and leave at any time. Existing security definitions for fully dynamic group signatures are informal, have shortcomings, and are mutually incompatible. We fill the gap by providing a formal rigorous security model for fully dynamic group signatures. Our model is general and is not tailored toward a specific design paradigm and can therefore, as we show, be used to argue about the security of different existing constructions following different design paradigms. Our definitions are stringent and when possible incorporate protection against maliciously chosen keys. We consider both the case where the group management and tracing signatures are administered by the same authority, i.e., a single group manager, and also the case where those roles are administered by two separate authorities, i.e., a group manager and an opening authority. We also show that a specialization of our model captures existing models for static and partially dynamic schemes. In the process, we identify a subtle gap in the security achieved by group signatures using revocation lists. We show that in such schemes new members achieve a slightly weaker notion of traceability. The flexibility of our security model allows to capture such relaxation of traceability.