Joint State Composition Theorems for Public-Key Encryption and Digital Signature Functionalities with Local Computation

Joint State Composition Theorems for Public-Key Encryption and Digital Signature Functionalities with Local Computation
复制标题

具有本地计算的公钥加密和数字签名功能的联合状态组合定理

DOI:
10.1007/s00145-020-09353-0
复制
发表时间:
2020
影响因子:
3
通讯作者:
Daniel
Daniel
中科院分区:
计算机科学4区
文献类型:
--
作者:
Küsters;Tuengerthal;Rausch;Daniel

文献摘要

参考文献

被引文献

相似文献

在通用可组合性框架中,复杂的协议可以使用组合定理以模块化的方式从子协议构建。然而,正如Canetti和Rabin首先指出和研究的那样,这种模块化方法通常会导致不切实际的实现。例如,当在更复杂的协议中使用数字签名功能时,各方必须为协议的每个会话生成新的验证和签名密钥。这促使将合成定理推广到所谓的联合状态(合成)定理,其中功能的不同副本可以共享某些状态,例如,相同的验证和签名密钥。本文提出了一个比Canetti和Rabin的原定理更一般的联合状态定理,并指出了它的一些问题和局限性。我们应用我们的定理,以获得联合状态实现的三个功能:公钥加密,可重放公钥加密和数字签名。与大多数其他公式不同,我们的功能模型是在本地计算密文和签名,而不是由对手提供。为了获得联合状态实现,必须仔细设计功能。文献中提出的其他制剂被证明是不合适的。我们的工作基于IITM模型。我们的定义和结果证明了这个模型的表达性和简单性。例如,与Canetti的UC模型不同,在IITM模型中不需要定义显式的联合状态算子,并且联合状态定理直接从IITM模型中的复合定理得出。
In frameworks for universal composability, complex protocols can be built from sub-protocols in a modular way using composition theorems. However, as first pointed out and studied by Canetti and Rabin, this modular approach often leads to impractical implementations. For example, when using a functionality for digital signatures within a more complex protocol, parties have to generate new verification and signing keys for every session of the protocol. This motivates to generalize composition theorems to so-called joint state (composition) theorems, where different copies of a functionality may share some state, e.g., the same verification and signing keys. In this paper, we present a joint state theorem which is more general than the original theorem of Canetti and Rabin, for which several problems and limitations are pointed out. We apply our theorem to obtain joint state realizations for three functionalities: public-key encryption, replayable public-key encryption, and digital signatures. Unlike most other formulations, our functionalities model that ciphertexts and signatures are computed locally, rather than being provided by the adversary. To obtain the joint state realizations, the functionalities have to be designed carefully. Other formulations proposed in the literature are shown to be unsuitable. Our work is based on the IITM model. Our definitions and results demonstrate the expressivity and simplicity of this model. For example, unlike Canetti’s UC model, in the IITM model no explicit joint state operator needs to be defined and the joint state theorem follows immediately from the composition theorem in the IITM model.
DOI: --
发表时间: 2005
影响因子: 3
作者:
Ralf Küsters;Anupam Datta;John C. Mitchell;A. Ramanathan
通讯作者: A. Ramanathan
反应式模拟认证邮件
DOI: --
发表时间: 2006
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
B. Pfitzmann;M. Schunter;M. Waidner
通讯作者: M. Waidner
DOI: --
发表时间: 2004
期刊:
影响因子: --
作者:
M. Backes;B. Pfitzmann;M. Waidner
通讯作者: M. Waidner
DOI: 10.1007/978-3-662-53890-6_27
发表时间: 2016-12
期刊: --
影响因子: --
作者:
J. Camenisch;Robert R. Enderlein;S. Krenn;Ralf Küsters;Daniel Rausch
通讯作者: J. Camenisch;Robert R. Enderlein;S. Krenn;Ralf Küsters;Daniel Rausch
IITM 模型:一个简单而富有表现力的通用可组合性模型
DOI: 10.1007/s00145-020-09352-1
发表时间: 2020
影响因子: 3
作者:
Küsters;Tuengerthal;Rausch;Daniel
通讯作者: Daniel