Enhanced Security Models and a Generic Construction Approach for Linkable Ring Signature

Enhanced Security Models and a Generic Construction Approach for Linkable Ring Signature
复制标题

DOI:
10.1142/s0129054106004480
复制
发表时间:
2006-12
期刊:
Int. J. Found. Comput. Sci.
影响因子:
--
通讯作者:
Joseph K. Liu;D. Wong
Joseph K. Liu;D. Wong
中科院分区:
其他
文献类型:
--
作者:
Joseph K. Liu;D. Wong

文献摘要

被引文献

相似文献

环签名方案是一种群签名方案,但没有群管理员来建立群或撤销签名者的身份。它允许组的成员对消息进行签名,从而得到的签名不会显示实际创建这些签名的组成员的身份(匿名),并且没有人可以知道两个签名是否由同一签名者创建(不可链接)。此外,一个群体的形成是自发的。转换组成员(非签名者)可能完全不知道自己被征召入组。可链接环签名的概念,由Liu等人提出。在2004年,还提供了签名者匿名性和自发性,但同时允许任何人确定是否有两个签名是由同一群成员颁发的(链接性)。在本文中,我们提出了一套增强的安全模型,并表明它们比Liu等人提出的原始安全模型具有更强的签名者匿名性和链接性。在2004年。我们还提出了一种构造可链接环签名方案的通用方法。一般方法使我们构造了两个有效的多项式结构的格式和一个类型受限的可分格式。可分离方案允许组成员具有不同的DL(离散对数)域参数集。在本文定义的增强安全模型下,所有方案都被证明是安全的。
A ring signature scheme is a group signature scheme but with no group manager to setup a group or revoke a signer's identity. It allows members of a group to sign messages such that the resulting signatures do not reveal the identities of the group members who actually created these signatures (anonymity) and no one can tell if two signatures are created by the same signer (unlinkability). Furthermore, the formation of a group is spontaneous. Diversion group members (non-signers) can be totally unaware of being conscripted to the group. The notion of linkable ring signature, introduced by Liu et al. in 2004, also provides signer anonymity and spontaneity, but at the same time, allows anyone to determine whether two signatures have been issued by the same group member (linkability). In this paper, we propose a suite of enhanced security models and show that they capture stronger notions of signer anonymity and linkability than the original ones proposed by Liu et al. in 2004. We also propose a generic approach for constructing a linkable ring signature scheme. The generic approach leads us to the construction of two efficient polynomial-structured schemes and one type-restricted separable scheme. The separable scheme allows group members to have different sets of DL (discrete logarithm) domain parameters. All schemes are shown secure under the enhanced security models defined in this paper.