Theory of Cryptography - 11th Theory of Cryptography Conference, TCC 2014, San Diego, CA, USA, February 24-26, 2014. Proceedings

Theory of Cryptography - 11th Theory of Cryptography Conference, TCC 2014, San Diego, CA, USA, February 24-26, 2014. Proceedings
复制标题

密码学理论 - 第 11 届密码学理论会议,TCC 2014,美国加利福尼亚州圣地亚哥,2014 年 2 月 24-26 日。会议记录

DOI:
10.1007/978-3-642-54242-8_29
复制
发表时间:
2014
期刊:
--
影响因子:
--
通讯作者:
Abe M
Abe M
中科院分区:
--
文献类型:
--
作者:
Abe M

文献摘要

被引文献

相似文献

我们构造了一个结构保持的签名方案,该方案是选择性随机化的,适用于所有类型的双线性群。我们给出了匹配下界,证明了我们的结构保持签名方案在签名长度和公开验证密钥长度方面都是最优的,现有的结构保持签名方案在非对称环境下由3个群元素组成,这是最优的.我们的构造保留了3个群元素的签名大小,同时将验证密钥大小最小化为1个群元素。根据应用,有时需要具有强不可伪造性,而在其他情况下需要具有随机化签名。为了两全其美,我们引入了选择性随机化的概念,其中签名者可以为特定的签名提供随机化令牌,使randomization.Our结构保持签名方案统一了不同的基于配对的设置,因为它可以在对称和非对称组中实例化。由于以前的最佳结构保持签名只在非对称双线性群中构造,这填补了我们知识中的一个重要空白。拥有一个适用于所有类型双线性群的统一签名方案不仅在概念上很好,而且还可以防范未来的密码分析攻击。我们的签名方案在一个非对称双线性群的实例可能仍然是安全的,即使密码分析师后来发现一个有效的可计算的同态之间的源组。
We construct a structure-preserving signature scheme that is selectively randomizable and works in all types of bilinear groups. We give matching lower bounds showing that our structure-preserving signature scheme is optimal with respect to both signature size and public verification key size.State of the art structure-preserving signatures in the asymmetric setting consist of 3 group elements, which is known to be optimal. Our construction preserves the signature size of 3 group elements and also at the same time minimizes the verification key size to 1 group element.Depending on the application, it is sometimes desirable to have strong unforgeability and in other situations desirable to have randomizable signatures. To get the best of both worlds, we introduce the notion of selective randomizability where the signer may for specific signatures provide randomization tokens that enable randomization.Our structure-preserving signature scheme unifies the different pairing-based settings since it can be instantiated in both symmetric and asymmetric groups. Since previously optimal structure-preserving signatures had only been constructed in asymmetric bilinear groups this closes an important gap in our knowledge. Having a unified signature scheme that works in all types of bilinear groups is not just conceptually nice but also gives a hedge against future cryptanalytic attacks. An instantiation of our signature scheme in an asymmetric bilinear group may remain secure even if cryptanalysts later discover an efficiently computable homomorphism between the source groups.