Are These Pairing Elements Correct?: Automated Verification and Applications

Are These Pairing Elements Correct?: Automated Verification and Applications
复制标题

这些配对元素正确吗?:自动验证和应用

DOI:
--
复制
发表时间:
2019
期刊:
Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Satyanarayana Vusirikala
Satyanarayana Vusirikala
中科院分区:
--
文献类型:
--
作者:
S. Hohenberger;Satyanarayana Vusirikala

文献摘要

参考文献

被引文献

相似文献

使用一组配对乘积方程(PPE)来验证一组不可信的配对元素相对于另一组可信元素的正确性具有大量的密码应用。这些措施包括设计基本的和保持结构的签名方案,建立盲目的IBE的不经意转移方案,寻找新的可验证的随机函数,以及使IBE/ABE当局对用户“负责”。一个自然的问题是:文献PPE中的所有可信-不可信配对元素组都是可测试的吗?我们提供了原始的观察结果,证明了答案是否定的,而且,确定是否存在一组PPE可以验证一些配对元素与其他配对元素之间的关系,这可能不是平凡的。许多IBE方案具有PPE可测试的私钥(关于公共参数),而其他方案,例如基于双系统加密的方案,显然不具有PPE可测试私钥。为了帮助那些希望在他们的密码系统中使用基于PPE的元素验证的人,我们设计了规则来系统地搜索一组可以相对于一组可信元素来验证不可信元素的PPE。我们证明了每个规则的正确性,并将它们结合到一个主搜索算法中,我们也证明了该算法的正确性。我们在一个新的软件工具AutoPPE中实现了该算法。AutoPPE在20多个案例研究中进行了测试,发现了一系列PPE(在存在的方案上),通常只需几秒钟。这项工作代表着朝着通过计算机自动化提高基于配对的密码设计的速度和精度这一更大目标迈出了重要的一步。
Using a set of pairing product equations (PPEs) to verify the correctness of an untrusted set of pairing elements with respect to another set of trusted elements has numerous cryptographic applications. These include the design of basic and structure-preserving signature schemes, building oblivious transfer schemes from "blind" IBE, finding new verifiable random functions and keeping the IBE/ABE authority "accountable" to the user. A natural question to ask is: are all trusted-untrusted pairing element groups in the literature PPE testable? We provide original observations demonstrating that the answer is no, and moreover, it can be non-trivial to determine whether or not there exists a set of PPEs that can verify some pairing elements with respect to others. Many IBE schemes have PPE-testable private keys (with respect to the public parameters), while others, such as those based on dual-system encryption, provably do not. To aid those wishing to use PPE-based element verification in their cryptosystems, we devised rules to systematically search for a set of PPEs that can verify untrusted elements with respect to a set of trusted elements. We prove the correctness of each rule and combine them into a main searching algorithm for which we also prove correctness. We implemented this algorithm in a new software tool, called AutoPPE. Tested on over two dozen case studies, AutoPPE found a set of PPEs (on schemes where they exist) usually in just a matter of seconds. This work represents an important step towards the larger goal of improving the speed and accuracy of pairing-based cryptographic design via computer automation.
DOI: 10.1145/3243734.3243825
发表时间: 2018-10
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
G. Barthe;Xiong Fan;Joshua Gancher;B. Grégoire;Charlie Jacomme;E. Shi
通讯作者: G. Barthe;Xiong Fan;Joshua Gancher;B. Grégoire;Charlie Jacomme;E. Shi