Structure-Preserving Signatures and Commitments to Group Elements

Structure-Preserving Signatures and Commitments to Group Elements
复制标题

DOI:
10.1007/s00145-014-9196-7
复制
发表时间:
2010-08
影响因子:
3
通讯作者:
Masayuki Abe;Georg Fuchsbauer;Jens Groth;Kristiyan Haralambiev;Miyako Ohkubo
Masayuki Abe;Georg Fuchsbauer;Jens Groth;Kristiyan Haralambiev;Miyako Ohkubo
中科院分区:
计算机科学4区
文献类型:
--
作者:
Masayuki Abe;Georg Fuchsbauer;Jens Groth;Kristiyan Haralambiev;Miyako Ohkubo

文献摘要

被引文献

相似文献

构造密码协议的模块化方法导致简单的设计,但通常是低效的实例化。另一方面,ad hoc构造可能以失去概念简单性为代价产生有效的协议。我们提出了一种新的设计范式,结构保持密码学,提供了一种方法来构建模块化的协议,合理的效率,同时保持概念的简单性。一个双线性群上的密码体制称为保结构的,如果它的公共输入和输出由双线性群的元素组成,并且它们的一致性可以通过计算对积方程来验证.由于保持结构的方案可以平滑地相互操作,因此它们可以作为密码应用程序模块化设计的构建块。本文介绍了双线性群上的保结构承诺和签名方案,并给出了几个令人满意的性质。承诺方案包括对群元素的同态承诺、陷门承诺和长度缩减承诺,而结构保持签名方案是第一个在多个群元素上产生恒定长度签名的方案。如果公钥位于消息空间中,则结构保持签名方案被称为自同构,这不能通过加密哈希函数压缩输入来实现,因为这会破坏我们试图保持的数学结构。自守签名可用于构建隐私保护协议底层的证书链。在大量结构保留协议的应用中,我们提出了一个高效的轮优盲签名方案和一个具有高效且并发安全的新成员注册协议的群签名方案。
A modular approach to constructing cryptographic protocols leads to simple designs but often inefficient instantiations. On the other hand, ad hoc constructions may yield efficient protocols at the cost of losing conceptual simplicity. We suggest a new design paradigm,structure-preserving cryptography, that provides a way to construct modular protocols with reasonable efficiency while retaining conceptual simplicity. A cryptographic scheme over a bilinear group is called structure-preserving if its public inputs and outputs consist of elements from the bilinear groups and their consistency can be verified by evaluating pairing-product equations. As structure-preserving schemes smoothly interoperate with each other, they are useful as building blocks in modular design of cryptographic applications. This paper introduces structure-preserving commitment and signature schemes over bilinear groups with several desirable properties. The commitment schemes include homomorphic, trapdoor and length-reducing commitments to group elements, and the structure-preserving signature schemes are the first ones that yield constant-size signatures on multiple group elements. A structure-preserving signature scheme is called automorphic if the public keys lie in the message space, which cannot be achieved by compressing inputs via a cryptographic hash function, as this would destroy the mathematical structure we are trying to preserve. Automorphic signatures can be used for building certification chains underlying privacy-preserving protocols. Among a vast number of applications of structure-preserving protocols, we present an efficient round-optimal blind-signature scheme and a group signature scheme with an efficient and concurrently secure protocol for enrolling new members.