A New Framework For More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor Sampling

A New Framework For More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor Sampling
复制标题

DOI:
10.1007/978-3-031-15979-4_11
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Rafaël del Pino;Shuichi Katsumata
Rafaël del Pino;Shuichi Katsumata
中科院分区:
其他
文献类型:
--
作者:
Rafaël del Pino;Shuichi Katsumata

文献摘要

相似文献

盲签名由Chaum(Crypto‘82)提出,是签名者和用户之间的交互协议,用户可以在不泄露要签名的消息的情况下获得签名。最近,Hauck et al.(Eurocrypt‘20)观察到,遵循Rükert原始盲签名(ASIACRYPT’10)的蓝图的所有有效的基于格的盲签名都存在安全证明缺陷。所有已知的格基盲签名都至少存在以下两个缺陷:启发式安全性;1MB或更大的签名长度;仅支持有界多项式多项式签名,或者基于非标准假设。在这项工作中,我们构造了签名大小约100kb的第一轮最优(即两轮)格基盲签名,它支持无界多项式多项式签名,并且在标准假设下是可证明安全的。即使我们允许非标准假设和更多的轮数,我们的方案也提供了最短的签名长度,同时支持无界多项式的多个签名。我们工作的主要思想是重温Fischlin(Crypto‘06)的通用盲签名构造,并使用为格定制的技术来优化提交然后打开的签名。我们的盲签名也是第一个在量子随机预言模型中具有形式安全性证明的构造。最后,我们的盲签名自然地扩展到部分盲签名,其中用户和签名者可以在消息中包括商定的公共字符串。
Blind signatures, proposed by Chaum (CRYPTO’82), are interactive protocols between a signer and a user, where a user can obtain a signature without revealing the message to be signed. Recently, Hauck et al. (EUROCRYPT’20) observed that all efficient lattice-based blind signatures following the blueprint of the original blind signature by Rükert (ASIACRYPT’10) have a flawed security proof. This puts us in a situation where all known lattice-based blind signatures have at least two of the following drawbacks: heuristic security; 1 MB or more signature size; only supporting bounded polynomially many signatures, or being based on non-standard assumptions.In this work, we construct the firstround-optimal(i.e., two-round) lattice-based blind signature with a signature size roughly 100 KB that supports unbounded polynomially many signatures and is provably secure under standard assumptions. Even if we allow non-standard assumptions and more rounds, ours provide the shortest signature size while simultaneously supporting unbounded polynomially many signatures. The main idea of our work is revisiting the generic blind signature construction by Fischlin (CRYPTO’06) and optimizing thecommit-then-openproof using techniques tailored to lattices. Our blind signature is also the first construction to have a formal security proof in thequantumrandom oracle model. Finally, our blind signature extends naturally topartiallyblind signatures, where the user and signer can include an agreed-upon public string in the message.