Anonymous Identification in Ad Hoc Groups

Anonymous Identification in Ad Hoc Groups
复制标题

DOI:
10.1007/978-3-540-24676-3_36
复制
发表时间:
2004-05
期刊:
--
影响因子:
--
通讯作者:
Y. Dodis;A. Kiayias;Antonio Nicolosi;V. Shoup
Y. Dodis;A. Kiayias;Antonio Nicolosi;V. Shoup
中科院分区:
其他
文献类型:
--
作者:
Y. Dodis;A. Kiayias;Antonio Nicolosi;V. Shoup

文献摘要

被引文献

相似文献

我们引入了一种新的多用户密码原语,它允许用户群中的参与者形成hocgroups,然后匿名地证明这些群组中的成员资格。我们的方案基于单向域累加器的概念,这是我们在这项工作中引入的密码累加器的自然扩展。我们为匿名识别方案提供了一个形式化的模型,并设计了安全的匿名识别方案(基于单向域的任何累加器)和基于强RSA假设的这种累加器的特定有效实现。我们的方法的一个显著特点是,所有的识别协议所花费的时间与特设组的大小无关。我们所有的方案和概念都可以普遍而有效地修改,以便允许权威机构恢复签名者的身份,如果需要的话。使用Fiat-Shamir变换,我们还获得了恒定大小、签名者不明确的群签名和环签名(可证明在随机Oracle模型中是安全的)。对于环签名,这是第一个这样的固定大小方案,因为之前所有的提议都将签名大小与环的大小成比例。对于组签名,我们获得了性能可与最先进方案相媲美的方案,其附加特性是,在密钥注册期间,组管理器的角色非常简单,基本上是被动的:它所做的就是接受新成员的公钥(并更新恒定大小的组公钥)。
We introduceAd hocAnonymous Identification schemes, a new multi-user cryptographic primitive that allows participants from a user population to formad-hocgroups, and then prove membership anonymously in such groups. Our schemes are based on the notion ofaccumulator with one-way domain, a natural extension of cryptographic accumulators we introduce in this work. We provide a formal model forAd hocAnonymous Identification schemes and design secure such schemes both generically (based on any accumulator with one-way domain) and for a specific efficient implementation of such an accumulator based on the Strong RSA Assumption. A salient feature of our approach is that all the identification protocols take time independent of the size of the ad-hoc group. All our schemes and notions can be generally and efficiently amended so that they allow the recovery of the signer’s identity by an authority, if the latter is desired.Using the Fiat-Shamir transform, we also obtainconstant-size, signer-ambiguous group and ring signatures (provably secure in the Random Oracle Model). For ring signatures, this is the first such constant-size scheme, as all the previous proposals had signature size proportional to the size of the ring. For group signatures, we obtain schemes comparable in performance with state-of-the-art schemes, with the additional feature that the role of the group manager during key registration is extremely simple and essentially passive: all it does is accept the public key of the new member (and update the constant-size public key of the group).