Attribute-based Signatures for Unbounded Circuits in the ROM and Efficient Instantiations from Lattices

Attribute-based Signatures for Unbounded Circuits in the ROM and Efficient Instantiations from Lattices
复制标题

DOI:
10.1007/978-3-319-76581-5_4
复制
发表时间:
2018-03
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
A. Kaafarani;Shuichi Katsumata
A. Kaafarani;Shuichi Katsumata
中科院分区:
其他
文献类型:
--
作者:
A. Kaafarani;Shuichi Katsumata

文献摘要

相似文献

基于属性的签名(ABS)最初由Maji等人(CT-RSA'11)提出,代表了一种允许细粒度认证的基本机制。与属性关联的用户可以签署w.r.t.一个给定的公共策略C只有当他的属性满足C,即,。到目前为止,人们已经在构造基于双线性映射的ABS方案方面做了大量的工作,Sakai等人(PKC'16)的最新方案支持非常广泛的一类无界电路作为策略。然而,没有双线性映射的ABS方案的构造研究较少,直到最近Tsabary(TCC'17)才提出了一种基于格的ABS方案,该方案支持有界电路作为策略,但代价是削弱了安全性要求。我们通过构造第一个格,肯定地缩小了基于双线性映射的ABS方案和基于格的ABS方案之间的差距,的ABS方案。我们开始我们的工作,提供了一个通用的建设ABS计划无界电路的兰德om预言模型,这反过来又意味着单向功能是足够的ABS计划。为了证明安全性,我们形式化并证明了一个广义的分叉引理,我们称之为“一般多分叉引理与Oracle访问”,捕捉的情况下,模拟器是互动的一些算法hecannotrewind,也涵盖了许多功能,最近的格为基础的ZKP。事实上,这是迄今为止许多现有的来自格的匿名签名所缺乏的形式化(例如,组签名)。因此,这种形式化被认为是独立的利益。最后,我们提供了一个具体的实例,我们的通用ABS建设从格通过引入一个新的协议,这是高度背离以前已知的技术,证明拥有一个有效的签名的格为基础的签名方案Boyen(PKC'10)。
Attribute-based signature (ABS), originally introduced by Maji et al. (CT-RSA’11), represents an essential mechanism to allow for fine-grained authentication. A user associated with an attributexcan sign w.r.t. a given public policyConly if his attribute satisfiesC, i.e.,. So far, much effort on constructing bilinear map-based ABS schemes have been made, where the state-of-the-art scheme of Sakai et al. (PKC’16) supports the very wide class ofunboundedcircuits as policies. However, construction of ABS schemes without bilinear maps are less investigated, where it was not until recently that Tsabary (TCC’17) showed a lattice-based ABS scheme supportingboundedcircuits as policies, at the cost of weakening the security requirement.In this work, we affirmatively close the gap between ABS schemes based on bilinear maps and lattices by constructing the first lattice-based ABS scheme forunbounded circuitsin the random oracle model. We start our work by providing a generic construction of ABS schemes for unbounded-circuits in the rand om oracle model, which in turn implies that one-way functions are sufficient to construct ABS schemes. To prove security, we formalize and prove a generalization of the Forking Lemma, which we call“general multi-forking lemma with oracle access”, capturing the situation where the simulator is interacting with some algorithms hecannotrewind, and also covering many features of the recent lattice-based ZKPs. This, in fact, was a formalization lacking in many existing anonymous signatures from lattices so far (e.g., group signatures). Therefore, this formalization is believed to be of independent interest. Finally, we provide a concrete instantiation of our generic ABS construction from lattices by introducing a new-protocol, that highly departs from the previously known techniques, for proving possession of a valid signature of the lattice-based signature scheme of Boyen (PKC’10).