Fully Subliminal-Free Schnorr Signature for Nonce

Fully Subliminal-Free Schnorr Signature for Nonce
复制标题

DOI:
10.1109/candar57322.2022.00032
复制
发表时间:
2022-11
期刊:
2022 Tenth International Symposium on Computing and Networking (CANDAR)
影响因子:
--
通讯作者:
Sho Sugauchi;Satoshi Obana
Sho Sugauchi;Satoshi Obana
中科院分区:
其他
文献类型:
--
作者:
Sho Sugauchi;Satoshi Obana

文献摘要

相似文献

潜意识通道是一种隐蔽通道,允许发送者和接收者在不被他人察觉的情况下传递信息。有人指出,通过将信息嵌入到签名生成算法中使用的随机数中,某些数字签名可以用作潜意识通道。迄今为止,阻止潜意识通道的无潜意识特征已被广泛研究。有两种主要方法可以使数字签名免于潜意识。第一个修改签名生成和签名验证算法以检测潜意识通道,第二个仅修改签名生成。后一种方法更具挑战性。事实上,不存在能够保证对手完全无意识地将信息嵌入到随机数中,并允许对手将少量信息嵌入到随机数中的方案。在本文中,我们提出了两种基于Schnorr签名的无潜意识签名。第一个我们称之为 PSF-Schnorr 是部分不受潜意识影响的。基于PSF-Shcnorr签名,我们提出了实现完全潜意识自由的SF-Schnorr签名。为了使 PSF-Schnorr 签名不受潜意识影响,要求签名者可以在不知道输入的情况下计算哈希值。在所提出的方案中,我们在计算哈希值时采用完全同态加密(FHE)来满足上述要求,这将具有独立的意义,因为所提出的方案展示了FHE的新颖应用。
Subliminal channel is a kind of covert channels that allows sender and receiver to transfer information without being realized by others. It has been pointed out that some digital signatures can be used as subliminal channel by embedding information into a nonce used in the signature generation algorithm. Subliminal-free signatures preventing subliminal channel have been studied extensively so far. There are two major approaches to make a digital signature subliminal-free. The first one modifies both the signature generation and signature verification algorithm to detect subliminal channels, and the second one only modifies signature generation. The latter approach is more challenging. In fact, there exists no scheme that guarantees fully subliminal-freeness against adversaries tries to embedded information into nonce, and allows adversaries to embed small amount of information into nonce. In this paper, we presents two subliminal-free signature based on Schnorr signature. The first one which we call PSF-Schnorr is partially subliminal-free. Based on PSF-Shcnorr signature, we presents SF-Schnorr signature that achieves fully subliminal-freeness. To make PSF-Schnorr signature subliminal-free, it is required that the signer can compute the hash value without knowing the input. In the proposed scheme, we employs fully homomorphic encryption (FHE) in computing hash value to fulfill the above-mentioned requirement, which will be of independent interest in the sense that the proposed scheme shows a novel application of FHE.