Proxy Re-Encryption and Re-Signatures from Lattices

Proxy Re-Encryption and Re-Signatures from Lattices
复制标题

DOI:
10.1007/978-3-030-21568-2_18
复制
发表时间:
2019-06
期刊:
--
影响因子:
--
通讯作者:
Xiong Fan;Feng-Hao Liu
Xiong Fan;Feng-Hao Liu
中科院分区:
其他
文献类型:
--
作者:
Xiong Fan;Feng-Hao Liu

文献摘要

被引文献

相似文献

代理重加密(PRE)和代理重签名(PRS)是由Blaze、Bleumer和Strauss[98]提出的。基本上,PRE允许半可信代理将一个密钥下加密的密文转换为另一个密钥下相同明文的加密,而不会泄露底层明文。从那时起,人们探索了许多有趣的应用,并提出了各种环境下的建筑。另一方面,PRS允许半可信代理将Alice对消息的签名转换为Bob对同一消息的签名,但代理不能对Alice和Bob的新消息产生新的有效签名。在这项工作中,我们首先指出了Kirshanova(PKC‘14)工作的安全证明中的一个细微错误,他提出了基于格的CCA1PRE。因此,这重新开启了基于晶格的CCA1安全构造的方向,即使在单跳设置中也是如此。然后,我们构造了一个单跳Pre方案,该方案在新的基于标签的CCA-Pre模型中被证明是安全的。接下来,我们构建了第一个多跳预构建。最后,我们还利用格构造了第一个在我们提出的统一安全模型中被证明是安全的PRS方案。
Proxy re-encryption (PRE) and Proxy re-signature (PRS) were introduced by Blaze, Bleumer and Strauss [Eurocrypt ’98]. Basically, PRE allows a semi-trusted proxy to transform a ciphertext encrypted under one key into an encryption of the same plaintext under another key, without revealing the underlying plaintext. Since then, many interesting applications have been explored, and constructions in various settings have been proposed. On the other hand, PRS allows a semi-trusted proxy to transform Alice’s signature on a message into Bob’s signature on the same message, but the proxy cannot produce new valid signature on new messages for either Alice or Bob.In this work, we first point out a subtle mistake in the security proof of the work by Kirshanova (PKC ’14), who proposed a lattice-based CCA1 PRE. Thus, this reopens the direction of lattice-based CCA1-secure constructions, even in the single-hop setting. Then we construct a single-hop PRE scheme that is proven secure in our new tag-based CCA-PRE model. Next, we construct thefirstmulti-hop PRE construction. Lastly, we also construct thefirstPRS scheme from lattices that is proved secure in our proposed unified security model.