A Publicly Verifiable Optimistic Fair Exchange Protocol Using Decentralized CP-ABE

A Publicly Verifiable Optimistic Fair Exchange Protocol Using Decentralized CP-ABE
复制标题

DOI:
10.1093/comjnl/bxad039
复制
发表时间:
2023-04
期刊:
Comput. J.
影响因子:
--
通讯作者:
Liangao Zhang;Haibin Kan;Feiyang Qiu;F. Hao
Liangao Zhang;Haibin Kan;Feiyang Qiu;F. Hao
中科院分区:
其他
文献类型:
--
作者:
Liangao Zhang;Haibin Kan;Feiyang Qiu;F. Hao

文献摘要

相似文献

对于两个互不信任的参与者来说,公平交换是一个具有挑战性的问题。众所周知,如果没有可信第三方(TTP),公平交换是不可能的。但是,依赖单个 TTP 可能会导致单点故障。一个直观的想法是采用多个TTP来分配信任。本文使用去中心化密文策略属性加密(CP-ABE)构建了两方乐观公平交换(OFE)协议,实现了去中心化的TTP。这是可以实现的,因为分散的 CP-ABE 密文支持嵌套访问控制策略。嵌套访问控制策略非常适合包含多个角色(即玩家和 TTP)的公平交换协议。此外,我们应用非交互式零知识证明来证明密文的格式良好性,以强制玩家诚实地遵循协议规范。因此,我们构建了一个 OFE 协议,其中每个玩家的操作都可以公开验证,而不会泄露秘密信息。此外,我们还获得了乐观的去中心化 TTP(即 TTP 仅在需要仲裁时才参与)、自治性(即 TTP 不需要相互交互)、无状态性(即 TTP 不需要为交换协议存储数据)和可验证性(即 TTP 是可公开验证的)。与之前的工作相比,我们的协议仅假设一个公共通信渠道,并且各方的操作都是可公开验证的。此外,它在正常情况下实现了有利的$O(n)$验证复杂度,其中$n$是TTP的数量。最后,我们提出了一个概念验证实施来证明可行性。
Fair exchange is a challenging problem for two mutually distrusting players. It is widely known that fair exchange is impossible without a trusted third party (TTP). However, relying on a single TTP can cause a single-point failure. An intuitive idea is to adopt multiple TTPs to distribute trust. This paper constructs a two-party optimistic fair exchange (OFE) protocol using decentralized ciphertext-policy attribute-based encryption (CP-ABE), achieving decentralized TTPs. This is achievable because decentralized CP-ABE ciphertext supports a nested access control policy. A nested access control policy fits perfectly in a fair exchange protocol which contains multiple roles (i.e. players and TTPs). Further, we apply non-interactive zero knowledge proofs to prove the well-formedness of ciphertexts, so as to enforce players to follow the protocol specification honestly. Consequently, we construct an OFE protocol in which each player’s operations are publicly verifiable without revealing secret information. Also, we obtain decentralized TTPs with optimism (i.e. the TTPs are involved only when arbitration is required), autonomy (i.e. the TTPs do not need to interact with each other), statelessness (i.e. the TTPs do not need to store data for the exchange protocol) and verifiability (i.e. the TTPs are publicly verifiable). Compared with previous work, our protocol assumes only a public communication channel and each party’s operations are publicly verifiable. Besides, it achieves a favorable $O(n)$ verification complexity in the normal case, where $n$ is the number of TTPs. Finally, we present a proof-of-concept implementation to demonstrate the feasibility.