Signatures Resilient to Uninvertible Leakage

Signatures Resilient to Uninvertible Leakage
复制标题

DOI:
10.1007/978-3-319-44618-9_20
复制
发表时间:
2016-08
期刊:
--
影响因子:
--
通讯作者:
Yuyu Wang;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka
Yuyu Wang;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka
中科院分区:
其他
文献类型:
--
作者:
Yuyu Wang;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka

文献摘要

相似文献

在本文中,我们在选择性辅助输入模型中提出了一种完全泄漏弹性签名方案,该方案捕获了基于算法的物理实现而不是选择的公共参数的极其广泛的侧信道攻击。我们的签名方案在选择消息攻击下保持存在不可伪造性,只要攻击者不能在多项式时间内以不可忽略的概率从泄漏中完全恢复整个秘密状态。正式地说,泄漏被允许是输入秘密状态的任何可计算的不可逆函数,没有任何额外的限制。我们通过利用带辅助输入的点函数混淆器(AIPO)和差分输入混淆器(diO)实例化了这样一个签名方案。据我们所知,这是第一个防止不可逆转泄漏的签名方案。此外,我们的签名方案是public-coin,这意味着签名过程中使用的随机性是签名的一部分,并且不使用额外的秘密随机性。此外,我们提供了上述签名方案的一种变体,其中泄漏函数额外要求是内射的,并且表示泄漏函数的电路的大小是上界的。该方案具有抗信息不可逆泄漏的能力,从理论上确定了秘密信息,并且可以仅基于diO构建而不利用AIPO。
In this paper, we present a fully leakage resilient signature scheme in the selective auxiliary input model, which captures an extremely wide class of side-channel attacks that are based on physical implementations of algorithms rather than public parameters chosen. Our signature scheme keeps existential unforgeability under chosen message attacks as long as the adversary cannot completely recover the entire secret state from leakage in polynomial time with non-negligible probability. Formally speaking, the leakage is allowed to be any computable uninvertible function on input the secret state, without any additional restrictions. We instantiate such a signature scheme by exploiting a point-function obfuscator with auxiliary input (AIPO) and a differing-inputs obfuscator (diO).As far as we know, this is the first signature scheme secure against uninvertible leakage. Furthermore, our signature scheme is public-coin, in the sense that the randomness used in the signing procedure is a part of a signature and no additional secret randomness is used.Additionally, we provide a variant of the above signature scheme, for which leakage functions are additionally required to be injective, and the sizes of the circuits representing leakage functions are upper bounded. This scheme is resilient to uninvertible leakage that information-theoretically determines the secret information, and can be constructed based only on diO, without exploiting AIPO.