Sakai-Ohgishi-Kasahara identity-based non-interactive key exchange revisited and more

Sakai-Ohgishi-Kasahara identity-based non-interactive key exchange revisited and more
复制标题

重新审视 Sakai-Ohgishi-Kasahara 基于身份的非交互式密钥交换等

DOI:
10.1007/s10207-015-0274-0
复制
发表时间:
2016-02-01
影响因子:
3.2
通讯作者:
Zhang, Zongyang
Zhang, Zongyang
中科院分区:
计算机科学4区
文献类型:
--
作者:
Chen, Yu;Huang, Qiong;Zhang, Zongyang

文献摘要

被引文献

相似文献

基于身份的非交互式密钥交换(IB-NIKE)是基于身份的密码学中一个功能强大但有点被忽视的原语。虽然基于身份的加密和签名在过去三十年中得到了广泛的研究,但IB-NIKE在很大程度上仍未得到研究。到目前为止,文献中只有很少的IB-NIKE方案。其中Sakai-Ohgishi-Kasahara(SOK)方案是第一个高效安全的两方IB-NIKE方案,对后续工作有很大的影响。然而,SOK方案要求其身份映射函数被建模为随机预言机来证明安全性。此外,现有的安全性证明严重依赖于随机预言机的编程能力。不知道这种依赖是否是固有的。在这项工作中,我们深入研究了SOK IB-NIKE方案,并在随机预言模型和标准模型下给出了一系列可能和不可能的结果。在随机预言模型中,我们首先改进了以前的安全性分析SOK IB-NIKE方案,给出了一个更严格的减少。然后,我们使用元归约技术表明,SOK计划是不可能被证明是安全的计算双线性Diffie-Hellman假设的基础上,没有编程的随机预言。在标准模型中,我们展示了如何在SOK方案中实例化随机预言机,该方案具有来自可接受散列函数(AHF)和不可混淆性的具体散列函数。该方案基于判定性双线性Diffie-Hellman反演假设,是自适应安全的.据我们所知,这是第一个自适应安全的IB-NIKE计划的标准模型,不明确要求多线性映射。标准模型中的先前方案要么仅仅具有选择性安全性,要么需要来自多线性映射的可编程散列函数。在我们的计划的技术核心,我们概括了AHF的定义,并提出了一个通用的建设,使AHF与以前未实现的参数。这可能是独立的利益。此外,我们还得到了一些关于IB-NIKE的新结果。首先,我们提出了一个通用的构造多方IB-NIKE从可提取的证人的PRF和存在不可伪造的签名。其次,研究了IB-NIKE协议的半自适应安全性和自适应安全性之间的关系。有些令人惊讶的是,我们表明,这两个概念是多项式等价的。
Identity-based non-interactive key exchange (IB-NIKE) is a powerful but a bit overlooked primitive in identity-based cryptography. While identity-based encryption and signature have been extensively investigated over the past three decades, IB-NIKE has remained largely unstudied. So far, there are only few IB-NIKE schemes in the literature. Among them, Sakai-Ohgishi-Kasahara (SOK) scheme is the first efficient and secure two-party IB-NIKE scheme, which has great influence on follow-up works. However, the SOK scheme required its identity mapping function to be modeled as a random oracle to prove security. Moreover, its existing security proof heavily relies on the ability of programming the random oracle. It is unknown whether such reliance is inherent. In this work, we intensively revisit the SOK IB-NIKE scheme and present a series of possible and impossible results in the random oracle model and the standard model. In the random oracle model, we first improve previous security analysis for the SOK IB-NIKE scheme by giving a tighter reduction. We then use meta-reduction technique to show that the SOK scheme is unlikely proven to be secure based on the computational bilinear Diffie-Hellman assumption without programming the random oracle. In the standard model, we show how to instantiate the random oracle in the SOK scheme with a concrete hash function from admissible hash functions (AHFs) and indistinguishability obfuscation. The resulting scheme is adaptively secure based on the decisional bilinear Diffie-Hellman inversion assumption. To the best of our knowledge, this is the first adaptively secure IB-NIKE scheme in the standard model that does not explicitly require multilinear maps. Previous schemes in the standard model either have merely selective security or require programmable hash functions from multilinear maps. At the technical heart of our scheme, we generalize the definition of AHFs and propose a generic construction which enables AHFs with previously unachieved parameters. This might be of independent interest. In addition, we present some new results about IB-NIKE. Firstly, we propose a generic construction of multiparty IB-NIKE from extractable witness PRFs and existentially unforgeable signatures. Secondly, we investigate the relation between semi-adaptive security and adaptive security of IB-NIKE. Somewhat surprisingly, we show that these two notions are polynomially equivalent.