Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions

Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions
复制标题

DOI:
10.1155/2019/4872403
复制
发表时间:
2019-08
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
K. Emura;Goichiro Hanaoka;Yutaka Kawai;Takahiro Matsuda;Kazuma Ohara;Kazumasa Omote;Yusuke Sakai
K. Emura;Goichiro Hanaoka;Yutaka Kawai;Takahiro Matsuda;Kazuma Ohara;Kazumasa Omote;Yusuke Sakai
中科院分区:
其他
文献类型:
--
作者:
K. Emura;Goichiro Hanaoka;Yutaka Kawai;Takahiro Matsuda;Kazuma Ohara;Kazumasa Omote;Yusuke Sakai

文献摘要

相似文献

本文介绍了一种新的群签名功能,称为消息相关打开。它的目的是削弱高度信任放在开瓶器;即,普通的组签名方案不提供针对开启者的匿名性。在具有消息依赖打开(GS-MDO)的组签名方案中,除了打开器之外,我们还设置了一个不能提取任何用户身份但允许打开器打开签名的收纳器,该收纳器通过指定消息允许打开器打开签名,指定消息上的签名将由打开器打开。开启者无法从任何与其对应的消息未由接收者指定的签名中提取签名者的身份。本文给出了GS-MDO的形式化定义,并从基于身份的加密和自适应非交互式零知识证明两个方面提出了GS-MDO的一般构造。此外,我们提出了两种具体的结构,一种是标准模型,一种是随机oracle模型。我们在标准模型中的方案是通用结构的实例化,但是依赖于消息的开放属性是有限的。相比之下,我们在随机oracle模型中的方案不是我们通用结构的直接实例化,而是经过优化以提高效率并实现无界消息依赖的打开属性。此外,我们还证明了GS-MDO包含基于身份的加密,这意味着基于身份的加密对于设计GS-MDO方案至关重要。
This paper introduces a new capability for group signatures called message-dependent opening. It is intended to weaken the high trust placed on the opener; i.e., no anonymity against the opener is provided by an ordinary group signature scheme. In a group signature scheme with message-dependent opening (GS-MDO), in addition to the opener, we set up an admitter that is not able to extract any user’s identity but admits the opener to open signatures by specifying messages where signatures on the specified messages will be opened by the opener. The opener cannot extract the signer’s identity from any signature whose corresponding message is not specified by the admitter. This paper presents formal definitions of GS-MDO and proposes a generic construction of it from identity-based encryption and adaptive non-interactive zero-knowledge proofs. Moreover, we propose two specific constructions, one in the standard model and one in the random oracle model. Our scheme in the standard model is an instantiation of our generic construction but the message-dependent opening property is bounded. In contrast, our scheme in the random oracle model is not a direct instantiation of our generic construction but is optimized to increase efficiency and achieves the unbounded message-dependent opening property. Furthermore, we also demonstrate that GS-MDO implies identity-based encryption, thus implying that identity-based encryption is essential for designing GS-MDO schemes.