An Efficient System for Non-transferable Anonymous Credentials with Optional Anonymity Revocation

An Efficient System for Non-transferable Anonymous Credentials with Optional Anonymity Revocation
复制标题

DOI:
10.1007/3-540-44987-6_7
复制
发表时间:
2001-05
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
J. Camenisch;Anna Lysyanskaya
J. Camenisch;Anna Lysyanskaya
中科院分区:
其他
文献类型:
--
作者:
J. Camenisch;Anna Lysyanskaya

文献摘要

被引文献

相似文献

凭据系统是用户可以从组织获取凭据并证明拥有这些凭据的系统。当同一用户执行的交易不能链接时,这样的系统是匿名的。匿名凭证系统具有重要的实际意义,因为它是为用户提供隐私的最佳手段。在本文中,我们提出了一个实用的匿名凭证系统,该系统基于强RSA假设和决策Diffie-Hellman假设模一个安全素数积,并且大大优于现有的匿名凭证系统:(1)我们给出了第一个实用的解决方案,该解决方案允许用户在不涉及颁发组织的情况下,在必要时多次不可链接地证明拥有凭证。(2)为了防止滥用匿名性,我们的方案是第一个为特定交易提供可选匿名撤销的方案。(3)方案具有可分离性:所有组织都可以独立地选择自己的加密密钥。此外,我们建议更有效的方法来防止用户共享他们的凭据,通过引入全有或全无共享:一个用户允许朋友使用她的一个凭据一次,给他使用她的所有凭据的能力,即接管她的身份。这是通过一种称为循环加密的新原语实现的,它是独立的,并且可以从随机oracle模型中的任何语义安全密码系统中实现。
A credential system is a system in which users can obtain credentials from organizations and demonstrate possession of these credentials. Such a system is anonymous when transactions carried out by the same user cannot be linked. An anonymous credential system is of significant practical relevance because it is the best means of providing privacy for users. In this paper we propose a practical anonymous credential system that is based on the strong RSA assumption and the decisional Diffie-Hellman assumption modulo a safe prime product and is considerably superior to existing ones: (1) We give the first practical solution that allows a user to unlinkably demonstrate possession of a credential as many times as necessary without involving the issuing organization. (2) To prevent misuse of anonymity, our scheme is the first to offer optional anonymity revocation for particular transactions. (3) Our scheme offers separability: all organizations can choose their cryptographic keys independently of each other. Moreover, we suggest more effective means of preventing users from sharing their credentials, by introducingall-or-nothingsharing: a user who allows a friend to use one of her credentials once, gives him the ability to use all of her credentials, i.e., taking over her identity. This is implemented by a new primitive, calledcircular encryption, which is of independent interest, and can be realized from any semantically secure cryptosystem in the random oracle model.