Impossibility on the Schnorr Signature from the One-more DL Assumption in the Non-programmable Random Oracle Model

Impossibility on the Schnorr Signature from the One-more DL Assumption in the Non-programmable Random Oracle Model
复制标题

DOI:
10.1587/transfun.2020dmp0008
复制
发表时间:
2020
期刊:
IEICE Trans. Fundam. Electron. Commun. Comput. Sci.
影响因子:
--
通讯作者:
Masayuki Fukumitsu;Shingo Hasegawa
Masayuki Fukumitsu;Shingo Hasegawa
中科院分区:
其他
文献类型:
--
作者:
Masayuki Fukumitsu;Shingo Hasegawa

文献摘要

相似文献

Schnorr签名是一个有代表性的签名方案,其安全性受到了广泛的讨论。在随机预言模型(ROM)中,它可以从DL假设中证明,而在标准模型中有负面的间接证据。Fleischhacker、Jager和Schröder证明了Schnorr签名的紧安全性是不可从强密码学假设中证明的,如一个多DL(OM-DL)假设和计算和决策的Di Blee-Hellman假设,只要底层密码学假设成立,则在ROM中通过一般约简。然而,Schnorr签名的可证明安全性是否不可能通过非紧合理约简从强随机性中证明仍然是一个未知数。在本文中,我们证明了Schnorr签名的安全性是不可证明的OM-DL映射在非可编程ROM中,只要OM-DL映射成立,我们的不可能性结果是通过一个非紧图灵约化证明的。
SUMMARY TheSchnorrsignatureisoneoftherepresentativesignature schemes and its security was widely discussed. In the random oracle model (ROM), it is provable from the DL assumption, whereas there is negative circumstantial evidence in the standard model. Fleischhacker, Jager, andSchrödershowedthatthetightsecurityoftheSchnorrsignatureis unprovable from a strong cryptographic assumption, such as the One-More DL (OM-DL) assumption and the computational and decisional Diffie-Hellman assumption, in the ROM via a generic reduction as long as the underlying cryptographic assumption holds. However, it remains open whether or not the impossibility of the provable security of the Schnorr signaturefromastrongassumptionviaa non-tight andreasonablereduction. Inthispaper,weshowthatthesecurityoftheSchnorrsignatureisunprovable fromtheOM-DLassumptioninthenon-programmableROMaslongastheOM-DLassumptionholds.Ourimpossibilityresultisprovenviaa non-tightTuringreduction.