Generic transformation from broadcast encryption to round-optimal deniable ring authentication

Generic transformation from broadcast encryption to round-optimal deniable ring authentication
复制标题

DOI:
10.1007/s10623-021-00975-4
复制
发表时间:
2022-01
期刊:
Designs, Codes and Cryptography
影响因子:
--
通讯作者:
Keisuke Hara;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka
Keisuke Hara;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka
中科院分区:
其他
文献类型:
--
作者:
Keisuke Hara;Takahiro Matsuda;Goichiro Hanaoka;Keisuke Tanaka

文献摘要

相似文献

可否认环认证使某个组(称为环)中的证明者能够使用其秘密密钥向验证者认证消息,同时允许证明者否认与验证者进行过交互。这个原语还保证了证明者的匿名性,在这个意义上,验证者除了知道证明者的身份被包含在环中之外,不会知道任何关于证明者身份的信息。在这项工作中,我们提出了一个新的两轮并发可否认环认证的随机预言机模型的通用结构。我们的通用构造是基于任意安全广播加密(BE)方案。利用Agrawal,Wichs,Yamada(TCC 2020)和Agrawal,Wichs,Yamada(EUROPHOTOPT 2020)提出的方案实例化基础安全BE方案,得到了第一个在渐近意义下具有最优效率的两轮并发可否认环认证方案.这里,最优效率是指所有的公开参数和密钥的大小、通信成本和配对操作的数量都与n无关,其中n是环中的用户数量。除了这些主要的实例化,通过我们的一般建设,我们进一步获得各种两轮并发可否认环认证方案。
Deniable ring authentication enables a prover in some group (called aring) to authenticate a message to a verifier using its secret key while at the same time allowing the prover to deny ever having interacted with the verifier. This primitive furthermore guarantees the anonymity of the prover in the sense that the verifier will learn nothing about the prover’s identity except that it is included in the ring. In this work, we propose a new generic construction of two-round concurrently deniable ring authentication in the random oracle model. Our generic construction is based on anysecure broadcast encryption (BE) scheme. Instantiating the underlyingsecure BE scheme with the schemes proposed by Agrawal and Yamada (EUROCRYPT 2020) or Agrawal, Wichs, and Yamada (TCC 2020), we obtain the first two-round concurrently deniable ring authentication scheme with optimal efficiency in an asymptotic sense. Here, by optimal efficiency, we mean that all of the sizes of a public parameter and secret keys, the communication costs, and the number of pairing operations are independent ofn, wherenis the number of users in a ring. In addition to these main instantiations, through our generic construction, we further obtain various two-round concurrently deniable ring authentication schemes.