Fault-Tolerant Aggregate Signatures

Fault-Tolerant Aggregate Signatures
复制标题

DOI:
10.1007/978-3-662-49384-7_13
复制
发表时间:
2016-03
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
G. Hartung;Björn Kaidel;Alexander Koch;Jessica Koch;Andy Rupp
G. Hartung;Björn Kaidel;Alexander Koch;Jessica Koch;Andy Rupp
中科院分区:
其他
文献类型:
--
作者:
G. Hartung;Björn Kaidel;Alexander Koch;Jessica Koch;Andy Rupp

文献摘要

被引文献

相似文献

聚合签名方案允许创建多个签名的短聚合。这一特性显著减少了传感器网络、安全路由协议、证书链、软件认证和安全日志机制中的带宽和存储空间。不幸的是,在所有先前的方案中,将单个invalidsignature添加到一个有效的聚合会使整个聚合无效。这种无效的集合体不能提供关于任何个人签名的有效性的信息。因此,添加单个错误签名会破坏可能大量数据的完整性和真实性证明。这在很多情况下是不切实际的,例如在安全日志中,一个被篡改的日志条目会使所有日志条目的聚合签名无效。在这样的方案中,验证算法能够确定属于一个集合的所有消息的子集,正确签名,提供了聚合的错误签名的数量不超过一定的bound.We给出了一个通用的容错聚合签名的构造从普通的聚合签名的基础上覆盖自由families。在我们的方案中的签名是一个小向量的聚合签名的基础方案。我们的方案是有界的,即可以聚合成一个签名的签名的数量必须预先固定。然而,聚合签名的长度是这个数字的对数。我们还提出了一个无界的构造,其中聚合签名的大小随聚合消息的数量线性增长,但是这个线性函数中的因子可以任意小。我们的签名中编码的附加信息也可以用来加速验证(与普通的集合签名相比)在人们只对验证集合中单个消息的有效性感兴趣的情况下,可能是独立感兴趣的超出容错的特征。为了具体起见,我们给出了一个使用合适的无覆盖族的实例。
Aggregate signature schemes allow for the creation of a short aggregate of multiple signatures. This feature leads to significant reductions of bandwidth and storage space in sensor networks, secure routing protocols, certificate chains, software authentication, and secure logging mechanisms. Unfortunately, in all prior schemes, adding a singleinvalidsignature to a valid aggregate renders the whole aggregate invalid. Verifying such an invalid aggregate provides no information on the validity of any individual signature. Hence, adding a single faulty signature destroys the proof of integrity and authenticity for a possibly large amount of data. This is largely impractical in a range of scenarios, e.g. secure logging, where a single tampered log entry would render the aggregate signature of all log entries invalid.In this paper, we introduce the notion of fault-tolerant aggregate signature schemes. In such a scheme, the verification algorithm is able to determine the subset of all messages belonging to an aggregate that were signed correctly, provided that the number of aggregated faulty signatures does not exceed a certain bound.We give a generic construction of fault-tolerant aggregate signatures from ordinary aggregate signatures based on cover-free families. A signature in our scheme is a small vector of aggregated signatures of the underlying scheme. Our scheme is bounded, i.e. the number of signatures that can be aggregated into one signature must be fixed in advance. However the length of an aggregate signature is logarithmic in this number. We also present an unbounded construction, where the size of the aggregate signature grows linearly in the number of aggregated messages, but the factor in this linear function can be made arbitrarily small.The additional information encoded in our signatures can also be used to speed up verification (compared to ordinary aggregate signatures) in cases where one is only interested in verifying the validity of a single message in an aggregate, a feature beyond fault-tolerance that might be of independent interest. For concreteness, we give an instantiation using a suitable cover-free family.