BUFFing signature schemes beyond unforgeability and the case of post-quantum signatures

BUFFing signature schemes beyond unforgeability and the case of post-quantum signatures
复制标题

增强签名方案的不可伪造性以及后量子签名的情况

DOI:
--
复制
发表时间:
2021
期刊:
IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Christian Janson
Christian Janson
中科院分区:
--
文献类型:
--
作者:
Cas J. F. Cremers;Samed Düzlü;Rune Fiedler;M. Fischlin;Christian Janson

文献摘要

被引文献

相似文献

现代数字签名方案可以提供比标准的(强)不可伪造性概念更多的保证,例如即使存在恶意生成的密钥也能提供安全性,或者需要知道消息才能为其生成签名。在这项工作中,我们重新审视了这些概念中的几个超越不可伪造性的概念,建立了它们之间的关系,提供了不可重签名性的第一个正式定义,以及一个变换,它可以以一种可证明和有效的方式为给定的签名方案提供这些性质。我们的结果不仅与已建立的方案相关:例如,正在进行的NIST PQC竞赛,旨在标准化后量子签名方案,在其第三轮中有六名决赛选手。我们对候选人的安全属性进行了深入的分析,超越了不可伪造性。我们发现,他们中的许多人还没有提供这些更强的保证,这意味着这些后量子方案的安全保证并不严格强于,而是无法比拟的,经典的签名方案。我们展示了如何应用我们的转换将有效地解决这个问题,为标准化方案提供这些额外的保证铺平了道路,从而使它们更难被滥用。
Modern digital signature schemes can provide more guarantees than the standard notion of (strong) unforgeability, such as offering security even in the presence of maliciously generated keys, or requiring to know a message to produce a signature for it. The use of signature schemes that lack these properties has previously enabled attacks on real-world protocols. In this work we revisit several of these notions beyond unforgeability, establish relations among them, provide the first formal definition of non re-signability, and a transformation that can provide these properties for a given signature scheme in a provable and efficient way.Our results are not only relevant for established schemes: for example, the ongoing NIST PQC competition towards standardizing post-quantum signature schemes has six finalists in its third round. We perform an in-depth analysis of the candidates with respect to their security properties beyond unforgeability. We show that many of them do not yet offer these stronger guarantees, which implies that the security guarantees of these post-quantum schemes are not strictly stronger than, but instead incomparable to, classical signature schemes. We show how applying our transformation would efficiently solve this, paving the way for the standardized schemes to provide these additional guarantees and thereby making them harder to misuse.