On Two Kinds of Flaws in Some Server-Aided Verification Schemes
On Two Kinds of Flaws in Some Server-Aided Verification Schemes
复制标题
DOI:
10.6633/ijns.201611.18(6).06
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Zhengjun Cao;Lihua Liu;O. Markowitch
中科院分区:
文献类型:
--
作者:
Zhengjun Cao;Lihua Liu;O. Markowitch
At Asiacrypt'05, Girault and Lefranc introduced the primitive of server-aided verification (SAV). In the proposed model, the server is assumed to be untrusted but is supposed to not collude with the legitimate prover. At ProvSec'08, Wu et al. have generalized the Girault-Lefranc SAV model by allowing the server to collude with the legitimate prover, and presented two corresponding SAV signature schemes, SAV-BLS-l and SAV-BLS-2. In this paper, we argue that the SAV-BLS-l scheme is somewhat artificial because the computational gain in the scheme is at the expense of additional communication costs. This is a common flaw in most outsourcing computation proposals which have neglected the comparisons between the computational gain and the incurred communication costs. We show also that the SAV-BLS-2 scheme is insecure against collusion attacks. It is another common flaw to have the verifier delegate most computations to the server in a way that prevent the verifier to confirm that the returned values are really bound to the signer's public key.