On Two Kinds of Flaws in Some Server-Aided Verification Schemes

On Two Kinds of Flaws in Some Server-Aided Verification Schemes
复制标题

DOI:
10.6633/ijns.201611.18(6).06
复制
发表时间:
2016
期刊:
Int. J. Netw. Secur.
影响因子:
--
通讯作者:
Zhengjun Cao;Lihua Liu;O. Markowitch
Zhengjun Cao;Lihua Liu;O. Markowitch
中科院分区:
其他
文献类型:
--
作者:
Zhengjun Cao;Lihua Liu;O. Markowitch

文献摘要

相似文献

在Asiacrypt'05上,Girault和Lefranc介绍了服务器辅助验证(SAV)的基本原理。在所提出的模型中,服务器被假定为不可信的,但不应该与合法的证明者勾结。在ProvSec'08中,Wu等人通过允许服务器与合法证明者勾结来推广Girault-Lefranc SAV模型,并提出了两个相应的SAV签名方案SAV-BLS-1和SAV-BLS-2。在本文中,我们认为,SAV-BLS-1计划是有点人为的,因为在该计划的计算增益是在额外的通信成本为代价。这是大多数外包计算方案中的一个常见缺陷,这些方案忽略了计算收益和所产生的通信成本之间的比较。我们还证明了SAV-BLS-2方案对共谋攻击是不安全的。另一个常见的缺陷是让验证者将大部分计算委托给服务器,从而阻止验证者确认返回的值是否确实绑定到签名者的公钥。
At Asiacrypt'05, Girault and Lefranc introduced the primitive of server-aided verification (SAV). In the proposed model, the server is assumed to be untrusted but is supposed to not collude with the legitimate prover. At ProvSec'08, Wu et al. have generalized the Girault-Lefranc SAV model by allowing the server to collude with the legitimate prover, and presented two corresponding SAV signature schemes, SAV-BLS-l and SAV-BLS-2. In this paper, we argue that the SAV-BLS-l scheme is somewhat artificial because the computational gain in the scheme is at the expense of additional communication costs. This is a common flaw in most outsourcing computation proposals which have neglected the comparisons between the computational gain and the incurred communication costs. We show also that the SAV-BLS-2 scheme is insecure against collusion attacks. It is another common flaw to have the verifier delegate most computations to the server in a way that prevent the verifier to confirm that the returned values are really bound to the signer's public key.