On cryptographic protocols employing asymmetric pairings - The role of Ψ revisited

On cryptographic protocols employing asymmetric pairings - The role of Ψ revisited
复制标题

DOI:
10.1016/j.dam.2011.04.021
复制
发表时间:
2011-08
期刊:
Discret. Appl. Math.
影响因子:
--
通讯作者:
S. Chatterjee;A. Menezes
S. Chatterjee;A. Menezes
中科院分区:
其他
文献类型:
--
作者:
S. Chatterjee;A. Menezes

文献摘要

被引文献

相似文献

不对称配对e:G 1× G 2→ G T,如果已知一个可有效计算的同构<$:G 2→ G 1,则称为2型配对;如果这样的同构<$未知,则e称为3型配对。在非对称环境下,许多密码协议依赖于密码子的存在来降低其安全性,而有些协议则在协议本身中使用密码子。由于这些原因,相信这些协议中的一些不能用类型3配对来实现,而对于一些,安全性降低不能被转换到类型3设置或者需要更强的复杂性假设。相反,这些广泛持有的信念,我们认为,类型2配对仅仅是低效的实现类型3配对,并似乎提供没有好处的协议的基础上不对称配对的功能,安全性和性能的角度来看。
Asymmetric pairings e: G 1× G 2→ G T for which an efficiently-computable isomorphism ψ: G 2→ G 1 is known are called Type 2 pairings; if such an isomorphism ψ is not known then e is called a Type 3 pairing. Many cryptographic protocols in the asymmetric setting rely on the existence of ψ for their security reduction while some use it in the protocol itself. For these reasons, it is believed that some of these protocols cannot be implemented with Type 3 pairings, while for some the security reductions either cannot be transformed to the Type 3 setting or else require a stronger complexity assumption. Contrary to these widely held beliefs, we argue that Type 2 pairings are merely inefficient implementations of Type 3 pairings, and appear to offer no benefit for protocols based on asymmetric pairings from the point of view of functionality, security, and performance.