A Unified Framework for Trapdoor-Permutation-Based Sequential Aggregate Signatures

A Unified Framework for Trapdoor-Permutation-Based Sequential Aggregate Signatures
复制标题

DOI:
10.1007/978-3-319-76581-5_2
复制
发表时间:
2018-03
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Craig Gentry;Adam O'Neill;Leonid Reyzin
Craig Gentry;Adam O'Neill;Leonid Reyzin
中科院分区:
其他
文献类型:
--
作者:
Craig Gentry;Adam O'Neill;Leonid Reyzin

文献摘要

被引文献

相似文献

我们给出了一个框架陷门置换为基础的顺序聚合签名(SAS),统一和简化以前的工作,并导致新的结果。该框架是基于理想密码在大的域,最近已被证明是可实现的随机预言模型。其基本思想是用一个理想的密码代替全域散列签名方案中的随机预言。序列中的每个签名者将由消息加密的理想密码应用于前一个签名者的输出,然后在结果上反转陷门置换。我们通过改变理想密码中的额外密钥材料和对陷门置换做出不同的假设来获得该方案的不同变体。特别是,我们得到了第一个计划与懒惰的验证和签名大小独立的签名者的数量,不依赖于双线性pairings.Since现有的证明,理想的密码在大域可以实现在随机预言模型是有损的,我们的计划目前不允许实际的实例化参数在一个合理的安全水平,因此,我们认为我们的贡献主要是概念性的。然而,我们乐观地认为,至少在我们的具体应用中,会找到更严格的证明。
We give a framework for trapdoor-permutation-based sequential aggregate signatures (SAS) that unifies and simplifies prior work and leads to new results. The framework is based onideal ciphers over large domains, which have recently been shown to be realizable in the random oracle model. The basic idea is to replace the random oracle in the full-domain-hash signature scheme with an ideal cipher. Each signer in sequence applies the ideal cipher, keyed by the message, to the output of the previous signer, and then inverts the trapdoor permutation on the result. We obtain different variants of the scheme by varying additional keying material in the ideal cipher and making different assumptions on the trapdoor permutation. In particular, we obtain the first scheme with lazy verification and signature size independent of the number of signers that does not rely on bilinear pairings.Since existing proofs that ideal ciphers over large domains can be realized in the random oracle model are lossy, our schemes do not currently permit practical instantiation parameters at a reasonable security level, and thus we view our contribution as mainly conceptual. However, we are optimistic tighter proofs will be found, at least in our specific application.