On the Security of Dynamic Group Signatures: Preventing Signature Hijacking

On the Security of Dynamic Group Signatures: Preventing Signature Hijacking
复制标题

DOI:
10.1007/978-3-642-30057-8_42
复制
发表时间:
2012-05
期刊:
--
影响因子:
--
通讯作者:
Yusuke Sakai;Jacob C. N. Schuldt;K. Emura;Goichiro Hanaoka;K. Ohta
Yusuke Sakai;Jacob C. N. Schuldt;K. Emura;Goichiro Hanaoka;K. Ohta
中科院分区:
其他
文献类型:
--
作者:
Yusuke Sakai;Jacob C. N. Schuldt;K. Emura;Goichiro Hanaoka;K. Ohta

文献摘要

被引文献

相似文献

我们发现了一个潜在的弱点,在标准的安全模型的动态组签名,似乎已经被忽视了以前。更具体地说,我们强调,即使一个计划可证明满足模型的安全要求,恶意的组成员可能会声称拥有一个诚实的组成员通过伪造所有权证明产生的组签名。在可能使用动态组签名的情况下,此属性会导致许多漏洞。我们进一步指出,目前最有效的动态群签名方案不提供对这种类型的恶意行为的保护。为了解决这个问题,我们引入了群签名的开放合理性的概念,它本质上要求除了原始签名人之外,任何用户都不可能证明有效群签名的所有权。然后我们给出了Groth(ASIACRYPT 2007,完整版)对该方案的一个相对简单的修改,在不引入任何额外假设的情况下证明了修改后方案的开放可靠性,我们相信开放可靠性是群签名的一个重要而自然的安全要求,并希望未来的方案能够采用这种类型的安全性。
We identify a potential weakness in the standard security model for dynamic group signatures which appears to have been overlooked previously. More specifically, we highlight that even if a scheme provably meets the security requirements of the model, a malicious group member can potentially claim ownership of a group signature produced by an honest group member by forging a proof of ownership. This property leads to a number of vulnerabilities in scenarios in which dynamic group signatures are likely to be used. We furthermore show that the currently most efficient dynamic group signature scheme does not provide protection against this type of malicious behavior.To address this, we introduce the notion ofopening soundnessfor group signatures which essentially requires that it is infeasible to produce a proof of ownership of a valid group signature for any user except the original signer. We then show a relatively simple modification of the scheme by Groth (ASIACRYPT 2007, full version) which allows us to prove opening soundness for the modified scheme without introducing any additional assumptions.We believe that opening soundness is an important and natural security requirement for group signatures, and hope that future schemes will adopt this type of security.