Composable and Modular Anonymous Credentials: Definitions and Practical Constructions

Composable and Modular Anonymous Credentials: Definitions and Practical Constructions
复制标题

DOI:
10.1007/978-3-662-48800-3_11
复制
发表时间:
2015-11
期刊:
--
影响因子:
--
通讯作者:
J. Camenisch;M. Dubovitskaya;Kristiyan Haralambiev;Markulf Kohlweiss
J. Camenisch;M. Dubovitskaya;Kristiyan Haralambiev;Markulf Kohlweiss
中科院分区:
其他
文献类型:
--
作者:
J. Camenisch;M. Dubovitskaya;Kristiyan Haralambiev;Markulf Kohlweiss

文献摘要

被引文献

相似文献

理论上的进步需要时间才能应用于实际方案。匿名凭证方案也不例外。例如,现有的适合于现实世界使用的方案缺乏正式的、可组合的定义,部分原因是它们不支持直线提取,并且依赖于随机预言机来进行安全论证。为了解决这一差距,我们提出了unauthorized可编辑签名(URS),一个新的构建块的隐私增强协议,我们使用它来构建第一个高效的UC安全的匿名证书系统,支持多个发行人,选择性披露的属性,和匿名。我们的计划是第一个这样的系统,其中的凭证的大小和它的演示证明是独立的凭证中发出的属性的数量之一。此外,我们的新证书方案不依赖于随机预言机。作为一个重要的中间步骤,我们解决的问题,建立一个复杂的凭证系统,可以涵盖许多不同的功能的功能。也就是说,我们设计了一个核心的构建块为一个单一的发行人,支持凭证的发放和演示方面的缩写,然后展示如何构建一个成熟的凭证系统与多个发行人在一个模块化的方式。我们希望这种定义方法是独立的利益。
It takes time for theoretical advances to get used in practical schemes. Anonymous credential schemes are no exception. For instance, existing schemes suited for real-world use lack formal, composable definitions, partly because they do not support straight-line extraction and rely on random oracles for their security arguments. To address this gap, we proposeunlinkable redactable signatures(URS), a new building block for privacy-enhancing protocols, which we use to construct the first efficient UC-secure anonymous credential system that supports multiple issuers, selective disclosure of attributes, and pseudonyms. Our scheme is one of the first such systems for which both the size of a credential and its presentation proof are independent of the number of attributes issued in a credential. Moreover, our new credential scheme does not rely on random oracles. As an important intermediary step, we address the problem of building a functionality for a complex credential system that can cover many different features. Namely, we design a core building block for a single issuer that supports credential issuance and presentation with respect to pseudonyms and then show how to construct a full-fledged credential system with multiple issuers in a modular way. We expect this definitional approach to be of independent interest.