Self Protecting Pirates and Black-Box Traitor Tracing

Self Protecting Pirates and Black-Box Traitor Tracing
复制标题

DOI:
10.1007/3-540-44647-8_4
复制
发表时间:
2001-08
期刊:
--
影响因子:
--
通讯作者:
A. Kiayias;M. Yung
A. Kiayias;M. Yung
中科院分区:
其他
文献类型:
--
作者:
A. Kiayias;M. Yung

文献摘要

被引文献

相似文献

我们提出了一种新的通用黑盒叛逆者追踪模型,在该模型中,海盗解码者采用了自我保护技术。这种机制很简单,很容易在任何(软件或硬件)设备中实现,并且是黑盒可访问的海盗(对手)试图逃避检测的一种自然方式。给出了自我保护装置黑盒叛逆者追踪的一个必要条件。我们构造性地证明了任何满足这一条件的系统都不能追踪包含基于叛逆者密钥的超对数的密钥的盗版解码器。然后,我们将上述条件与具体系统的具体性质相结合。我们证明了Boneh-Franklin(BF)方案和Kurosawa-Desmedt方案在自保护模型中都不具有黑盒追踪能力,当叛逆者的数量是超对数时,除非密文大小与平凡系统中的一样大,即用户数量是线性的。这部分地解决了Boneh和Franklin关于BF方案的一般黑盒可追踪性的公开问题:至少对于超对数叛徒的情况是这样。我们的否定结果不适用于Chor-Fiat-Naor(CFN)方案(事实上,它允许在我们的自我保护模型中进行跟踪);这将CFN的黑盒可追溯性与BF的黑盒可追溯性分开。我们还研究了一种较弱的黑盒跟踪形式,称为单查询“黑盒确认”。我们证明,当怀疑被建模为置信度(这偏向于叛徒的均匀分布)时,对于包含基于超对数叛徒密钥的密钥的自保护盗版解码器,这种单次查询确认本质上是不可能的。
We present a new generic black-box traitor tracing model in which the pirate-decoder employs a self-protection technique. This mechanism is simple, easy to implement in any (software or hardware) device and is a natural way by which a pirate (an adversary) which is black-box accessible, may try to evade detection. We present a necessary combinatorial condition for black-box traitor tracing of self-protecting devices. We constructively prove that any system that fails this condition, is incapable of tracing pirate-decoders that contain keys based on a superlogarithmic number of traitor keys. We then combine the above condition with specific properties of concrete systems. We show that the Boneh-Franklin (BF) scheme as well as the Kurosawa-Desmedt scheme have no black-box tracing capability in the self-protecting model when the number of traitors is superlogarithmic, unless the ciphertext size is as large as in a trivial system, namely linear in the number of users. This partially settles in the negative the open problem of Boneh and Franklin regarding the general black-box traceability of the BF scheme: at least for the case of superlogarithmic traitors. Our negative result does not apply to the Chor-Fiat-Naor (CFN) scheme (which, in fact, allows tracing in our self-protecting model); this separates CFN black-box traceability from that of BF. We also investigate a weaker form of black-box tracing called single-query “black-box confirmation.” We show that, when suspicion is modeled as a confidence weight (which biases the uniform distribution of traitors), such single-query confirmation is essentially not possible against a self-protecting pirate-decoder that contains keys based on a superlogarithmic number of traitor keys.