An Aggregate Signature with Pre-communication in the Plain Public Key Model

An Aggregate Signature with Pre-communication in the Plain Public Key Model
复制标题

DOI:
10.1007/978-3-030-91859-0_1
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Masayuki Fukumitsu;Shingo Hasegawa
Masayuki Fukumitsu;Shingo Hasegawa
中科院分区:
其他
文献类型:
--
作者:
Masayuki Fukumitsu;Shingo Hasegawa

文献摘要

相似文献

没有双线性映射的聚合签名是密码学实践和理论中一个具有挑战性的重要问题。该方案仅存在一个不使用双线性映射的聚合签名,但在安全性证明中需要一个非标准的密码假设。在ProvSec 2020中,Takemureet等人提出了一种新的聚合签名变体,即预通信聚合签名(ASwPC),以实现从标准假设出发的安全证明。ASwPC要求签名者在决定要签名的消息之前相互交互以共享临时随机性。在预通信之后,每个签名者可以单独启动签名过程。给出了基于离散对数(DL)假设的ASwPC实例,并在随机oracle和密钥知识(KOSK)模型下证明了其安全性。虽然前面的构造从标准假设中实现了可证明的安全性,但它需要一个稍强的安全模型,即KOSK模型。因此,我们的目标是构建一个新的ASwPC方案,该方案的安全性在聚合签名的标准安全概念——普通公钥(PPK)模型中得到证明。我们采用DDH假设而不是DL假设,决策假设的性质有助于我们在PPK模型中应用有损密钥技术来构造安全性证明。
Aggregate signatures without the bilinear map is a challenging and important problem in aspects of practical and theoretical cryptology. There exists only one aggregate signature which does not use the bilinear map, however, the scheme requires a non-standard cryptographic assumption in the security proof. In ProvSec 2020, Takemureet al.proposed a new variant of aggregate signatures, the aggregate signature with the pre-communication (ASwPC), to realize the security proof from a standard assumption. The ASwPC requires signers to interact with each other to share a temporary randomness before deciding their messages to be signed. After the pre-communication, each signer can start the signing process individually. They gave an instantiation of ASwPC based on the discrete logarithm (DL) assumption, and its security is proven in the random oracle and the knowledge of secret key (KOSK) model.Although the previous construction achieved the provable security from the standard assumption, it requires a slightly stronger security model, the KOSK model. Thus we aim to construct a new ASwPC scheme whose security is proven in the plain public key (PPK) model which is the standard security notion of the aggregate signature. We employ the DDH assumption rather than the DL assumption and the property of the decisional assumption helps us to apply the lossy key technique to construct a security proof in the PPK model.