首页> 外文会议>IMA conference on cryptography and coding >Subset Signatures with Controlled Context-Hiding
【24h】

Subset Signatures with Controlled Context-Hiding

机译:具有受控上下文隐藏的子集签名

获取原文

摘要

Subset signatures are a variant of malleable signatures which allow anyone to derive signatures on any subset of previously signed sets in such a way that derived signatures are indistinguishable from new signatures on the subset (i.e. context-hiding). Such a primitive has many applications. In some scenarios, it might be desirable to restrict some elements in the set from preserving the context-hiding property. In other words, it might be desirable to allow the signer, at the time of the signing, to mark specific elements (which we refer to hereafter as the restricted subset) such that the inclusion of any elements from the restricted subset in any derived signatures would violate the context-hiding property and make the derived signature linkable to the original signature. In this paper, we put forward the notion of subset signatures with controlled context-hiding. We propose a security model and a generic construction as well as efficient instantiations which do not rely on random oracles. Our instantiations are structure-preserving and therefore could be useful for other applications. As a special case of our constructions when the restricted subset is empty, we obtain more efficient constructions of standard subset signatures. Our constructions, which satisfy the strongest existing security definitions, have constant-size keys and outperform existing constructions in every respect. As part of our contribution, we construct a structure-preserving signature scheme with combined unforgeability that signs a vector of group elements while maintaining constant-size signatures. The scheme has some desirable properties and combines nicely with Groth-Sahai proofs, and thus could be of independent interest.
机译:子集签名是可延展签名的一种变体,它允许任何人以先前签名集的任何子集上的派生签名的方式,使派生签名与子集上的新签名没有区别(即,上下文隐藏)。这样的原语有很多应用。在某些情况下,可能希望限制集合中的某些元素保留上下文隐藏属性。换句话说,可能希望允许签名者在签名时标记特定元素(在下文中称为受限子集),以便在任何派生签名中包含来自受限子集的任何元素。将违反上下文隐藏属性,并使派生的签名可链接到原始签名。在本文中,我们提出了具有受控上下文隐藏的子集签名的概念。我们提出了一个不依赖于随机预言的安全模型和泛型构造以及有效的实例化。我们的实例是保留结构的,因此对于其他应用程序可能很有用。当受限子集为空时,作为构造的一种特殊情况,我们可以获得标准子集签名的更有效构造。我们的结构满足最强的现有安全性定义,具有恒定大小的密钥,并且在各个方面都优于现有结构。作为我们贡献的一部分,我们构建了一种具有组合不可伪造性的保留结构的签名方案,该方案在保持不变大小的签名的同时对组元素的向量进行签名。该方案具有一些理想的特性,并与Groth-Sahai证明很好地结合在一起,因此可能具有独立利益。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号