首页> 外文会议>Annual international conference on the theory and applications of cryptographic techniques >Bifurcated Signatures: Folding the Accountability vs. Anonymity Dilemma into a Single Private Signing Scheme
【24h】

Bifurcated Signatures: Folding the Accountability vs. Anonymity Dilemma into a Single Private Signing Scheme

机译:分叉的签名:将问责制与匿名困境折叠成单个私人签名方案

获取原文

摘要

Over the development of modern cryptography, often, alternative cryptographic schemes are developed to achieve goals that in some important respect are orthogonal. Thus, we have to choose either a scheme which achieves the first goal and not the second, or vice versa. This results in two types of schemes that compete with each other. In the basic area of user privacy, specifically in anonymous (multi-use credentials) signing, such an orthogonality exists between anonymity and accountability. The conceptual contribution of this work is to reverse the above orthogonality by design, which essentially typifies the last 25 years or so, and to suggest an alternative methodology where the opposed properties are carefully folded into a single scheme. The schemes will support both opposing properties simultaneously in a bifurcated fashion, where: 1. First, based on rich semantics expressed over the message's context and content, the user, etc., the relevant property is applied point-wise per message operation depending on a predicate; and 2. Secondly, at the same time, the schemes provide what we call "branch-hiding;" namely, the resulting calculated value hides from outsiders which property has actually been locally applied. Specifically, we precisely define and give the first construction and security proof of a "Bifurcated Anonymous Signature" (BiAS): A scheme which supports either absolute anonymity or anonymity with accountability, based on a specific contextual predicate, while being branch-hiding. This novel signing scheme has numerous applications not easily implementable or not considered before, especially because: (ⅰ) the conditional traceability does not rely on a trusted authority as it is (non-interactively) encapsulated into signatures; and (ⅱ) signers know the predicate value and can make a conscious choice at each signing time. Technically, we realize BiAS from homomorphic commitments for a general family of predicates that can be represented by bounded-depth circuits. Our construction is generic and can be instantiated in the standard model from lattices and, more efficiently, from bilinear maps. In particular, the signature length is independent of the circuit size when we use commitments with suitable efficiency properties.
机译:在现代密码学的发展中,通常开发了替代加密方案,以实现在一些重要方面的目标是正交的。因此,我们必须选择一个实现第一目标而不是第二个目标的方案,反之亦然。这导致两种类型的方案彼此竞争。在用户隐私的基本领域,特别是在匿名(多用凭证)签名中,存在匿名和问责制之间存在这样的正交性。这项工作的概念贡献是通过设计逆转上述正交性,这基本上是最后25年左右的方式,并建议将反对属性仔细折叠成单一方案的替代方法。这些方案将以分支的方式同时支持两个相反的属性,其中:1。首先,基于在消息的上下文和内容上表达的丰富语义,用户等,根据谓词;其次,同时,这些计划提供了我们所谓的“分支隐藏”;即,由此产生的计算值从外部施用的局部施用的局部应用。具体而言,我们精确地定义并提供了“分叉匿名签名”(偏见)的第一个构建和安全证明:一种基于特定的上下文谓词,同时基于特定的上下文谓词,支持绝对匿名或匿名的方案。这种新的签名方案具有许多不容易实现或未考虑的应用程序,特别是:(Ⅰ)条件可追溯性不依赖于封装在签名中(非交互式); (Ⅱ)签名者知道谓词价值,可以在每个签名时间作出有意识的选择。从技术上讲,我们实现了可以由有界深度电路表示的一般谓词的同性恋承诺的偏见。我们的施工是通用的,可以从格子的标准模型中实例化,更有效地从双线性地图。特别地,当我们使用具有合适效率特性的承诺时,签名长度与电路大小无关。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号