首页> 外文会议>International conference on financial cryptography and data security >Attack on U-Prove Revocation Scheme from FC'13 - Passing Verification by Revoked Users
【24h】

Attack on U-Prove Revocation Scheme from FC'13 - Passing Verification by Revoked Users

机译:从FC'13攻击U-Prove吊销方案-通过吊销用户的验证

获取原文

摘要

We analyse security of the scheme proposed in the paper "Accumulators and U-Prove Revocation" from the Financial Cryptograr phy 2013 proceedings. Its authors propose an extension for the U-Prove, the credential system developed by Microsoft. This extension allows to revoke tokens (containers for credentials) using a new cryptographic accumulator scheme. We show that, under certain conditions, there exists a weakness that allows a user to pass the verification while using a revoked U-Prove token. It follows that the proposed solution fails to fulfil the primary goal of revocation schemes. Recently, a closely related system has been published by Microsoft Research in "U-Prove Designated-Verifier Accumulator Revocation Extension, Draft 1 Revision". Our attack does not work for this scheme, but the draft lacks formal justification and we cannot exclude problems of this kind.
机译:我们从2013年金融加密货币法律程序中分析了“累加器和U-Prove撤销”一文中提出的方案的安全性。它的作者提出了对U-Prove(微软开发的凭据系统)的扩展。此扩展允许使用新的密码累加器方案撤销令牌(凭证的容器)。我们证明,在某些情况下,存在一个弱点,该弱点允许用户在使用已撤销的U-Prove令牌时通过验证。因此,提出的解决方案无法实现吊销计划的主要目标。最近,Microsoft Research已在“ U-Prove指定验证者累加器撤销扩展草案1修订版”中发布了一个紧密相关的系统。我们的攻击方式不适用于该方案,但是草案缺乏正式理由,我们不能排除此类问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号