【24h】

Practical Signing-Right Revocation

机译:实用的签署权撤销

获取原文

摘要

One of the key features that must be supported by every modern PKI is an efficient way to determine (at verification) whether the signing key had been revoked. In most solutions, the verifier periodically contacts the certificate authority (CA) to obtain a list of blacklisted, or whitelisted, certificates. In the worst case this has to be done for every signature verification. Besides the computational costs of verification, after revocation all signatures under the revoked key become invalid. In the solution by Boneh et al. at USENIX'01, the CA holds a share of the private signing key and contributes to the signature generation. After revocation, the CA simply denies its participation in the interactive signing protocol. Thus, the revoked user can no longer generate valid signatures. We extend this solution to also cover privacy, non-trusted setups, and time-stamps. We give a formal definitional framework, and provide elegantly simple, yet provably secure, instantiations from efficient standard building blocks such as digital signatures, commitments, and partially blind signatures. Finally, we propose extensions to our scheme.
机译:每个现代PKI都必须支持的关键功能之一是确定(验证)签名密钥是否已被撤销的有效方法。在大多数解决方案中,验证者会定期与证书颁发机构(CA)联系,以获得列入黑名单或列入白名单的证书的列表。在最坏的情况下,必须对每个签名验证都执行此操作。除了验证的计算成本外,在撤销后,已撤销密钥下的所有签名都将变为无效。在Boneh等人的解决方案中。在USENIX'01,CA拥有一部分私有签名密钥,并为签名生成做出了贡献。撤销后,CA仅拒绝其参与交互式签名协议。因此,被撤销的用户将无法再生成有效的签名。我们扩展了该解决方案,使其涵盖了隐私,不受信任的设置和时间戳。我们提供了一个正式的定义框架,并从有效的标准构建块(例如数字签名,承诺和部分盲签名)中提供了优雅简单但可证明安全的实例。最后,我们提议扩展我们的计划。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号