首页> 外文会议>International conference on financial cryptography and data security >Minimizing Trust in Hardware Wallets with Two Factor Signatures
【24h】

Minimizing Trust in Hardware Wallets with Two Factor Signatures

机译:通过两个要素签名最大程度地减少对硬件钱包的信任

获取原文

摘要

We introduce the notion of two-factor signatures (2FS), a generalization of a two-out-of-two threshold signature scheme in which one of the parties is a hardware token which can store a high-entropy secret, and the other party is a human who knows a low-entropy password. The security (unforgeability) property of 2FS requires that an external adversary corrupting either party (the token or the computer the human is using) cannot forge a signature. This primitive is useful in contexts like hardware cryptocurrency wallets in which a signature conveys the authorization of a transaction. By the above security property, a hardware wallet implementing a two-factor signature scheme is secure against attacks mounted by a malicious hardware vendor; in contrast, all currently used wallet systems break under such an attack (and as such are not secure under our definition). We construct efficient provably-secure 2PS schemes which produce either Schnorr signature (assuming the DLOG assumption), or EC-DSA signatures (assuming security of EC-DSA and the CDH assumption) in the Random Oracle Model, and evaluate the performance of implementations of them. Our EC-DSA based 2FS scheme can directly replace currently used hardware wallets for Bitcoin and other major cryptocurrencies to enable security against malicious hardware vendors.
机译:我们介绍了两因素签名(2FS)的概念,是二选一阈值签名方案的概括,其中一方是可以存储高熵秘密的硬件令牌,另一方是是知道低熵密码的人。 2FS的安全性(不可伪造性)属性要求破坏任何一方(令牌或人类正在使用的计算机)的外部对手都不能伪造签名。此原语在诸如硬件加密货币钱包之类的上下文中很有用,在该上下文中,签名传达了交易的授权。通过上述安全属性,实施两因素签名方案的硬件钱包可抵御恶意硬件供应商发起的攻击;相反,当前使用的所有钱包系统都会受到这种攻击(因此在我们的定义下并不安全)。我们构建有效的可证明安全的2PS方案,该方案在随机Oracle模型中产生Schnorr签名(假设DLOG假设)或EC-DSA签名(假设EC-DSA和CDH假设的安全性),并评估他们。我们基于EC-DSA的2FS方案可以直接替代比特币和其他主要加密货币的当前使用的硬件钱包,以实现针对恶意硬件供应商的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号