首页> 外文会议>Cryptographers' track at the RSA conference >Group Signatures with Message-Dependent Opening in the Standard Model
【24h】

Group Signatures with Message-Dependent Opening in the Standard Model

机译:在标准模型中具有与消息相关的打开的组签名

获取原文

摘要

Group signatures allow members of a group to anonymously sign messages in the name of this group. They typically involve an opening authority that can identify the origin of any signature if the need arises. In some applications, such a tracing capability can be excessively strong and it seems desirable to restrict the power of the authority. Sakai et al. recently suggested the notion of group signatures with message-dependent opening (GS-MDO), where the opening operation is made contingent on the knowledge of a trapdoor information - generated by a second authority - associated with the message. Sakai et al. showed that their primitive implies identity-based encryption (IBE). In the standard model, efficiently constructing such a system thus requires a structure-preserving IBE scheme, where the plaintext space is the source group G (rather than the target group G_T) of a bilinear map e:G×G→ G_T. Sakai et al. used a structure-preserving IBE which only provides bounded collusion-resistance. As a result, their GS-MDO construction only provides a weak form of anonymity where the maximal number of trapdoor queries is determined by the length of the group public key. In this paper, we construct the first fully collusion-resistant IBE scheme that encrypts messages in G. Using this construction, we obtain a GS-MDO system with logarithmic signature size (in the number N of group members) and prove its security in the standard model under simple assumptions.
机译:组签名允许组成员以该组的名称匿名签名邮件。它们通常涉及开放机构,如果需要,可以识别任何签名的来源。在某些应用中,这种跟踪能力可能过强,并且似乎希望限制授权机构的权力。酒井等。最近,有人提出了具有消息依赖的打开方式(GS-MDO)的组签名的概念,其中,打开操作取决于对与该消息相关联的第二权限生成的活板门信息的了解。酒井等。表明它们的原语暗示了基于身份的加密(IBE)。因此,在标准模型中,有效地构建这样的系统需要保留结构的IBE方案,其中明文空间是双线性映射e:G×G→G_T的源组G(而不是目标组G_T)。酒井等。使用保留结构的IBE,该结构仅提供有限的抗串扰性。结果,它们的GS-MDO构造仅提供了一种较弱的匿名形式,其中陷门查询的最大数量由组公共密钥的长度确定。在本文中,我们构造了第一个完全抗串通的IBE方案,该方案对G中的消息进行加密。使用这种构造,我们获得了具有对数签名大小(在组成员的数量N中)的GS-MDO系统,并证明了其安全性。简单假设下的标准模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号