首页> 外文会议>Symposium on Chemistry as a second language >Dynamic Fully Forward-Secure Group Signatures
【24h】

Dynamic Fully Forward-Secure Group Signatures

机译:动态完全前向安全组签名

获取原文

摘要

Enhancing user privacy while allowing the use of digital cre dentials in network-wide applications is a very active area. Group signatures are primary privacy-preserving credentials that enable both, non-repudiation and abuser-tracing. When embedding cryptographic tools in actual computing systems, it is important to ensure physical layer protection to cryptographic keys. A simple risk analysis shows that taking advantage of system (i.e., hardware, software, net work) vulnerabilities is usually much easier than cryptan alyzing the cryptographic primitives themselves. Forward secure cryptosystems, in turn, are one of the suggested pro tective measures, where private keys periodically evolve in such a way that, if a break-in occurs, past uses of those keys in earlier periods are protected. At CCS 2001, Song argued why key exposures may cause even more important concerns in the context of group sig natures (namely, under the mask of anonymity within a group of other key holders). She then gave two examples of forward-secure group signatures, and argued their ad hoc properties based on the state of understanding of group signature security properties at that time (proper security models had not been formalized yet). These implementa tions are fruitful initial efforts, but still suffer from certain imperfections. In the first scheme for instance, forward se curity is only guaranteed to signers as long as the group manager's private key is safe. Another scheme recently de scribed by Nakanishi et al. for static groups also fails to maintain security when the group manager is compromised. In this paper, we reconsider the subject and first formal ize the notion of "fully forward-secure group signature" (FS GS) in dynamic groups. We carefully define the correctness and security properties that such a scheme ought to have. We then give a realization of the primitive with quite at tractive features: constant-size signatures, constant cost of signing/verifying, and at most polylog complexity of other metrics. The scheme is further proven secure in the standard model (no random oracle idealization is used).
机译:增强用户隐私,同时允许在网络范围内使用数字CRE推导是一个非常有源区域。组签名是主要隐私保留凭据,其启用不拒绝和滥用滥用追溯。在实际计算系统中嵌入加密工具时,重要的是确保对加密密钥的物理层保护。一个简单的风险分析表明,利用系统(即硬件,软件,网络工作)漏洞通常比Cryptan alyzing本身更容易。反过来,转发安全密码系统是建议的Pro细胞措施之一,其中私钥以这样的方式经过定期发展,即如果发生突破,则在早期的时间内使用这些键的过去使用。在CCS 2001,歌曲争论为什么密钥曝光可能在组SIG自然的上下文中导致更重要的问题(即,在一组其他关键持有人的匿名掩码下)。然后,她给出了两个前向安全组签名的示例,并基于对该时间的组签名安全性属性的理解状态(正确的安全模型尚未正式化)争论其临时属性。这些实现是富有成效的初步努力,但仍然遭受某些不完美的侵害。例如,在第一种方案中,只要组经理的私钥是安全的,只能保证转发SE强度。另一个方案最近由Nakanishi等人描绘。对于静态组,当组经理受到损害时,还无法维护安全性。在本文中,我们重新考虑了主题,并首先正式Ize在动态组中的“完全前向安全组签名”(FS GS)的概念。我们仔细定义了这样一个方案的正确性和安全性质。然后,我们在牵引力的情况下实现了原始的原语:常量尺寸签名,签名/验证的不断成本,以及其他度量的大多数Polylog复杂性。该方案在标准模型中进一步证明了安全的安全(没有使用随机的Oracle理想化)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号