论文标题
改进了基于Camenisch- lysyanskaya的安全性证明基于签名的同步总签名方案
Improved Security Proof for the Camenisch-Lysyanskaya Signature-Based Synchronized Aggregate Signature Scheme
论文作者
论文摘要
Crypto 2004中的Camenisch-Lysyanskaya签名计划是一个有用的构建块,用于构建隐私保护方案,例如匿名凭证,团体签名或戒指签名。但是,此签名方案的安全性取决于称为LRSW假设的交互式假设。即使在通用组模型或双线性组模型中证明了交互式假设,对这些假设的担忧也会在加密社区中产生。这一事实造成了使用安全方案的障碍,其安全性依赖于这些假设。最近,Pointcheval和Sanders在CT-RSA 2018中提出了修改的Camenisch-Lysyanskaya签名方案。该方案在新的Q-Type假设下满足了EUF-CMA安全性,称为“修改后的Q-strong diffie-hellman-2(q-MSDH-2)”假设。但是,Q型假设的大小动态增长,这一事实导致方案效率低下。在这项工作中,我们在FC 2013中重新访问Camenisch-Lysyanskaya基于同步的聚合签名方案。该方案是与双线性组最有效的最有效的同步聚合签名方案之一。但是,在随机Oracle模型中的一次性LRSW假设下证明了该同步聚合方案的安全性。我们在随机Oracle模型中的1-MSDH-2(静态)假设下为这种同步聚合方案提供了新的安全性证明,而效率却很少。
The Camenisch-Lysyanskaya signature scheme in CRYPTO 2004 is a useful building block to construct privacy-preserving schemes such as anonymous credentials, group signatures or ring signatures. However, the security of this signature scheme relies on the interactive assumption called the LRSW assumption. Even if the interactive assumptions are proven in the generic group model or bilinear group model, the concerns about these assumptions arise in a cryptographic community. This fact caused a barrier to the use of cryptographic schemes whose security relies on these assumptions. Recently, Pointcheval and Sanders proposed the modified Camenisch-Lysyanskaya signature scheme in CT-RSA 2018. This scheme satisfies the EUF-CMA security under the new q-type assumption called the Modified-q-Strong Diffie-Hellman-2 (q-MSDH-2) assumption. However, the size of a q- type assumptions grows dynamically and this fact leads to inefficiency of schemes. In this work, we revisit the Camenisch-Lysyanskaya signature-based synchronized aggregate signature scheme in FC 2013. This scheme is one of the most efficient synchronized aggregate signature schemes with bilinear groups. However, the security of this synchronized aggregate scheme was proven under the one-time LRSW assumption in the random oracle model. We give the new security proof for this synchronized aggregate scheme under the 1-MSDH-2 (static) assumption in the random oracle model with little loss of efficiency.