More Efficient Digital Signatures with Tight Multi-user Security

被引:20
作者
Diemert, Denis [1 ]
Gellert, Kai [1 ]
Jager, Tibor [1 ]
Lyu, Lin [1 ]
机构
[1] Berg Univ Wuppertal, Wuppertal, Germany
来源
PUBLIC-KEY CRYPTOGRAPHY - PKC 2021, PT II | 2021年 / 12711卷
基金
欧洲研究理事会;
关键词
IDENTIFICATION; PROOFS;
D O I
10.1007/978-3-030-75248-4_1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We construct the currently most efficient signature schemes with tight multi-user security against adaptive corruptions. It is the first generic construction of such schemes, based on lossy identification schemes (Abdalla et al.; JoC 2016), and the first to achieve strong existential unforgeability. It also has significantly more compact signatures than the previously most efficient construction by Gjosteen and Jager (CRYPTO 2018). When instantiated based on the decisional Diffie-Hellman assumption, a signature consists of only three exponents. We propose a new variant of the generic construction of signatures from sequential OR-proofs by Abe, Ohkubo, and Suzuki (ASIACRYPT 2002) and Fischlin, Harasser, and Janson (EUROCRYPT 2020). In comparison to Fischlin et al., who focus on constructing signatures in the non-programmable random oracle model (NPROM), we aim to achieve tight security against adaptive corruptions, maximize efficiency, and to directly achieve strong existential unforgeability (also in the NPROM). This yields a slightly different construction and we use slightly different and additional properties of the lossy identification scheme. Signatures with tight multi-user security against adaptive corruptions are a commonly-used standard building block for tightly-secure authenticated key exchange protocols. We also show how our construction improves the efficiency of all existing tightly-secure AKE protocols.
引用
收藏
页码:1 / 31
页数:31
相关论文
共 37 条
[31]  
Kiltz E, 2010, LECT NOTES COMPUT SC, V6223, P295, DOI 10.1007/978-3-642-14623-7_16
[32]  
Krawczyk H, 2003, LECT NOTES COMPUT SC, V2729, P400
[33]   No-Match Attacks and Robust Partnering Definitions - Defining Trivial Attacks for Security Protocols is Not Trivial [J].
Li, Yong ;
Schaege, Sven .
CCS'17: PROCEEDINGS OF THE 2017 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2017, :1343-1360
[34]   Two-Pass Authenticated Key Exchange with Explicit Authentication and Tight Security [J].
Liu, Xiangyu ;
Liu, Shengli ;
Gu, Dawu ;
Weng, Jian .
ADVANCES IN CRYPTOLOGY - ASIACRYPT 2020, PT II, 2020, 12492 :785-814
[35]  
Paillier P, 2005, LECT NOTES COMPUT SC, V3788, P1
[36]  
SCHNORR CP, 1990, LECT NOTES COMPUT SC, V435, P239
[37]  
Seurin Y, 2012, LECT NOTES COMPUT SC, V7237, P554, DOI 10.1007/978-3-642-29011-4_33