引用本文:陈伟东,冯登国,谭作文.指定验证方的门限验证签名方案及安全性证明.软件学报,2005,16(11):1967-1974
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 5920次   下载 6268 本文二维码信息
码上扫一扫!
分享到: 微信 更多
指定验证方的门限验证签名方案及安全性证明
陈伟东1,2, 冯登国3, 谭作文4
1.信息安全国家重点实验室(中国科学院,研究生院),北京,100049;2.中国科学院,电子学研究所,北京,100080;3.信息安全国家重点实验室(中国科学院,软件研究所),北京,100080;4.中国科学院,数学与系统科学研究院,系统科学研究所,北京,100080
摘要:
Laih提出了指定验证方的签名方案设计问题,并给出一种解决方案.首先分析指出该方案存在严重安全缺陷,然后提出了签名方案SV-EDL,解决了如上密码学问题.同时,把可证明安全理论引入这类方案的分析设计,并在RO(random oracle)模型中证明:SV-EDL的抗伪造安全性和计算Diffie-Hellman(computationalDiffie-Hellman,简称CDH)问题紧密关联,亦即伪造SV-EDL签名几乎和解决CDH问题一样困难;除指定方以外,任何人验证签名的能力都与决策Diffie-Hellman(decisionalDiffie-Hellman,简称DDH)问题密切相关.由于CDH问题和DDH问题的困难性与离散对数(discretelogarithm,简称DL)问题紧密相关已成为广泛共识,因此与当前同类方案比较,该签名方案提供了更好的安全性保证.此外,上述签名方案还以非常简明、直接的方式满足不可否认要求.最后提出并构造了验证服务器系统的门限验证协议,并在标准模型中给出了安全性证明.该方案不要求可信中心的存在.
关键词:  数字签名方案  可证明安全性  计算Diffie-Hellman(CDH)假设  决策Diffie-Hellman(DDH)假设  随机预言模型
DOI:
分类号:
基金项目:Supported by the National Natural Science Foundation of China under Grant No.60253027 (国家自然科学基金); the National Grand Fundamental Research 973 Program of China under Grant No. G1999035802 (国家重点基础研究发展规划(973))
Signature Scheme for Specified Threshold Verifiers and Security Proofs
CHEN Wei-Dong,FENG Deng-Guo,TAN Zuo-Wen
Abstract:
The problem called “constructing signature schemes for specified verifiers” is proposed by Laih, and such a scheme is also given by Laih. It is shown that this scheme is not secure and a scheme called SV-EDL is put forward. Furthermore, the provable security theory is used to analyze such schemes, i.e. the security of SV-EDL scheme is proved in RO (random oracle) model. The security against forgery is tightly related to the Computational Diffie-Hellman problem, i.e. the forgery is almost as difficult as solving CDH (computational Diffie-Hellman) problem. Especially, for anyone except the specified verifiers, the ability of verifying signature is tightly related to DDH (decisional Diffie-Hellman) problem. Since the hardness of the CDH and DDH problem is widely believed to be closely related to the hardness of the DL (discrete logarithm) problem, the scheme offers better security guarantees than the existing schemes. In addition, it offers non-repudiation in a very straight-forward manner. Finally, the concept of threshold verification is proposed and a (t,m)-threshold verification protocol is constructed, and its security is proved in the standard model. Especially, the scheme does not ask for the existence of the trusted center.
Key words:  signature scheme  provable security  computational Diffie-Hellman assumption  decisional Diffie-Hellman assumption  random oracle model

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: