講演抄録/キーワード |
講演名 |
2012-09-21 14:35
[招待講演]損失認証法に基づいた緊密安全性をもつ署名 ミシェル アブダラ・ピエールアラン フーク・ヴァディム リュバシェフスキー(ENS)・○メディ ティブシ(NTT) ISEC2012-51 |
抄録 |
(和) |
The Fiat-Shamir heuristic is a well-known technique for converting commitment-challenge-response identification schemes to signature schemes that can be proved secure in the random oracle model. One limitation of this approach, however, is that the security reduction of the signature scheme involves rewinding, and hence incurs a large polynomial loss.
To alleviate this problem, we introduce the stronger notion of "lossy identification scheme", and prove that there exists a Fiat-Shamir-like black-box transformation from such a scheme to a secure signature scheme (in the random oracle model) without rewinding. We use this transformation to obtain several tightly-secure signature schemes based on various decisional assumptions: short discrete logarithms, learning with errors, and random subset sums. |
(英) |
The Fiat-Shamir heuristic is a well-known technique for converting commitment-challenge-response identification schemes to signature schemes that can be proved secure in the random oracle model. One limitation of this approach, however, is that the security reduction of the signature scheme involves rewinding, and hence incurs a large polynomial loss.
To alleviate this problem, we introduce the stronger notion of "lossy identification scheme", and prove that there exists a Fiat-Shamir-like black-box transformation from such a scheme to a secure signature scheme (in the random oracle model) without rewinding. We use this transformation to obtain several tightly-secure signature schemes based on various decisional assumptions: short discrete logarithms, learning with errors, and random subset sums. |
キーワード |
(和) |
/ / / / / / / |
(英) |
Signature schemes / Tight reduction / Fiat-Shamir / Identification schemes / Lossiness / / / |
文献情報 |
信学技報, vol. 112, no. 211, ISEC2012-51, pp. 39-39, 2012年9月. |
資料番号 |
ISEC2012-51 |
発行日 |
2012-09-14 (ISEC) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
PDFダウンロード |
ISEC2012-51 |
|