网上分享。
Abstract
BilinearpairinghasrecentlybecomeallimportantconstrBc垃vetoolincryptography.Itiswidelyexploitedfordevisingcryptographicsystems
orpreviouslydifficultinthecontextoflargeintegerfaetodzationanddiserctelogarithmimproving
theexistingschemes.Thisthesis
paimg-basadgroupcryptosysemsfurtherinvestigatesinthisareaandfocuseson
withthefollowingmaincontributionsingroup
keyexchange.
seecqlresignature,groupdeeryptionandgroupWeproposeanextremelyshortgroupsignatureproveninthestandard
modal.Thesecurityproofsadoptastrongergroupsignaturedefinitionintheuniversallycomposablemodelsothattheproofsworknotonlywhensolyimplementedbutalsowhen
groupcomposedsignatureswithothersl∞ureprimitives.Comparedwiththestate-of-tho-artofwithoutrandomoracleswhichare
oneconstructedfrompairings.foramid-sealegroup,oursignature
signatureduetoinsizeisonlyfourteenthoftheBoyen-WatersschemeinEurocrypt2007,andabouthalfoftheveryrecemtrandom-oracle-freegroupAteniesecta1.,approximatelongasanormalRSAsignature.
groupdeeryptionandrealizethefirstWeintroducethenotionofimplementation
frompairings.Anonymityisoneofthemainconcernsingroupcryptography.However,mostefforts,forinstance,groupsignaturesandringsignatures,areonlymadetoprovideanonymityonthesender’spointofview.Thereisonlyfewworkdonetoensureanonymityinacryptographicsenseontherecipient’spointofview.Weandthreecryptographers,i.e.,Kiayias,TsiounisandYung,ind印eadentlyformalizesimiliarnotionsofgroupdeeryption/encryption,whichcanbeviewedasananalogofgroupsignatureinthecontextofencryptionswhere
anyasendercanencryptacommittedmessageintendedto
theeiphertext
withoutleakingtheplaintextortheidentityoftherecipient.Ifrequired,thegroupmanagercallverifiablyopentheidentityoftherecipient.Weproposeanefficientgroupdeeryptionschemethatisprovensecureintherandomoraclemodel.Theoverheadinmemberofagroup,managedbyagroupmanager,whiletherecipientofremainsanollymous.Thesendercanconvinceaverifieraboutthisfactbothcomputationandcommunicationisind印endentofthegroupsize.
Wepresentthefirstone-roundasymmctriegroupkeyexchangeprotoc01.WefirstrevisittheGKEdefinitionanddistinguishtheconventional(symmctri曲group
exploitingakeyaexchangefromasymmetricgroupkeyexchange(ASGr④)protocols,andproposegenericconstruction
primitivereferredofone.roundstaticASGKEsbyneweryptographicto嬲siguaturc-basadeacryptionofindependentinterest.Weinstantiateefficientsignature-basedencryptionandone-roundASGKEschemesrelyingonourshortsignatureconvertedfromtheE1Gamalecrypitoninthecontextofpairings.Signature-basedencryptioncanalsobeusedasascalablebroadcastorconferencekeydistributingscheme,whileone-roundASGKEcanbeusedabroadcastschemeinadhoesettingswithoutatrustedparty,whichaddressesthekey-escrowprobleminexistingbroadcastsystems.