Signature Schemes with Efficient Protocols and Dynamic Group Signatures from Lattice Assumptions - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

Signature Schemes with Efficient Protocols and Dynamic Group Signatures from Lattice Assumptions

Résumé

A recent line of works – initiated by Gordon, Katz and Vaikuntanathan (Asiacrypt 2010) – gave lattice-based realizations of privacy-preserving protocols allowing users to authenticate while remaining hidden in a crowd. Despite five years of efforts, known constructions remain limited to static populations of users, which cannot be dynamically updated. For example, none of the existing lattice-based group signatures seems easily extendable to the more realistic setting of dynamic groups. This work provides new tools enabling the design of anonymous authen-tication systems whereby new users can register and obtain credentials at any time. Our first contribution is a signature scheme with efficient protocols, which allows users to obtain a signature on a committed value and subsequently prove knowledge of a signature on a committed message. This construction, which builds on the lattice-based signature of Böhl et al. (Eurocrypt'13), is well-suited to the design of anonymous credentials and dynamic group signatures. As a second technical contribution, we provide a simple, round-optimal joining mechanism for introducing new members in a group. This mechanism consists of zero-knowledge arguments allowing registered group members to prove knowledge of a secret short vector of which the corresponding public syndrome was certified by the group manager. This method provides similar advantages to those of structure-preserving signatures in the realm of bilinear groups. Namely, it allows group members to generate their public key on their own without having to prove knowledge of the underlying secret key. This results in a two-round join protocol supporting concurrent enrollments, which can be used in other settings such as group encryption.
Fichier principal
Vignette du fichier
dynamic-lgsig-even-simpler.pdf (843.83 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01267123 , version 1 (03-02-2016)

Identifiants

  • HAL Id : hal-01267123 , version 1

Citer

Benoît Libert, San Ling, Fabrice Mouhartem, Khoa Nguyen, Huaxiong Wang. Signature Schemes with Efficient Protocols and Dynamic Group Signatures from Lattice Assumptions. Asiacrypt 2016, IACR, Dec 2016, Hanoi, Vietnam. ⟨hal-01267123⟩
222 Consultations
550 Téléchargements

Partager

Gmail Facebook X LinkedIn More