节点文献

可证明安全公钥密码方案的设计与分析

Design and Analysis of Provably Secure Public Key Cryptosystems

【作者】 张乐友

【导师】 胡予濮;

【作者基本信息】 西安电子科技大学 , 应用数学, 2009, 博士

【摘要】 可证明安全理论本质上是一种公理化的研究方法,它将密码学方案的安全性规约为“好”的基础理论或“公理”:如某个基础密码算法或数学难题等,目前已成为现代密码学尤其是公钥密码学研究的主线.可证明安全不仅是一种证明方法,也是一种设计方案的方法,它们构成了本文的研究主线:既注重方案的设计,又注重方案的理论上的可证明安全性.本文内容涉及到了公钥加密、协议及数字签名,这也是目前公钥密码领域研究的热点,得到的主要结果如下:1.在标准模型下设计了基于分级身份的加密方案:第一个方案基于selective-identity安全模型,该方案具有公钥短、私钥计算量小的优点,且安全性被规约到一个一般的困难问题假设-判定性BDH假设;针对第一个方案中selective-identity模型是相对较弱的安全模型,基于推广的selective-identity安全模型中的Model one,设计了第二个方案,同时基于Model two,设计了改进方案,该方案的密文长度为常数,且私钥长度随着分级级数的增加而减小.这些方案在标准模型下都是可证明安全的. 2.设计了高效的广播加密方案:两个方案基于随机预言机模型,另外三个方案基于标准模型.基于随机预言机下方案具有较高的传输效率及较低的用户存储代价,适合资源受限的网络环境-ad hoc网络;其余的方案都是基于标准模型设计的,目前,这样的方案国内外出现的比较少,我们的第一个方案公钥短,密文长度为常数仅仅含有三个群元素,这是目前标准模型下基于身份的最有效的方案之一,另外两个方案也是为动态网络如ad hoc网设计的,具有较高的群钥生成效率.  3.设计了标准模型下的门限广播加密方案:具体提出了三个高效的方案.门限广播加密不同于传统的门限密码方案,它具有传统的门限密码不具有的优势:动态性,因而非常适合动态的网络环境如ad hoc网络.在方案I中我们首次提出了基于身份及标准模型的门限广播加密方案,随后针对密文与私钥长度依赖于用户规模的缺点,相继提出了更为有效的方案II、III,这三个方案在标准模型下都是可证明安全的. 4.设计了标准模型下的基于分级身份的签名方案:针对目前的基于分级身份的签名方案所依赖的困难问题太强,我们提出了三个方案,方案I基于CDH问题,此困难问题比已有(标准模型下)的方案所依赖的困难问题更具一般性,然而方案I的私钥长度与密文长度都依赖于分级身份的级数,为此我们提出了两个改进方案,它们共同的优点是私钥长度随着分级级数的增加而减小,而签名长度为常数,仅仅含有三个群元素.5.设计了标准模型下基于身份的门限签名方案:将目前具有代表性的Waters方案推广到基于身份的门限方案,然后为解决PKG的权利过大问题,基于Gennaro的分布式密钥生成协议又提出了一种改进方案.6.最后首次给出了一个有效的标准模型下基于身份的强不可伪造签名方案:先给出了一个一般的转化方案,它可将任何基于身份且具有模拟可分割性质的不可伪造方案转化为强不可伪造方案,基于该转化方案及Paterson签名方案,具体给出了一个强不可伪造签名方案.

【Abstract】 Provable security is essentially an axiomatic research method, in which the securityof cryptographic schemes is reduced to a“well-known”basic theory or“an axiom”, e.g.,some basic cryptographic algorithm or a number-theoretic assumption. Now it has alreadybecome an important theme of theoretical researches in modern cryptography, especiallyin the public key cryptography. Provable security is not only a method for proving thesecurity of the cryptographic schemes but also a method for constructing new schemes,which are also a theme of this dissertation. So our dissertation puts emphasis on boththe construction of public key cryptographic schemes and their security proof. The mainresults are specified as follows:1. New e?cient hierarchical identity-based encryption schemes are introduced in thestandard model. The first scheme is constructed in the selective-identity model. Ithas short ciphertexts and little computation at the phase of private keys generation.Furthermore, its security is reduced to the decision BDH assumption, which is morenatural than those in the available schemes. Based on the model 1 in the generalizedselective-identity model, the second scheme is obtained. Finally, we proposed themodified scheme of the second scheme. It achieves constant-size ciphertexts andprivate keys in this scheme shrink as the identity depth increases. It is worth notingthat the proposed schemes are constructed in the standard model.2. We propose some e?cient broadcast encryption schemes for ad hoc networks. Twoschemes are constructed under the random oracle model, the others are constructedunder the standard model. The schemes under the random oracles have short trans-missions and achieve low cost of users storage, which are important for a mobile adhoc network. To the best of our knowledge, very few works have dealt with theconstruction in the standard model. So the others are constructed in the standardmodel. The first scheme in the standard model is one of the most e?cient con-structions at present, which has short PKs and achieves constant-size ciphertextsas it consists of three group elements. Finally, we propose two broadcast encryp-tion protocols in the standard model, which are e?cient at the phase of group keysgeneration.3. Three efficient threshold broadcast encryption schemes are proposed. The thresholdbroadcast encryption is a dynamic threshold encryption, which is different withgeneral threshold encryption and especially useful in the mobile ad hoc networks.We first propose an identity-based threshold broadcast encryption in the standard model. However, the size of cipertexts and private keys relies on the numbers ofusers. Therefore, two e?cient modified schemes are introduced at last. It is worthnoting that three schemes are provable security without using random oracles.4. We construct three e?cient hierarchical identity-based signature schemes. Our pro-posed schemes are natural extensions of the existing schemes since their security isbased on the strong assumption or non-standard cryptographic assumption. Thefirst scheme is constructed under the CDH assumption. This assumption is morenatural than those in the available schemes. However, the size of private keys andciphertexts increases as the depth of identity increases. So two modified schemesare proposed. Both schemes achieve constant-size ciphertexts which consist of threegroup elements. Furthermore, their private keys shrinks as the identity depth in-creases.5. Two threshold signature schemes are presented. The first one is based on the Wa-ters’s scheme and involves a PKG. The other is based on the Gennaro’s distributedkey generation protocol.6. Finally, we first propose a strongly unforgeable signature. A transformation is pro-posed at first. It can convert any existentially unforgeable ID-Based signature whichis simulative-partitioned to a strongly unforgeable signature. Then based on Pater-son’s scheme, a concrete construction of the strongly unforgeable ID-Based signatureis introduced in the standard model.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络