节点文献
属性基服务器辅助签名方案研究
Research on Attribute-based Server-aided Signature Schemes
【作者】 陈宇;
【导师】 李继国;
【作者基本信息】 福建师范大学 , 应用数学, 2021, 硕士
【摘要】 近年来,随着物联网设备爆发式增加,物联网将不断影响人们生活和生产的各个方面。因此,物联网设备间数据的访问和认证成为密码与信息安全领域富有挑战的热点课题。传统的数字签名能够提供数据的认证性,但无法提供物联网设备间的访问控制来保护用户的隐私。属性基签名是最近提出的新型密码原语,不仅提供了数据的认证,而且也支持访问控制来保证用户的匿名性,对其进行研究不仅具有重要的理论意义而且具有广泛应用价值。属性基签名允许用户的属性满足访问策略从而进行消息的签署,签名不会泄露用户的身份,因此适用于隐私保护的场景。现有属性基签名方案大都存在计算效率和密钥托管问题,一方面,签名的计算开销随着用户属性数量的增长呈线性增长,因此对物联网中资源受限设备的使用提出了挑战。另一方面,在属性基签名中,签名的私钥是由属性授权方生成,属性授权方可以代替用户进行消息的签署生成有效的签名。如果属性授权方腐败,则签名将会被伪造,因此存在密钥托管的问题。针对上述问题,本文提出了两个服务器辅助的属性基签名方案来提高计算效率和减轻密钥托管问题。论文的主要工作如下:(1)为了支持灵活的访问控制,运用属性树作为访问策略来支持大规模用户的细粒度访问控制。同时,通过一个服务器进行大量的指数运算和配对运算来减少计算开销。为此,提出了一个高效的属性基服务辅助验证签名方案。基于Computation Diffie-Hellman(CDH)问题困难性假设,在标准模型下证明提出的方案是自适应选择策略安全的。仿真实验结果表明该方案适用于资源受限的设备。(2)现有的属性基签名方案大多基于单个属性授权方来生成和颁发用户的属性私钥。如果属性授权方腐败,用户的签名将会被伪造,属性基密码体制存在固有的密钥托管问题。为了降低单个授权方权限,运用了分布式多授权方与用户进行交互生成私钥。每一个授权方为用户颁发部分私钥,只有当N个授权方同时颁发给用户私钥时,用户才能生成有效的签名。简而言之,只有当N个授权方合谋才能生成私钥伪造签名。因此,分布式属性基签名方案可以抵抗N-1个腐败的属性授权方,减轻密钥托管问题。为了提高分布式属性签名方案中签名算法和验证算法的计算效率,引入一个服务器来降低两阶段的计算开销。为此,提出一个分布式的属性基服务器辅助的签名方案。基于Computation co-Diffie-Hellman(co-CDH)问题困难性假设,在随机预言模型下证明提出的方案是自适应选择策略安全的,仿真实验结果表明该方案计算开销低,在资源受限的物联网设备中具有潜在应用。
【Abstract】 In recent years,with the explosive increase of Internet of Things(IoT)devices,IoT affects all aspects of people’s life and production continuously.Therefore,data access and authentication of IoT devices have become a popular and challenging topic in the field of cryptography and information security.The traditional digital signature only provides data authentication and does not provide access control to protect the signer’ privacy in IoT.Attribute-based signature(ABS),which is recently proposed a novel cryptographic primitive,not only provides data authentication,but also supports access control to guarantee users’ anonymity.The research not only has important theoretical significance,but also wide application value.In ABS,the user generates a valid signature if his/her attributes satisfy the access policy,where the signature does not reveal the identity of the user.Therefore,it is suitable for scenarios requiring privacy protection.However,most of the existing ABS schemes have computational efficiency and key escrow problems.On the one hand,as the users’ attributes increase linearly,the computational overhead of signature will also increase in signature.It’s a challenge for resource-constrained devices in IoT.On the other hand,in ABS,an attribute authority generates users’ private key and signs the message instead of the legal user to create a valid signature.If the attribute authority is corrupt,the signature will be forged.It is named key escrow problem.In order to solve the above problems,we propose two attribute based server-aided signature schemes to improve computational efficiency and mitigate key escrow problem.The main contribution of this paper is summarized as follows.(1)In order to support flexible access control,we utilize the attribute tree as the access policy to support the fine-grained access control of large-scale users.Meanwhile,to reduce the computation overhead of exponentiation and pairing operations,we introduce a server to execute the heavy computation overhead.Therefore,we propose an efficient attribute-based server-aided verification signature scheme.The proposed scheme is proven secure in the standard model.The security of proposed scheme is reduced to the Computational Diffie-Hellman(CDH)assumption.The experimental result shows that the proposed scheme is suitable for the resource-limited devices.(2)Most of the existing ABS schemes are based on single attribute authority,which generate and issue the user’s attribute private key.If the attribute authority is corrupted,the signature will be forged.It’s an inherent key escrow problem for attribute based crypto-system.In order to reduce the power of the single attribute authority,we apply decentralized attribute authorities to generate private keys with the user.Every attribute authority generates partial private key for the user.The user will generate the valid signature only if N attribute authorities issue the private key together for him/her.In short,only when N attribute authorities conspire,they will generate private keys to forge valid signature.The proposed scheme can resist N-1 corrupted attribute authorities.Therefore,we reduce the key escrow problem.For the sake of reducing the computation overhead of signature and verification algorithms,we use the server to execute the larger computation overheads for the signer and verifier.Therefore,we present decentralized server-aided ABS scheme.The security of proposed scheme is reduced to the Computational co-Diffie-Hellman(CDH)assumption and is adaptive selective-policy security in the random oracle model.The experiment result shows that the scheme is efficient and suits the resource-constrained devices in IoT.
【Key words】 Access control; server-aided technology; decentralized attribute authorities; adaptive security;
- 【网络出版投稿人】 福建师范大学 【网络出版年期】2024年 06期
- 【分类号】TN918.4