检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:张文芳[1,2] 熊丹[1,3] 王小敏[1] 陈桢[1,2] 刘旭东[1,2]
机构地区:[1]西南交通大学信息科学与技术学院,成都610031 [2]西南交通大学信息安全与国家计算网格四川省重点实验室,成都610031 [3]中国电子科技网络信息安全有限公司,成都200233
出 处:《计算机学报》2017年第5期1168-1180,共13页Chinese Journal of Computers
基 金:国家自然科学基金(61003245;61371098);四川省科技厅应用基础研究基金(2015JY0182);中央高校基本科研业务费专项基金(SWJTU11CX041)资助~~
摘 要:环签名因其无条件匿名性、自发性和灵活的群结构被广泛应用于电子现金、电子投票等强匿名认证领域.其中,关联环签名可以在不泄露真实签名者身份的前提下证明两个签名是否由同一人签发,因此可以在保障匿名性的前提下避免签名权滥用,如重复投票、电子现金重复花费等问题.然而,已有关联环签名的安全性大多数建立在离散对数困难问题基础上,且绝大多数方案因强关联性导致匿名性退化.为了克服上述问题,该文提出一个基于大整数分解难题和RSA公钥密码体制的可选择关联可转换环签名方案,并给出该类环签名的形式化安全模型.通过选择随机参数生成关联标签的方式,使得所提方案不仅具备强匿名性,而且环签名的关联性可由签名者自主决定.此外,签名者可以在不公开秘密随机参数的前提下将环签名转换为普通数字签名,能够抵抗可转换性攻击.在随机预言机模型下可证明该方案在适应性选择消息和选择公钥攻击下是存在性不可伪造的.此外,性能分析表明,该文方案与同类方案相比具有较高的运行效率.Ring signatures are widely used in strong anonymous athentication environments such as electronic cash and electronic voting,because of their unconditional anonymity,spontaneity and flexible group structures.However,for some special purpose,we should discriminate if two signatures are signed by the same signer.For example,we should distinguish if a voter has cast mutiple ballots and the same e-cash has been repeatedly consumed.To solve the above mentiond problems,linkable ring signatures were proposed,by which any two signatures generated by the same person can be detected,with the premise of not disclosing the indentity of the real signer.However,most of the existing linkable ring signature schemes are based on discrete logarithm public key cryptosystems,and the vast majority of schemes only have the characteristics of weak anonymity and strong linkability.In this paper,a selectively linkable and convertible ring signature based on RSA public key cryptosystem was proposed,and a formal security model ofthis kind of ring signature was presented.The scheme is proven to be unconditionally anonymous,and the linkability of the signature can be decided by the signer through selecting random parameters to generate the linkable tag.Besides,in necessary occasions,the signer can convert the ring signature into an ordinary digital signature on the premise of not revealing secret parameters,so that he can prove himself as the real signer.It is proven that the proposed scheme can resist the convertable attack and is existentially unforgeable against the adaptive chosen plaintext attack and the chosen public-key attack under the random oracle model.Finally,the performance analysis shows that the proposed scheme has high operating efficiency.
关 键 词:RSA公钥密码体制 环签名 选择关联性 强匿名性 可转换性
分 类 号:TP309[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.148.247.50