基于RSA公钥密码体制的可选择可转换关联环签名  被引量:9

Selectively Linkable and Convertible Ring Signature Based on RSA Public Key Cryptosystem

在线阅读下载全文

作  者:张文芳[1,2] 熊丹[1,3] 王小敏[1] 陈桢[1,2] 刘旭东[1,2] 

机构地区:[1]西南交通大学信息科学与技术学院,成都610031 [2]西南交通大学信息安全与国家计算网格四川省重点实验室,成都610031 [3]中国电子科技网络信息安全有限公司,成都200233

出  处:《计算机学报》2017年第5期1168-1180,共13页Chinese Journal of Computers

基  金:国家自然科学基金(61003245;61371098);四川省科技厅应用基础研究基金(2015JY0182);中央高校基本科研业务费专项基金(SWJTU11CX041)资助~~

摘  要:环签名因其无条件匿名性、自发性和灵活的群结构被广泛应用于电子现金、电子投票等强匿名认证领域.其中,关联环签名可以在不泄露真实签名者身份的前提下证明两个签名是否由同一人签发,因此可以在保障匿名性的前提下避免签名权滥用,如重复投票、电子现金重复花费等问题.然而,已有关联环签名的安全性大多数建立在离散对数困难问题基础上,且绝大多数方案因强关联性导致匿名性退化.为了克服上述问题,该文提出一个基于大整数分解难题和RSA公钥密码体制的可选择关联可转换环签名方案,并给出该类环签名的形式化安全模型.通过选择随机参数生成关联标签的方式,使得所提方案不仅具备强匿名性,而且环签名的关联性可由签名者自主决定.此外,签名者可以在不公开秘密随机参数的前提下将环签名转换为普通数字签名,能够抵抗可转换性攻击.在随机预言机模型下可证明该方案在适应性选择消息和选择公钥攻击下是存在性不可伪造的.此外,性能分析表明,该文方案与同类方案相比具有较高的运行效率.Ring signatures are widely used in strong anonymous athentication environments such as electronic cash and electronic voting,because of their unconditional anonymity,spontaneity and flexible group structures.However,for some special purpose,we should discriminate if two signatures are signed by the same signer.For example,we should distinguish if a voter has cast mutiple ballots and the same e-cash has been repeatedly consumed.To solve the above mentiond problems,linkable ring signatures were proposed,by which any two signatures generated by the same person can be detected,with the premise of not disclosing the indentity of the real signer.However,most of the existing linkable ring signature schemes are based on discrete logarithm public key cryptosystems,and the vast majority of schemes only have the characteristics of weak anonymity and strong linkability.In this paper,a selectively linkable and convertible ring signature based on RSA public key cryptosystem was proposed,and a formal security model ofthis kind of ring signature was presented.The scheme is proven to be unconditionally anonymous,and the linkability of the signature can be decided by the signer through selecting random parameters to generate the linkable tag.Besides,in necessary occasions,the signer can convert the ring signature into an ordinary digital signature on the premise of not revealing secret parameters,so that he can prove himself as the real signer.It is proven that the proposed scheme can resist the convertable attack and is existentially unforgeable against the adaptive chosen plaintext attack and the chosen public-key attack under the random oracle model.Finally,the performance analysis shows that the proposed scheme has high operating efficiency.

关 键 词:RSA公钥密码体制 环签名 选择关联性 强匿名性 可转换性 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象