|
ABSTRACT
A group signature scheme allows a group member to sign messages anonymously on behalf of the group, while in case of a dispute, a designated entity can reveal the identity of a signature's originator. Group signature schemes can be used as a basic building block for many security applications such as electronic banking systems and electronic voting. Two important issues -- forward security and efficient revocation -- have not been addressed by prior schemes. We construct the first forward-secure group signature schemes. While satisfying all the security properties proposed in previous group signature schemes, our schemes provide a new desired security property, forward-security: while the group public key stays fixed, a group signing key of a group member evolves over time such that compromise of a group signing key of the current time period does not enable an attacker to forge group signatures pertaining to the past time periods. Such forward-security is important to mitigate the damage caused by key exposure and particularly desirable for group signature schemes because the risk of signing key exposure escalates as the size of the group increases. Our schemes are provably secure in the random oracle model and under the strong RSA and decisional Diffie Hellman assumptions.Furthermore, we extend our forward-secure group signature scheme to provide a solution for the problem of group member exclusion without the need to re-key all other group members. When a group member is excluded, he should not be able to generate valid signatures any more and yet his previous signatures remain anonymous. We provide the first solutions which support both retroactive public revocation and backward unlinkability and the signature size is independent of the number of revoked members.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
Ross Anderson.Invited Lecture,4th ACM Computer and Communications Security,1997.
|
| |
3
|
|
| |
4
|
|
| |
5
|
N.Baric and B.P .tzman.Collision-free accumulators and fail-stopsignature schemes without trees.In Advances in Cryptology - EUROCRYPT 1997 pages 480 -494. Springer-Verlag,1997.Lecture Notes in Computer Science Volume 1233.
|
| |
6
|
|
| |
7
|
|
| |
8
|
F.Boudot.E .cient proofs that committed number lies in an interval.In B.Preneel,editor,Advances in Cryptology - EUROCRYPT 2000 pages 431 -444,Berlin, 2000.Springer-Verlag.Lecture Notes in Computer Science Volume 1807.
|
| |
9
|
|
| |
10
|
|
| |
11
|
|
| |
12
|
|
| |
13
|
|
| |
14
|
|
| |
15
|
D.Chaum,J.H.Evertse,and J.van de Graaf.An improved protocol for demonstrating possession of discrete logarithms nd some generalizations.In D vid Chaum nd Wyn L.Price,editors,Advances in Cryptology - EuroCrypt '87 pages 127 -142,Berlin,1987.Springer-Verlag.Lecture Notes in Computer Science Volume 304.
|
| |
16
|
D.Chaum nd E.v n Heyst.Groupsignatures.In Donald W.Davies,editor,Advances in Cryptology -EuroCrypt '91 pages 257 -265,Berlin,1991. Springer-Verlag.Lecture Notes in Computer Science Volume 547.
|
| |
17
|
|
| |
18
|
L.Chen and T.P.Pedersen.New groupsignature schemes. In Alfredo De Santis,editor,Advances in Cryptology -EuroCrypt '94 pages 171 -181,Berlin,1995. Springer-Verlag.Lecture Notes in Computer Science Volume 950.
|
| |
19
|
I.Damgard.E .cient concurrent zero-knowledge in the auxiliary string model.In B.Preneel,editor,Advances in Cryptology - EUROCRYPT 2000 pages 431 -444,Berlin, 2000.Springer-Verlag.Lecture Notes in Computer Science Volume 1807.
|
| |
20
|
W.Difie and M.E.Hellman.New directions in cryptography.IEEE Transactions on Information Theory 6(IT-22):644 -654,1976.
|
| |
21
|
|
| |
22
|
|
| |
23
|
|
| |
24
|
|
| |
25
|
|
 |
26
|
|
| |
27
|
|
| |
28
|
Chanathip Namprempre Michel Abdalla,Sara Miner. Forward security in threshold signature schemes.In RSA 2001 2001.
|
| |
29
|
|
CITED BY 13
|
|
|
|
|
Eric Cronin , Sugih Jamin , Tal Malkin , Patrick McDaniel, On the performance, feasibility, and use of forward-secure signatures, Proceedings of the 10th ACM conference on Computer and communications security, October 27-30, 2003, Washington D.C., USA
|
|
|
|
|
|
|
|
|
Arindam Mitra , Ranganath Udupa , Muthucumaru Maheswaran, A secured hierarchical trust management framework for public computing utilities, Proceedings of the 2005 conference of the Centre for Advanced Studies on Collaborative research, p.185-199, October 17-20, 2005, Toranto, Ontario, Canada
|
|
|
Noburou Taniguchi , Koji Chida , Osamu Shionoiri , Atsushi Kanai, DECIDE: a scheme for decentralized identity escrow, Proceedings of the 2005 workshop on Digital identity management, November 11-11, 2005, Fairfax, VA, USA
|
|
|
Xavier Boyen , Hovav Shacham , Emily Shen , Brent Waters, Forward-secure signatures with untrusted update, Proceedings of the 13th ACM conference on Computer and communications security, October 30-November 03, 2006, Alexandria, Virginia, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|