Signature Schemes with Randomized Verification

Published  . 0 views
↓ Download
Signature Schemes with Randomized Verification
1 / 1
Signature Schemes with Randomized Verification - slide 1 of 20 Signature Schemes with Randomized Verification - slide 2 of 20 Signature Schemes with Randomized Verification - slide 3 of 20 Signature Schemes with Randomized Verification - slide 4 of 20 Signature Schemes with Randomized Verification - slide 5 of 20 Signature Schemes with Randomized Verification - slide 6 of 20 Signature Schemes with Randomized Verification - slide 7 of 20 Signature Schemes with Randomized Verification - slide 8 of 20 Signature Schemes with Randomized Verification - slide 9 of 20 Signature Schemes with Randomized Verification - slide 10 of 20 Signature Schemes with Randomized Verification - slide 11 of 20 Signature Schemes with Randomized Verification - slide 12 of 20 Signature Schemes with Randomized Verification - slide 13 of 20 Signature Schemes with Randomized Verification - slide 14 of 20 Signature Schemes with Randomized Verification - slide 15 of 20 Signature Schemes with Randomized Verification - slide 16 of 20 Signature Schemes with Randomized Verification - slide 17 of 20 Signature Schemes with Randomized Verification - slide 18 of 20 Signature Schemes with Randomized Verification - slide 19 of 20 Signature Schemes with Randomized Verification - slide 20 of 20
Description: Signature Schemes with Randomized Verification Cody Freitag, Rishab Goyal, Susan Hohenberger, Venkata Koppula, Eysa Lee, Tatsuaki Okamoto and Brent Waters Basic building blocks Public Key Signatures Could be randomized! m Authority

Related Topics

Download Presentation

"Signature Schemes with Randomized Verification" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Signature Schemes with Randomized Verification Cody Freitag, Rishab Goyal, Susan Hohenberger, Venkata Koppula, Eysa Lee, Tatsuaki Okamoto and Brent Waters<br>
slide2. Basic building blocks Public Key Signatures Could be randomized!<br>
slide3. m Authority Identity-Based Encryption [Shamir84 ...]<br>
slide4. Identity-Based Encryption [Shamir84 ...]<br>
slide5. Naor’s Transformation: IBE  Signatures Interpreted as ‘identity’. For IBE encryption.<br>
slide6. Challenger Attacker Adv = | Pr[Verify(vk, m*, 𝝈*) = 1] | m*, 𝝈* m1 … mQ vk EUFCMA Security<br>
slide7. Guess IBE Challenger Attacker on Signatures (d0, d1), m* PP skm Naor’s Transformation: Proving Security m*, 𝝈* m Reduction ct* Chooses d0, d1 randomly

Decrypts ct* using 𝝈*<br>
slide8. Weakening EUFCMA # of accepting coins Total # of random coins<br>
slide9. Challenger Attacker Adv = | Pr[Verify(vk, m*, 𝝈*) = 1] |
Adv = | Pr[V-Prob(vk, m*, 𝝈*) > 𝛘 + negl] | m*, 𝝈* EUFCMA 𝛘-EUFCMA m1 … mQ vk<br>
slide10. Naor’s transformation gives weak security

Amplifying soundness (weak to standard)

Derandomizing in the ROM

Derandomizing in standard model Rest of the talk: Outline<br>
slide11. Naor’s transformation gives weak security Naor’s Transformation<br>
slide12. IBE Challenger Attacker on Signatures (d0, d1), m* PP skm Naor’s Transformation: Proving Security m*, 𝝈* m Reduction ct* Chooses d0, d1 randomly

Decrypts ct* using 𝝈* Guess Problem is to
use 𝝈* directly! Doesn’t work<br>
slide13. Solution
Estimates quality of forgery (/secret key) by counting
Artificial Abort-type step [Waters05]

Reduction runs verification sufficiently many times
# of successful verifications < threshold  Abort & Guess
# of successful verifications ≥ threshold  Decrypt & Test Naor’s Transformation: Proving Security 0 1 Bad Mid Good Worse than random guessing<br>
slide14. Amplifying soundness Idea. Direct product amplification.
Run Verify sufficiently many times with fresh randomness.<br>
slide15. Derandomization: ROM<br>
slide16. Sufficiently many random coins generated at Setup
Verify accepts iff successful on all coins Derandomization: Standard Model<br>
slide17. Derandomization: Standard Model Set of random coins Verification Key<br>
slide18. Introduced a weaker security notion for signature schemes with randomized verification

Proved security of Naor transformed scheme

Generic soundness amplification

Generic derandomization of verification
Both in ROM and standard model Conclusions<br>
slide19. Thank you! Questions?<br>