Signature Schemes with Randomized Verification
Description: Signature Schemes with Randomized Verification Cody Freitag, Rishab Goyal, Susan Hohenberger, Venkata Koppula, Eysa Lee, Tatsuaki Okamoto and Brent Waters Basic building blocks Public Key Signatures Could be randomized! m Authority
Related Topics
Download Presentation
"Signature Schemes with Randomized Verification" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Signature Schemes with Randomized Verification Cody Freitag, Rishab Goyal, Susan Hohenberger, Venkata Koppula, Eysa Lee, Tatsuaki Okamoto and Brent Waters<br>
slide2. Basic building blocks Public Key Signatures Could be randomized!<br>
slide3. m Authority Identity-Based Encryption [Shamir84 ...]<br>
slide4. Identity-Based Encryption [Shamir84 ...]<br>
slide5. Naor’s Transformation: IBE Signatures Interpreted as ‘identity’. For IBE encryption.<br>
slide6. Challenger Attacker Adv = | Pr[Verify(vk, m*, 𝝈*) = 1] | m*, 𝝈* m1 … mQ vk EUFCMA Security<br>
slide7. Guess IBE Challenger Attacker onSignatures (d0, d1), m* PP skm Naor’s Transformation: Proving Security m*, 𝝈* m Reduction ct* Chooses d0, d1 randomly
Decrypts ct* using 𝝈*<br>
slide8. Weakening EUFCMA # of accepting coins Total # of random coins<br>
slide9. Challenger Attacker Adv = | Pr[Verify(vk, m*, 𝝈*) = 1] |
Adv = | Pr[V-Prob(vk, m*, 𝝈*) > 𝛘 + negl] | m*, 𝝈* EUFCMA 𝛘-EUFCMA m1 … mQ vk<br>
slide10. Naor’s transformation gives weak security
Amplifying soundness (weak to standard)
Derandomizing in the ROM
Derandomizing in standard model Rest of the talk: Outline<br>
slide11. Naor’s transformation gives weak security Naor’s Transformation<br>
slide12. IBE Challenger Attacker onSignatures (d0, d1), m* PP skm Naor’s Transformation: Proving Security m*, 𝝈* m Reduction ct* Chooses d0, d1 randomly
Decrypts ct* using 𝝈* Guess Problem is to
use 𝝈* directly! Doesn’t work<br>
slide13. Solution
Estimates quality of forgery (/secret key) by counting
Artificial Abort-type step [Waters05]
Reduction runs verification sufficiently many times
# of successful verifications < threshold Abort & Guess
# of successful verifications ≥ threshold Decrypt & Test Naor’s Transformation: Proving Security 0 1 Bad Mid Good Worse than random guessing<br>
slide14. Amplifying soundness Idea. Direct product amplification.
Run Verify sufficiently many times with fresh randomness.<br>
slide15. Derandomization: ROM<br>
slide16. Sufficiently many random coins generated at Setup
Verify accepts iff successful on all coins Derandomization: Standard Model<br>
slide17. Derandomization: Standard Model Set of random coins Verification Key<br>
slide18. Introduced a weaker security notion for signature schemes with randomized verification
Proved security of Naor transformed scheme
Generic soundness amplification
Generic derandomization of verification
Both in ROM and standard model Conclusions<br>
slide19. Thank you! Questions?<br>
slide2. Basic building blocks Public Key Signatures Could be randomized!<br>
slide3. m Authority Identity-Based Encryption [Shamir84 ...]<br>
slide4. Identity-Based Encryption [Shamir84 ...]<br>
slide5. Naor’s Transformation: IBE Signatures Interpreted as ‘identity’. For IBE encryption.<br>
slide6. Challenger Attacker Adv = | Pr[Verify(vk, m*, 𝝈*) = 1] | m*, 𝝈* m1 … mQ vk EUFCMA Security<br>
slide7. Guess IBE Challenger Attacker onSignatures (d0, d1), m* PP skm Naor’s Transformation: Proving Security m*, 𝝈* m Reduction ct* Chooses d0, d1 randomly
Decrypts ct* using 𝝈*<br>
slide8. Weakening EUFCMA # of accepting coins Total # of random coins<br>
slide9. Challenger Attacker Adv = | Pr[Verify(vk, m*, 𝝈*) = 1] |
Adv = | Pr[V-Prob(vk, m*, 𝝈*) > 𝛘 + negl] | m*, 𝝈* EUFCMA 𝛘-EUFCMA m1 … mQ vk<br>
slide10. Naor’s transformation gives weak security
Amplifying soundness (weak to standard)
Derandomizing in the ROM
Derandomizing in standard model Rest of the talk: Outline<br>
slide11. Naor’s transformation gives weak security Naor’s Transformation<br>
slide12. IBE Challenger Attacker onSignatures (d0, d1), m* PP skm Naor’s Transformation: Proving Security m*, 𝝈* m Reduction ct* Chooses d0, d1 randomly
Decrypts ct* using 𝝈* Guess Problem is to
use 𝝈* directly! Doesn’t work<br>
slide13. Solution
Estimates quality of forgery (/secret key) by counting
Artificial Abort-type step [Waters05]
Reduction runs verification sufficiently many times
# of successful verifications < threshold Abort & Guess
# of successful verifications ≥ threshold Decrypt & Test Naor’s Transformation: Proving Security 0 1 Bad Mid Good Worse than random guessing<br>
slide14. Amplifying soundness Idea. Direct product amplification.
Run Verify sufficiently many times with fresh randomness.<br>
slide15. Derandomization: ROM<br>
slide16. Sufficiently many random coins generated at Setup
Verify accepts iff successful on all coins Derandomization: Standard Model<br>
slide17. Derandomization: Standard Model Set of random coins Verification Key<br>
slide18. Introduced a weaker security notion for signature schemes with randomized verification
Proved security of Naor transformed scheme
Generic soundness amplification
Generic derandomization of verification
Both in ROM and standard model Conclusions<br>
slide19. Thank you! Questions?<br>