Existential unforgeability under chosen-identity/message attack (EUF-ID-CMA) is the standard security model for identity-based signatures (IBS), where an attacker can adaptively choose message-identity pairs and identities respectively for the signing and key oracles. Recently, Pan and Wagner (PQC 2021) claimed to have realized tightly EUF-ID-CMA-secure IBS schemes from lattices using a two-stage approach: first, constructing a non-adaptively tightly secure IBS scheme from lattices, and then lifting this scheme to adaptive security (EUF-ID-CMA) using two generic approaches - one based on chameleon hashes in the standard model and the other on hash functions in the random oracle model (ROM). In this paper, we critically analyze the adaptive unforgeability model used by Pan and Wagner, as well as the consequent security reduction of their generic conversions from non-adaptive to adaptive security, both in the standard model and in the ROM. We identify some subtle yet serious gaps in their approach. To bridge these gaps, we propose new security reductions for their generic conversions while arguing why the Pan-Wagner technique by itself is unlikely to yield a tight reduction. On the other hand, we show that their generic technique can be extended to application scenarios, such as IoT, where a user can register more than one signing devices under a single identity. The extended scheme has hardly any additional overhead and we argue its security in a suitably modified version of EUF-ID-CMA model.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Revisiting Generic Conversion from Non-adaptive to Adaptively Secure IBS: Tightness and an Extension

  • Sanjit Chatterjee,
  • Tapas Pandit

摘要

Existential unforgeability under chosen-identity/message attack (EUF-ID-CMA) is the standard security model for identity-based signatures (IBS), where an attacker can adaptively choose message-identity pairs and identities respectively for the signing and key oracles. Recently, Pan and Wagner (PQC 2021) claimed to have realized tightly EUF-ID-CMA-secure IBS schemes from lattices using a two-stage approach: first, constructing a non-adaptively tightly secure IBS scheme from lattices, and then lifting this scheme to adaptive security (EUF-ID-CMA) using two generic approaches - one based on chameleon hashes in the standard model and the other on hash functions in the random oracle model (ROM). In this paper, we critically analyze the adaptive unforgeability model used by Pan and Wagner, as well as the consequent security reduction of their generic conversions from non-adaptive to adaptive security, both in the standard model and in the ROM. We identify some subtle yet serious gaps in their approach. To bridge these gaps, we propose new security reductions for their generic conversions while arguing why the Pan-Wagner technique by itself is unlikely to yield a tight reduction. On the other hand, we show that their generic technique can be extended to application scenarios, such as IoT, where a user can register more than one signing devices under a single identity. The extended scheme has hardly any additional overhead and we argue its security in a suitably modified version of EUF-ID-CMA model.