Stealth Address serves as a widely adopted privacy-preserving technique for blockchain systems. However, Liu et al. (EuroS&P 2019) identified a security flaw in the existing Stealth Address algorithms, potentially compromising both the master secret key and derived secret keys. To address these vulnerabilities, Liu et al. (EuroS&P 2019) proposed the Key-Insulated&Privacy-Preserving Signature Scheme with Publicly Derived Public Key (PDPKS), designed to meet the functionality, security, and privacy requirements of Stealth Address. In this paper, we modularly analyze the PDPKS scheme and present a generic construction by integrating a Deterministic Public Key Encryption scheme with a Signature scheme using Rerandomizable Keys. We provide rigorous proof of security and privacy for this construction in the Random Oracle Model. With our construction, the security requirements (Anonymity under Chosen-Ciphertext Attacks and Indistinguishability under Chosen-Ciphertext Attacks) of the underlying PKE scheme in existing constructions can be relaxed to Weak Anonymity.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

From Signature with Re-randomizable Keys: Generic Construction of PDPKS

  • Ziyi Li,
  • Ruida Wang,
  • Xianhui Lu,
  • Yao Cheng,
  • Liming Gao

摘要

Stealth Address serves as a widely adopted privacy-preserving technique for blockchain systems. However, Liu et al. (EuroS&P 2019) identified a security flaw in the existing Stealth Address algorithms, potentially compromising both the master secret key and derived secret keys. To address these vulnerabilities, Liu et al. (EuroS&P 2019) proposed the Key-Insulated&Privacy-Preserving Signature Scheme with Publicly Derived Public Key (PDPKS), designed to meet the functionality, security, and privacy requirements of Stealth Address. In this paper, we modularly analyze the PDPKS scheme and present a generic construction by integrating a Deterministic Public Key Encryption scheme with a Signature scheme using Rerandomizable Keys. We provide rigorous proof of security and privacy for this construction in the Random Oracle Model. With our construction, the security requirements (Anonymity under Chosen-Ciphertext Attacks and Indistinguishability under Chosen-Ciphertext Attacks) of the underlying PKE scheme in existing constructions can be relaxed to Weak Anonymity.