我々の署名スキームは、CDH 問題は困難だが Decision Diffie-Hellman 問題 (DDH) は容易である群を使用している。このような群の最初の例は [12] で与えられ、以前には [11,4] で用いられた。このような群を Gap Diffie-Hellman 群、略して GDH 群と呼ぶ。Okamoto and Pointcheval [20] は Gap Diffie-Hellman 群が署名スキームを生み出すとコメントした。しかし、ほとんどの Gap Diffie-Hellman 群は比較的長く、短い署名にはつながらない。GDH 群から派生した署名スキームのセキュリティを証明し、それらが非常に短い署名をもたらす方法を示す。セクション 5 で提案した署名スキームを実験し実行時間を与える。
2 Gap Diffie-Hellman に基づく署名スキーム
我々は任意の Gap Diffie-Hellman 群で機能する署名スキームを提示する。前述のように、このスキームは Okamoto and Pointcheval [20] によって暗黙的に記述されている。このスキームは Chaum and Pederson [5] によって提案された否認不可署名スキームに似ている。次のセクションではこの署名スキームがどのように非常に短い署名を生成するかを示す。
The authors thank Steven Galbraith, Alice Silverberg, and Moni Naor for helpful discussions about this work.
References
ANSI X9.62 and FIPS 186-2. Elliptic Curve Digital Signature Algorithm, 1998.
R. Balasubramanian and N. Koblitz. The Improbability That an Elliptic Curve Has Subexponential Discrete Log Problem under the Menezes-Okamoto-Vanstone Algorithm. Journal of Cryptology, 11(2):141–145, 1998.
M. Bellare and P. Rogaway. The Exact Security of Digital Signatures: How to Sign with RSA and Rabin. In U. Maurer, editor, Proceedings of Eurocrypt ’96, volume 1070 of LNCS, pages 399–416. Springer-Verlag, 1996.
D. Boneh and M. Franklin. Identity-Based Encryption from the Weil Pairing. In J. Kilian, editor, Proceedings of Crypto ’2001, volume 2139 of LNCS, pages 213–229. Springer-Verlag, 2001.
D. Chaum and T. Pederson. Wallet Databases with Observers. In E. Brickell, editor, Proceedings of Crypto ’92, volume 740 of LNCS, pages 89–105. SpringerVerlag, 1992.
J.-S. Coron. On the Exact Security of Full Domain Hash. In M. Bellare, editor, Proceedings of Crypto ’2000, volume 1880 of LNCS, pages 229–235. Springer-Verlag, 2000.
G. Frey, M. Muller, and H. Ruck. The Tate Pairing and the Discrete Logarithm Applied to Elliptic Curve Cryptosystems. IEEE Tran. on Info. Th., 45(5):1717–1719, 1999.
S. Galbraith. Supersingular curves in cryptography. In Proceedings of Asiacrypt ’2001, LNCS. Springer-Verlag, 2001.
S. Galbraith and N. P. Smart. A Cryptographic Application of Weil Descent. In M. Walker, editor, Cryptology and Coding, volume 1746 of LNCS, pages 191–200. 532 D. Boneh, B. Lynn, and H. Shacham
P. Gaudry, F. Hess, and N. P. Smart. Constructive and Destructive Facets of Weil Descent on Elliptic Curves. Technical Report CSTR-00-016, Department of Computer Science, University of Bristol, 2000.
A. Joux. A One Round Protocol for Tripartite Diffie-Hellman. In W. Bosma, editor, Proceedings of ANTS IV, volume 1838 of LNCS, pages 385–394. Springer-Verlag, 2000.
A. Joux and K. Nguyen. Separating Decision Diffie-Hellman from Diffie-Hellman in Cryptographic Groups. Cryptology ePrint Archive, Report 2001/003, 2001. http://eprint.iacr.org/.
N. Koblitz. An Elliptic Curve Implementation of the Finite Field Digital Signature Algorithm. In H. Krawczyk, editor, Proceedings of Crypto ’98, volume 1462 of LNCS, pages 327–333. Springer-Verlag, 1998.
S. Lang. Elliptic Functions. Addison-Wesley, Reading, MA, 1973.
A. Menezes, T. Okamoto, and P. Vanstone. Reducing Elliptic Curve Logarithms to Logarithms in a Finite Field. IEEE Transactions on Information Theory, 39(5):1639–1646, 1993.
A. J. Menezes, P. C. Van Oorschot, and S. A. Vanstone. Handbook of Applied Cryptography. CRC Press, 1997.
V. Miller. Short Programs for Functions on Curves. unpublished manuscript, 1986.
I. Mironov. A Short Signature as Secure as DSA. Preprint, 2001.
D. Naccache and J. Stern. Signing on a Postcard. In Proceedings of Financial Cryptography ’00, 2000.
T. Okamoto and D. Pointcheval. The Gap Problems: A New Class of Problems for the Security of Cryptographic Primitives. In K. Kim, editor, Public Key Cryptography, PKC 2001, volume 1992 of LNCS, pages 104–118. Springer-Verlag, 2001.
L. Pintsov and S. Vanstone. Postal Revenue Collection in the Digital Age. In Proceedings of Financial Cryptography ’00, 2000.
J. H. Silverman. The Arithmetic of Elliptic Curves, volume 106 of Graduate Texts in Mathematics. Springer-Verlag, 1986.
W. C. Waterhouse. Abelian Varieties over Finite Fields. Ann. Sci. École Norm. Sup., 2:521–60, 1969.
翻訳抄
Gap Diffie-Hellman 群でのヴェイユペアリングを使用することで、一般的な RSA や DSA での署名と比べて同じ強度で短い署名を生成する方法を示す 2001 年の論文。