摘要
广义签密和组合公钥密码都可以实现加密、签名和签密共用一对密钥,并且广义签密还可以实现三者共用一个算法.结合这两个概念,本文提出广义代理签密的概念.广义代理签密可以实现代理签名和代理签密共用一个算法和一对密钥.对于具有大量用户的系统、存储空间受限的系统或功能需求有变化的系统,它会带来效率的明显提高.本文给出了广义代理签密在基于身份的密码体制下的形式化定义和安全模型,并基于双线性对提出一个在标准模型中安全的基于身份的广义代理签密方案.方案具有在代理签密模式下可公开验证、防止代理密钥暴露攻击、可以自代理、具有较短的系统公开参数以及在原始签名(签密)者和代理签名(签密)者之间不需要安全信道的特点.本文方案在适应性选择密文、选择身份和选择授权攻击下的保密性安全性可以归结为DBDH困难问题;在适应性选择消息、选择身份和选择授权攻击下,本文方案的不可伪造性安全性可以归结为CDH困难问题.最后,本文对方案的效率进行了比较,结果表明它是属于高效的方案.
Both generalized signcryption and combined public key cryptosystem can realize encryption, signature and signcryption to share one key pair, and generalized signcryption can also realize them to share one algorithm. In this paper, we introduce a new concept called generalized proxy signcryption based on these two notions. Generalized proxy signcryption can realize proxy signature and proxy signcryption to share one key pair and one algorithm, which will significantly improve the efficiency of cryptosystems with a large number of users, storage-constrained environments or possible changes in the functional requirements. We give a formal definition and security model of generalized proxy signcryption in the identity-based cryptosystem setting, and propose a concrete scheme in the identity-based setting in the standard model by using bilinear pairing. The scheme has the properties of public verification in the proxy signcryption mode, resisting proxy key exposure attack, having self-delegation, short system public parameters and it does not need a secure channel between the original signer (signcrypter) and the proxy signer (signcrypter). Under adaptive chosen ciphertext, chosen identity and chosen warrant attack, the confidentiality of our scheme can be reduced to the DBDH hard problem; under adaptive chosen message, chosen identity and chosen warrant attack, the unforgeability of our scheme can be reduced to the CDH hard problem. At last, we compare our scheme with others. The result shows that it is a high efficient scheme.
出处
《密码学报》
CSCD
2016年第3期307-320,共14页
Journal of Cryptologic Research
基金
国家自然科学基金项目(61462048
61562047)
九江学院校级重点课题(2013ZD02)
关键词
代理签名
代理签密
广义代理签密
组合公钥密码
标准模型
双线性对
proxy signature
proxy signcryption
generalized proxy signcryption
combined public key cryptosystem
standard model
bilinear pairing