《计算机应用》唯一官方网站 ›› 2023, Vol. 43 ›› Issue (1): 154-159.DOI: 10.11772/j.issn.1001-9081.2021111945

所属专题: 网络空间安全

• 网络空间安全 • 上一篇    下一篇

基于格的分层无证书代理签名方案

农强1,2, 张棒棒1,2, 欧阳玉豪1,2   

  1. 1.闽南师范大学 计算机学院,福建 漳州 363000
    2.数据科学与智能应用福建省高等学校重点实验室(闽南师范大学),福建 漳州 363000
  • 收稿日期:2021-11-14 修回日期:2022-04-28 发布日期:2022-05-24
  • 通讯作者: 农强(1978—),男(壮族),广西崇左人,副教授,硕士,主要研究方向:应用密码学、信息安全nong_qiang@163.com
  • 作者简介:张棒棒(1998—),男,河南汝州人,硕士研究生,CCF会员,主要研究方向:抗量子密码学;欧阳玉豪(1996—),男,福建漳州人,硕士研究生,CCF会员,主要研究方向:车载网信息安全;
  • 基金资助:
    福建省自然科学基金资助项目(2019J01750)。

Lattice-based hierarchical certificateless proxy signature scheme

NONG Qiang1,2, ZHANG Bangbang1,2, OUYANG Yuhao1,2   

  1. 1.School of Computer Science, Minnan Normal University, Zhangzhou Fujian 363000, China
    2.Key Laboratory of Data Science and Intelligence Application, Fujian Province University (Minnan Normal University),Zhangzhou Fujian 363000, China
  • Received:2021-11-14 Revised:2022-04-28 Online:2022-05-24
  • Contact: NONG Qiang, born in 1978, M. S., associate professor. His research interests include applied cryptography, information security.
  • About author:ZHANG Bangbang, born in 1998, M. S. candidate. His research interests include anti-quantum cryptography;OUYANG Yuhao, born in 1996, M. S. candidate. His research interests include vehicular ad hoc network information security;
  • Supported by:
    This work is partially supported by Natural Science Foundation of Fujian Province (2019J01750).

摘要: 现有基于经典数论问题假设的无证书代理签名方案无法抵御量子计算机攻击,在应用于有大量用户的系统时会存在单点失效和不易扩展等局限。针对这些问题,提出一种基于格的分层无证书代理签名方案。首先,采用拒绝采样技术和无陷门技术提高密钥生成的计算效率;其次,不同层级的原始签名人和代理签名人通过交换随机选取的矩阵进行互认证,实现代理授权;最后,在随机预言机模型下的小整数解(SIS)困难问题假设下证明了该方案的安全性。相较于现有的代理签名方案,所提方案允许签名人来自不同层级且隶属于不同密钥生成中心(KGC)。性能评价实验结果表明,该方案的公钥尺寸是一个常数,代理签名和验证开销与层级无关,且代理密钥和签名尺寸非层级的线性量。因此,该方案可更好地满足大规模分布式异构网络对均衡负载的需求,是高效可行的。

关键词: 分层, 无证书, 代理签名, 格, 单点失效, 拒绝采样, 无陷门

Abstract: Existing certificateless proxy signature schemes based on classical number theory problem assumptions cannot resist to quantum computer attacks, and when these schemes are applied to systems with a large number of users, there are limitations such as single point of failure and low scalability. Aiming at these problems, a lattice-based hierarchical certificateless proxy signature scheme was proposed. Firstly, the rejection sampling technology and trapdoor-free technology were used to improve the computational efficiency of key generation. Secondly, the mutual authentication was performed by the original signers and proxy signers at different levels by exchanging randomly selected matrices, and then the proxy authorization was realized. Finally, the security of this scheme was proved under the of the Small Integer Solution (SIS) hard problem assumption in the random oracle model. Compared with the existing proxy signature schemes, the proposed scheme allows signers coming from different levels and belonging to different Key Generation Centers (KGCs). The performance evaluation experimental results show that in the proposed scheme, the public key size is a constant, the overhead of proxy signature and verification is independent of the level, and the proxy key size and the signature size are not hierarchical linear quantities, so that this scheme can better meet the needs of large-scale distributed heterogeneous networks for load balancing, and is efficient and feasible.

Key words: hierarchichy, certificateless, proxy signature, lattice, single point of failure, rejection sampling, trapdoor-free

中图分类号: