• •    

一种基于CRT的动态门限签名方案

王岩1,侯整风2,章雪琦1,黄梦洁1   

  1. 1. 安徽省合肥市屯溪路合肥工业大学计算机与信息学院
    2. 合肥工业大学
  • 收稿日期:2017-09-14 修回日期:2017-10-25 发布日期:2017-10-25
  • 通讯作者: 王岩

A Dynamic Threshold Signature Scheme Based on CRT

  • Received:2017-09-14 Revised:2017-10-25 Online:2017-10-25

摘要: 摘 要: 针对移动攻击,提出一种基于中国剩余定理的动态门限签名方案。首先,成员交换影子产生各自的私钥和组公钥,然后由成员协作产生部分签名,最后通过部分签名合成签名。方案在签名过程中没有暴露组私钥,从而保证组私钥可重复使用。方案允许成员定期更新私钥,且组公钥不变,以保证更新前的签名仍然有效。此外,方案允许新成员加入,并保证老成员私钥和组私钥不会泄露。分析表明,方案具有良好的前向安全性,能够有效地抵抗移动攻击。理论分析和仿真实验表明,与徐甫提出的前摄性门限RSA方案相比,该方案更新时间消耗和签名时间消耗均为常数级,时间效率较高。

关键词: 门限签名, 中国剩余定理, 移动攻击, 更新私钥, 成员加入

Abstract: Abstract: To resist the mobile attacks, the paper proposed a dynamic threshold signature scheme based on Chinese Remainder Theorem. Firstly,members exchanged their shadows to generate their private keys and the group public key. Secondly, the partial signature was generated by cooperation. Finally, the partial signature was used to synthesize the signature. The scheme does not expose the group private key in the signature process, so that the group private key can be reused. The members updated their private keys periodically without changing the group public key to ensure that the signature before update is still valid. Besides, the scheme allows new members to join while keep the old member’s private keys and group private key unexposed. The scheme has forward security, which can resist the mobile attacks effectively. Theoretical analysis and simulation results show that, compared with the proactive threshold RSA scheme proposed by Xu Fu, the updating time consumption and signature time consumption of the scheme are constant, the scheme has higher time efficiency.

Key words: threshold signature, Chinese Remainder Theorem(CRT), mobile attacks, update private key, member expansion

中图分类号: