Abstract
In this paper, we point out some faulty instantiations of threshold ring signatures (TRS) based on the threshold proof-of-knowledge (TPoK) protocol. Although a TRS can be regarded as the non-interactive version of the TPoK, the computational domains of the variables should be carefully chosen. We show that by choosing some inappropriate domains, two such instantiations suffer from forgery and anonymity attacks. Our attacks rely on algebraic techniques which involve solving some particular instances of the well-known subset sum problem. While we focus our attacks on two particular instantiations of the TRS, they are generic and are applicable to other schemes with the same choice of domains or a similar structure. We believe this paper can act as an important security remark on the design of future TRS schemes.
| Original language | English |
|---|---|
| Pages (from-to) | 945-954 |
| Journal | Computer Journal |
| Volume | 59 |
| Issue number | 7 |
| DOIs | |
| Publication status | Published - 1 Jul 2016 |
Research Keywords
- threshold proof of knowledge
- Threshold ring signature
Fingerprint
Dive into the research topics of 'Faulty instantiations of threshold ring signature from threshold proof-of-knowledge protocol'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver