Ring signature, formally introduced by Rivest, Shamir, and Tauman in 2001
is a type of signature schemes similar to group signature schemes but have
two distinct properties: spontaneity and anonymity. Spontaneity ensures
that no participation or collaboration of other ring members is needed for
the actual signer to form a ring (or group) of members and generate a signature
on behalf of this ring. Anonymity means signer-ambiguous in the sense
that a signature can be verified as coming from a certain ring, without revealing
the identity of the actual signer. Due to ring signature’s distinct and
interesting properties, it has been studied extensively, and there are many
applications of ring signature proposed. These include secret leaking, which
is the original motivation of ring signature, and ad hoc group authentication.
A special case of ring signature is two-member ring signature which inherits
all the properties of ring signature but has only two members involved.
One prominent application of this special case is the concurrent signature.
Another interesting application is the construction of designated verifier signature.
Given these application, a natural question is whether we could
further apply two-member ring signature to other applications. We answer
this question positively by proposing a new application of two-member ring
signature. We apply the techniques to the construction of Nominative Signature
and show that we are able to build a provably secure while efficient
nominative signature scheme with some properties which cannot be realized
by comparable constructions.
In a nominative signature scheme, there are three parties involved, namely
nominator, nominee and verifier. Unlike other non-self-authenticating signature
schemes such as Undeniable Signature, only NS is able to dethrone the
ability of proving the validity of a signature from the signer who chooses the
message (or Nominator). Due to this special property, it is considered to be
more suitable for User Certification System than Universal Designated Verifier
Signature. However for the past few years, only a few secure and efficient
NS constructions which satisfy all NS properties have been proposed and
they all require multiple rounds of interaction between the nominator and
the nominee which is inefficient. In this thesis, we propose for the first time
a one-move NS scheme based on two-member ring signature which satisfies
all the properties of NS and is secure under NS’s strongest security models.
Besides the application of the special two-member ring signature, we also
work on another interesting problem of ring signature. Currently, all ring signature
schemes are either built under the PKI (Public Key Infrastructure) or
the Identity-Based setting. In the setting where there is no certificate while
without key escrow, for example, in the certificateless cryptographic setting,
we find that the main problem of constructing a ring signature is that there is
no satisfactory security model available. When comparing with the research
work on other aspects of certificateless cryptography, such as certificateless
encryption, the work on certificateless ring signature is inadequate. In the
second part of this thesis therefore, we focus ourselves on the security definition
and construction of certificateless ring signature. Our results show that
they are currently the strongest models and the most efficient constructions
available.
| Date of Award | 2 Oct 2008 |
|---|
| Original language | English |
|---|
| Awarding Institution | - City University of Hong Kong
|
|---|
| Supervisor | Shek Duncan WONG (Supervisor) |
|---|
- Digital signatures
- Cryptography
- Computer security
Ring signature based certificateless cryptography and nominative signature
CHANG, S. (Author). 2 Oct 2008
Student thesis: Master's Thesis