Round Optimal Blind Signatures
Sanjam Garg Vanishree Rao Amit Sahai Dominique Schroeder* Dominique Unruh
*Postdoctoral Fellow of the DAAD
UCLA
University of Maryland University of Tartu
(http://eprint.iacr.org/2011/264)
Blind Signatures Sanjam Garg Vanishree Rao Amit Sahai - - PowerPoint PPT Presentation
Round Optimal Blind Signatures Sanjam Garg Vanishree Rao Amit Sahai UCLA Dominique Schroeder* Dominique Unruh University of Maryland University of Tartu (http://eprint.iacr.org/2011/264) *Postdoctoral Fellow of the DAAD Blind
*Postdoctoral Fellow of the DAAD
University of Maryland University of Tartu
(http://eprint.iacr.org/2011/264)
signer user
CRYPTO 2011 2 Dominique Schröder
signer user
CRYPTO 2011 3 Dominique Schröder
CRYPTO 2011 4 Dominique Schröder
– User cannot vote for an additional candidate (unforgeability), voting agency does not see the vote (blindness) – FIFA world soccer cup selected in 2002 Most Valuable Player using Votopia
– Microsoft U-PROVE – National Strategy for Trusted Identities in Cyberspace - NISTIC
CRYPTO 2011 5 Dominique Schröder
Unforgeability [JLO97,PS00] n-times signer user
CRYPTO 2011 6 Dominique Schröder
Blindness [JLO97,PS00] user user
CRYPTO 2011 7 Dominique Schröder
(Aborts: PKC, FS[09])
CRYPTO 2011 Dominique Schröder 8
signer user
CRYPTO 2011 Dominique Schröder 9
Chaum, Boldyreva: interactive assumption, ROM Fischlin: CRS 2 moves (optimal): 3 moves: Pointcheval Stern, Abe ROM 4 moves: Okamoto TCC06
CRYPTO 2011 Dominique Schröder 10
signer user
CRYPTO 2011 Dominique Schröder 11
Extension: Pass (STOC 11): unique blind signature.
CRYPTO 2011 Dominique Schröder 12
signer user
(Caution: actual results may vary)
CRYPTO 2011 Sanjam Garg 13
CRYPTO 2011 Sanjam Garg 14
signer user
CRYPTO 2011 Sanjam Garg 15
signer user
OT1 OT2,Yao
Unique signature In fact PRF suffices More fundamental issue
CRYPTO 2011 Sanjam Garg 16
signer user
OT1 OT2,Yao
CRYPTO 2011 Sanjam Garg 17
Accepts/Rejects
– Using deterministic signatures – Enforcing honest behavior by a Zero Knowledge protocol
– Subtle issue remains: in proof of security, need to extract signatures – Solution: Use super-poly-time extraction – But can avoid the use of super-poly-time by specific rewinding technique (see paper)
CRYPTO 2011 Sanjam Garg 18
signer user
OT1,zk1 OT2,Yao, zk2
CRYPTO 2011 Sanjam Garg 19
CRYPTO 2011 Sanjam Garg 20
CRYPTO 2011 Sanjam Garg 21
(Impossible from OWP: Katz, S, Yerukhimovich, TCC 2011)
CRYPTO 2011 Sanjam Garg and Dominique Schröder 22
Amit Sahai Dominique Unruh Vanishree Rao