Overview Background The Transformation Conclusion and Future Work
From Selective-ID to Full-ID IBS without Random Oracles
Sanjit Chatterjee and Chethan Kamath
Indian Institute of Science, Bangalore
From Selective-ID to Full-ID IBS without Random Oracles Sanjit - - PowerPoint PPT Presentation
Overview Background The Transformation Conclusion and Future Work From Selective-ID to Full-ID IBS without Random Oracles Sanjit Chatterjee and Chethan Kamath Indian Institute of Science, Bangalore November 3, 2013 Overview Background The
Overview Background The Transformation Conclusion and Future Work
Indian Institute of Science, Bangalore
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
msk
mpk
Alice Bob
Overview Background The Transformation Conclusion and Future Work
msk
mpk
Alice Bob A l i c e u s kA
Overview Background The Transformation Conclusion and Future Work
msk
mpk
Alice Bob uskA Alice Alice
Overview Background The Transformation Conclusion and Future Work
msk
mpk
Alice Bob uskA Alice Alice uskB Bob Bob
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
some message m
identity id; otherwise, outputs 0
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Os
pk (ˆ σ; ˆ m)
A
$
$
Overview Background The Transformation Conclusion and Future Work
O{s,ε}
mpk (ˆ σ; ( ˆ id, ˆ m))
A
Pr
σ; ( ˆ id, ˆ m)) | (msk, mpk)
$
← − G(κ); (ˆ σ; ( ˆ id, ˆ m))
$
← − AO{s,ε}(mpk)
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
O{s,ε}
ˆ id mpk (ˆ σ; ( ˆ id, ˆ m))
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
polynomial degradation
degradation
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
td (m, r, m′):
collision: hek(m, r) = hek(m′, r ′)
Overview Background The Transformation Conclusion and Future Work
M
M
Os
˜ M pk, σi (ˆ σ; ˆ m)
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Set-up, G(κ):
Key Extraction, Emsk(id):
$
← − Es,msks(ids) and σp
$
← − Sp,sk(ids)
Signing, Susk(id, m):
$
← − Ss,usks(ids, m)
Verification, Vmpk(σ, id, m):
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Table: qs denotes the number of signature queries
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
Cs Is O{s,ε} Bs Is I O{s,ε} A I ˜ ids
Overview Background The Transformation Conclusion and Future Work
Cs Is O{s,ε} Bs Is I O{s,ε} A I ˜ ids mpks mpk
Overview Background The Transformation Conclusion and Future Work
Cs Is O{s,ε} Bs Is I O{s,ε} A I ˜ ids mpks mpk
a random ids
id
Overview Background The Transformation Conclusion and Future Work
Cs Is O{s,ε} Bs Is I O{s,ε} A I ˜ ids mpks mpk
ℓth identity then map id to ˜ ids (using knowledge of trapdoor td); else map to a random ids
id, m)
Overview Background The Transformation Conclusion and Future Work
Cs Is O{s,ε} Bs Is I O{s,ε} A I ˜ ids mpks ˆ σs mpk ˆ σ
ℓth identity then map id to ˜ ids (using knowledge of trapdoor td); else map to a random ids
id, m)
Overview Background The Transformation Conclusion and Future Work
B
A
Overview Background The Transformation Conclusion and Future Work
B
A
B
A
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work
O{s,ε}
ˆ id,ˆ I mpk (ˆ σ; ( ˆ id, ˆ m))
Overview Background The Transformation Conclusion and Future Work
O{s,ε}
ˆ id,ˆ I mpk (ˆ σ; ( ˆ id, ˆ m))
(EU-wID-CMA-IBS)+(EU-GCMA-PKS)+(CR-CHF)
Overview Background The Transformation Conclusion and Future Work
Overview Background The Transformation Conclusion and Future Work