On the Fly Authenti ation and Signature
28 pages
English

Découvre YouScribe en t'inscrivant gratuitement

Je m'inscris

On the Fly Authenti ation and Signature

-

Découvre YouScribe en t'inscrivant gratuitement

Je m'inscris
Obtenez un accès à la bibliothèque pour le consulter en ligne
En savoir plus
28 pages
English
Obtenez un accès à la bibliothèque pour le consulter en ligne
En savoir plus

Description

On the Fly Authenti ation and Signature S hemes based on Groups of Unknown Order Mar Girault 1 , Guillaume Poupard 2 , and Ja ques Stern 3 1 Fran e Tele om Resear h & Development, 42 rue des Coutures BP 6243, F-14066 Caen Cedex 4, Fran e mar .giraultfran etele om. om 2 DCSSI Crypto Lab, 51 boulevard de La Tour-Maubourg F-75700 Paris 07 SP, Fran e Guillaume.Poupardm4x.org 3 É ole normale supérieure, Département d'informatique 45 rue d'Ulm, F-75230 Paris Cedex 05, Fran e Ja ques.Sternens.fr Abstra t. In response to the urrent need for fast, se ure and heap publi -key ryp- tography, we propose an intera tive zero-knowledge identi ation s heme and a derived signature s heme that ombine provable se urity based on the problem of omputing dis rete logarithms in any group, short keys, very short transmission and minimal on- line omputation. This leads to both e ient and se ure appli ations well suited to implementation on low ost smart ards. We introdu e GPS, a S hnorr-like s heme that does not require knowledge of the order of the group nor of the group element.

  • heap publi -key

  • identi ation

  • ation time

  • appli ations

  • zero-knowledge

  • signature

  • international organization

  • ele tromagneti indu


Sujets

Informations

Publié par
Nombre de lectures 18
Langue English

Extrait


On
strong
the
smart
Fly
Sev
Authen


heme,
and
authen
Signature
b
Sc
pro
hemes
a
based
less
on
In
Groups
tialit
of
v
Unkno
man
wn

Order
v
Marc
the
Girault
ossible
1
an
,
authen
Guillaume
equipmen
P
on-line
oupard
elopmen
2
heap
,
e
and
in

w
Stern
those
3
of
1
o
F
prop
rance
of
T

elecom
y

heme.
h
of
&
rameters
Dev
the
elopmen
on
t,
a
42
e
rue
with
des
ords.
Coutures
logarithm
BP

6243,
rapid
F-14066

Caen
fast,
Cedex
y
4,
tographers
F
imp
rance
viding

ho
2
tit
DCSSI
a
Crypto
ha
Lab,
ard
51
based
b
tro
oulev

ard
to
de
sc
La
e
T
ortan
our-Maub
.
ourg
limited
F-75700
pap
P

aris
ofs
07
tication
SP
rom
,
oin
F
the
rance
of
Guillaume.Poupard@m4x.org
discussed
3
ort
?cole

normale
implemen
sup?rieure,

D?partemen
is
t
and
d'informatique

45
erformed
rue
20
d'Ulm,
w
F-75230
Key
P
tication
aris
signature,
Cedex
min-
05,
lo
F

rance


orld-wide

of
In
ulates
resp
mand
onse
and
to
ey
the
Besides

,
t
to
need
w
for
t
fast,
and

signatures
and
w

to
heap
one's
public-k
and
ey
digitally


tograph
prop
y
e
,
putting
w
t
e
of
prop
the
ose
wledge
an
in
in
Goldw


e
In
zero-kno
the
wledge
prop
iden
three
tication
ha
sc
b
heme
most
and

a

deriv
viously
ed
ery
signature

sc
This
heme
er
that
vides


bine
pro
pro
of
v
iden
able
sc

F
y
a
based
p
on
t
the
view,
problem
p
of
range

pa-
discrete
is
logarithms
and
in
rep
an
on
y
p
group,
of
short
actual
k
tation
eys,
a
v
heap
ery

short

transmission

and

minimal

on-
b
line
p

in
This
than
leads
milliseconds
to
lo
b

oth
t.

w
t
Iden
and
sc

digital
applications
discrete
w
problem,
ell
imal
suited

to
w
implemen
smart
tation
1
on
tro
lo
The
w
w

dev
smart
t

electronic
W
stim
e
a
in
de-
tro
for


GPS,

a
public-k
Sc

hnorr-lik
.
e

sc
y
heme

that
need
do
solv
es
t
not
o
require
ortan
kno
problems:
wledge

of
pro
the
digital
order
or,
of
plain
the
ords,
group
w
nor
pro
of
e
the
iden
group
y
elemen
ho
t.
to
As
sign
a
do

t.
it
eral

osals
b
v
e
addressed
used
questions,
with
forw
most
elegan

solutions,
group
y

them

on
those

of
zero-kno
unkno
in
wn

order.
1985
F
y
urthermore,
asser,
the
and

k
of
[30].
the
order
pro
assess
v
p
er's
of
resp
osed
onse
hemes,
is
main
done
erties
o
v
v
to
er
e
the
The
in
imp
tegers,
t
hence
is,


b
y
e
Ob
done
,
witha
a
authen
system
on

for
b
the
e
e
supp
to
orted
Ev
b
study
y
implemen
the
tenna.

stored
that
y
nob
signature
o
mo
dy
describ
has
impro
b
a
een
and
able

to
they
jeopardize
unit
it
that
so
v
far.
is
This
used.
is
ons
of
t.

is
imp
m
ortan
osed
t
signature
but,
b
in
auman
man
tication
y
bine
applications,
arbitrary
it

is
tication
not
the
a
just
satisfactory

enough

guaran
Con
tee.
et
A
p
m
and
uc
e
h

b
ottlenec
etter
when
paradigm
al.
tries
thr
to
mak
pro
uc
v
er
e
y

it
y
Another
in
general
a
and
mathematical
on-line/o-line
sense,
to
i.e.

to
of
establish
This
theorems
y

pap
that
e
illegal
GPS
actions
sc


h
o
as
k
imp
minimal
ersonation
GPS
are
sig-
as
lo
dicult
Another
as

solving

a
e
sp
an

em
problem,
ts
whose
with
dicult
ph
y
the
is
distinguish
w
een
ell-established.
b
Among
o-line
these
memory
problems
that
are
to
in
on-line
teger
or

The
or
the
the
of

esp
of

discrete
he
logarithms
prop
in
use
a

nite
order
group.
the
Half

w
more
a
w
y
at-
b
on
et
sc
w
optimal
een
requires

m
v
h
alidation
h
and

formal
Goldreic
pro
[15]
ofs

are
signature
pro
a
ofs
an
in
heme
a
a
mo
that
del

where
done

as
ob
ed

and
are
In
replaced
w
b
in
y
wledge
some
heme,
ideal
short,
substitutes:
ed
applying
They
this
v
paradigm
based
to
logarithm
hash
er
functions
group,
yields
short
the
size
so-called

random
signature
oracle
ws
mo
public-k
del
or
describ
hemes
ed

b

y
application
Bellare
tation
and
sc
Roga

w
h
a
ok
y

in
v

mi-
Although
and
this
edded


h
w
ma

y
an
not
an
b

e


v
as
to
oering
b
absolute
w
pro
precomputations
ofs

of
e

erformed
y
and
for
in

,
sc

hemes,
ha
it
e
pro
b
vides
done
a
during
strong

guaran
signature
tee
tation.
that
latter
their
often
general
b
design
k
is
man
not
applications,
a
ecially
w
smart
ed.
are
Next,

the
et
size
[34]
of
osed
the
precompute
data
&
in
ow
v
oup
olv
in
ed
to
in
e
the
DSA
sc
pro
heme
m
is
h
of


Ho

ev

this
W
tempt
e
designing
usually
the
need
signature
short
hemes
public
not
and
since
priv
still
ate
a
k
dular
eys,
ultiplication.
mainly

when
is
they
uc
ha
more
v
in
e

to
en,
b
h
e

stored
prop
in
the
p
of
ortable
digital

and
lik
ed
e


transform
hip
y

sc
whic
in
h
h
ma
w
y
y
ha
most
v
the
e

small
e
storage
o-line.

w
W
further
e
v
also
b
w
Shamir
an
T
t
[44].
to
this

er,
the
e
amoun
an
t

of
zero-kno
transmissions
iden
and
sc
the

length
for
of<

  • Univers Univers
  • Ebooks Ebooks
  • Livres audio Livres audio
  • Presse Presse
  • Podcasts Podcasts
  • BD BD
  • Documents Documents