作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程

• 安全技术 • 上一篇    下一篇

Schnorr方案推广及其在格密码学中的应用

巩博儒1a,赵运磊1b,Rudolf Fleischer 1a,2,3,王晓阳1a   

  1. (1. 复旦大学 a. 计算机科学技术学院;b. 软件学院,上海 201203; 2. 上海市智能信息处理重点实验室,上海 200433;3. 德国科技大学阿曼分校应用信息技术学院,阿曼 马斯喀特 1816)
  • 收稿日期:2013-05-10 出版日期:2014-04-15 发布日期:2014-04-14
  • 作者简介:巩博儒(1982-),男,硕士研究生,主研方向:计算复杂性理论,密码学;赵运磊,副教授、博士生导师;Rudolf Fleischer、王晓阳,教授、博士生导师。
  • 基金资助:
    国家自然科学基金资助项目(61070248, 61272012);上海市教育委员会科研创新基金资助项目(12ZZ013);上海市重点学科建设基金资助项目(B114);上海科学技术委员会基金资助项目(08DZ2271800, 09DZ2272800)。

Generalization of Schnorr Scheme and Its Application in Lattice Cryptography

GONG Bo-ru 1a, ZHAO Yun-lei 1b, Rudolf Fleischer 1a,2,3, WANG Xiao-yang 1a   

  1. (1a. School of Computer Science; 1b. Software School, Fudan University, Shanghai 201203, China; 2. Shanghai Key Laboratory of Intelligent Information Processing, Shanghai 200433, China; 3. Department of Applied Information Technology, German University of Technology in Oman, Muscat 1816, Oman)
  • Received:2013-05-10 Online:2014-04-15 Published:2014-04-14

摘要: Schnorr身份认证方案是密码学中的经典方案,可以推广到很多其他数学问题(如离散对数问题)上,从而构造出在标准模式中安全的身份认证方案,并且可以通过Fiat-Shamir转换工具,将其转换为在随机谕示模式中安全的数字签名方案。但将上述转换方法用于基于格的密码学中时会出现一些特殊现象(如方案中止现象)。为此,通过矩阵表示方法分析Schnorr方案的构造方法,得出其构造方法成立的充要条件,从而使其可在更大范围内构造出安全的类Schnorr方案。根据类Schnorr方案,分析基于格的身份认证方案中的方案中止现象,并通过数学方法证明,对于某些身份认证方案(如∑-身份认证方案),其中的方案中止现象不可避免,该结论为深入研究基于格的密码学提供了参考依据。

关键词: Schnorr签名方案, 身份认证方案, 数字签名, 基于格的密码学, Fiat-Shamir转换, 方案中止

Abstract: As one of classic identification schemes in cryptography, Schnorr’s scheme can be applied with respect to many underlying mathematical hard problems, as well as discrete logarithm problem. Moreover, it can apply the Fiat-Shamir transform to convert a secure Schnorr’s identification scheme in standard model into a secure digital signature scheme in the random oracle model. Aiming at the condition, this paper analyzes the features of Schnorr’s scheme, the necessary and sufficient conditions for a secure Schnorr’s scheme are derived, and hence it can construct the secure Schnorr-like scheme in a broader sense. Then, by using the concept of Schnorr-like scheme, it can prove rigorously that the existence of aborts in some lattice-based identification scheme, such as ∑-identity authentication scheme is inevitable, which sheds light on a better understanding of the lattice-based signature in the future.

Key words: Schnorr signature scheme, identity authentication scheme, digital signature, lattice-based cryptography, Fiat-Shamir transform, scheme abort

中图分类号: