AI 中文总结
本文针对BBS签名,在每条消息最多签一次的情况给出新型紧归约,同时证明同消息多签时无紧代数归约,缩小了BBS与BBS+的紧安全性差距。
AI 中文摘要
本文研究BBS签名(Boneh、Boyen、Shacham于2004年CRYPTO会议;Camenisch和Lysyanskaya于2004年CRYPTO会议)的具体安全性,BBS签名是一种流行的代数数字签名构造,是实用隐私保护认证系统的基础,目前正在由W3C和IRTF进行标准化。Schäge(2015年《密码学期刊》)针对该方案效率较低的变体BBS+,在q-SDH假设下给出了紧标准模型安全证明,其中q是已签发签名的数量。相比之下,BBS的安全证明(Tessaro和Zhu,2023年EUROCRYPT会议)同样基于q-SDH假设,但并非紧证明。尽管如此,这一近期证明推动了标准化和行业采用转向效率更高的BBS而非BBS+,因此理解这种紧性差距是否是固有的十分重要。Chairattana-Apirom和Tessaro(2025年ASIACRYPT会议)的近期密码分析也表明,对q-SDH的紧归约是我们所能期望的最好结果。本文以两种不同方式缩小了这一差距:从积极方面,我们针对每条消息最多签名一次的情况,给出了BBS的新型紧归约,该情况尤其涵盖了使签名非随机化的常见实际用例;从消极方面,我们使用元归约论证证明,若允许为同一条消息生成多个签名,则不存在对q-SDH及其变体的代数归约是紧的。
英文摘要
This paper studies the concrete security of BBS signatures (Boneh, Boyen, Shacham, CRYPTO '04; Camenisch and Lysyanskaya, CRYPTO '04), a popular algebraic construction of digital signatures which underlies practical privacy-preserving authentication systems and is undergoing standardization by the W3C and IRTF. Schäge (Journal of Cryptology '15) gave a tight standard-model security proof under the q-SDH assumption for a less efficient variant of the scheme, called BBS+--here, q is the number of issued signatures. In contrast, the security proof for BBS (Tessaro and Zhu, EUROCRYPT '23), also under the q-SDH assumption, is \emph{not} tight. Nonetheless, this recent proof shifted both standardization and industry adoption towards the more efficient BBS, instead of BBS+, and for this reason, it is important to understand whether this tightness gap is inherent. Recent cryptanalysis by Chairattana-Apirom and Tessaro (ASIACRYPT '25) also shows that a tight reduction to q-SDH is the best we can hope for. This paper closes this gap in two different ways. On the positive end, we show a novel tight reduction for BBS in the case where each message is signed at most once--this case covers in particular the common practical use case which derandomizes signing. On the negative end, we use a meta-reduction argument to prove that if we allow generating multiple signatures for the same message, then {\em no} algebraic reduction to q-SDH (and its variants) can be tight.
Journal refIn: Daemen, J., Thome, E. (eds) Advances in Cryptology - EUROCRYPT 2026. Lecture Notes in Computer Science, vol 16541. Springer, Cham
DOI:10.1007/978-3-032-25291-3_9