AI 中文总结
该研究提出一种无证书的协议,通过单向视觉通道和硬件证明,实现两个移动设备对文档的互共同签名,消除循环签名依赖,完成了实例实现与安全验证。
AI 中文摘要
我们描述并分析了一种由两个移动设备对文档进行互共同签名的协议,该协议满足以下条件:(i)仅通过单向、有损、低带宽的光学通道(由对方相机读取的屏幕上的动画代码)进行通信;(ii)信任路径上不使用中介服务器;(iii)不使用证书机构。各方公钥的信任基于平台安全元件生成的硬件证明令牌,该令牌通过无速率(喷泉)码完整地在视觉通道上传输,并以密码方式绑定到共同签名中。核心技术贡献是一种两阶段哈希锚,它消除了交互式共同签名固有的循环签名依赖:第一方在知晓第二方身份之前对文档做出承诺,之后将第二方身份绑定到该承诺而不会使第一签名无效。我们给出了威胁模型,定义了四项安全属性(锚绑定、共同签名不可分离、证明绑定密钥来源以及签名后篡改证据),并将其归约为标准假设(H 的抗碰撞性和底层签名方案的 EUF-CMA 安全性),其中安全元件被建模为理想签名预言机。我们报告了在 iOS/Android 上使用 Secure Enclave/StrongBox 中的 ECDSA P-256、SHA-256、Apple App Attest / Play Integrity 以及 LT 型喷泉码实现的可用实例,以及一个独立第三方验证器,该验证器可完全离线重新计算所有锚并检查两个签名。
英文摘要
We describe and analyze a protocol for mutual co-signing of a document by two mobile devices that (i) communicate only over a one-way, lossy, low-bandwidth optical channel (an animated on-screen code read by the counterparty's camera), (ii) use no intermediary server on the trust path, and (iii) use no certificate authority. Trust in each party's public key is instead grounded in a hardware attestation token produced by the platform secure element, transported in full over the visual channel by a rateless (fountain) code and cryptographically bound into the co-signature. The core technical contribution is a two-stage hash anchor that removes the circular signing dependency inherent to interactive co-signing: the first party commits to the document before the identity of the second party is known, and the second party's identity is later bound to that commitment without invalidating the first signature. We give a threat model, define four security properties (anchor binding, co-signature inseparability, attestation-bound key provenance, and post-signing tamper evidence) and reduce them to standard assumptions (collision resistance of H and EUF-CMA security of the underlying signature scheme), with the secure element modeled as an ideal signing oracle. We report a working instantiation on iOS/Android using ECDSA P-256 in the Secure Enclave/StrongBox, SHA-256, Apple App Attest / Play Integrity, and an LT-style fountain code, together with an independent third-party verifier that recomputes all anchors and checks both signatures fully offline.
Comments20 pages, 3 figures. Also available at Zenodo, doi:10.5281/zenodo.22055260