代理人再暗号化方式の安全性について
2
0
0
全文
(2) 情報処理学会第 73 回全国大会. fied by the proxy. Unfortunately, the [3] Weng, J., and Zhao, Y. On the security of a bidirectional proxy reMatsuda-Nishimaki-Tanaka PRE scheme encryption scheme from pkc 2010. violates this principle. Indeed, for a eprint (2010). ciphertext Ci = (vk, c1,i , c2 , c3 , τ, σ), the validity of vk, c2 , c3 , τ and σ can be ensured by checking whether SigVer(vk, (c2 , c3 , τ 0 ), σ) = 1 holds. However, it is impossible for the proxy to verify the validity of component c1,i : observe that in the encryption algorithm, component c1,i is not included in the generation of the one-time signature, and it will be transformed into c1,j in the re-encryption algorithm. Thus, the Matsuda-Nishimaki-Tanaka PRE scheme inevitably suffers from a chosenciphertext attack. Roughly speaking, an adversary can break the CCA-security of the Matsuda-Nishimaki- Tanaka PRE scheme as follows: Given the challenge ciphertext Ci? = (vk, c1,i∗ , c2 , c3 , τ, σ), the adversary can first modify the ciphertext component c1,i∗ to obtain a new (ill-formed) ciphertext Ci0∗ and then ask the re-encryption oracle to re-encrypt Ci0∗ into another ciphertext Cj0 for a corrupted user j (note that according to the security model, it is legal for the adversary to issue such a query); next, the adversary can modify Cj0 to obtain the right reencrypted ciphertext Cj of the challenge ciphertext, and thus he can obtain the underlying plaintext by decrypting Cj with user j 0 s secret key.. References [1] Matsuda, T., Nishimaki, R., and Tanaka, K. CCA Proxy ReEncryption without Bilinear Maps in the Standard Model. In Public Key Cryptography (2010), P. Q. Nguyen and D. Pointcheval, Eds., vol. 6056 of Lecture Notes in Computer Science, Springer, pp. 261–278. [2] Peikert, C., and Waters, B. Lossy trapdoor functions and their applications. In STOC (2008), C. Dwork, Ed., ACM, pp. 187–196.. 3-434. Copyright 2011 Information Processing Society of Japan. All Rights Reserved..
(3)
関連したドキュメント
In this study, we focused on the structural difference, and selected two analysis methods: (1) quantitative determination of reducing sugar obtained by enzymatic hydrolysis, and
② 現地業務期間中は安全管理に十分留意してください。現地の治安状況に ついては、
全体構想において、施設整備については、良好
年平均濃度 SO2,Ox, NO2)、mg/m3(SPM) 年平均濃度µg/m3 (PM2.5)、×0.1ppmC
問2-2 貸出⼯具の充実度 問3 作業場所の安全性について 問4 救急医療室(ER)の
ダイダン株式会社 北陸支店 野菜の必要性とおいしい食べ方 酒井工業株式会社 歯と口腔の健康について 米沢電気工事株式会社
協⼒企業 × ・⼿順書、TBM-KY、リスクアセスメント活動において、危険箇所の抽出不⾜がある 共通 ◯
分だけ自動車の安全設計についても厳格性︑確実性の追究と実用化が進んでいる︒車対人の事故では︑衝突すれば当