跳到主要內容

臺灣博碩士論文加值系統

(216.73.216.146) 您好!臺灣時間:2026/09/27 22:31
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:蔡靜芬
研究生(外文):Tsai Ching-Fen
論文名稱:適用於階層授權之門檻策略代理簽章方法
論文名稱(外文):Threshold proxy signature in hierarchical authorization
指導教授:吳宗成
指導教授(外文):Wu Tzong-Chen
學位類別:碩士
校院名稱:國立臺灣科技大學
系所名稱:資訊管理系
學門:電算機學門
學類:電算機一般學類
論文種類:學術論文
論文出版年:2000
畢業學年度:88
語文別:中文
論文頁數:60
中文關鍵詞:授權、代理簽章、門檻策略代理簽章、階層授權、優先順序、離散對數問題、單向雜湊函數
外文關鍵詞:(t、n) threshold proxy signature、authorization、hierarchical authorization
相關次數:
  • 被引用被引用:0
  • 點閱點閱:366
  • 評分評分:
  • 下載下載:27
  • 收藏至我的研究室書目清單書目收藏:0
1996年,Mambo等人首先提出代理簽章(proxy signature)方法。所謂的代理簽章方法是指代理簽署者(proxy signer)在原始簽署者(original signer)的授權下,可以代表原始簽署者執行簽署任務。代理簽章方法實現了管理上的組織授權,而為達到風險分攤的目的,Kim等人藉由秘密分享(secret sharing)技術提出了 門檻策略代理簽章(threshold proxy signature)方法。所謂的 門檻策略代理簽章方法是指在原始簽署者所授權的 個人之代理群組(proxy group)中,任t個以上的代理簽署者一起合作,即可產生有效的代理簽章。
然而當 門檻策略代理簽章於實務運作時,由於代理群組內的成員不一定都是available,故可能該群組無法湊出 個代理簽署者以共同合作執行簽署。在此情況下,代理群組原本的任務為在門檻策略下代理原始簽署者執行簽署,然而代理群組卻因為無法湊出 個成員,而使得代理任務無法完成,也因此失去其代理的意義。而且當代理群組內non-available的成員越多時,此情況發生的機率越高。為避免發生此情形,解決的方法為由原始簽署者將代理群組內成員的代理權限往下授予給其各自的代理群組並訂定各自的門檻策略。當任何一個代理群組內之代理簽署者的權限皆可以往下授予給各自的代理群組時,則形成一個具階層的授權架構(hierarchical authorization)。在此種授權情況下,因為代理簽署者的代理權限可往下授予,故為與其它代理簽章方法有所區別,本論文另定義其名稱為授權代理簽署者(authorized proxy signer)。
由於目前學術界對授權簽署之探討,只著眼於指定代理人的代理簽章與門檻策略代理簽章,尚未有人考量適用於階層授權之門檻策略代理簽章,因而我們以此為研究動機,提出解決方法。
本方法中,原始簽署者依組織內授權代理簽署者的優先順序(priority)與從屬關係定義一個階層的授權架構。在此架構中除了原始簽署者有自己的代理群組與門檻外,每位授權代理簽署者的代理權限亦可往下授予給自己的代理群組,並擁有自己的門檻。在授權期間內,一旦有人要求原始簽署者執行簽署時,即由授權架構內的成員依照授權策略共同地完成代理簽署任務。本方法的安全性是碁建於離散對數問題(discrete logarithm problem, DLP)與單向雜湊函數(one-way hash function, OWH)兩個密碼假設。本方法具有以下三個特點:(1)授權代理簽署者的代理權限可往下授予給自己的代理群組,並擁有自己的門檻策略(2)因為驗證時需要使用active授權代理簽署者的公鑰,所以這些active授權代理簽署者是非匿名的(3)本方法達到簽署的不可否認性。
Proxy signature scheme, introduced by Mambo et al. in 1996, allow a designated person, a proxy signer, to sign messages on behalf of an original signer. After that, Kim et al. presented another new type of proxy signature scheme, called (t,n) threshold proxy signature scheme. That scheme allows t or more proxy signers from a designated group of proxy signers to sign messages on behalf of the original one.
The (t,n) threshold proxy signature scheme conceptualized from Kim''s one has a drawback in practical applications. That is, the proxy group might not find t proxy signers to sign messages on behalf of the original signer, since not all proxy signers of the proxy group are always ready and available for signing messages.
The solution to eliminate above drawback is to let proxy signers have their proxy groups with their threshold policies. As any proxy signer belonging to any proxy group can have his/her proxy group, the structure of authorization will form a hierarchy.
So far, the proposed (t,n) threshold proxy signature schemes have the limitation on that only the original singer has his/her proxy group. Therefore it''s not suitable for a hierarchical authorization. Inspiration from the above practical operation, we propose a new proxy signature scheme called threshold proxy signature in hierarchical authorization. In our scheme, not only does the original signer have his/her proxy group but each proxy signer in any proxy group can also have his/her one. Differing from other proxy signature schemes, we refer to a proxy signer as an authorized proxy signer, since his/her authority can be delegated to his/her proxy group.
The proposed scheme has the following properties:
1. The authority of an authorized proxy signer can be delegated to his/her proxy group.
2. The actual signers are known and identified.
3. It is nonrepudiable.
中文摘要 i
英文摘要 iv
誌謝 vi
目錄 vii
第一章 緒論 1
1.1 研究背景與動機 1
1.2 研究目的 8
1.3 論文架構 9
第二章 相關研究文獻回顧 10
2.1 Kim等人之(t, n)門檻策略代理簽章方法 13
2.2 Sun之具簽署者身分的(t, n)門檻策略代理簽章方法 16
第三章 適用於階層授權之門檻策略代理簽章方法 20
3.1 系統模式 21
3.2 簽署與驗證演算法 24
3.3 正確性分析 36
第四章 安全性與效率性分析 39
4.1 安全性分析 39
4.2 效率性分析 45
第五章 結論與未來研究方向 49
5.1 結論 49
5.2 未來研究方向 50
參考文獻 52
附錄A 重要名詞之英、中文對照表 56
參考文獻
[Cam98] J. Camenish, "Group signature schemes and payment systems based on the discrete logarithm problem. PhD thesis", ETH Zurich, 1998
[CM97] J. Camenisch, and M. Stadler, "Efficient group signature schemes for large groups", Advances in Cryptology - CRYPTO''97, 1997, pp. 410-424.
[CM99] J. Camenisch, and M. Michels, "Separability and efficiency for generic group signature schemes", Advances in Cryptology - CRYPTO''99, 1999, pp. 413-430.
[CS97] J. Camenisch, and M. Stadler, "Efficient group signature schemes for large groups", Advances in Cryptology - CRYPTO''97, 1997, pp. 410-424.
[DSS91] National Institute of Standards and Technology (NIST), "A proposal federal information processing standard for digital signature standard (DSS)", Federal Register 56, No. 169, 1991, pp. 42980-42982.
[ElG85] T. ElGamal, "A public key cryptosystem and signature scheme based on discrete logarithms", IEEE Transactions on Information Theory, Vol. IT-31, No. 4, 1985, pp. 469-472.
[Har94] L. Harn, "Group-oriented threshold digital signature scheme and digital multisignature", IEE Proceedings Computers Digital Techniques, Vol. 141, No. 5, 1994, pp.307-313.
[HY93] L. Harn, and S. Yang, "Group-oriented undeniable signature schemes without the assistance of a mutually trusted party", Advances in Cryptology - AUSCRYPT''92, Springer-Verlag, 1993, pp. 133-142.
[KPW97] S. Kim, S. Park, and D. Won, "Proxy signature, revisited", ICICS''97, Lecture Notes in Computer Science, Springer-Verlag, 1997, pp. 223-232.
[Lan95] S.K. Langford, "Threshold DSS signatures without a trusted party", Advances in Cryptology - CRYPTO''95, Springer-Verlag, 1995, pp. 397-405.
[MOI90] S. Miyaguchi, K. Ohta, and M. Iwata, 蕐-bit hash function (N-Hash)", Proceedings of SECURICOM''90, 1990, pp. 127-137.
[MUO96a] M. Mambo, K. Usuda, and E. Okamoto, "Proxy signatures: delegation of the power to sign messages", IEICE Transactions Fundamentals, Vol. E79-A, No. 9, 1996, pp. 1338-1354.
[MUO96b] M. Mambo, K. Usuda, and E. Okamoto, "Proxy signature for delegating signing operation", Proceedings Third ACM Conference On Computer and Communications Security, ACM press, 1996, pp 48-57.
[Neu93] B. C. Neuman, "Proxy-based authorization and accounting for distributed systems", Proceedings 13th International Conference on Distributed Systems, 1993, pp.283-291.
[NIST92] "The digital signature standard proposed by NIST", Communications of the ACM, Vol. 35, No. 7, 1992, pp. 36-40.
[NIST93] National Institute of Standards and Technology, NIST FIPS PUB 180, "Secure hash standard", U. S. Department of Commerce, 1993.
[Ped91] T. Pedersen, "Distributed provers with applications to undeniable signatures", Proceedings EUROCRYPT''91, Lecture Notes in Computer Science, Berlin, 1991 pp. 221-238.
[SC99] H. M. Sun, and B. J. Chen, "Time-stamped proxy signatures with traceable receivers", 第九屆全國資訊安全會議論文 集, 1999, pp. 247-253.
[SH99] H. M. Sun, and B. T. Hsieh, "Remarks on two nonrepudiable proxy signature schemes", 第九屆全國資訊安全會議論 文集, 1999, pp. 241-246.
[SLH99] H. M. Sun, N. Y. Lee, and T. Hwang, "Threshold proxy signatures", IEE Proceedings Computers Digital Techniques, Vol. 146, No. 5, 1999, pp. 254-261.
[Sun99a] H. M. Sun, "An efficient nonrepudiable threshold proxy signature scheme with known signers", Computer Communications, Vol. 22, No. 8, 1999, pp. 717-722.
[Sun99b] H. M. Sun, "Convertible proxy signature scheme", 1999全國計算機會議, 1999, pp. 186-189.
[UMUO96] K. Usuda, M. Mambo, T. Uyematsu, and E. Okamoto, "Proposal of an automatic signature scheme using a compiler", IEICE Transactions Fundamentals, Vol. E79-A, No.1, 1996, pp. 94-101.
[VAB91] V. Varadharajan, P. Allen, and S. Black, "An analysis of the proxy problem in distributed systems", Proceedings 1991 IEEE Computer Society Symposium on Research in Security and Privacy, 1991, pp. 225-275.
[Zha97] K. Zhang, "Threshold proxy signature schemes", Information Security Workshop, Japan, 1997, pp. 191-197.
[李陳99] 李國熙/陳永旺譯, "電子商務與網路安全", 歐萊禮出版商, 1999.
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top