跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.177) 您好!臺灣時間:2026/08/13 01:42
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:李志豪
研究生(外文):Chi-Hao Lee
論文名稱:一個植基於因數分解和離散對數雙重難題的公平盲簽章及其在網際網路安全的電子付款系統設計之應用
論文名稱(外文):A Factoring and Discrete Logarithm Based Fair Blind Signature and Its Application on the Design of a Secure Electronic Payment System
指導教授:林秀峰林秀峰引用關係
指導教授(外文):Hsiu-Feng Lin
學位類別:碩士
校院名稱:逢甲大學
系所名稱:電子工程所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2002
畢業學年度:90
語文別:中文
論文頁數:54
中文關鍵詞:盲簽章公平盲簽章雙重難題離散對數問題分解因數問題電子付款系統。
外文關鍵詞:Blind SignatureFair Blind SignatureFactoring problemDiscrete logarithm problemElectronic Payment SystemDouble hard problems
相關次數:
  • 被引用被引用:0
  • 點閱點閱:211
  • 評分評分:
  • 下載下載:13
  • 收藏至我的研究室書目清單書目收藏:1
盲簽章可以有效的應用在例如電子付款及電子投票等匿名的電子環境中。它有兩個特性:(1)簽章者不知道所要簽署的文件內容(2)簽章者事後看到簽章也無法追蹤此簽章是在何時對何者所簽署的。1995年,Sadler等三位學者發現盲簽章應用在商業行為上可能發生勒索或洗錢的犯罪問題。因此,提出了公平盲簽章的觀念及演算法來防止。
早期所發表的公開金匙密碼系統及簽章系統,其安全性都是維繫在某一個目前尚未有有效解法的難題,例如離散對數問題及分解因數問題…等。然而,由於近年來電腦系統的運算能力快速提升,相對的降低了這些僅繫於單一難題的密碼系統之安全性。因此,有人提出了植基於雙重或多重難題的密碼系統以為因應。1998年,Shao提出了兩個號稱安全性植基於離散對數及分解因數雙重難題的簽章技術。但是,Lee在1999年證明Shao的簽章系統事實上只與解離散對數的困難度有關。
本論文首先改良Shao的簽章系統,使其安全性確實植基於解離散對數及分解因數的雙重難題。其次,根據改良的系統,我們進一步的提出一個植基於離散對數及分解因數雙重難題的公平盲簽章並分析其安全性。據我們所知,本論文所提出的公平盲簽章是第一個安全性植基於雙重難題的公平盲簽章。
最後,我們將所提的公平盲簽章技術應用於Camenisch等三位學者在1996年所提出的公平電子付款系統中。使得系統中的顧客更有保障。
The security of most previously suggested public-key cryptographic systems is based upon a single computationally hard problem, such as the factoring problem or the discrete logarithm problem etc. however, they will no longer be secure if the corresponding hard problem is solved in the future. A significant solution to the problem is to develop cryptographic systems whose securities are based on solving several different hard problems simultaneously. In 1998, Shao proposed two signature schemes and claimed that their securities are based on both the factoring problem and the discrete logarithm problem. Nevertheless, it was shown by Lee in 1999 that Shao’s schemes can be broken if one can only solve the factoring problem.
In this thesis, we first give an improvement of Shao’s schemes and show that the presented scheme is indeed secure unless both the factoring problem and the discrete logarithm problem are solved simultaneously.
Based upon the presented improvements. We further proposed the first fair blind signature of which the security is also based on computing both the factoring problem and the discrete logarithm problem simultaneously.
Blind signatures provide two interesting properties: blindness (i.e., the signer shouldn’t have any idea about the content of messages he signs) and unlinkability (i.e., when the signer gets the message and the signature later, he can’t learn or trace when or for whom this signature is produce). Accordingly, blind signatures are often used in anonymous digital payment applications. However, due to the unlinkability property, such payment systems could be misused by criminals, e.g., to safely obtain an ransom or to launder money. Fair blind signatures are then developed to cope with the misuse of unlinkability. They have the additional property that, with the help of a trusted entity, it is possible for the signer to link his view of the protocol and the message-signature pair.
Accordingly, based upon our proposed fair blind signature, we finally develop a new digital payment system. It is pointed out that our developed system is more flexible and robust than other previously suggested systems.
中文摘要…………………………………………………………………...Ⅰ
英文摘要……………………………………………….…………………..Ⅲ
誌謝………………………………………………………………………...Ⅴ
目錄………………………………………………………………………...Ⅵ
圖目錄……………………………………………………………………...Ⅷ
縮寫及符號對照表………………………………………………………...Ⅸ
第一章緒論………………………………………………………………...1
1.1 數位簽章技術和其應用之回顧……………………………...1
1.2 研究動機……………………………………………………...3
1.3 論文架構……………………………………………………...6
第二章Shao的改良式數位簽章…………………………………………..7
2.1 回顧Shao的數位簽章………………………………………..7
2.2 回顧Lee的證明………………………………………………8
2.3 Shao的數位簽章的改良………….………………………….10
2.3.1 二次剩餘回顧………………………………………...10
2.3.2 改良的數位簽章……………………………………...15
2.3.3 安全性分析…………………………………………...17
第三章植基於分解因數和離散對數雙重難題之公平盲簽章………….20
3.1 植基於雙重難題的公平盲簽章…………………………….20
3.2 安全性分析………………………………………………….25
第四章公平電子付款系統……………………………………………….29
4.1 電子付款系統的介紹與回顧……………………………….29
4.2 公平電子付款系統的改善………………………………….33
4.3 比較與分析………………………………………………….35
第五章結論……………………………………………………………….36
5.1 研究結果…………………………………………………….36
5.2 未來的研究方向…………………………………………….36
參考文獻…………………………………………………………………...37
附錄………………………………………………………………………...48
作者簡介…………………………………………………………………...54
[1]E. Brickell and K. Mccurley, “An interactive identification scheme base- d on discrete logarithms and factoring”, J.Cryptol.1992, 5(1), pp.29-39.[2]W.J. Caelli, E.P. Dawson and S.A. Rea, “PKI, Elliptic Curve Cryptogra- phy and Digital Signatures”, Computers and Security, vol.18, pp.47-66, 1999.[3]D. Chaum and H.V. Antwerpen, “Undeniable Signatures”, Advances in Eurocrypt’89, pp.212-216, 1989.[4]D. Chaum, “Zero-Knowledge Undeniable signatures”, Advances in Cry- ptography: Eurocrypt’90, pp.458-464, 1990.[5]D. Chaum, “Designated Confirmer Signatures”, Advances in Cryptogra- phy: Eurocrypt’94, pp.86-91, 1995.[6]J.L. Carmenisch, J.M. Piveteau and M.A. Stadler, “Blind Signature on t-he Discrete Logarithm Problem”, Advances in Cryptology: Eurocrypt’94, Perugia, Italy, pp.428-432, 1994.[7]D. Chaum, “Blind Signature Systems”, Proceeding of Crypto’88, Plenu-m, pp.153.[8]D. Chaum, A. Fiat and M. Naor, “Untraceable Electronic Cash”, Procee-ding of Crypto’88, LNCS 403, Springer Verlag, pp.319-327.[9]J. Camenisch, J.M. Piveteau and M. Stadler, “An efficient fair payment system”, 3rd ACM Conference on computer Communications Security, pp.88-94, 1996.[10]B. Clifford Neuman, “Security, Payment and Privacy for Network Com-merce”, IEEE Journal on Selected Areas in Communications, vol.13, No.8, pp.1523-1531, Oct. 1995.[11]Z.D. Dai, J.H. Yang, D.F. Ye and G. Gong, “Cryptanalysis of Wang’s ori-ginal and revised digital signature scheme”, Electronics Letters, Vol.37, No.4, pp.220, 2001.[12]Y. Desmedt and Y. Frankel, “Shared generation of authenticators and si-gnatures”, Advances in Cryptology: Crypto’91, pp.457-469, 1992.[13]W. Diffie and M.E. Hellman, “New Directions in Cryptography”, IEEE Transactions on Information Theory, Vol.IT-22, No.6, pp.644-654, Nov.1976.[14]S. Dukach, “SNPP: A Simple Network Payment Protocol”, Computer S-ecurity Applications Conference, 1992.[15]T. EIGamal, “A public key Cryptosystem and a signature scheme based on discrete logarithms”, IEEE Transactions on Information Theory, Vol.31, No.4, pp469-472, 1985.[16]S. Even, O. Goldreich and A. Lempel, “A Randomized Protocol for Sig-ning Contracts, Communications of the ACM, 28, pp.637-647, 1985.[17]C.I. Fan and C.L. Lei, “User Efficient Blind Signatures”, Electronics Le-tters, Vol.34, No.6, pp544-546, 1998.[18]C.I. Fan and C.L. Lei, “Low-computation partially blind signatures for electronic cash”, IEICE Trans. Fundamentals, Vol.E-81-A, No.5, pp.818-824, 1998.[19]C.I. Fan and C.L. Lei, “A User Efficient Fair Blind Signature Scheme f-or Untraceable Electronic Cash”, Journal of Information Science and E-ngineering 18. 41-46, 2002.[20]A. Fiat and A. Shamir, “How to rpove yourself: Practical solutions to id-entification and signature problems”, Proceeding of Crypto’86, LNCS 263, Springer Verlag, pp.186-194.[21]W.H. He, “Digital signature scheme based on factoring and discrete log-arithms”, Electronics Letters, Vol.37, No.4, pp.220-222, 2001.[22]T. Hardjono and Y. Zheng, “A Practical Digital Multisignature SchemeBased on Discrete Logarithms”, Advances in Cryptology: Asiacrypt’92,Spring-Verlag, New York, pp.123-132, 1993.[23]L. Harn, “Digital multisignature with distinguished signing authorities”, Electronics Letters, Vol.35, No.4, pp.294-295, 1999.[24]L. Harn, “Group-oriented (t,n) threshold digital signature scheme and di-gital multisignature”, IEE Proc. Computers and Digital Techniques, Vol.141, No.5, pp.307-313, 1994.[25]L. Harn and S. Yang, “Group-Oriented Undeniable Signature Schemes without the Assistance of a Mutually Trusted Party”, Advances in Crypt-ograph: Auscrypt’92, pp.133-142, 1992.[26]L. Harn, “Public-Key Cryptosystem Design Based on Factoring and Di-screte logarithms”, IEE Proc, Comput. Ditig Tech, 141, (3), pp.193-195,1994.[27]J. He and T. Kiesler, “Enhancing the security of EIGamal’s signature sc-heme”, IEE Proc, Comput. Digit Tech, 144, (4), pp.249-252, 1994.[28]P. Horster, M. Michels and H. Petersen, “Meta Message Recorery and Meta Blind Signature Schemes Based on the Discrete Logarithm Proble-m and Their Applications”, Pre-Proceeding Asiacrypt’94, pp.185-196.[29]L. Harn, “Cryptanalysis of the blind signatures based on the discrete lo-garithm problem”, IEE, Electronics Letters, Volume: 31 Issue: 14, pp.1136, 6 July 1995.[30]P. Horster, Michels and H. Petersen, “Cryptanalysis of the blind signatu- res based on the discrete logarithm problem (comment)”, IEE, Electroni-cs Letters, Volume: 31 Issue: 21, pp.319-327, 12 Oct 1995.[31]K. Ireland and M. Rosen, A Classical Introduction to Modern Number T-heory. 2nd ed. New York: Spring-Verlag, 1992.[32]W.S. Juang and C.L. Lei, “Blind threshold signatures based on discrete logarithm”, Proc. Second asian computing Science Conference on Netw- orking and Security, LNCS 1179, Springer, New York, pp.172-181, 1996.[33]W.S. Juang and C.L. Lei, “Partially blind threshold signatures based on discrete logarithm”, Computer Communications, Vol.22, No.1, pp73-86, 1999.[34]N.Y. Lee, “Security of Shao’s signature schemes based on factoring and discrete logarithms”, IEE Proc. Comput. Digit. Tech, Vol.146, No.2, pp.119-121, 1999.[35]Z. Li and Y. Yang, “EIGamal’s multisignature digital signature scheme”, Journal of Beijing University of Posts and Telecommunications, Vol.22, No.2, pp.30-34, 1999.[36]Z.C. Li, L.C.K. Hui, K.P. Chow, C.F. Chong, W.W. Tsang and H.W. Ch-an, “Cryptanalysis of Harn digital multisignature with distinguished sig-ning authorities”, Electronics letters, Vol.36, No.4, pp.314-315, 2000.[37]J. Li and G.Xiao, “Improvement on a new convertible undeniable signat-ure scheme”, Journal of Xidian University, Vol.26, No.1, pp.24-35, 1999.[38]N.Y. Lee and T. Hwang, “Group-oriented undeniable signature schemes with a trusted center”, Computer Communications, Vol.22, No.8, pp.730-734, 1999.[39]H.W. Lee and T.Y. Kim, “fair blind signature with message recovery ba-sed on oblivious transfer protocol”, Journal of KISS(A) (Computer syst-ems and Theory), Vol.26, No.4, pp.455-463, 1999.[40]N.Y. Lee and T. Hwang, “On the security of fair blind signature scheme using oblivious transfer”, Computer Communications, Vol.22, No.3, pp.287-290, 1999.[41]N.Y. Lee and T. Wang, “Modified Harn signature scheme based on fact-orizing and discrete logarithms”, IEE Proc, Comput. Digit. Tech, 143, (3), pp.196-198, 1996.[42]M. Michels and P. Horster, “On the risk of disruption in several multipa-rty signature schemes”, Advances in Cryptology: Asiacrypt’96, pp.334-345, 1997.[43]K. Miyazaki and K. Takaragi, “A threshold digital signature scheme for a smart caard based system”, IEICE Trans. Fundamentals, Vol.E-84-A, No.1, pp.205-213, 2001.[44]M. Mambo, E. Okamoto and K. Usuda, “Prosy signatures for delegating signing operation”, 3rd ACM Conf. On computer and Communication S-ecurity, 99.48-57, 1996.[45]M. Mambo, K. Usuda and E. Okamoto, “Proxy signatures: Delegation of the power to sign messages”, IEICE Trans. Fundamentals,Vol.E-79-A, No.9, pp.1339-1354, 1996.[46]K. Mccurley, “A key distribution system equivalent to factoring”, J.Cry-ptol.1998, (2), pp.95-106.[47]K. Nyberg, “New digital signature scheme based on discrete logarithm (comment)”, Electronic Letter, 30, (6), pp.481, 1994.[48]K. Ohta and T. Okamoto, “A Ditigal Multisignature Scheme Based on t-he Fiat-Shamir Scheme”, Advances in Cryptology: Asiacrypt’91, Sprin-ger-Verlag, NewYork, pp.122-132, 1991.[49]T. Okamoto, “A Digital Multisignature Scheme Using Bijective Public Key Cryptosystem”, ACM Transactions on Computer Systems, Vol.6, No.8, pp.432-441, 1988.[50]R.L. Rivest, A. Shamir and L. Adelman, “A method for obtaining digital signature and public key cryptosystem”, Communications of the ACM, Vol.21, No.2, pp.120-126, 1978.[51]M.O. Rabin, “Digitalized signatures and Public-key functions as intract-able as factorization”, Technical Report LCS/TR212, Cambridge MA:MIT, 1979.[52]R.L. Rivest, A. Shamir and L. Adelman, “A method for obtaining digital signatures and public-key cryptosystem”, Commum. ACM, 21(2), pp.120- 126, 1978.[53]K.H. Rosen, Elementary Number Theory and It’s Applications, 2nd td.Addision Wesle, 1988.[54]Z. Shao, “Signature schemes based on factoring and discrete logarithms”, IEE Proc. Comp. Digit. Tech, Vol.145, No.1, pp.33-36, 1998.[55]Z. Shao, “Improved user efficient blind signatures”, Electronics Letters, Vol.36, No.16, pp.1372-1374, 2000.[56]M. Stadle, J.M. Piveteau and J. Camenisch, “Fair Blind Signatures”, Ad-vances in Cryptology: Eurocrypt’95, pp.209-219, 1995.[57]H.M. Sun, N.Y. Lee and T. Hwang, “Threshold proxy signatures”, IEE Proc. Comp. Digit. Tech, Vol.146, No.5, pp.259-263, 1999.[58]H.M. Sun, “An efficient nonrepudiable threshold proxy signature sche-me with known signers”, Computer Communications, Vol.22, No.8, pp.717-722, 1999.[59]S. von Solms, D. Naccache, “On blind signature and perfect crime”, co- mputer security, 11, 1992.[60]Y.M. Tseng and J.K. Jan, “Attacks on threshold signature scheme with t-raceable signers”, Information Processing Letters, Vol.71, No.1, pp.205-213, 2001.[61]X.M. Wang, “Modification of the digital signature scheme based on err-or-correcting codes”, Acta Electronica Sinica, Vol.28, No.2, pp.110-112, 2000.[62]T.C Wu, C.C. huang and D.J. Guan, “Delegated multisignature with doc-ument decomposition”, The Journal of Systems and Software, Vol.55, pp.321-328, 2001.[63]C.T. Wang, C.H. Lin and C.C. Chang, “Threshold signature schemes wi- th traceable signers in group communications”, Computer Communicati-ons, Vol.21, No.8, pp.771-776, 1998.[64]S.M. Yen and C.S. Laih, “Fast algorithms for LUC digital signature co-mputation”, IEE Proc-Comput. Digit. Tech. Vol.142. No.2, March 1995.[65]L. Yi, G. Bai and G. Xiao, “Proxy multi-signature scheme: A new type of proxy signature scheme”, Electronics Letter, Vol.36, No.6, pp.527-528, 2000.[66]“The digital signature standard proposed by NIST”, Communications of the ACM, Vol.35, No.7, pp.36-40, 1992.[67]Secure Electronic Transaction (SET) Specification: Book 1. Business D-escription (draft for testing), Visa International & MasterCard Internatio-nal, June 1996.[68]Secure Electronic Transaction (SET) Specification: Book 2. Programme-r’s Guide (draft for testing), Visa International & MasterCard Internatio-nal, June 1996.[69]Secure Electronic Transaction (SET) Specification: Book 3. Formal Pro-tocol Definition (draft for testing), Visa International & MasterCard Int-ernational, June 1996.[70]ITU Rec. X.509 (1993)|Iso/IEC 9594-8: 1995, Information Technology─Open systems Interconnection─The Directory: Authentication Framework, including Draft Amendment 1: Certificate Extensions (Version 3certificate), ISO/IECJTC1/SC21/WG4(April 1996).[71]曾育民,數位簽章之類型及應用,資訊安全通訊Vol.7 No.3, 2001[72]賴溪松、韓亮、張真誠,近代密碼學及其應用,松崗,84年 9月。
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top