Revocation in Anonymous Authetication Systems
Fueyo Pestaña, Maria do Mar Rosa · 2015
An attribute-based signature with respect to a signing policy chosen by the signer, convinces the verifier that the signer sustains a subset of attributes satisfying that signing policy. The verifier must not obtain any other information about the identity of the signer or the attributes he holds. This type of signatures have a lot of applications in real life scenarios that demand both authentication and privacy properties. The ability of revoking users that have misbehaved or lost their attributes, so that they can not compute more valid signatures, is very desirable for real life applications of attribute-based signatures. In this project, the main goal consists in studying different protocols of revocation and incorporating them into an already existing RSA attribute-based signature. In order to achieve these objectives, two different protocols were chosen from those available in the literature, taking into account the efficiency of the existing protocols and the necessity that the protocol is built in an anonymous way: the user must not reveal his identity when proving that he is not in the revocation list. The first one is based on a polynomial evaluation argument, and some of its main advantages are that this argument has logarithmic communication cost in the number of revoked users in contrast to other protocols with cubic root complexity at best, thus obtaining a more efficient protocol and besides its security relies only on the discrete logarithm assumption. The second one was based on a protocol for special cases when the revoked elements are coprime, since in the attribute based signature the elements are prime, this protocol was considered suitable. While demonstrating its soundness it was found that the original protocol was not secure because we found a particular attack (that we describe in this work). Thus, a new secure protocol was designed which fits with the attribute-based signature. Finally, the previous protocols have been incorporated into an existing RSA attribute-based signature scheme, and both resulting signatures have been analyzed in terms of efficiency of the communication cost. The second protocol is shown to be always more efficient than the first one, even for the case with a single revoked user.