论文部分内容阅读
本文在通用可组合框架(universally composable framework,UC)下研究了基于一次签名的广播认证的问题.基于一次签名的广播认证的计算效率高,并能够实现即时认证,可以适用于能量受限的网络环境下广播消息的认证.在UC框架下,提出了基于一次签名的广播认证安全模型.在模型中形式化定义了一次签名理想函数F_(OTS)和广播认证理想函数F_(BAUTH).并且设计了广播通信的理想函数F_(BCOM)和多值注册理想函数F_(mREG).然后,在(F_(OTS),F_(mREG),F_(BCOM))-混合模型下设计了安全实现理想函数F_(BAUTH)的广播认证方案π_(BAUTH).同时,在UC框架下设计了安全实现F_(OTS)的一次签名算法HORS+;基于单向链构造了在F_(REG)-混合模型下安全实现F_(mREG)的协议OWC.在π_(BAUTH)的基础上组合协议HORS+和OWC,可以构造出新的一次签名的广播认证协议.根据组合定理,新的广播认证协议具有通用可组合的安全性,适用于能量受限网络中广播消息的认证.
This paper studies the one-signature-based broadcast authentication under the universally composable framework (UC) .The one-signature-based broadcast authentication is computationally efficient and enables real-time authentication and can be applied to energy-constrained networks Under the UC framework, this paper proposes a security model based on one-time signature for broadcast authentication, in which a signature ideal function F_ (OTS) and a radio authentication ideal function F_ (BAUTH) are formally defined in the model, and the design The ideal function F BCOM for multi-valued registration and the ideal m F F mREG for multivalued registration are presented.Furthermore, the ideal function for security is designed under the hybrid models F_ (OTS), F_ (mREG) and F_ (BCOM) (BAUTH) .At the same time, the HORS +, a secure signature F_ (OTS) algorithm, is designed under the framework of UC, and the secure implementation is implemented based on the unidirectional chain in F_ (REG) (MREG) protocol OWC.A new one-signature broadcast authentication protocol can be constructed by combining protocols HORS + and OWC on the basis of π_ (BAUTH). According to the combinatorial theorem, the new broadcast authentication protocol has universal combinatorial security Suitable for The amount of restricted authentication network broadcast message.