In card-based cryptography for performing secure computation, after each player places an input commitment consisting of two face-down cards, all players cooperate to manipulate a sequence of cards according to a protocol. In the presence of a malicious player who does not follow the protocol, prior work has considered the active card-revealing attack and defined the t-secureness as the ability to prevent information about the input from being leaked even if at most t cards are turned over illegally. In this paper, we first propose an efficient 1-secure AND protocol: our proposed protocol uses only eight cards and one shuffle, whereas the existing protocol requires 16 cards and eight shuffles. Our 1-secure AND protocol is quite simple and easy to implement. We next design a committed-format 1-secure AND protocol by adding four more cards; a committed-format protocol produces its output in the same format as its inputs.
Card-based cryptography uses a physical deck of cards to achieve secure computations. To evaluate the performance of card-based protocols, the numbers of helping cards and shuffles required to execute are often used as evaluation metrics. In this paper, we focus on n -input AND protocols that use at most two helping cards, and investigate how many shuffles suffice to construct such a two-helping-card AND protocol. Since the Mizuki–Sone two-input AND protocol uses two helping cards and it can be repeatedly applied n - 1 times to perform a secure n -input AND computation, an obvious upper bound on the number of required shuffles is n - 1 . In this paper, to obtain better bounds (than n - 1 ), we consider making use of the “batching” technique, which was developed by Shinagawa and Nuida in 2020 to reduce the number of shuffles. Specifically, we first formulate the class of two-helping-card n -input AND protocols obtained by applying the batching technique to the Mizuki–Sone AND protocol, and then show n -input AND protocols requiring the minimum number of shuffles (among the class) for the case of 2 ≤ n ≤ 500 .
Path validation has been explored as an indispensable security feature for the future Internet. Motivated by the Path-Aware Networking Research Group (PANRG) under the Internet Engineering Task Force (IETF) and Internet Research Task Force (IRTF), it gives end-hosts more control over packet forwarding and ensures that the forwarding history is verifiable. The main idea is to require that routers add proofs in packet headers for other routers to verify. We identify linear-scale proofs as the essential efficiency barrier of existing path validation solutions. In this paper, we propose Atomos to validate network paths with constant-size proofs. To this end, we construct a noncommutative homomorphic asymmetric-key encryption scheme. Asymmetric cryptography minimizes the number of proofs needed and saves time in processing proofs. The homomorphism we design yields constant-size proofs. It limits the header-space overhead and outperforms existing linear-scale counterparts when the path length exceeds a value that is usually small. Furthermore, the proposed encryption scheme is noncommutative so that any deviation from the forwarding path can be detected. We explore a series of design strategies for security and efficiency. The evaluation results show that Atomos yields not only shorter proofs but also faster validation than existing solutions.
To produce human resources who are good at OT security is important task for KOSEN which is closely cooperation with the industry on which faces increasing cyber-attacks. We examined the educational effect and issues on multiple practicing of KIPS (Kaspersky Industrial Protection Simulation) which is based on gamification. Practicing experimental results showed that multiple playing simple contribute to the positive educational effect and we find the possibility of positive skill transfer, however we obtained a great future work which we need the educational contents that can fill the gap of multiple practicing effectively. KOSEN has the big mission that updates the practice-based curriculum constantly.
Consider the holiday season, where there are n players who would like to exchange gifts. That is, we would like to generate a random permutation having no fixed point. It is known that such a random permutation can be obtained in a hidden form by using a number of physical cards of four colors with identical backs, guaranteeing that it has no fixed point (without revealing the permutation itself). This paper deals with such a problem and improves the known result: whereas the known protocol needs O(n^2) cards of four colors, our efficient protocol uses only O(n log n) cards of two colors.
Ordered multisignature scheme is a signature scheme to guarantee both validity of an electronic document and its signing order. Although the security of most of such schemes has been proven in the random oracle model, the difficulty of implementation of the random oracle implies that the security should be proven without random oracles, i.e., in the standard model. A straightforward way to construct such schemes in the standard model is to apply aggregate signature schemes. However, the existing schemes based on the CDH problem are inefficient in the sense that the number of computations of the bilinear maps and the length of public keys depend upon the length of (a hash value of) the message. Therefore, in this paper, we propose a CDH-based ordered multisignature scheme which is provably secure in the standard model under a moderate attack model. Its computational cost for the bilinear maps and the size of public key are independent of the length of (a hash value of) the message. More specifically, in comparison with the existing schemes, the public key length is reduced to three group elements from 512 group elements while the computational cost is reduced to 0.85msec from 1.6msec.
Verifying the signing order is sometimes very important in multisignature schemes. A multisignature scheme in which the signing order can be verified is called structured multisignature scheme and many such schemes have been proposed so far. However, there are not many structured multisignature schemes utilizing an algebraic structure of underlying algebraic operation. Ohmori, Chida, Shizuya and Nishizeki have proposed a structured multisignature scheme by utilizing a non-commutative ring homomorphism. Since their scheme does not fully reflect the structure of signers and its rigorous security analysis is not provided, we construct an improved structured multisignature scheme overcoming these problems by utilizing the non-commutative ring homomorphism in a different way and discuss its rigorous security against various attacks, including signer structure forgery, rogue key attack and attack-0 under the discrete logarithm assumption. As far as we know, the scheme in [30], which does not use non-commutative ring homomorphism, guarantees the most rigorous security but the number of signers is restricted in order to prevent attack-0. In contrast, our scheme overcomes attack-0 by virtue of a ring homomorphism and no restriction is imposed on the number of signers.
In multisignature scheme, verifiying the signing order is sometimes very important. A multisignature scheme in which generated signatures reflect the structure of signers, e.g. signing order, is called structured multisignature scheme and many such schemes have been proposed so far. Structured multisignature schemes are dedicated to represent not only serial/parallel signer structures but also mixture of serial and parallel signer structures. In most structured schemes, the signature size depends on the number of signers. There are some structured schemes which can generate fixed-size signatures, but these schemes do not have order-flexibility, i.e. public keys arranged for one signer structure cannot be used for other signer structure. On the other hand, a sequential multisignature scheme is one type of structured multisignature schemes, which is dedicated to represent the serial signer structure. Some sequential multisig-nature scheme like sequential aggregate signature schemes can generate fixed-size signatures and have order-flexibility but no structured aggregate signature scheme has been proposed so far. In this paper, we construct a structured aggregate scheme which provides order-flexiblity, the fixed-size signature and applicability to mixed signer structures by extending the sequential aggregate signature scheme by Boldyreva et al.
Users’ signing order is an important factor in multisignature schemes. In fact the signing order often reflects signer’s rank in a signing group. So far, many multisignature schemes, called structured schemes, have been proposed that provide verifiability of the signing order associated with the structure of a group of signers. However, there are not many structured multisignature schemes utilizing an algebraic structure of underlying algebraic operation. In this paper, we adopt a non-commutative ring homomorphism for constructing a structured multisignature scheme and study the security of the constructed scheme under the discrete logarithm assumption.
In the purchase with electronic money customers are sometimes required to spend multiple electronic coins at a time. In case of physical coins a customer simply grabs multiple coins and hands them out to a merchant. Likewise, the customer spends multiple electronic coins just by giving all coins to the merchant. However, we can expect one step further in the electronic coins. There is room to create a combined coin from multiple coins. If the combining leads to an efficient spending, the customer as well as the merchant and the bank can get benefit of the reduction of cost. There is a proposal by Chaum for the combining operation in the online cash, but no method has been proposed for offline coins up to now. Thus we seek a way to spend offline electronic coins in a combined form without assistance of an issuing bank. The combining reduces either computational complexity associated with the spending or communication complexity between the customer and the merchant. We propose a method to achieve combining capability in the Eng-Okamoto offline divisible electronic cash, and show that (2n - 2)|p| - (n - 1)|q| bits of the message length can be reduced in the combining of n coins under the parameter of moduli p and q satisfying q|p-1. If preliminary computation is allowed, the verification cost is also slightly reduced. Significantly, even after combining coins, the bank can identify overspenders.
Intuitively, a function ƒ(fnof) is zero-way if, without a trapdoor, both computing ƒ and computing ƒ-1 are hard. We first point out that there exists a counterexample for the generic method to construct zero-way functions shown by Niemi-Renvall in Asiacrypt’94. We then give some examples of zero-way functions that are provably hard to compute, that is computing ƒ and ƒ-1 is proven to be as hard as breaking the Diffie-Hellman key exchange scheme or breaking the RSA cryptosystem.
Digital money, a digital substitute of physical money, has been extensively examined and developed in a past decade. Especially anonymous digital money has received much attention. Based on a thorough survey on digital money, mostly on anonymous digital money, we explain basic components and a history of digital money systems.
Qian-Ping Gu合作论文数Computing Science;Network Modeling Lab1