高级检索

    RCCA安全的支持等式测试的SM9标识加密方案

    RCCA Secure Identity-Based SM9 Encryption Scheme with Equality Test

    • 摘要: 在云计算环境中,等式测试有效解决了加密数据无法进行底层明文比较的问题,其中支持等式测试的标识加密算法(identity-based encryption with equality test,IBEET)有效简化了传统公钥加密的证书管理,具有重要价值。我国自主研发的SM9加密算法已入选ISO/IEC国际标准,但现有基于SM9的等式测试方案普遍难以抵抗颠覆攻击,即通过篡改随机数生成方式,掌握后门密钥的敌手可恢复明文从而破坏算法的安全性。针对该问题,提出了一种RCCA安全的支持等式测试的SM9标识加密方案(relaxed chosen-ciphertext attack secure identity-based SM9 encryption scheme with equality test,RCCA-SM9-IBEET),通过部署密码逆向防火墙(cryptographic reverse firewalls,CRF)重随机化用户输入/输出信息来抵抗颠覆攻击;然后定义了OW-ID-RCCA(one-way chosen-ciphertext security against a relaxed chosen identity attack)安全模型,支持密文可重随机化以兼容逆向防火墙;同时在随机谕言机模型下给出了安全证明。最后,从理论与实验2个维度对方案的计算成本和通信成本进行了分析。

       

      Abstract: In cloud computing environments, equality test can effectively address the challenge of comparing whether two ciphertexts are encrypted under the same plaintext without decryption. Among existing schemes, identity-based encryption with equality test (IBEET) significantly simplifies certificate management compared with traditional public-key encryption schemes, demonstrating considerable value. While China’s independently developed SM9 encryption algorithm has been successfully selected as an ISO/IEC international standard, existing SM9-based equality test schemes generally remain vulnerable to subversion attacks. Specifically, by subverting the randomness generation process, an adversary in possession of a backdoor key can recover the plaintext, thereby compromising the security of the scheme. To address this issue, an RCCA (relaxed chosen-ciphertext attack) secure identity-based SM9 encryption scheme with equality test (RCCA-SM9-IBEET) was proposed. The scheme employs cryptographic reverse firewalls (CRF) to re-randomize the inputs and outputs of potentially compromised users, thereby resisting subversion attacks. Furthermore, we define the concept of OW-ID-RCCA (one-way chosen-ciphertext security against a relaxed chosen identity attack) security model, which supports ciphertext re-randomization for compatibility with the reverse firewalls. A rigorous security proof is provided in the random oracle model. Finally, we analyze the computational and communication costs of the proposed scheme from both theoretical and experimental perspectives.

       

    /

    返回文章
    返回