Cryptanalysis of multivariate threshold ring signature schemes
Petzoldt et al. proposed the first multivariate threshold ring signature scheme extending the idea of a ring identification scheme in 2013. They claimed that their t-out of n threshold ring signature satisfies the security properties of unforgeability and source anonymity. Later, Zhang-Zhao in 2014...
Gespeichert in:
Veröffentlicht in: | Information processing letters 2023-03, Vol.181, p.106357, Article 106357 |
---|---|
Hauptverfasser: | , , |
Format: | Artikel |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | Petzoldt et al. proposed the first multivariate threshold ring signature scheme extending the idea of a ring identification scheme in 2013. They claimed that their t-out of n threshold ring signature satisfies the security properties of unforgeability and source anonymity. Later, Zhang-Zhao in 2014 and Duong et al. in 2021 proposed other multivariate threshold ring signature schemes using different tools with the same technique. In this article, we cryptanalyze all these schemes and give an attack on their source anonymity which shows how the verifier can find the actual set of signers after some finite number of trials, viz., with at most N=(nn−t)+(nn−t−1)+…+(n1)+(n0) in t-out of n threshold ring.
•We did cryptanalysis of multivariate threshold ring signature schemes proposed by Petzoldt et al. in 2013, Zhang-Zhao in 2014, and Duong et al. in 2021.•They claimed that their threshold ring signature satisfies source anonymity properties.•We gave a polynomial time attack on their source anonymity.•Using our attack, the verifier can find the actual set of signers after some finite number of trials. |
---|---|
ISSN: | 0020-0190 1872-6119 |
DOI: | 10.1016/j.ipl.2022.106357 |