Font Size: a A A

Research On Digital Signature Schemes Of NTRU Lattice

Posted on:2017-03-18Degree:DoctorType:Dissertation
Country:ChinaCandidate:J XieFull Text:PDF
GTID:1368330542992921Subject:Cryptography
Abstract/Summary:PDF Full Text Request
As an important part of public key cryptography,digital signature schemes are applied to authenticate the identity of users(authentication),guarantee data integrity(integrity)and ensure the non-repudiation of senders(non-repudiation).With the rapid development of e-commerce and e-government,the enormous effect of digital signature in network security is increasingly prominent.Digital signature schemes based on intractable lattice problems have become the best candidate in quantum era for its quantum-immune,simple calculation and reduction from worst-case to average-case.However,the lattice-based digital signature also has disadvantage that both of the space size and communication overhead are large,and they have been a big hurdle on the way to putting lattice-based digital signature schemes into use.To solve this problem above,this dissertation is dedicated to improving the efficiency and increasing the varieties of digital signatures on NTRU lattice.And we obtaine the following results.(1)By applying the rejection sampling technique and pre-image sampling algorithm,we propose an identity-based digital signature over NTRU lattice.And compared with the previous identity-based signature on lattice,it is more efficient.In order to further reduce the communication overhead,the message recovery technique is added into this scheme to obtain the identity-based message recovery signature over NTRU lattice.The scheme can reduce the communication overhead without sending the full message.(2)We present a ring signature scheme over NTRU lattice.Under the assumption that the small integer solution problem in ring(R-SIS)is hard,the new scheme is unconditionally anonymous and unforgeable against adaptively chosen message attack in random oracle model.Compared with the previous lattice-based ring signature schemes,the new scheme is efficient but not the most efficient one.In order to further improve the efficiency,another ring signature scheme on NTRU lattice is proposed by using rejection sampling technique.Compared with the previous schemes,this scheme is more efficient.And it is also unconditionally anonymous and unforgeable against adaptively chosen message attack and chosen subring attack in random oracle model.(3)Using the pre-image sampling algorithm to extract the secret key and using rejection sampling technique to sign the message,an attribute-based signature on lattice is proposed.Compared with the existing three attribute-based signatures on lattice,our new scheme has shorter public key and signature.Then,we extend it into an attribute-based signature on NTRU lattice,which is more efficient.Finally,an attribute-based ring signature on NTRU lattice is proposed,where the length of the signature is no longer related to the number of members in ring.(4)We present the certificateless signature on NTRU lattice by using rejection sampling technique.And it is secure under the R-SIS assumption.In addition,through the comparison with the previous scheme,it is indicated that the proposed scheme has shorter master private key,partial private key,secret value and signature.Moreover,a certificate-based signature on NTRU lattice is proposed through the simple deformation.And it has the same size of master private key,private key,certificate and signature with the certificateless signature on NTRU lattice.And the proposed certicate-based signature scheme over NTRU lattice is also secure under the assumption that the R-SIS problem is hard.(5)We delegate the signing right to the proxy signer by invoking preimage sampling technique,and the proxy signer uses rejection sampling technique to sign messages.An efficient proxy signature scheme on NTRU lattice and an identity-based proxy signature scheme over NTRU lattice are presented in this dissertation,which are proven unforgeable under the hardness assumption of the R-SIS problem.That is to say,both of the original signer and the proxy signer are protected.Moreover,compared with the previous signature on lattices,the new proxy signature schemes on NTRU lattice are more efficient.
Keywords/Search Tags:Lattice public key cryptography, NTRU lattice, Signature, Rejection sampling technique, Unforgeability
PDF Full Text Request
Related items