Lecure 5 November 9, 00 HW Auhenicion & Idenificion Secre Shring Blind signures e-cshe /0/0 Gene Tsudi, ICS 68 Fll 00 Fi-Shmir ID Scheme, q lrge rimes n q securiy rmeer Publics : n,, ID x mod n Secres :, q globl, x Alice Noe : gcd( x, n). Alice : [, n[, w mod n. Bob : r [0,] r 3. Alice : y x mod n r 4. Bob : y? wid mod n Ree imes! /0/0 Gene Tsudi, ICS 68 Fll 00
q g Schnorr ID Scheme lrge rime lrge(rime)divisor of generor g ( )/ q securiy rmeer (40?) Publics :, q, g,,, ID Secres : x (Alice) x Alice : Bob : r Alice : y Bob : w [0, q[, w [, ]? xr mod q y r ID /0/0 Gene Tsudi, ICS 68 Fll 00 3 Omoo ID Scheme q g lrge rime lrge (rime) divisor of generor ( )/ q c g securiy rmeer Publics :, q, g,,,, ID Secres : x, x Alice, c globl x x Alice:, [0, q[, w Bob : r [, ] Alice: y xr mod q y xr mod q y y r Bob : w? ID /0/0 Gene Tsudi, ICS 68 Fll 00 4
Omoo ID Scheme (cond) If Eve cn imersone Alice hen Eve nd Alice cn comue c! y,y r Cer,w /0/0 Gene Tsudi, ICS 68 Fll 00 5 Guillou-Quisquer (GQ) ID Scheme q, n e q lrge rimes globl 'encryion' ey Publics neid x n e :,, ( ) mod Secres :, q globl, x Alice Cer{ Alice,ID} CA e Alice: [0, n [, w modn Bob : r [0,e[ r Alice: y x modn r e Bob : w? ID y modn Error(s) in boo! /0/0 Gene Tsudi, ICS 68 Fll 00 6 3
GQ Ideniy-bsed Scheme, q lrge rimes n q, ( e, d ) RSA ey-ir x h Alice d ( (" ") ) i.e., TTP signs h( " Alice " ) Publics : n, e, ID h(" Alice ")mod n Secres:, q, d globl, x Alice e Alice : [0, n [, w mod n Bob : r [0,e[ r Alice : y x mod n B : r e ob w? ID y mod n /0/0 Gene Tsudi, ICS 68 Fll 00 7 Convering ID o Signure Scheme (Schnorr) q g lrge rime lrge(rime)divisor of generor g ( )/ q securiy rmeer (40?) q g lrge rime lrge(rime) divisor of generor / q h(), h() " good" hsh fn Publics :, q, g,,, ID Secres : x Alice : Bob : r Alice : y Bob : w [0, q[, w [, ]? (Alice) xr mod q y r ID x Publics :, q, g,,, ID Secres : x Alice: Alice: y Bob : w [0, q[, w? xh( msg, w,...) modq y ID h( msg, w,...) x /0/0 Gene Tsudi, ICS 68 Fll 00 8 4
Secre Shring Why shre secres? Criicl services: ccess by consen Relice/bcu vluble d In generl, shred conrol... E.g., ou of 3 /0/0 Gene Tsudi, ICS 68 Fll 00 9 Unnimous consen (-ou ou-of-) TTP is needed o genere nd disribue he secre. SETUP : - - - - - - - - m lrge number TTP generes : i [, nd S K S is given o P i ] ( S S i i... R S Z m ) RECONSTRUCTION : -- -- --- -- -- --- -- -- -- - Alice, Bob,Eve ool ogeher: K' S S S3 S S K ( S S ) K Noe: why no jus sli he secre in smller chuns? /0/0 Gene Tsudi, ICS 68 Fll 00 0 5
Threshold Scheme (Shmir 79) (-ou ou-of-n) Need TTP o se u he sysem! SETUP: lrge rime, > mx( K, n ), < n TTP generes: i [, n ] x Z i [, [ Z i [, n ] y f ( x ) is given o P where: f ( x) x x... x 0 K i R i R 0 0 ublics: {x,..., x } secres: {,,..., i i i n 0 } RECONSTRUCTION: ricins ool ogeher: y x x... x... 0 y x x... x... i 0 i i i y x x... x 0 equions, unnowns yield unique soluion vecor: < 0,..., > /0/0 Gene Tsudi, ICS 68 Fll 00 Shmir Threshold Schemes (exmle) SETUP: n 7 5, 3 TTP generes: x i 0 i for ll i Z i [,] i R K y f ( x ) is given o P i i i where : f ( x) x x x mod7 0 0 y 8, y 3, y 9 y 3 5, y 4 5 RECONSTRUCTION: Suose 3 5 ool heir shres y 8, y 0, y 3 5 0 3 9 0 0 5 8 0 0 3 0 P,P,P 8 /0/0 Gene Tsudi, ICS 68 Fll 00 6
Elecronic Csh /0/0 Gene Tsudi, ICS 68 Fll 00 3 Ouline Wh is elecronic csh? Why elecronic csh? Issues: Off-line oversending Anonymiy How does e-csh e wor? Adding rusee rce-biliy biliy The nonymous chnge roblem /0/0 Gene Tsudi, ICS 68 Fll 00 4 7
Moivion Convenionl Csh is: Counerfeible Slow Cosly Vulnerble Bd for Remoe Trnscions /0/0 Gene Tsudi, ICS 68 Fll 00 5 Credi Crds, Bn Crds, Checs, nd Phone/subwy crds: Esy Frud Lile Privcy /0/0 Gene Tsudi, ICS 68 Fll 00 6 8
Off-line Elecronic Csh refers o wo-ry ymen Wihdrwl Pymen Deosi Low Communicion Requiremens /0/0 Gene Tsudi, ICS 68 Fll 00 7 By Conrs, On-line Pymens Loo Lie This OK /0/0 Gene Tsudi, ICS 68 Fll 00 8 9
Oversending: A roblem wih off-line e-csh Se : The bd user coies his money /0/0 Gene Tsudi, ICS 68 Fll 00 9 Se : The bd user gives coied csh o mulile eole /0/0 Gene Tsudi, ICS 68 Fll 00 0 0
!!! The Bn is wre of rouble only ler /0/0 Gene Tsudi, ICS 68 Fll 00 Techniques o Conin Over-Sending Use mer-resisn resisn hrdwre o reven over-sending (e.g., MONDEX in Euroe) Trce over-senders Blclis over-senders Pu bound on dollr-vlue of off-line rnscions /0/0 Gene Tsudi, ICS 68 Fll 00
Tmer-resisnce resisnce is gre -- so fr s i wors Resources Trdeoff /0/0 Gene Tsudi, ICS 68 Fll 00 3