A multi-authority attribute ring signature supporting dynamic policies and dual anonymity for zero-trust networks

一种支持动态策略和双重匿名性的零信任网络多权威属性环签名

阅读:1

Abstract

The advent of Decentralized Identity (DID) technology is fundamentally changing the way digital identity is managed, allowing user-controlled, privacy-preserving authentication across trust domains a fundamental requirement if zero trust architectures are to be realized, in which continuous verification and least-privilege access are inherent properties. Under traditional ABS (attribute-based signature) schemes, these are difficult to achieve as fine-grained access control is not always possible in practice and anonymity may not be straightforward when policy is evolving dynamically and different authorities may be involved. In this paper, we present a new multi-authority attribute ring signature scheme, which leverages DID philosophy and anonymous credential techniques, enabling users to mix attributes dynamically according to the policies of veriers without disclosing their pseudonyms or partial attributes. The proposed scheme enables distributed key generation by multiple authorities and is shown to be secure in the random oracle model, achieving existential unforgeability against adaptive chosen-message, identity, and attribute attacks (EUF-CMIAA) as well as full signer and attribute anonymity. Based on the SM9 cryptographic standard, our approach reduces the number of [Formula: see text] exponentiations and scalar multiplications during signing by approximately 30% compared to existing ring signatures, offering a practical and efficient authentication solution for emerging DID-driven zero-trust networks.

特别声明

1、本页面内容包含部分的内容是基于公开信息的合理引用;引用内容仅为补充信息,不代表本站立场。

2、若认为本页面引用内容涉及侵权,请及时与本站联系,我们将第一时间处理。

3、其他媒体/个人如需使用本页面原创内容,需注明“来源:[生知库]”并获得授权;使用引用内容的,需自行联系原作者获得许可。

4、投稿及合作请联系:info@biocloudy.com。