Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Cryptanalysis of a Dynamic Universal Accumulator over Bilinear Groups
BIRYUKOV, Alexei; UDOVENKO, Aleksei; VITTO, Giuseppe
2021In Topics in Cryptology – CT-RSA 2021
Peer reviewed
 

Documents


Texte intégral
cryptanalysis_accumulator.pdf
Postprint Auteur (512.63 kB)
Télécharger

This version of the contribution has been accepted for publication, after peer review (when applicable) but is not the Version of Record and does not reflect post-acceptance improvements, or any corrections. The Version of Record is available online at: http://dx.doi.org/10.1007/978-3-030-75539-3_12. Use of this Accepted Version is subject to the publisher’s Accepted Manuscript terms of use https://www.springernature.com/gp/open-research/policies/accepted-manuscript-terms.


Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
accumulator; universal; dynamic; cryptanalysis; anonymous credentials
Résumé :
[en] In this paper we cryptanalyse the two accumulator variants proposed by Au et al., which we call the alpha-based construction and the common reference string-based (CRS-based) construction. We show that if non-membership witnesses are issued according to the alpha-based construction, an attacker that has access to multiple witnesses is able to efficiently recover the secret accumulator parameter alpha and completely break its security. More precisely, if p is the order of the underlying bilinear group, the knowledge of O(log p log log p) non-membership witnesses permits to successfully recover alpha. Further optimizations and different attack scenarios allow to reduce the number of required witnesses to O(log p), together with practical attack complexity. Moreover, we show that accumulator's collision resistance can be broken if just one of these non-membership witnesses is known to the attacker. We then show how all these attacks for the alpha-based construction can be easily prevented by using instead a corrected expression for witnesses. Although outside the original security model assumed by Au \etal but motivated by some possible concrete application of the scheme where the Manager must have exclusive rights for issuing witnesses (e.g. white/black list based authentication mechanisms), we show that if non-membership witnesses are issued using the CRS-based construction and the CRS is kept secret by the Manager, an attacker accessing multiple witnesses can reconstruct the CRS and compute witnesses for arbitrary new elements. In particular, if the accumulator is initialized by adding m secret elements, the knowledge of m non-membership witnesses allows to succeed in such attack.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
BIRYUKOV, Alexei ;  University of Luxembourg > Faculty of Science, Technology and Medicine (FSTM) > Department of Computer Science (DCS)
UDOVENKO, Aleksei  ;  CryptoExperts, Paris, France
VITTO, Giuseppe ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Cryptolux
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Cryptanalysis of a Dynamic Universal Accumulator over Bilinear Groups
Date de publication/diffusion :
2021
Nom de la manifestation :
Topics in Cryptology – CT-RSA 2021
Date de la manifestation :
May 17–20, 2021
Manifestation à portée :
International
Titre de l'ouvrage principal :
Topics in Cryptology – CT-RSA 2021
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
URL complémentaire :
Projet FnR :
FNR11684537 - Security, Scalability, And Privacy In Blockchain Applications And Smart Contracts, 2017 (01/08/2018-31/07/2021) - Alex Biryukov
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 12 janvier 2022

Statistiques


Nombre de vues
190 (dont 22 Unilu)
Nombre de téléchargements
134 (dont 2 Unilu)

citations Scopus®
 
13
citations Scopus®
sans auto-citations
13
OpenCitations
 
1
citations OpenAlex
 
2
citations WoS
 
11

Bibliographie


Publications similaires



Contacter ORBilu