School of Life Sciences and Technology, Xidian University, Xi'an, China.
PLoS One. 2013 May 10;8(5):e63562. doi: 10.1371/journal.pone.0063562. Print 2013.
Most of the existing multi-recipient signcryption schemes do not take the anonymity of recipients into consideration because the list of the identities of all recipients must be included in the ciphertext as a necessary element for decryption. Although the signer's anonymity has been taken into account in several alternative schemes, these schemes often suffer from the cross-comparison attack and joint conspiracy attack. That is to say, there are few schemes that can achieve complete anonymity for both the signer and the recipient. However, in many practical applications, such as network conference, both the signer's and the recipient's anonymity should be considered carefully. Motivated by these concerns, we propose a novel multi-recipient signcryption scheme with complete anonymity. The new scheme can achieve both the signer's and the recipient's anonymity at the same time. Each recipient can easily judge whether the received ciphertext is from an authorized source, but cannot determine the real identity of the sender, and at the same time, each participant can easily check decryption permission, but cannot determine the identity of any other recipient. The scheme also provides a public verification method which enables anyone to publicly verify the validity of the ciphertext. Analyses show that the proposed scheme is more efficient in terms of computation complexity and ciphertext length and possesses more advantages than existing schemes, which makes it suitable for practical applications. The proposed scheme could be used for network conferences, paid-TV or DVD broadcasting applications to solve the secure communication problem without violating the privacy of each participant.
大多数现有的多收件人签密方案都没有考虑收件人的匿名性,因为所有收件人的身份列表必须包含在密文中,作为解密的必要元素。虽然在几个替代方案中已经考虑到了签名者的匿名性,但这些方案通常容易受到交叉比较攻击和联合共谋攻击。也就是说,很少有方案可以为签名者和收件人都实现完全的匿名性。然而,在许多实际应用中,如网络会议,签名者和收件人的匿名性都应该仔细考虑。出于这些考虑,我们提出了一种新的具有完全匿名性的多收件人签密方案。新方案可以同时实现签名者和收件人的匿名性。每个收件人都可以轻松判断接收到的密文是否来自授权来源,但无法确定发送者的真实身份,同时,每个参与者都可以轻松检查解密权限,但无法确定任何其他收件人的身份。该方案还提供了一种公共验证方法,任何人都可以公开验证密文的有效性。分析表明,与现有方案相比,所提出的方案在计算复杂度和密文长度方面更具优势,使其更适用于实际应用。该方案可用于网络会议、付费电视或 DVD 广播应用,以解决安全通信问题,同时不侵犯每个参与者的隐私。