School of Software, Henan Polytechnic University, Jiaozuo 454000, China.
Comput Intell Neurosci. 2022 Sep 19;2022:6547464. doi: 10.1155/2022/6547464. eCollection 2022.
Machine learning (ML) and privacy protection are inseparable. On the one hand, ML can be the target of privacy protection; on the other hand, it can also be used as an attack tool for privacy protection. Ring signature (RS) is an effective way for privacy protection in cryptography. In particular, lattice-based RS can still protect the privacy of users even in the presence of quantum computers. However, most current lattice-based RS schemes are based on a strong trapdoor like hash-and-sign, and in such constructions, there is a hidden algebraic structure, that is, added to lattice so that the trapdoor shape is not leaked, which greatly affects the computational efficiency of RS. In this study, utilizing Lyubashevsky collision-resistant hash function over lattice, we construct an RS scheme without trapdoors based on ideal lattice via Fiat‒Shamir with aborts (FSwA) protocol. Regarding security, the proposed scheme satisfies unconditional anonymity against chosen setting attacks (UA-CSA), which is stronger than anonymity against full key exposure (anonymity-FKE), and moreover, our scheme satisfies unforgeability with respect to insider corruption (EU-IC). Regarding computational overhead, compared with other RS schemes that satisfy the same degree of security, our scheme has the highest computational efficiency, the signing and verification time costs of the proposed scheme are obviously better than those of other lattice-based RS schemes without trapdoors, which is more suitable for ML scenarios.
机器学习(ML)和隐私保护是不可分割的。一方面,ML 可以成为隐私保护的目标;另一方面,它也可以作为隐私保护的攻击工具。环签名(RS)是密码学中一种有效的隐私保护方法。特别是基于格的 RS 即使在存在量子计算机的情况下也能保护用户的隐私。然而,目前大多数基于格的 RS 方案都基于像哈希签名这样的强陷门,在这些构造中,存在隐藏的代数结构,即添加到格中,以防止陷门形状泄露,这极大地影响了 RS 的计算效率。在这项研究中,我们利用基于格的 Lyubashevsky 碰撞抵抗哈希函数,通过 Fiat-Shamir with aborts(FSwA)协议,在理想格上构建了一种无陷门的 RS 方案。关于安全性,所提出的方案满足针对选择设置攻击的无条件匿名性(UA-CSA),比针对完全密钥暴露的匿名性(匿名性-FKE)更强,而且,我们的方案满足针对内部人员腐败的不可伪造性(EU-IC)。关于计算开销,与满足相同安全程度的其他 RS 方案相比,我们的方案具有最高的计算效率,所提出方案的签名和验证时间成本明显优于其他无陷门的基于格的 RS 方案,更适合 ML 场景。