Zero-Knowledge Accumulators and Set Algebra

被引:17
|
作者
Ghosh, Esha [1 ]
Ohrimenko, Olga [2 ]
Papadopoulos, Dimitrios [3 ]
Tamassia, Roberto [1 ]
Triandopoulos, Nikos [4 ]
机构
[1] Brown Univ, Dept Comp Sci, Providence, RI 02912 USA
[2] Microsoft Res, Cambridge, England
[3] Univ Maryland, College Pk, MD 20742 USA
[4] Stevens Inst Technol, Hoboken, NJ 07030 USA
来源
ADVANCES IN CRYPTOLOGY - ASIACRYPT 2016, PT II | 2016年 / 10032卷
关键词
Zero-knowledge dynamic and universal accumulators; Zero-knowledge updates; Zero-knowledge set algebra; Outsourced computation; Integrity; Privacy; Bilinear accumulators; Cloud privacy; UNIVERSAL ACCUMULATORS; EFFICIENT REVOCATION; COMMITMENTS; PAIRINGS;
D O I
10.1007/978-3-662-53890-6_3
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cryptographic accumulators allowto succinctly represent a set by an accumulation value with respect to which short (non-) membership proofs about the set can be efficiently constructed and verified. Traditionally, their security captures soundness but offers no privacy: Convincing proofs reliably encode set membership, but they may well leak information about the accumulated set. In this paper we put forward a strong privacy-preserving enhancement by introducing and devising zero-knowledge accumulators that additionally provide hiding guarantees: Accumulation values and proofs leak nothing about a dynamic set that evolves via element insertions/deletions. We formalize the new property using the standard real-ideal paradigm, namely demanding that an adaptive adversary with access to query/update oracles, cannot tell whether he interacts with honest protocol executions or a simulator fully ignorant of the set (even of the type of updates on it). We rigorously compare the new primitive to existing ones for privacy-preserving verification of set membership (or other relations) and derive interesting implications among related security definitions, showing that zero-knowledge accumulators offer stronger privacy than recent related works by Naor et al. [TCC 2015] and Derler et al. [CT-RSA 2015]. We construct the first dynamic universal zero-knowledge accumulator that we show to be perfect zero-knowledge and secure under the q-Strong Bilinear Diffie-Hellman assumption. Finally, we extend our new privacy notion and our new construction to provide privacy-preserving proofs also for an authenticated dynamic set collection-a primitive for efficiently verifying more elaborate set operations, beyond set-membership. We introduce a primitive that supports a zero-knowledge verifiable set algebra: Succinct proofs for union, intersection and set difference queries over a dynamically evolving collection of sets can be efficiently constructed and optimally verified, while-for the first time-they leak nothing about the collection beyond the query result.
引用
收藏
页码:67 / 100
页数:34
相关论文
共 50 条
  • [21] Subquadratic zero-knowledge
    J Assoc Comput Mach, 6 (1169):
  • [22] Subquadratic zero-knowledge
    Boyar, J
    Brassard, G
    Peralta, R
    JOURNAL OF THE ACM, 1995, 42 (06) : 1169 - 1193
  • [23] Reduction zero-knowledge
    LEE C. H.
    ProgressinNaturalScience, 2004, (04) : 64 - 72
  • [24] NONINTERACTIVE ZERO-KNOWLEDGE
    BLUM, M
    DESANTIS, A
    MICALI, S
    PERSIANO, G
    SIAM JOURNAL ON COMPUTING, 1991, 20 (06) : 1084 - 1118
  • [25] Zero-knowledge sets
    Micali, S
    Rabin, M
    Kilian, J
    44TH ANNUAL IEEE SYMPOSIUM ON FOUNDATIONS OF COMPUTER SCIENCE, PROCEEDINGS, 2003, : 80 - 91
  • [26] Zero-knowledge proofs for finite field arithmetic, or:: Can zero-knowledge be for free?
    Cramer, R
    Damgård, I
    ADVANCES IN CRYPTOLOGY - CRYPTO'98, 1998, 1462 : 424 - 441
  • [27] ON THE KNOWLEDGE TIGHTNESS OF ZERO-KNOWLEDGE PROOFS
    ITOH, T
    KAWAKUBO, A
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 1994, E77A (01) : 47 - 55
  • [28] The Knowledge Tightness of Parallel Zero-Knowledge
    Chung, Kai-Min
    Pass, Rafael
    Tseng, Wei-Lung Dustin
    THEORY OF CRYPTOGRAPHY (TCC 2012), 2012, 7194 : 512 - 529
  • [29] Unifying Zero-Knowledge Proofs of Knowledge
    Maurer, Ueli
    PROGRESS IN CRYPTOLOGY - AFRICACRYPT 2009, 2009, 5580 : 272 - 286
  • [30] Zero-knowledge and code obfuscation
    Hada, S
    ADVANCES IN CRYPTOLOGY ASIACRYPT 2000, PROCEEDINGS, 2000, 1976 : 443 - 457