论文标题

关于BGN用于隐私保护数据聚合协议的不安全用途

On Insecure Uses of BGN for Privacy Preserving Data Aggregation Protocols

论文作者

Lee, Hyang-Sook, Lim, Seongan, Yie, Ikkwon, Yun, Aaram

论文摘要

Shi等人的AO安全性盲目技术的特定构造对保留数据聚合的汇总(AO)安全性(AO)的概念是正式的。数据聚合方案的一些建议使用Shi等人的盲目技术。对于BGN密码系统,加性同构加密。以前,在数据的完整性或真实性的背景下,已经对一些基于BGN的数据聚合协议进行了一些安全分析。即使有这样的安全性分析,BGN密码系统仍然是保留数据聚合协议的隐私构件。在本文中,我们研究了Shi等人的盲目技术中的隐私问题。用于BGN密码系统。我们表明,在几种协议中使用的BGN加密系统的盲目技术并不是针对接收者解密者的隐私。我们的分析基于以下事实:BGN加密系统使用配对e:gxg-> g_t和配对的存在使G上的DDH问题易于求解。我们还建议如何在Shi等人的盲目技术中防止这种隐私泄漏。用于BGN密码系统。

The notion of aggregator oblivious (AO) security for privacy preserving data aggregation was formalized with a specific construction of AO-secure blinding technique over a cyclic group by Shi et al. Some of proposals of data aggregation protocols use the blinding technique of Shi et al. for BGN cryptosystem, an additive homomorphic encryption. Previously, there have been some security analysis on some of BGN based data aggregation protocols in the context of integrity or authenticity of data. Even with such security analysis, the BGN cryptosystem has been a popular building block of privacy preserving data aggregation protocol. In this paper, we study the privacy issues in the blinding technique of Shi et al. used for BGN cryptosystem. We show that the blinding techniques for the BGN cryptosystem used in several protocols are not privacy preserving against the recipient, the decryptor. Our analysis is based on the fact that the BGN cryptosystem uses a pairing e:GxG-->G_T and the existence of the pairing makes the DDH problem on G easy to solve. We also suggest how to prevent such privacy leakage in the blinding technique of Shi et al. used for BGN cryptosystem.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源