Tightly Secure Linearly Homomorphic Signature Schemes for Subspace Under DL Assumption in AGM
摘要
Linearly homomorphic signature (LHS) allows to perform any linear combination on the already signed vectors so that it is widely applied in various scenarios. Unfortunately, the existing LHS schemes do not have tight security proof based on the hardest problem in the cyclic group setting, namely, the discrete logarithm (DL) problem, and they all rely on computationally expensive pairing operations over bilinear groups. Recently, the proposal of the algebraic group model (AGM) enables some ordinary signature schemes to be tightly reduced to the DL problem. However, it remains unknown whether LHS schemes can be proven as secure as the DL problem in the AGM. In this paper, we revisit the security of Boneh’s LHS scheme and first give a tight security proof under the DL assumption in the AGM. To improve computational efficiency, we propose a pairing-free linearly homomorphic signature (PF-LHS) scheme and a map-to-point hash function-free linearly homomorphic signature (MF-LHS) scheme, and the latter is given a tight security proof under the DL assumption in the AGM. Finally, the efficiency comparisons show that both our PF-LHS scheme and MF-LHS scheme are computationally efficient.