• No results found

We present the first pay-friendly DoS protection system that furnishes ISPs with a better value proposition for deploying anti-DoS systems: a way to turn DoS protection into a commodity. Our pay-per-use system is based on the WebSOS DoS protection archi- tecture, extended to include OTPchecks, a light-weight and flexible pay-per-use micro- payment scheme. Its hardware and software deployment can be done without changing any of the current ISP infrastructure. The initial investment and maintenance cost can regulated and scaled depending on the actual services protected.

From the end user perspective, the system acts almost transparently: no modifications are required in the browsers since we are taking advantage of browser extensibility. Moreover, the target site offering the web service can have a more fine-grained control of the users that it serves without altering any of its current servers’ protocols. Finally, we allow a web service to charge its clients for the DoS protection service or provide the service as an added value feature.

References

D. G. Andersen. Mayday: Distributed Filtering for Internet Services. In 4th USENIX Sym- posium on Internet Technologies and Systems USITS, March 2003.

S. M. Bellovin. Distributed Firewalls. ;login: magazine, special issue on security, pages 37–39, November 1999.

W. J. Blackert, D. M. Gregg, A. K. Castner, E. M. Kyle, R. L. Horn, and R. M. Jokerst. Analyz- ing Interaction Between Distributed Denial of Service Attacks and Mitigation Technologies. In Proceedings of DISCEX III, pages 26–36, April 2003.

M. Blaze, J. Feigenbaum, J. Ioannidis, and A. D. Keromytis. The KeyNote Trust Management System Version 2. RFC 2704, September 1999.

M. Blaze, J. Ioannidis, and A. D. Keromytis. Offline Micropayments without Trusted Hard- ware. In Proceedings of the Fifth International Conference on Financial Cryptography, pages 21–40,2001.

CCITT. X.509: The Directory Authentication Framework. International Telecommunications Union, Geneva, 1989.

D. Chaum. Achieving Electronic Privacy. Scientific American, pages 96–101, August 1992. B. Cox, D. Tygar, and M. Sirbu. NetBill security and transaction protocol. In Proceedings of the First USENIX Workshop on Electronic commerce. USENIX, July 1995.

D. Dean, M. Franklin, and A. Stubblefield. An Algebraic Approach to IP Traceback. In

Proceedings of the Network and Dsitributed System Security Symposium (NDSS), pages 3– 12, February 2001.

D. Dean and A. Stubblefield. Using client puzzles to protect TLS. In Proceedings of the 10th USENIX Security Symposium, August 2001.

V. D. Gligor. Guaranteeing Access in Spite of Distributed Service-Flooding Attacks. In

Proceedings of the Security Protocols Workshop, April 2003.

M. T. Goodrich. Efficient Packet Marking for Large-Scale IP Traceback. In Proceedings of the 9th ACM Conference on Computer and Communications Security (CCS), pages 117–126, November 2002.

A. Herzberg. Safeguarding Digital Library Contents. D-Lib Magazine, January 1998. A. Hussain, J. Heidemann, and C. Papadopoulos. A Framework for Classifying Denial of Service Attacks. In Proceedings of ACM SIGCOMM, August 2003.

J. Ioannidis and S. M. Bellovin. Implementing Pushback: Router-Based Defense Against DDoS Attacks. In Proceedings of the Network and Distributed System Security Symposium (NDSS), February 2002.

J. Ioannidis, S. Ioannidis, A. D. Keromytis, and V. Prevelakis. Fileteller: Paying and Getting Paid for File Storage. In Proceeding of Financial Cryptography (FC) Conference, pages 282–299, March 2002.

S. Ioannidis, A. Keromytis, S. Bellovin, and J. Smith. Implementing a Distributed Firewall. In

Proceedings of Computer and Communications Security (CCS), pages 190–199, November 2000.

C. Jin, H. Wang, and K. G. Shin. Hop-Count Filtering: An Effective Defense Against Spoofed DoS Traffic. In Proceedings of the 10th ACM International Conference on Computer and Communications Security (CCS), pages 30–41, October 2003.

D. Karger, E. Lehman, F. Leighton, R. Panigrahy, M. Levine, and D. Lewin. Consistent Hashing and Random Trees: Distributed Caching Protocols for Relievig Hot Spots on the World Wide Web. In Proceedings of ACM Symposium on Theory of Computing (STOC),

pages 654–663, May 1997.

F. Kargl, J. Maier, and M. Weber. Protecting web servers from distributed denial of service attacks. In World Wide Web, pages 514–524, 2001.

1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20.

S. Kent and R. Atkinson. Security Architecture for the Internet Protocol. RFC 2401, Nov.

1998.

A. D. Keromytis, V. Misra, and D. Rubenstein. SOS: Secure Overlay Services. In Proceedings of ACM SIGCOMM, pages 61–72, August 2002.

W. G. Morein, A. Stavrou, D. L. Cook, A. D. Keromytis, V. Misra, and D. Rubenstein. Using Graphic Turing Tests to Counter Automated DDoS Attacks Against Web Servers. In

Proceedings of the 10th ACM International Conference on Computer and Communications Security (CCS), pages 8–19, October 2003.

G. Mori and J. Malik. Recognizing Objects in Adversarial Clutter: Breaking a Visual CAPTCHA. In Computer Vision and Pattern Recognition CVPR’03, June 2003.

C. Papadopoulos, R. Lindell, J. Mehringer, A. Hussain, and R. Govindan. COSSACK: Co- ordinated Suppression of Simultaneous Attacks. In Proceedings of DISCEX III, pages 2–13, April 2003.

K. Park and H. Lee. On the Effectiveness of Route-based PAcket Filtering for Distributed DoS Attack Prevention in Power-law Internets. In Proceedings of ACM SIGCOMM, pages 15–26, August 2001.

T. Poutanen, H. Hinton, and M. Stumm. NetCents: A Lightweight Protocol for Secure Micro- payments. In Proceedings of the Third USENIX Workshop on Electronic Commerce. USENIX, September 1998.

P. Reiher, J. Mirkovic, and G. Prier. Attacking DDoS at the source. In Proceedings of the 10th IEEE International Conference on Network Protocols, November 2002.

S. Savage, D. Wetherall, A. Karlin, and T. Anderson. Network Support for IP Traceback.

ACM/IEEE Transactions on Networking, 9(3):226–237, June 2001.

I. Stoica, R. Morris, D. Karger, F. Kaashoek, and H. Balakrishnan. Chord: A Scalable Peer- To-Peer Lookup Service for Internet Application. In Proceedings of ACM SIGCOMM, August

2001.

L. Tang. A Set of Protocols for MicroPayments in Distributed Systems. In Proceedings of the First USENIX Workshop on Electronic Commerce. USENIX, July 1995.

R. Thomas, B. Mark, T. Johnson, and J. Croall. NetBouncer: Client-legitimacy-based High- performance DDoS Filtering. In Proceedings of DISCEX III, pages 14–25, April 2003.

L. von Ahn, M. Blum, N. J. Hopper, and J. Langford. CAPTCHA: Using Hard AI Problems For Security. In Proceedings of EUROCRYPT’03, 2003.

A. Yaar, A. Perrig, and D. Song. Pi: A Path Identification Mechanism to Defend against DDoS Attacks. In Proceedings of the IEEE Symposium on Security and Privacy, May 2003.

21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34.

Xiaofeng Chen1, Fangguo Zhang2, and Kwangjo Kim1

1

International Research center for Information Security (IRIS) Information and Communications University(ICU), 103-6 Munji-dong, Yusong-ku, Taejon, 305-714 KOREA

{crazymount ,kk j }@icu. ac. kr

2 Department of Electronics and Communication Engineering,

Institute of Information Security Technology, Sun Yat-Sen University,

Guangzhou 510275, P.R.China [email protected]

Abstract. Motivated by the conflict between authenticity and privacy in the digital signature, the notion of limited verifier signature was in- troduced [1]. The signature can be verified by a limited verifier, who will try to preserve the privacy of the signer if the signer follows some spec- ified rules. Also, the limited verifier can provide a proof to convince a judge that the signer has indeed generated the signature if he violated the predetermined rule. However, the judge cannot transfer this proof to convince any other party. Also, the limited verifier signature should be converted into an ordinary one for public verification if required. In this paper, we first present the precise definition and clear security notions for (convertible) limited verifier signature, and then propose two efficient (convertible) limited verifier signature schemes from bilinear pairings. Our schemes were proved to achieve the desired security notions under the random oracle model.

Keywords: Undeniable signature, Designated verifier signature, Lim- ited verifier signature, Bilinear pairings.

1

Introduction

Undeniable signature, introduced by Chaum and van Antwerpen [10], is a kind of digital signature which cannot be verified without interacting with the signer. It is useful in a case where the validity of a signature must not be verified universally. For example, a software vendor might embed his signature into his products and only allow the paying customers to verify the authentication of the products. If the vendor signed a message (product), he must provide some proofs to convince the customer of the fact. Also, these proofs must be non-transferable, i.e., once a verifier (customer) is convinced that the vendor signed (or did not sign) the message, he cannot transfer these proofs to convince any third party. After the initial work of Chaum and van Antwerpen, several undeniable signature schemes were proposed [9,17,15,22]. Also, Boyar et al. [5] introduced the notion of convertible undeniable signature.

M. Jakobsson, M. Yung, J. Zhou (Eds.): ACNS 2004, LNCS 3089, pp. 135–148, 2004. © Springer-Verlag Berlin Heidelberg 2004

In some cases, it will be a disadvantage that the signature can be verified only with the cooperation of the signer. If the signer should be unavailable, or should refuse to cooperate, then the recipient cannot make use of the signature. This facilitates the concept of “designated confirmer signature” [8]. The designated confirmer can confirm the signature even without the cooperation of the signer when a dispute occurs.

In some applications, it is important for the signer to decide not only when but also by whom his signatures can be verified due to the blackmailing [13, 20] and mafia [12] attacks. For example, the voting center presents a proof to convince a certain voter that his vote was counted while without letting him to convince others (e.g., a coercer) of his vote, which is important to design a receipt-free electronic voting scheme preventing vote buying and coercion. This is the motivation of the concept of “designated verifier signature” [21]. The designated verifier will trust the signer indeed signed a message with a proof of the signer. However, he cannot present the proof to convince any third party because he is fully capable of generating the same proof by himself.

Recently, motivated by privacy issues associated with dissemination of signed digital certificate, Steinfeld et al. [26] introduced the conception of “universal designated verifier signature”, which can be viewed as an extended notion of designated verifier signature. Universal designated verifier signature allows any holder of the signature (not necessarily the signer) to designate the signature to any desired designated verifier. The verifier can be convinced that the signer indeed generated the signature, but cannot transfer the proof to convince any third party. For example, a user Alice is issued a signed certificate by the CA. When Alice wishes to send her certificate to a verifier Bob, she uses Bob’s public key to transfer the CA’s signature into a universal designated verifier signature to Bob. Bob can verifier the signature with CA’s public key but is unable to use this designated signature to convince any third party that the certificate is issued by the CA, even if Bob is willing to reveal his secret key to the third party.

In some applications, it is also important for the recipient to decide when and whom the signer’s signature should be verified. For example, a credit com- pany will try his best to preserve the client’s privacy in order to get his trust, provided that the client obeys the rules of the company. So, it is sufficient for the company only to be convinced the validity of the client’s signature for his dishonorable message such as a bill. Furthermore, the company will preserve the client’s privacy if he pays the bill in a certain time. However, if the client violated the rules, the company can provide a proof to convince a Judge of the client’s treachery while the Judge cannot transfer the proof to convince any other third party.

It is obvious that undeniable signature and designated verifier signature are unsuitable for these situations. In the undeniable signatures, the signature can be verified only the cooperation of the signer. In the designated verifier signature, the designated verifier can never transfer the signature or the proof to convince any third party even he would like to reveal his secret key. This is because the

designated verifier is fully capable to generate a “signature” himself which is indistinguishable from the real signature of the signer.

Araki et al. [1] introduced the concept of “limited verifier signature” to solve these problems. The limited verifier signature can only be verified by a limited verifier, who will try to preserve the signer’s privacy (especially some dishonor- able message) unless the signer violated some rules. When a later dispute occurs, the limited verifier can convince a third party, usually a Judge, that the signer indeed generated a signature. We argue that the goal of the limited verifier is not to make the signature to be verified publicly, but force the signer to obey the rules. In some cases, the signer may not intentionally violate the rules and the limited verifier should give the signer some chances to correct his fault. Therefore, the Judge should not transfer this proof to convince any other party. In some situations, the signer’s privacy is closely related to the recipient’s privacy. For example, a spy, Carol, has a certificate with a signature of the President, which can be verified by Carol herself. Also, Carol can provide a proof to prove her real identity to a third party in case of an emergency. However, the signature and the proof cannot be transferred by the third party to convince any other party in order to ensure Carol’s safety. Therefore, limited verifier signature can be used in any cases that the signer’s signature should be protected by the recipient.

Some official documents, which is treated as limited verifier signature, should be verified by everyone after a period of time if necessary. This is the motivation of “convertible limited verifier signatures”, also introduced by Araki et al. [1]. Convertible limited verifier signatures enable the limited verifier to convert the signature into an ordinary one for public verification.1

In the convertible limited verifier signature [1], the conversion of the sig- nature requires the cooperation of the original signer, who must release some information. This might not be workable if the original signer is unwilling or in- convenient to cooperate. Furthermore, Zhang and Kim [28] proposed a universal forgery attack on this scheme. Wu et al. [24] proposed a convertible authenti- cated encryption scheme, which overcomes some disadvantages of Araki et al.’s scheme. However, if the recipient publishes the message and signature together, anyone can be convinced that the signer generated the signature. It does not satisfy the non-transferability. There seems no secure convertible limited verifier signature scheme to the best of our knowledge.

In this paper, we first present the precise definition and clear security no- tions for (convertible) limited verifier signature. Based on the power of different adversaries, we then propose two efficient (convertible) limited verifier signature schemes from bilinear pairings. Moreover, the conversion of the proposed limited verifier signature schemes does not need the cooperation of the original signer.

The rest of the paper is organized as follows: Some preliminary works are given in Section 2. In Section 3, the precise definition and notions of security for Convertible limited verifier signature is different from the notion of converted unde- niable signature, where only the signer can release some information to convert his originally undeniable signature into an ordinary one.

limited verifier signature are presented. Our efficient limited verifier signature schemes from bilinear pairings are given in Section 4. In Section 5, the security and efficiency analysis of our schemes are given. Finally, conclusions will be made in Section 6.

Related documents