{"id":402160,"date":"2024-06-29T16:19:42","date_gmt":"2024-06-29T16:19:42","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=402160"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=402160","title":{"rendered":"<span>Instant Digital Signature Mode<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>We adhere to established tradition and continue to present the latest findings. In this note, we discuss the Instant Digital Signature (IDS) mode, which was <a href=\"https:\/\/habr.com\/ru\/articles\/705266\/\" rel=\"noopener noreferrer nofollow\"><u>announced earlier<\/u><\/a>. While the main content of the IDS mode was already disclosed in a <a href=\"https:\/\/habr.com\/ru\/articles\/705266\/\" rel=\"noopener noreferrer nofollow\"><u>previous publication<\/u><\/a>, we believe that additional specifications will improve understanding.<\/p>\n<p>It should be emphasized that the IDS is not a distinct type of signature, but rather a special mode in which any known digital signature (DS) scheme can be used. In other words, we do not take responsibility for developing a new scheme, but rather propose a practical way to apply existing schemes.<\/p>\n<p>As the name suggests, the IDS mode operates in real-time, specifically, at the moment of signature generation. This means that the mode is used to certify data that is directly associated with an identifying entity, as confirmed in a previously presented proof. Such proof can be obtained through executing an interactive identification protocol, which is necessary for justifying the IDS mode. When discussing this combination, we assume that certain unique variables from the current identification session are used in generating the signature. It is important to understand that these variables are ephemeral by design and only have an effect within the current session.<\/p>\n<p>It should be noted that in this <a href=\"https:\/\/habr.com\/ru\/articles\/705266\/\" rel=\"noopener noreferrer nofollow\"><u>publication<\/u><\/a>, we use personal data assurance as an example, which is perhaps the most natural application for the IDS mode.<\/p>\n<p>We demonstrate that the IDS mode is compatible with any known DS scheme. However, it is an open question whether this mode can be used with arbitrary identification protocols. On the other hand, the IDS mode is easily combined with an interactive identification protocol that enables the generation of a shared secret session key, which was created in the development of the protocol presented <a href=\"https:\/\/habr.com\/ru\/articles\/572994\/\" rel=\"noopener noreferrer nofollow\"><u>in this note<\/u><\/a>.<\/p>\n<p>We do not provide formal proofs in this text, but rather present examples to convey the essence of our findings. Unfortunately, we could not avoid using formal notation, but we hope that it will not pose any difficulties, as all necessary notation was introduced in <a href=\"https:\/\/habr.com\/ru\/articles\/572994\/\" rel=\"noopener noreferrer nofollow\"><u>our earlier publication<\/u><\/a>. Additionally, we use standard mathematical notation adopted in specialized literature, such as [Cohen_etc._2006].<\/p>\n<p><strong>Interactive Identification Protocol<\/strong><\/p>\n<p>First of all, let us recall what an interactive identification protocol is. In fact, this is a game of <u>two participants<\/u>, each of which is endowed with its own role. To avoid unnecessary complications, we will deliberately limit the number of subjects of interaction.<\/p>\n<p>There are two distinct roles: <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/764\/a07\/dc2\/764a07dc29392acbdf2069a11c5abee9.svg\" width=\"14\" height=\"17\"\/> (Prover) and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/3a1\/d3a\/c78\/3a1d3ac789f5f4ca9a1d576d5a4a1586.svg\" width=\"15\" height=\"17\"\/> (Verifier). <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6a5\/7e8\/ec4\/6a57e8ec497808c2bf98c0fe78767a7f.svg\" width=\"14\" height=\"17\"\/> provides proof of knowledge, such as a secret, which <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/272\/39a\/358\/27239a35821ac0ce0cff96e425e99153.svg\" width=\"15\" height=\"17\"\/> then verifies using a decision rule. The verdict can be positive (evidence accepted), negative (evidence rejected), or indeterminate. Typically, upon acceptance or rejection of the evidence, a specific action is initiated. For example, a common scenario is when <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/249\/37e\/c79\/24937ec795e8925bd767f16d518a1736.svg\" width=\"14\" height=\"17\"\/> requests access to a resource, which is granted if <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/559\/fea\/138\/559fea1381a4a8c0d6dfaea15113cbb9.svg\" width=\"15\" height=\"17\"\/> accepts the proof. There are other applications for this protocol as well.<\/p>\n<p>Identification protocols belong to a more general class of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hbox{$\\Sigma$-protocols}\" alt=\"\\hbox{$\\Sigma$-protocols}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c4f\/039\/2fa\/c4f0392fa391da497363c36d4c22c4d6.svg\" width=\"97\" height=\"20\"\/>, which were first introduced in [Cramer_1996]. <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/07c\/d80\/fca\/07cd80fca68d9f35512b76ad1b6b49bd.svg\" width=\"14\" height=\"17\"\/> and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/8bc\/b35\/54b\/8bcb3554b4bde76eca4be5f2fb449fb0.svg\" width=\"15\" height=\"17\"\/> are modeled using a probabilistic interactive Turing machine, and the <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hbox{$\\Sigma$-protocols}\" alt=\"\\hbox{$\\Sigma$-protocols}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/989\/a10\/ab1\/989a10ab155c3df32d221927dd52fbf3.svg\" width=\"97\" height=\"20\"\/> itself is an interactive proof scheme based on Arthur-Merlin game style [Babai_Moran_1988], in which <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/275\/d29\/46c\/275d2946c879c5dae9a0455bd1404b56.svg\" width=\"15\" height=\"17\"\/> always chooses some variable with a random distribution.<\/p>\n<p>Let&#8217;s focus on identification protocols that rely on asymmetric cryptography.\u00a0<\/p>\n<p>The interactive identification protocol can be represented by the following diagram:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula\" source=\"P \\stackrel{\\mbox{witness}}{\\longrightarrow} V  \\stackrel{\\mbox{challenge}}{\\longrightarrow} P \\stackrel{\\mbox{response}}{\\longrightarrow} V.\" alt=\"P \\stackrel{\\mbox{witness}}{\\longrightarrow} V  \\stackrel{\\mbox{challenge}}{\\longrightarrow} P \\stackrel{\\mbox{response}}{\\longrightarrow} V.\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/3b4\/0a2\/27a\/3b40a227ae4df0c97ef17deb1909e335.svg\" width=\"306\" height=\"35\"\/><\/p>\n<p>It is clear that three messages are transmitted during the protocol: <em>witness, challenge, <\/em>and <em>response<\/em>. In this case, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/7f5\/44e\/7dd\/7f544e7dd0e1662c7c4d2f8662f892dd.svg\" width=\"14\" height=\"17\"\/> transmits two messages (<em>witness<\/em> and <em>response<\/em>), and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/9fe\/4b9\/eca\/9fe4b9ecad0f73f9a9d777e6af7a45cb.svg\" width=\"15\" height=\"17\"\/> transmits only one message (<em>challenge<\/em>). The purpose of each message is clear from its name.\u00a0<\/p>\n<p>Let&#8217;s call the independent variables with a random distribution that change from one protocol session to another as the <em>ephemeris<\/em>. In cryptographic terms, ephemeris is equivalent to secret keys. To reveal an unknown ephemeris, it is necessary to find a solution to some computational complexity problem or to undertake a brute force attack.<\/p>\n<p>It is assumed that each participant has a pair of unique keys: a secret key and a public key. Additionally, proper certificates have been issued for the public keys.<\/p>\n<p>The parties do the following:<\/p>\n<ul>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/707\/0b0\/a0f\/7070b0a0ffb8f75ffa158a58f5285956.svg\" width=\"14\" height=\"17\"\/> generates a <em>witness<\/em> based on the public key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/df3\/e5f\/076\/df3e5f0768771f3580c14ad3a6887213.svg\" width=\"15\" height=\"17\"\/> and at least one ephemeris known only to <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d55\/670\/52f\/d5567052f00f821f55d4f12f0af2239e.svg\" width=\"14\" height=\"17\"\/>.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/3a4\/b37\/531\/3a4b3753144e1e403632f410e4182500.svg\" width=\"15\" height=\"17\"\/> creates a <em>challenge<\/em> using at least one ephemeris known only to <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/204\/6b8\/703\/2046b870373919f88adfe8505edf4488.svg\" width=\"15\" height=\"17\"\/>.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/2c9\/833\/c11\/2c9833c11a79c498f620198e3d852a60.svg\" width=\"14\" height=\"17\"\/> generates a <em>response<\/em> based on their own private and public keys and the <em>challenge<\/em>.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/002\/112\/49c\/00211249cd9d493ab3c61c58bb7f5ac0.svg\" width=\"15\" height=\"17\"\/> renders a verdict based on the <em>witness<\/em>, the <em>response<\/em>, the ephemeris involved in the <em>challenge<\/em>, and the public key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a8c\/2be\/9c1\/a8c2be9c111ee6e920c05db7e334fcbc.svg\" width=\"14\" height=\"17\"\/>.<\/p>\n<\/li>\n<\/ul>\n<p>All identification protocols include three messages, which, thanks to ephemeris, are randomly distributed. It is proven that there cannot be fewer messages (there can be more). All of the above messages carry the same semantic load in different identification protocols, but the methods of their computation can vary significantly and depend on the main provisions of the computational complexity problem, as well as the chosen mathematical apparatus.<\/p>\n<p>After some deliberation, we decided to keep the designations used in the interactive identification protocol we developed with the possibility of generating a shared secret session key, which has not yet been made public. Therefore, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"c=\\hslash(g_1)\" alt=\"c=\\hslash(g_1)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/929\/603\/969\/9296039696de08f371f1d39ee0e84e7c.svg\" width=\"78\" height=\"22\"\/> is passed as a <em>response<\/em>, where <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(\\cdot)\" alt=\"\\hslash(\\cdot)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/7a1\/0f6\/a00\/7a10f6a0064e8c7b47854e141c9de7e8.svg\" width=\"31\" height=\"22\"\/> is some cryptographic hash function known to both parties. To check the proof, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/8f6\/078\/340\/8f6078340bd3e22875824e14f587e5cf.svg\" width=\"15\" height=\"17\"\/> computes <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_3\" alt=\"g_3\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/8db\/42f\/a31\/8db42fa3142d29f2dd75e1a1ad2b5ec4.svg\" width=\"18\" height=\"15\"\/>. This uses a simple decision rule like <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(g_1)\\stackrel{?}{=}\\hslash(g_3)\" alt=\"\\hslash(g_1)\\stackrel{?}{=}\\hslash(g_3)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/62f\/034\/840\/62f034840ffe1479ff24d8aa09bbfbb5.svg\" width=\"113\" height=\"30\"\/>. Here <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1, g_3\\in\\mathbb{G}_3\" alt=\"g_1, g_3\\in\\mathbb{G}_3\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/8ee\/0e6\/db2\/8ee0e6db2a1a9852032e5ca0a2a1e04a.svg\" width=\"92\" height=\"20\"\/>. Note that the way <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/815\/644\/d53\/815644d535f2d7fae61a4ecccb2c8494.svg\" width=\"18\" height=\"15\"\/> and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_3\" alt=\"g_3\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f66\/d9e\/89f\/f66d9e89f876e28f3370f589be1c270c.svg\" width=\"18\" height=\"15\"\/> are computed is irrelevant in this context.<\/p>\n<p>Since most of the texts we publish are interconnected, we hope that this approach will further simplify the \u201cbridge\u201d between our various posts.<\/p>\n<p><strong>Compatibility with any DS scheme<\/strong><\/p>\n<p>Let there be a pair of keys <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{\\mathbf{z}, \\mathsf{P}=[\\mathbf{z}]\\mathsf{G}_1\\}\" alt=\"\\{\\mathbf{z}, \\mathsf{P}=[\\mathbf{z}]\\mathsf{G}_1\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/221\/f72\/c98\/221f72c989acdae5b2f5f11db5b5fc9e.svg\" width=\"118\" height=\"22\"\/> and a certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" alt=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/03d\/371\/8df\/03d3718df21636fe2412b56abdaf6e88.svg\" width=\"97\" height=\"22\"\/>. Let&#8217;s show how it works taking the well-known Schnorr&#8217;s DS scheme [Schnorr_1990] as an example.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f3f\/77b\/35c\/f3f77b35cac5730e6aa758ad0db7bbdc.svg\" width=\"14\" height=\"17\"\/> acts as the signer. Given message <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"M\" alt=\"M\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c2f\/9de\/84f\/c2f9de84fac35fed1185ad2a8491f6ba.svg\" width=\"20\" height=\"17\"\/>, secret key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}\" alt=\"\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c1f\/a7b\/6da\/c1fa7b6da6fbf37b7fcbbf4c07598e9e.svg\" width=\"10\" height=\"12\"\/>, and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/90c\/ce3\/537\/90cce35373e4e7292d171a9dcf73b2f9.svg\" width=\"18\" height=\"15\"\/>, the signer performs the following computations:<\/p>\n<ol>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{Q}=[\\varepsilon]\\mathsf{G}_1\" alt=\"\\mathsf{Q}=[\\varepsilon]\\mathsf{G}_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6a0\/4a3\/441\/6a04a3441f6008dc1a6ba4689a7c008b.svg\" width=\"81\" height=\"22\"\/>, where <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\varepsilon\\in_R\\!(0,m-1]\" alt=\"\\varepsilon\\in_R\\!(0,m-1]\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/db0\/f62\/e9c\/db0f62e9c546dd8bf7ef35c274de0557.svg\" width=\"123\" height=\"22\"\/>;<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\gamma=\\hslash(g_1\\|M\\|x_{\\mathsf{Q}})\" alt=\"\\gamma=\\hslash(g_1\\|M\\|x_{\\mathsf{Q}})\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/5ba\/9ff\/a46\/5ba9ffa466840156c50b4c3ee78aa072.svg\" width=\"143\" height=\"22\"\/>;<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\delta=\\varepsilon-\\gamma\\mathbf{z}\\pmod m\" alt=\"\\delta=\\varepsilon-\\gamma\\mathbf{z}\\pmod m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/860\/452\/bb5\/860452bb558c098718265de86bc75795.svg\" width=\"185\" height=\"22\"\/>;<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\Im=\\{\\gamma, \\delta\\}\" alt=\"\\Im=\\{\\gamma, \\delta\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/fca\/e20\/82a\/fcae2082ae53f64f43e66cc69c90ff4c.svg\" width=\"83\" height=\"22\"\/>.<\/p>\n<\/li>\n<\/ol>\n<p>Let there be a signature <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\Im'=\\{\\gamma', \\delta'\\}\" alt=\"\\Im'=\\{\\gamma', \\delta'\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/1ce\/0d3\/b42\/1ce0d3b42acbccf72d01e5efbd83e98b.svg\" width=\"101\" height=\"23\"\/> and a message <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"M'\" alt=\"M'\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/fb6\/0a1\/de8\/fb60a1de84850e4c844d0b6e37239810.svg\" width=\"26\" height=\"19\"\/> such that <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"(\\delta'\\neq\\delta)\\land(\\gamma'\\neq\\gamma )\\land(M'\\neq M)\" alt=\"(\\delta'\\neq\\delta)\\land(\\gamma'\\neq\\gamma )\\land(M'\\neq M)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/3cf\/c1f\/6f3\/3cfc1f6f3de1818e92f845684790689d.svg\" width=\"262\" height=\"23\"\/>. Let&#8217;s assume that the authenticity and integrity of the key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{P}\" alt=\"\\mathsf{P}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/94b\/294\/68b\/94b29468b361647eaffa77b07d1d7105.svg\" width=\"12\" height=\"17\"\/> is confirmed by checking the valid certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" alt=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c1b\/9ba\/7db\/c1b9ba7db74188d904933ab6328ec1fd.svg\" width=\"97\" height=\"22\"\/>. <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6cb\/462\/006\/6cb46200641f8dbc22635cdd96e461b0.svg\" width=\"15\" height=\"17\"\/> performs the following computations:<\/p>\n<ol>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{S}=[\\delta']\\mathsf{G}_1+[\\gamma']\\mathsf{P}=[\\delta'+\\gamma'\\mathbf{z}\\pmod m]\\mathsf{G }_1\" alt=\"\\mathsf{S}=[\\delta']\\mathsf{G}_1+[\\gamma']\\mathsf{P}=[\\delta'+\\gamma'\\mathbf{z}\\pmod m]\\mathsf{G }_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/2aa\/18e\/356\/2aa18e3563f40dc1e3e730c438a53144.svg\" width=\"366\" height=\"23\"\/>;<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(g_3\\|M'\\|x_\\mathsf{S})\\stackrel{?}{=}\\gamma'\" alt=\"\\hslash(g_3\\|M'\\|x_\\mathsf{S})\\stackrel{?}{=}\\gamma'\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/182\/541\/d6e\/182541d6e352af5bb0b0a6a8903e06bb.svg\" width=\"152\" height=\"30\"\/>.<\/p>\n<\/li>\n<\/ol>\n<p>If <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(g_3\\|M'\\|x_\\mathsf{S})=\\gamma\" alt=\"\\hslash(g_3\\|M'\\|x_\\mathsf{S})=\\gamma\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/e29\/803\/378\/e298033787f990c2367e17c268e2b504.svg\" width=\"146\" height=\"23\"\/>, then <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}=True\" alt=\"\\mathfrak{B}=True\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/cb8\/58f\/835\/cb858f83507e8ce5648e8aee82b4a6f9.svg\" width=\"85\" height=\"17\"\/>, where <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}\\Leftarrow{\\rm{Verify}}(\\hslash(g_3\\|M'\\|x_{\\mathsf{S}})),\\Im',\\mathsf{P})\" alt=\"\\mathfrak{B}\\Leftarrow{\\rm{Verify}}(\\hslash(g_3\\|M'\\|x_{\\mathsf{S}})),\\Im',\\mathsf{P})\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b67\/15d\/e1f\/b6715de1f89960678ce83a3a0de13b7a.svg\" width=\"279\" height=\"23\"\/>. Suppose <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\delta'=\\varepsilon-\\gamma\\mathbf{z}\\pmod m\" alt=\"\\delta'=\\varepsilon-\\gamma\\mathbf{z}\\pmod m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/e56\/5db\/5ce\/e565db5ce47e53eef13bf0be2a4b060c.svg\" width=\"190\" height=\"23\"\/>. Therefore, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{S}=[\\varepsilon-\\gamma\\mathbf{z}+\\gamma'\\mathbf{z}\\pmod m]\\mathsf{G}_1=[\\varepsilon]\\mathsf{G}_1 =\\mathsf{Q}\" alt=\"\\mathsf{S}=[\\varepsilon-\\gamma\\mathbf{z}+\\gamma'\\mathbf{z}\\pmod m]\\mathsf{G}_1=[\\varepsilon]\\mathsf{G}_1 =\\mathsf{Q}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a27\/92d\/a8d\/a2792da8db07a18457a127128d49af36.svg\" width=\"376\" height=\"23\"\/> if <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\gamma'=\\gamma=\\hslash(g_3\\|M'\\|x_\\mathsf{S})\\Rightarrow (M'=M)\\land(x_\\mathsf{S }=x_\\mathsf{Q})\\land(g_3=g_1)\" alt=\"\\gamma'=\\gamma=\\hslash(g_3\\|M'\\|x_\\mathsf{S})\\Rightarrow (M'=M)\\land(x_\\mathsf{S }=x_\\mathsf{Q})\\land(g_3=g_1)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/95a\/906\/1c5\/95a9061c5e691ff14073540afe800f43.svg\" width=\"509\" height=\"23\"\/>. For <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"((\\delta'\\neq\\delta)\\land(\\gamma'=\\gamma))\\lor((\\delta'=\\delta)\\land(\\gamma'\\neq\\gamma))\\lor(( \\delta'\\neq\\delta)\\land(\\gamma'\\neq\\gamma))\" alt=\"((\\delta'\\neq\\delta)\\land(\\gamma'=\\gamma))\\lor((\\delta'=\\delta)\\land(\\gamma'\\neq\\gamma))\\lor(( \\delta'\\neq\\delta)\\land(\\gamma'\\neq\\gamma))\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/443\/785\/785\/44378578553f8e1094633c9d20ec3eb8.svg\" width=\"546\" height=\"23\"\/> with overwhelming probability <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}=False\" alt=\"\\mathfrak{B}=False\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/3c4\/3c5\/f02\/3c43c5f029e34c275c07d5a24e60e70a.svg\" width=\"91\" height=\"17\"\/> and negligible <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}=True\" alt=\"\\mathfrak{B}=True\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/4f8\/471\/518\/4f847151899e0847b5a764b34f967d73.svg\" width=\"85\" height=\"17\"\/>. However, if <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"(\\delta'=\\delta)\\land(\\gamma'=\\gamma)\" alt=\"(\\delta'=\\delta)\\land(\\gamma'=\\gamma)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/646\/71c\/fa1\/64671cfa1d4b8559d3b9e5fb2321185d.svg\" width=\"153\" height=\"23\"\/>, then it is <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}=True\" alt=\"\\mathfrak{B}=True\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d98\/2eb\/4b9\/d982eb4b986f8c7f8d630ddf3ba2dc5a.svg\" width=\"85\" height=\"17\"\/> with overwhelming probability and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}=False\" alt=\"\\mathfrak{B}=False\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/dfa\/b86\/459\/dfab86459d8c0fd8fb60656cb83c41d2.svg\" width=\"91\" height=\"17\"\/> with negligible probability.<\/p>\n<p>DS verification and verification of personal data are interconnected. Let <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D\" alt=\"D\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/325\/dda\/3e2\/325dda3e2a89a1d6225104012741e0c3.svg\" width=\"16\" height=\"17\"\/> be some personal data and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\Im\\Leftarrow{\\rm{Sign}}(\\hslash(D), \\mathbf{z})\" alt=\"\\Im\\Leftarrow{\\rm{Sign}}(\\hslash(D), \\mathbf{z})\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d04\/ce1\/2d5\/d04ce12d537edeea9d03aee5b6a95f3f.svg\" width=\"152\" height=\"22\"\/>. <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D'\" alt=\"D'\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/53b\/b22\/3e0\/53bb223e034735d29b1793675dda8d9f.svg\" width=\"22\" height=\"19\"\/>, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\Im'\" alt=\"\\Im'\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/0e4\/25f\/3d5\/0e425f3d51611123b258fc9a105b576b.svg\" width=\"16\" height=\"19\"\/> and a valid certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" alt=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b0e\/a8f\/f05\/b0ea8ff0544348bda72a80c1694511c4.svg\" width=\"97\" height=\"22\"\/> are presented for verification. If the DS is valid, in other words <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(g_3\\|D'\\|x_\\mathsf{S})=\\gamma\" alt=\"\\hslash(g_3\\|D'\\|x_\\mathsf{S})=\\gamma\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/872\/e84\/7dd\/872e847dd44931658978754f7143d23a.svg\" width=\"141\" height=\"23\"\/>, then <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D'=D\" alt=\"D'=D\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/22c\/08a\/352\/22c08a352d60f9e3f08d99a092761306.svg\" width=\"63\" height=\"19\"\/>. If valid, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D'\\stackrel{?}{=}D_{\\mathsf{P}}\" alt=\"D'\\stackrel{?}{=}D_{\\mathsf{P}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/8e6\/37f\/6ed\/8e637f6ed1830d61b762f9c6b57ee4d6.svg\" width=\"74\" height=\"28\"\/> is verified. The authenticity of personal data arises from <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D'=D_{\\mathsf{P}}\" alt=\"D'=D_{\\mathsf{P}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6af\/bfc\/2a9\/6afbfc2a971203ca0581ba49992d81bf.svg\" width=\"74\" height=\"21\"\/>.<\/p>\n<p>The IDS mode can be implemented using an arbitrary conventional scheme based on the elliptic curve points arithmetic. This approach is inherent in the vast majority of modern DS schemes [Schnorr_1990, Paterson_2002, Hess_2003, Boneh_Shacham_Lynn_2004, Zhang_Safavi-Naini_Susilo_2004, Boneh_Boyen_2004]. However, this condition is not necessary. For example, without losing the generality, one can replace a subgroup of the group of elliptic curve points with a subgroup of prime order <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"m\" alt=\"m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/2d8\/e56\/67b\/2d8e5667b7509d00945791f5c88e5272.svg\" width=\"17\" height=\"12\"\/> of the group <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbb{F}^*_p\" alt=\"\\mathbb{F}^*_p\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/bef\/975\/bc0\/bef975bc016e5eb5a91d2744e0a77d95.svg\" width=\"21\" height=\"25\"\/>. Note that the mode is also compatible with DS schemes, which are developed consistent with the provisions of post-quantum cryptography.<\/p>\n<p>This compatibility has a simple explanation. Since in an arbitrary conventional DS scheme the computation of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(M)\" alt=\"\\hslash(M)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/bbf\/bc7\/a5d\/bbfbc7a5de6edde8932cf2087cec4a97.svg\" width=\"46\" height=\"22\"\/> is normative in nature, that means that it is always present in any DS scheme, then replacing <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(M)\" alt=\"\\hslash(M)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d46\/f0d\/c1e\/d46f0dc1ea94c83c6c346b2ee8aa126a.svg\" width=\"46\" height=\"22\"\/> with <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(\\ldots\\|M\\|\\ldots)\" alt=\"\\hslash(\\ldots\\|M\\|\\ldots)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/da5\/c02\/859\/da5c028596a95cdf0ab41942d6956b55.svg\" width=\"117\" height=\"22\"\/> does not lead to negative consequences for the cryptographic strength of this scheme, since in the general case the dependence of the collision probability on the argument of the cryptographic hash function <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(\\cdot)\" alt=\"\\hslash(\\cdot)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/571\/a70\/24e\/571a7024edb2366e3e1bebeef6d71540.svg\" width=\"31\" height=\"22\"\/> is unknown. Here, by collision we mean <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(\\mathsf{x})=\\hslash(\\mathsf{y})\" alt=\"\\hslash(\\mathsf{x})=\\hslash(\\mathsf{y})\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/fe5\/ca8\/f0d\/fe5ca8f0d2dabb5e9c5f7069b2ab6f10.svg\" width=\"95\" height=\"22\"\/> for <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{x}\\neq\\mathsf{y}\" alt=\"\\mathsf{x}\\neq\\mathsf{y}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/25b\/6b3\/6ec\/25b6b36ec6c9cb09cd0fe3d467850729.svg\" width=\"43\" height=\"21\"\/> and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{x},\\mathsf{y}\\in\\{0,1\\}^*\" alt=\"\\mathsf{x},\\mathsf{y}\\in\\{0,1\\}^*\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/9e9\/eef\/97a\/9e9eef97a4a5562b3cfa356105852989.svg\" width=\"106\" height=\"22\"\/>.<\/p>\n<p>For example, if the DS scheme [Zhang Safavi-Naini_Susilo_2004] is used for this purpose, then for the given message <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"M\" alt=\"M\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ac5\/bcd\/dd3\/ac5bcddd30ab92cc159df55c678fac06.svg\" width=\"20\" height=\"17\"\/> and secret key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}\" alt=\"\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/4a2\/c77\/2fd\/4a2c772fd752f41a2cb5de24ad93226c.svg\" width=\"10\" height=\"12\"\/> the signer first computes <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\phi=\\hslash(g_1\\|M)\" alt=\"\\phi=\\hslash(g_1\\|M)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/0cf\/86c\/f36\/0cf86cf360ad658a88e44b382768995c.svg\" width=\"111\" height=\"22\"\/>, and then generates the signature <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{Q}=[\\frac{1}{\\phi+\\mathbf{z}\\pmod m}]\\mathsf{G}_1=[\\psi]\\mathsf{G}_1\" alt=\"\\mathsf{Q}=[\\frac{1}{\\phi+\\mathbf{z}\\pmod m}]\\mathsf{G}_1=[\\psi]\\mathsf{G}_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/2b9\/c24\/730\/2b9c247304dd8fc28e67ff08a9ca98a3.svg\" width=\"281\" height=\"47\"\/>.<\/p>\n<p>Let there be a signature <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{Q}'=[\\psi']\\mathsf{G}_1\" alt=\"\\mathsf{Q}'=[\\psi']\\mathsf{G}_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/fc3\/58b\/fec\/fc358bfece8611c21409d65d4a4b0c06.svg\" width=\"96\" height=\"24\"\/> and a message <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"M'\" alt=\"M'\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/20b\/deb\/10d\/20bdeb10d74c95464752296d01f85e42.svg\" width=\"26\" height=\"19\"\/> such that <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"(\\mathsf{Q'}\\neq\\mathsf{Q})\\land(M'\\neq M)\" alt=\"(\\mathsf{Q'}\\neq\\mathsf{Q})\\land(M'\\neq M)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/568\/d77\/292\/568d77292eb106bd507856a94a4a5c36.svg\" width=\"184\" height=\"23\"\/>. <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f0d\/890\/119\/f0d8901193e33d8144c69b1c30ad7508.svg\" width=\"15\" height=\"17\"\/> first evaluates <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\phi'=\\hslash(g_3\\|M')\" alt=\"\\phi'=\\hslash(g_3\\|M')\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/bbf\/a97\/bca\/bbfa97bca553dafc0b807bc31444abea.svg\" width=\"123\" height=\"23\"\/> and then <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g'=e_m([\\phi']\\mathsf{G}_1+ \\mathsf{P}, \\mathsf{Q} ')=e_m([\\phi'+\\mathbf{z}\\pmod m]\\mathsf{G}_1, [\\psi']\\mathsf{G}_1)=g^{\\psi'(\\phi'+ \\mathbf{z})\\pmod m}\" alt=\"g'=e_m([\\phi']\\mathsf{G}_1+ \\mathsf{P}, \\mathsf{Q} ')=e_m([\\phi'+\\mathbf{z}\\pmod m]\\mathsf{G}_1, [\\psi']\\mathsf{G}_1)=g^{\\psi'(\\phi'+ \\mathbf{z})\\pmod m}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/eb5\/603\/14c\/eb560314cb5e40a89976e9d847934695.svg\" width=\"650\" height=\"27\"\/>. Checks <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g'\\stackrel{?}{=}e_m(\\mathsf{G}_1, \\mathsf{G}_1)\" alt=\"g'\\stackrel{?}{=}e_m(\\mathsf{G}_1, \\mathsf{G}_1)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/154\/d03\/c2b\/154d03c2befdd6c0030b4943d00ba3af.svg\" width=\"130\" height=\"30\"\/> and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g'=g\" alt=\"g'=g\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c9d\/305\/c48\/c9d305c48bd9bebe9fd20d652865ceab.svg\" width=\"50\" height=\"22\"\/> if <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"(\\psi'=\\psi)\\land( \\phi'=\\phi)\\Rightarrow (M'=M)\\land(g_3=g_1)\" alt=\"(\\psi'=\\psi)\\land( \\phi'=\\phi)\\Rightarrow (M'=M)\\land(g_3=g_1)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/931\/631\/58f\/93163158fd19f75bc99a7afb7bc17741.svg\" width=\"378\" height=\"23\"\/>.<\/p>\n<p>Note that at the identification stage, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"c=\\hslash(g_1)\" alt=\"c=\\hslash(g_1)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/28d\/795\/635\/28d795635d9defe4b790637aece7a6de.svg\" width=\"78\" height=\"22\"\/> is transmitted over an insecure communication channel, and to reveal <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f3d\/a96\/64b\/f3da9664b5c5596ee1b35a034d4b6b86.svg\" width=\"18\" height=\"15\"\/> with an unknown secret message, you must either compute <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1=\\hslash^{-1}(c)\" alt=\"g_1=\\hslash^{-1}(c)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/43e\/55d\/603\/43e55d603936cee1c5b9ca46250b44ad.svg\" width=\"97\" height=\"25\"\/>, or find solution of some computational complexity problem.<\/p>\n<p>Let&#8217;s summarize.<\/p>\n<ol>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/035\/a01\/e95\/035a01e953ddd4bc8d1b21bd82dc3c01.svg\" width=\"15\" height=\"17\"\/> is unable to forge\/falsify the DS given <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_3\" alt=\"g_3\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/827\/210\/4e0\/8272104e0b354e47b8c7a220adac07f7.svg\" width=\"18\" height=\"15\"\/> is known, because it does not know <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}\" alt=\"\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/58e\/85a\/902\/58e85a902dcafaf2013957df2dfef56a.svg\" width=\"10\" height=\"12\"\/>. He can use the key pair <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{\\mathbf{z}', \\mathsf{P}'\\}\" alt=\"\\{\\mathbf{z}', \\mathsf{P}'\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d77\/f27\/d9d\/d77f27d9d62a03eed053b441e58b372b.svg\" width=\"61\" height=\"23\"\/>, where <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}'\\neq\\mathbf{z}\" alt=\"\\mathbf{z}'\\neq\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/1ac\/aa3\/fc8\/1acaa3fc8ecd499451dd889cf6c5e16d.svg\" width=\"51\" height=\"23\"\/>, and certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{P}'}, \\mathsf{P}', \\Im_{\\mathsf{P}'}\\}\" alt=\"\\{D_{\\mathsf{P}'}, \\mathsf{P}', \\Im_{\\mathsf{P}'}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/66b\/cbf\/48a\/66bcbf48a181e084e204d8410653ed94.svg\" width=\"110\" height=\"23\"\/> has been issued for <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{P}'\" alt=\"\\mathsf{P}'\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a15\/707\/afb\/a15707afb77ebc5e50e539ad279a90fa.svg\" width=\"18\" height=\"19\"\/>, but subsequent verification will show that <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D_{\\mathsf{ P}'}\\neq D_{\\mathsf{P}}\" alt=\"D_{\\mathsf{ P}'}\\neq D_{\\mathsf{P}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/e53\/f5a\/ff8\/e53f5aff89c5433771b436f3a48128dc.svg\" width=\"83\" height=\"21\"\/>.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/7d2\/134\/60e\/7d213460e77b3f2a7359fe8f0783a25b.svg\" width=\"14\" height=\"17\"\/> (signer) can generate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\Im=\\{\\gamma, \\delta\\}\" alt=\"\\Im=\\{\\gamma, \\delta\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/33e\/23a\/840\/33e23a8407eba215b104e6a11c66b37b.svg\" width=\"83\" height=\"22\"\/> only if he knows the secret <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}\" alt=\"\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b9e\/638\/50f\/b9e63850f3fcd359d86184216843a524.svg\" width=\"10\" height=\"12\"\/>.<\/p>\n<\/li>\n<li>\n<p>DS verification is possible only if there is a positive decision regarding the <em>response<\/em> <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"c=\\hslash(g_1)\" alt=\"c=\\hslash(g_1)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/167\/0fe\/e33\/1670fee3385cabcefca3818ba1b76a2d.svg\" width=\"78\" height=\"22\"\/>.<\/p>\n<\/li>\n<\/ol>\n<p>Let&#8217;s list the distinctive features of the IDS mode.<\/p>\n<ol>\n<li>\n<p>The mode is active within the current session and is relevant only for <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/78d\/920\/930\/78d9209302ac07f4269783653c0efeb9.svg\" width=\"15\" height=\"17\"\/>.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/48d\/f1f\/691\/48df1f691f7339b236f2dea4f0fa7d75.svg\" width=\"15\" height=\"17\"\/> cannot convince a third party of the authenticity and integrity of the data received during a particular session.<\/p>\n<\/li>\n<li>\n<p>The IDS can be formed by someone who knows the secret key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}\" alt=\"\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/49f\/476\/fc4\/49f476fc4d8bad27df56ca245dd75cad.svg\" width=\"10\" height=\"12\"\/> and is able to compute <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1.\" alt=\"g_1.\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c6e\/584\/33e\/c6e58433efecc72225f312a11c1aa42a.svg\" width=\"23\" height=\"15\"\/><\/p>\n<\/li>\n<li>\n<p>Anyone who knows <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{P}\" alt=\"\\mathsf{P}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c39\/628\/3b6\/c396283b6c1f4b7204e8b9fbb625a76b.svg\" width=\"12\" height=\"17\"\/> and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_3\" alt=\"g_3\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b64\/dd4\/054\/b64dd405443d9f72eeaff7c4f316e567.svg\" width=\"18\" height=\"15\"\/> can check the IDS.<\/p>\n<\/li>\n<li>\n<p>The correctness of the IDS is guaranteed if the proof is accepted.<\/p>\n<\/li>\n<\/ol>\n<p>The IDS mode is ideologically close to the work of [Dwork_Naor_Sahai_1998], in which the problem of <em>deniable authentication<\/em> was first formulated and the authors proposed a specific solution.<\/p>\n<p>Let&#8217;s assume that <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/470\/ab7\/1a9\/470ab71a9220fa73ad47dac8b3e734d8.svg\" width=\"15\" height=\"17\"\/> verified the authenticity of the signer&#8217;s personal data using the IDS mode with subsequent verification. Now the signer can use the secret key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}\" alt=\"\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/912\/e0b\/042\/912e0b0424dcce37518f07085e1556cb.svg\" width=\"10\" height=\"12\"\/> to generate a signature using an arbitrary conventional DS scheme based on the elliptic curve points arithmetic (or any other). Note that this scheme may differ from the one used to verify personal data. It makes sense to keep such the DS in long-term memory, and you need a valid certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" alt=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/9e5\/49d\/96c\/9e549d96c596f2ef20eba081cf397f08.svg\" width=\"97\" height=\"22\"\/> to verify it. This means that after authentication in the IDS mode, undeniable authentication is guaranteed for all other data, the certification of which is made within the framework of the conventional DS scheme. And it does not need auxiliary computation and additional organizational costs.<\/p>\n<p>In general, an attacker does not have access to personal data, since it is transmitted and stored in encrypted form, but can determine the serial numbers of certificates of public keys of signers by tracking requests from verifiers, for example, according to the rules of the OCSP (Online Certificate Status Protocol). Such monitoring should be regarded as a threat, because certificates contain information that allows to deanonymize a participant. Potential risks are offset by the transfer of certificates through a secure tunnel. Furthermore, certificates can be read using the Private Information Retrieval (PIR) method [Chor_Goldreich_Kushilevitz_Sudan_1995, Kushilevitz_Ostrovsky_1997].<\/p>\n<p><strong>Incompatibility with arbitrary protocol\u00a0<\/strong><\/p>\n<p>As it was shown, in the IDS mode, any known DS scheme based on the elliptic curve points arithmetic (or any other) can be applied.\u00a0<\/p>\n<p>All identification protocols consist of one and a half rounds and provide for the transmission of <em>witness<\/em>, <em>challenge<\/em> and <em>response<\/em> messages. There is the following fundamental question to be answered: is the IDS mode possible only for a specific identification protocol or is it compatible with an arbitrary protocol?<\/p>\n<p>Let&#8217;s consider a specific example. To do this, when describing the Schnorr&#8217;s identification protocol [Schnorr_1990], we pass from a subgroup of prime order <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"m\" alt=\"m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/e45\/f61\/101\/e45f61101213327e62ceaac1533f3c63.svg\" width=\"17\" height=\"12\"\/> of the group <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbb{F}^*_p\" alt=\"\\mathbb{F}^*_p\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/74d\/279\/375\/74d279375f29baba117f6b9b0ee4f09c.svg\" width=\"21\" height=\"25\"\/> to a subgroup of order <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"m\" alt=\"m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/717\/13c\/dbe\/71713cdbefdd7a3deb5122a531385fe3.svg\" width=\"17\" height=\"12\"\/> of the elliptic curve points group.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ceb\/797\/31c\/ceb79731ce84300f8d93e8e7178c97d3.svg\" width=\"14\" height=\"17\"\/> first selects <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{x}\\in_R\\!(0, m-1]\" alt=\"\\mathbf{x}\\in_R\\!(0, m-1]\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/48b\/1bd\/8e0\/48b1bd8e0f7e0893ee2b99479151e1e2.svg\" width=\"126\" height=\"22\"\/> and generates a pair of keys <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{\\mathbf{x},\\mathsf{R}=[-\\mathbf{x}] \\mathsf{G}_1\\}\" alt=\"\\{\\mathbf{x},\\mathsf{R}=[-\\mathbf{x}] \\mathsf{G}_1\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/362\/976\/33a\/36297633a988c61cdff57b1596e7c700.svg\" width=\"137\" height=\"22\"\/> . Then contacts trusted authority <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"T\" alt=\"T\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a1f\/b47\/312\/a1fb47312edd8c252be2317e55a2561d.svg\" width=\"14\" height=\"17\"\/> to issue a certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{R}},\\mathsf{R}, \\Im_{\\mathsf{R}}\\}\" alt=\"\\{D_{\\mathsf{R}},\\mathsf{R}, \\Im_{\\mathsf{R}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/5dd\/010\/0a5\/5dd0100a51728ded438ad99d092afae6.svg\" width=\"97\" height=\"22\"\/>, where <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\Im_{\\mathsf{R}}\\Leftarrow{\\rm{Sign}}(\\hslash(\\mathsf{R}||D_{\\mathsf{R}}), \\rm{S}_T)\" alt=\"\\Im_{\\mathsf{R}}\\Leftarrow{\\rm{Sign}}(\\hslash(\\mathsf{R}||D_{\\mathsf{R}}), \\rm{S}_T)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/cf8\/de0\/e67\/cf8de0e670adb8f6362ceb38ce81a508.svg\" width=\"210\" height=\"22\"\/> and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D_{\\mathsf{R}}\" alt=\"D_{\\mathsf{R}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b25\/048\/26e\/b2504826ea016f4d773e088c19aa0300.svg\" width=\"27\" height=\"19\"\/> are personal data of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/dff\/b2b\/7e1\/dffb2b7e1e90501f46f8b1ee31fb0098.svg\" width=\"14\" height=\"17\"\/>.<\/p>\n<p>For simplicity, we omit information about the location of the certificate, as well as its updating by checking with the list of revoked certificates.<\/p>\n<p><u>Schnorr&#8217;s Identification Protocol<\/u><\/p>\n<p><em>Protocol messages.<\/em><\/p>\n<ol>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P \\longrightarrow V : \\mathsf{S}=[\\upsilon]\\mathsf{G}_1\" alt=\"P \\longrightarrow V : \\mathsf{S}=[\\upsilon]\\mathsf{G}_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c14\/df5\/8fe\/c14df58fe64c240259e4ede046f59ef5.svg\" width=\"167\" height=\"22\"\/><\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P \\longleftarrow V :\u00a0 \\phi\" alt=\"P \\longleftarrow V :\u00a0 \\phi\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/976\/f44\/23e\/976f4423e092a1f483f84e75ab2f6dd4.svg\" width=\"99\" height=\"20\"\/><\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P \\longrightarrow\u00a0 V : \\psi=\\mathbf{x}\\phi+\\upsilon\\pmod m\" alt=\"P \\longrightarrow\u00a0 V : \\psi=\\mathbf{x}\\phi+\\upsilon\\pmod m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a07\/b99\/d65\/a07b99d654039859989c67161ca6b935.svg\" width=\"280\" height=\"22\"\/><\/p>\n<\/li>\n<\/ol>\n<p><em>Actions of the parties.\u00a0<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6a5\/19e\/36c\/6a519e36cab2e8f87c95be4b5105fbf0.svg\" width=\"14\" height=\"17\"\/> proves to <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/da6\/5da\/655\/da65da655d48bc7da29458a7eb3ec47c.svg\" width=\"15\" height=\"17\"\/> that he owns (knows) <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{x}\" alt=\"\\mathbf{x}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/7d7\/7bd\/b3c\/7d77bdb3c285002328dad640f6437092.svg\" width=\"12\" height=\"12\"\/>. To do this, the following steps are performed:<\/p>\n<ol>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/44e\/d25\/e24\/44ed25e24eadbf66ed7c53994dd84cc0.svg\" width=\"14\" height=\"17\"\/> selects <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"{\\upsilon\\in_R\\!(0,m-1]}\" alt=\"{\\upsilon\\in_R\\!(0,m-1]}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/aa7\/5f1\/1ee\/aa75f11eef7d3e61b93032cd2e4e8112.svg\" width=\"124\" height=\"22\"\/> (<em>commitment<\/em>), computes <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{S}=[\\upsilon]\\mathsf{G}_1\" alt=\"\\mathsf{S}=[\\upsilon]\\mathsf{G}_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/bdb\/035\/b96\/bdb035b96db4f91c6dc16cc4e01c1bfa.svg\" width=\"79\" height=\"22\"\/> (<em>witness<\/em>), checks the condition <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{S}\\stackrel{?}\\neq\\infty\" alt=\"\\mathsf{S}\\stackrel{?}\\neq\\infty\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/215\/7ae\/ef2\/2157aeef255892776b86bd0f673bbeab.svg\" width=\"56\" height=\"37\"\/> . If <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{S}=\\infty\" alt=\"\\mathsf{S}=\\infty\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/216\/7c0\/f37\/2167c0f375f888d7fd8ca64a4fc6e0d0.svg\" width=\"56\" height=\"17\"\/>, then choose a new <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\upsilon\" alt=\"\\upsilon\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d73\/5d6\/3cf\/d735d63cfd25b011a35fcd8bc0f00ece.svg\" width=\"10\" height=\"12\"\/> and re-do the necessary computations and checks.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/db6\/99a\/794\/db699a79495cf4d6231040db321f0dbc.svg\" width=\"15\" height=\"17\"\/> reads the valid certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{R}},\\mathsf{R}, \\Im_{\\mathsf{R}}\\}\" alt=\"\\{D_{\\mathsf{R}},\\mathsf{R}, \\Im_{\\mathsf{R}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f96\/f7c\/686\/f96f7c68638cff82267e989a15dd66a0.svg\" width=\"97\" height=\"22\"\/> and checks the DS <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}\\Leftarrow{\\rm {Verify}}(\\hslash(\\mathsf{R}||D_{\\mathsf{R}}),\\Im_{\\mathsf{R}}, \\rm{P}_T)\" alt=\"\\mathfrak{B}\\Leftarrow{\\rm {Verify}}(\\hslash(\\mathsf{R}||D_{\\mathsf{R}}),\\Im_{\\mathsf{R}}, \\rm{P}_T)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ef3\/ba7\/07f\/ef3ba707f2cd162e435259590e47e891.svg\" width=\"255\" height=\"22\"\/>. If <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathfrak{B}=True\" alt=\"\\mathfrak{B}=True\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/7a7\/810\/359\/7a78103591491cdc44f61b04a21be86e.svg\" width=\"85\" height=\"17\"\/> then <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/0e6\/a81\/a4d\/0e6a81a4d905a285757de82b3ef38ca7.svg\" width=\"15\" height=\"17\"\/> chooses <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\phi\\in_R\\!(0, m-1]\" alt=\"\\phi\\in_R\\!(0, m-1]\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/1f3\/65b\/576\/1f365b576783af22d5df8010afe5cc2d.svg\" width=\"125\" height=\"22\"\/> (<em>challenge<\/em>), otherwise the session ends.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a0c\/524\/5e6\/a0c5245e6c106822f158a3cd17a5ab49.svg\" width=\"14\" height=\"17\"\/> checks the condition <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\phi\\stackrel{?}\\neq 0\" alt=\"\\phi\\stackrel{?}\\neq 0\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a4f\/fcb\/161\/a4ffcb161e8970e2bea2a89f72c6edbf.svg\" width=\"47\" height=\"37\"\/>. If it is true, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/513\/181\/1c4\/5131811c4558bfd9d036de270ff50a3f.svg\" width=\"14\" height=\"17\"\/> evaluates <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\psi=\\mathbf{x}\\phi+\\upsilon\\pmod m\" alt=\"\\psi=\\mathbf{x}\\phi+\\upsilon\\pmod m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f1d\/5e7\/48f\/f1d5e748feb8f6686eacc49e8aaf88c0.svg\" width=\"193\" height=\"22\"\/> (<em>response<\/em>), otherwise the session ends.<\/p>\n<\/li>\n<li>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/14a\/e37\/5d3\/14ae375d338001bf7e462e6b9b7e1b1d.svg\" width=\"15\" height=\"17\"\/> computes <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{Q}=[\\psi]\\mathsf{G}_1+[\\phi]\\mathsf{R}=[\\psi-\\phi\\mathbf{x}\\pmod m]\\mathsf{G }_1\" alt=\"\\mathsf{Q}=[\\psi]\\mathsf{G}_1+[\\phi]\\mathsf{R}=[\\psi-\\phi\\mathbf{x}\\pmod m]\\mathsf{G }_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/4ee\/080\/324\/4ee0803242fe7b6e1cbe32c7efdf83b7.svg\" width=\"358\" height=\"22\"\/>. Then <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/9d8\/a23\/264\/9d8a232642295e822a01216a962eb280.svg\" width=\"15\" height=\"17\"\/> checks <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"x_{\\mathsf{Q}}\\stackrel{?}{=}x_{\\mathsf{S}}\" alt=\"x_{\\mathsf{Q}}\\stackrel{?}{=}x_{\\mathsf{S}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d94\/b2b\/2d1\/d94b2b2d110da7c6d32914fa7f778435.svg\" width=\"69\" height=\"30\"\/>. If equal, then the proof is accepted, or it is rejected otherwise.<\/p>\n<\/li>\n<\/ol>\n<p>In the general case, the pair of keys <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{\\mathbf{z}, \\mathsf{P}=[\\mathbf{z}]\\mathsf{G}_1]\\}\" alt=\"\\{\\mathbf{z}, \\mathsf{P}=[\\mathbf{z}]\\mathsf{G}_1]\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/e6c\/ea8\/850\/e6cea8850c8bc59d8732ce7dda3967b7.svg\" width=\"123\" height=\"22\"\/>, with wich is signed\/verified, differs from <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{\\mathbf{x}, \\mathsf{R}\\}\" alt=\"\\{\\mathbf{x}, \\mathsf{R}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/152\/e8a\/295\/152e8a295af1a06c100c365d4f0065c9.svg\" width=\"52\" height=\"22\"\/>. For <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{P}\" alt=\"\\mathsf{P}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ceb\/833\/690\/ceb833690c43839ab12cc03e80b6dee9.svg\" width=\"12\" height=\"17\"\/>, trusted authority <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"T\" alt=\"T\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/696\/1c3\/794\/6961c37948fb769f8ba6ff7309c5fcba.svg\" width=\"14\" height=\"17\"\/> also issues a certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{P}},\\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" alt=\"\\{D_{\\mathsf{P}},\\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b72\/5fc\/6ad\/b725fc6ad54c22489cacf7a7bc22c0b5.svg\" width=\"97\" height=\"22\"\/>. For simplicity, we set <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D_{\\mathsf{P}}=D_{\\mathsf{R}}\" alt=\"D_{\\mathsf{P}}=D_{\\mathsf{R}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/75a\/ef0\/741\/75aef0741649837d2d2ed39b68475a3f.svg\" width=\"79\" height=\"19\"\/>.<\/p>\n<p>Let&#8217;s assume that <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c5d\/70e\/ae0\/c5d70eae0a6106277251921b828ffbad.svg\" width=\"14\" height=\"17\"\/> sends <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/51e\/620\/38b\/51e62038b2c0b1e6e11b158d49948e7c.svg\" width=\"15\" height=\"17\"\/> some data certified by DS. Moreover, the DS is generated using the secret key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{z}\" alt=\"\\mathbf{z}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a3b\/196\/e1c\/a3b196e1cfeb651f3e087d386f73dacd.svg\" width=\"10\" height=\"12\"\/>, and it is necessary to use the public key <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{P}\" alt=\"\\mathsf{P}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b7e\/8b0\/72b\/b7e8b072b0aa65a9eb298f6e058aaf4c.svg\" width=\"12\" height=\"17\"\/> from the certificate <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" alt=\"\\{D_{\\mathsf{P}}, \\mathsf{P}, \\Im_{\\mathsf{P}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/68f\/9fc\/d2a\/68f9fcd2a5a500710e4babb3d87a1f3f.svg\" width=\"97\" height=\"22\"\/> for verification. At the same time, there is no guarantee that it was <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/42f\/2e0\/d70\/42f2e0d70303428626cd7af78905fda0.svg\" width=\"14\" height=\"17\"\/> who certified the data, and not an attacker who fraudulently forced <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6e6\/72e\/995\/6e672e99543bc5d1aecad4109f9585ab.svg\" width=\"14\" height=\"17\"\/> to generate the DS for this data or obtained it from open sources. However, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"D_{\\mathsf{P}}=D_{\\mathsf{R}}\" alt=\"D_{\\mathsf{P}}=D_{\\mathsf{R}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f69\/dc2\/b35\/f69dc2b35aee73e9b46b64ac939c9b8f.svg\" width=\"79\" height=\"19\"\/> also does not mean that the data was certified by the one who provided the proof at the current time. Thus, for example, an attacker can impose data certified by the DS, but at the same time no longer relevant. We have shown above that the IDS mode also can be used to solve this problem. Therefore, it is necessary to demonstrate the operability of the IDS mode in the Schnorr&#8217;s identification protocol.<\/p>\n<p>Note that the DS in this protocol, as well as any other action, is \u201ctorn off\u201d from the identification results. Indeed, if <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/bd4\/2f5\/f6a\/bd42f5f6aec4f32b25e7317a2548d2b9.svg\" width=\"15\" height=\"17\"\/> accepted the proof from <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/9a7\/f2d\/6ed\/9a7f2d6edeb1e6f7057f4759f8ff141c.svg\" width=\"14\" height=\"17\"\/>, and then <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/9d8\/575\/8b2\/9d85758b2bc467e68c6ea1cc8dcfd284.svg\" width=\"14\" height=\"17\"\/> certified some data with the DS and sent them to <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/793\/a0a\/906\/793a0a9067b659f2efb8bf0c71360e95.svg\" width=\"15\" height=\"17\"\/> then it is impossible to guarantee that the identity of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c59\/f0b\/3bc\/c59f0b3bc9ca72d9c64be50824941aa4.svg\" width=\"14\" height=\"17\"\/> did not undergo fundamental changes as a result of <em>significant events <\/em>in the time interval between the acceptance of the proof and the moment the DS was created. Such events include, for example, revocation of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\{D_{\\mathsf{R}},\\mathsf{R}, \\Im_{\\mathsf{R}}\\}\" alt=\"\\{D_{\\mathsf{R}},\\mathsf{R}, \\Im_{\\mathsf{R}}\\}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/1e2\/8e1\/7a8\/1e28e17a8f9c97280a4f8bbd26ddeb6b.svg\" width=\"97\" height=\"22\"\/> certificate due to <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathbf{x}\" alt=\"\\mathbf{x}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/2bf\/a4b\/4fc\/2bfa4b4fc258ac55fc608d997452df57.svg\" width=\"12\" height=\"12\"\/> secret key being compromised, its expiration, and others. As a result, <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/90e\/84f\/bf1\/90e84fbf18a8709817909f80e15e2383.svg\" width=\"14\" height=\"17\"\/> will not be able to provide proof, while the proof provided earlier loses legitimacy. The time interval with a significant event can be arbitrarily small, but it is nonzero, and therefore the problem is classified as fundamental.\u00a0<\/p>\n<p>Thus, when discussing the IDS mode in the Schnorr&#8217;s identification protocol, it is necessary to follow the unreasonable assumption of a negligible probability of a significant event.<\/p>\n<p>It should be noted that significant events are also possible in the identification protocol developed by us, however, a secure data transmission tunnel due to encryption, which is established only upon the fact of proof, provides additional guarantees. In other words, identification is legitimate within a single session, which ends as a result of the session key deactivation after a predetermined time interval, which in turn is set up by the provisions of the current security policy.<\/p>\n<p>The<strong> necessary condition<\/strong> is that the <em>response<\/em> cannot be transmitted over an unsecured communication channel without first being converted by a one-way function. Let&#8217;s explain why.<\/p>\n<p>If <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/7fc\/c8c\/4cd\/7fcc8c4cd478579574df6ef7b3d4bd65.svg\" width=\"18\" height=\"15\"\/> is sent as a <em>response<\/em> instead of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"c=\\hslash(g_1)\" alt=\"c=\\hslash(g_1)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a4b\/6ea\/113\/a4b6ea113489fb29c4a6d65d18ca1ab1.svg\" width=\"78\" height=\"22\"\/>, then not only <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a6d\/225\/3ab\/a6d2253ab6390b54a28844de577ec814.svg\" width=\"14\" height=\"17\"\/>, but anyone who has gained access to <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/12c\/2a1\/b72\/12c2a1b72d3e8bb733121469b0319f06.svg\" width=\"18\" height=\"15\"\/> will be able to generate the DS. Obviously, the use of a one-way pseudo-random function, assuming a random oracle model, such as <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(\\cdot)\" alt=\"\\hslash(\\cdot)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/131\/3d4\/30d\/1313d430d669a355e4d8614cff550664.svg\" width=\"31\" height=\"22\"\/>, violates the algebraic structure of the response in the form of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/49b\/99b\/0e9\/49b99b0e9cb0d4f3d79b1cab8eafad24.svg\" width=\"18\" height=\"15\"\/>.\u00a0<\/p>\n<p>The latter means that the verification of the proof must be based on a method different from the algebraic one. This is how our protocol checks <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(g_1)\\stackrel{?}{=}\\hslash(g_3)\" alt=\"\\hslash(g_1)\\stackrel{?}{=}\\hslash(g_3)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/01c\/1e5\/405\/01c1e54053ab31ac057e0869efc10338.svg\" width=\"113\" height=\"30\"\/>. Only <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"P\" alt=\"P\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b95\/011\/5a4\/b950115a41755be02fc22bc5b92a301b.svg\" width=\"14\" height=\"17\"\/> can compute <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/1de\/313\/c87\/1de313c8733318979bfe531bb38555ff.svg\" width=\"18\" height=\"15\"\/> because it knows the secret, and <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"V\" alt=\"V\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/ba8\/7de\/a9e\/ba87dea9eaaf6151f39fd80d592c539b.svg\" width=\"15\" height=\"17\"\/> is the only one able to compute <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_3\" alt=\"g_3\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/82d\/c93\/aa9\/82dc93aa9b2e476098c3ba9bae314cf5.svg\" width=\"18\" height=\"15\"\/> because he knows the <em>challenge<\/em>. An attacker observes <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"c\" alt=\"c\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/30b\/cc5\/08d\/30bcc508da59b16ba347dd742cb9b984.svg\" width=\"8\" height=\"12\"\/>, and in order to reveal <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1\" alt=\"g_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/461\/39d\/250\/46139d250036fa2b9b22df4a8d37a8f5.svg\" width=\"18\" height=\"15\"\/>, he needs to solve a computational complexity problem or compute <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"g_1=\\hslash^{-1}(c)\" alt=\"g_1=\\hslash^{-1}(c)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/845\/f3f\/89c\/845f3f89c6005ce94ef4c700f03f91e1.svg\" width=\"97\" height=\"25\"\/>.<\/p>\n<p>In the Schnorr&#8217;s identification protocol, the <em>response<\/em> is given as <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\psi=\\mathbf{x}\\phi+\\upsilon\\pmod m\" alt=\"\\psi=\\mathbf{x}\\phi+\\upsilon\\pmod m\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6ab\/477\/5dc\/6ab4775dc2a9d247f81acf78679991c9.svg\" width=\"193\" height=\"22\"\/>, and to check, you must first compute the point <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{Q}=[\\psi]\\mathsf{G}_1+[ \\phi]\\mathsf{R}=[\\psi-\\phi\\mathbf{x}\\pmod m]\\mathsf{G}_1\" alt=\"\\mathsf{Q}=[\\psi]\\mathsf{G}_1+[ \\phi]\\mathsf{R}=[\\psi-\\phi\\mathbf{x}\\pmod m]\\mathsf{G}_1\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/8a1\/0b5\/835\/8a10b5835f92fca45649aca5349a25fc.svg\" width=\"358\" height=\"22\"\/> and then check <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"x_{\\mathsf{Q}}\\stackrel{?}{= }x_{\\mathsf{S}}\" alt=\"x_{\\mathsf{Q}}\\stackrel{?}{= }x_{\\mathsf{S}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/569\/b9d\/6d4\/569b9d6d4bd330b1cf8d3906f7a59a2d.svg\" width=\"69\" height=\"30\"\/>. It is clear that if you pass <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(\\psi)\" alt=\"\\hslash(\\psi)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a02\/ec9\/c52\/a02ec9c524453008241fda0eaf44ebf8.svg\" width=\"38\" height=\"22\"\/> instead of <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\psi\" alt=\"\\psi\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/fff\/78a\/2c2\/fff78a2c2b0441c63a4e651351a82818.svg\" width=\"13\" height=\"20\"\/> and compute <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\mathsf{Q}'=[\\hslash(\\psi)]\\mathsf{G}_1+[\\phi]\\mathsf{R }\" alt=\"\\mathsf{Q}'=[\\hslash(\\psi)]\\mathsf{G}_1+[\\phi]\\mathsf{R }\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/4bc\/bb6\/3bc\/4bcbb63bc59c412d88c2bba75236ff4c.svg\" width=\"175\" height=\"24\"\/>, then with overwhelming probability <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"x_{\\mathsf{Q}'}\\neq x_{\\mathsf{S}}\" alt=\"x_{\\mathsf{Q}'}\\neq x_{\\mathsf{S}}\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/68e\/42c\/1cf\/68e42c1cf1ba7829ed1f43a754b60e92.svg\" width=\"73\" height=\"23\"\/>.\u00a0<\/p>\n<p>Therefore, checking is possible for <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\psi\" alt=\"\\psi\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/94e\/d40\/4a5\/94ed404a5d9a3aa475760f471f116601.svg\" width=\"13\" height=\"20\"\/>, but not for <img loading=\"lazy\" decoding=\"async\" class=\"formula inline\" source=\"\\hslash(\\psi)\" alt=\"\\hslash(\\psi)\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/3b6\/8d0\/35a\/3b68d035a01f74e213a8d3366199bb3e.svg\" width=\"38\" height=\"22\"\/>. This means that in this protocol, the <em>response<\/em> can only be transmitted in cleartext, but then the IDS mode does not meet the necessary condition.<\/p>\n<p>There are two directions for future research under consideration:<\/p>\n<ol>\n<li>\n<p>Search\/development of identification protocols for which the necessary condition is met.<\/p>\n<\/li>\n<li>\n<p>A formal proof of the fact that a necessary condition is not met for any identification protocol using an algebraic way of checking the proof.<\/p>\n<\/li>\n<\/ol>\n<p>We also do not rule out that the proof of the properties such as <em>witness indistinguishable<\/em> and <em>witness hiding<\/em> [Feige_Shamir_1990] may be questioned. However, only the expert community is able to confirm\/refute this proof after the publication of the identification protocol developed by us in a peer-reviewed periodical.<\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>Compared to the conventional scheme, the IDS mode has some limitations. However, as follows from the explanations, the conventional DS schemes themselves are useless from the point of view of solving the <a href=\"https:\/\/habr.com\/ru\/articles\/705266\/\" rel=\"noopener noreferrer nofollow\"><u>task<\/u><\/a>, since they do not guarantee that the signature was created by the one who provided the certified data at the current time.<\/p>\n<p>Presumably, the IDS mode works only in our protocol, since the algebraic equation is used to verify the proof in all known identification protocols [Fiat_Shamir_1987, Feige_Fiat_Shamir_1988, Guillou_Quisquater_1988, Schnorr_1990, Brickell_Mccurley_1992, Okamoto_1993, Nguyen_2005]. For all these protocols, the necessary condition is not met.<\/p>\n<p>This post omits the proof of cryptographic strength of the IDS mode. This is a conscious step, as we wanted to cut and simplify the text. Additionally, for such reasoning, it is necessary to have a detailed description of the identification protocol. We reserve the right to return to this topic after the corresponding publication.<\/p>\n<p>The pdf version of this article is available <a href=\"https:\/\/mega.nz\/file\/lHgnxIRQ#mcyGhJM7YrbAkCaZPDXwhCAjvl_zs4WFfFLdAl4t_YE\" rel=\"noopener noreferrer nofollow\">here<\/a>.<\/p>\n<h2>The Bibliography<\/h2>\n<p>[Cohen_etc._2006] Cohen, H., Frey, G., Roberto Avanzi, R., Doche C., Lange, T., Nguyen, K. and Vercauteren, F. Handbook of Elliptic and Hyperelliptic Curve Cryptography, Chapman and Hall\/CRC, 2006.<\/p>\n<p>[Cramer_1996] Cramer, R. \u201cModular Design of Secure, yet Practical Cryptographic Protocols.\u201d PhD Thesis, University of Amsterdam, 1996.<\/p>\n<p>[Babai_Moran_1988] Babai, L. and Moran, S. \u201cArthur-Merlin games: A randomized proof system, and a hierarchy of complexity classes.\u201d Journal of Computer and System Sciences, Volume 36, Issue 2, April (1988) 254\u2013276.<\/p>\n<p>[Schnorr_1990] Schnorr, C. P. \u201cEfficient identification and signatures for smart cards.\u201d Advances in Cryptology \u2014 CRYPTO\u201989 LNCS 435, (1990) 239\u2013252.<\/p>\n<p>[Paterson_2002] Paterson, K. G. \u201cID-based signatures from pairings on elliptic curves.\u201d IEEE Electronic Letters, 38(18), (2002) 1025\u20131026.<\/p>\n<p>[Hess_2003] Hess, F. \u201cEfficient Identity Based Signature Schemes Based on Pairings.\u201d Revised Papers from the 9th Annual International Workshop on Selected Areas in Cryptography \u2014 SAC\u201902, (2003) 310\u2013324.<\/p>\n<p>[Boneh_Shacham_Lynn_2004] Boneh, D., Shacham, H. and Lynn B. \u201cShort Signatures from the Weil Pairing.\u201d J. Cryptol., Vol. 17, No. 4, (2004) 297\u2013319.<\/p>\n<p>[Zhang_Safavi-Naini_Susilo_2004] Zhang, F., Safavi-Naini, R. and Susilo, W. \u201cAn efficient signature scheme from bilinear pairing and its applications.\u201d Public Key Cryptography, LNCS 2947, (2004) 277\u2013290.<\/p>\n<p>[Boneh_Boyen_2004] Boneh, D. and Boyen, X. \u201cShort Signatures Without Random Oracles.\u201d EUROCRYPT 2004, LNCS 3027, (2004) 56\u201373.<\/p>\n<p>[Chor_Goldreich_Kushilevitz_Sudan_1995] Chor, B., Goldreich, O., Kushilevitz, E. and Sudan M. \u201cPrivate information retrieval.\u201d In Proc. of the 36th IEEE Symp. on Foundations of Computer Science, (1995) 41\u201351.<\/p>\n<p>[Kushilevitz_Ostrovsky_1997] Kushilevitz, E. and Ostrovsky, R. \u201cReplication is not needed: Single database, computationally-private information retrieval.\u201d In Proc. of the 38th IEEE Symp. on Foundations of Computer Science, (1997) 36\u2013373.<\/p>\n<p>[Fiat_Shamir_1987] Fiat, A. and Shamir, A. \u201cHow to prove yourself: Practical solutions to identification and signature problems.\u201d Advances in Cryptology[ \u2014 CRYPTO\u201986 LNCS 263, (1987) 186\u2013194.<\/p>\n<p>[Feige_Fiat_Shamir_1988] Feige, U., Fiat, A. and Shamir, A. \u201cZero-knowledge Proofs of Identity.\u201d Journal of Cryptology, 1 (1988) 77\u201394.<\/p>\n<p>[Guillou_Quisquater_1988] Guillou, L. C. and Quisquater, J. -J. \u201cA practical zero-knowledge protocol fitted to security microprocessor minimizing both transmission and memory.\u201d Advances in Cryptology \u2014 EUROCRYPT\u201988 LNCS 330, (1988) 123\u2013128.<\/p>\n<p>[Brickell_Mccurley_1992] Brickell, E. F. and Mccurley, K. S. \u201cAn interactive identification scheme based on discrete logarithms and factoring.\u201d Journal of Cryptology, 5 (1992) 29\u201339.<\/p>\n<p>[Okamoto_1993] Okamoto, T. \u201cProvably secure and practical identification schemes and corresponding signature schemes.\u201d Advances in Cryptology\u00a0 \u2014 CRYPTO\u201992 LNCS 740, (1993) 31\u201353.<\/p>\n<p>[Nguyen_2005] Nguyen, L. \u201cAccumulators from Bilinear Pairings and Applications.\u201d In Topics in Cryptology \u2014 CT-RSA\u201905, LNCS 3376, (2005) 275\u2013292.<\/p>\n<p>[Dwork_Naor_Sahai_1998] Dwork, C., Naor, M. and Sahai, A. \u201cConcurrent Zero-Knowledge.\u201d Proc. 30th ACM Symposium on the Theory of Computing, (1998), 409\u2013418.<\/p>\n<p>[Feige_Shamir_1990] Feige, U. and Shamir, A. \u201cWitness Indistinguishable and Witness Hiding Protocols.\u201d In Proceedings of 22nd STOC, ACM Press, (1990) 416\u2013426.<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/733124\/\"> https:\/\/habr.com\/ru\/articles\/733124\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>We adhere to established tradition and continue to present the latest findings. In this note, we discuss the Instant Digital Signature (IDS) mode, which was <a href=\"https:\/\/habr.com\/ru\/articles\/705266\/\" rel=\"noopener noreferrer nofollow\"><u>announced earlier<\/u><\/a>. While the main content of the IDS mode was already disclosed in a <a href=\"https:\/\/habr.com\/ru\/articles\/705266\/\" rel=\"noopener noreferrer nofollow\"><u>previous publication<\/u><\/a>, we believe that additional specifications will improve understanding.<\/p>\n<p>It should be emphasized that the IDS is not a distinct type of signature, but rather a special mode in which any known digital signature (DS) scheme can be used. In other words, we do not take responsibility for developing a new scheme, but rather propose a practical way to apply existing schemes.<\/p>\n<p>As the name suggests, the IDS mode operates in real-time, specifically, at the moment of signature generation. This means that the mode is used to certify data that is directly associated with an identifying entity, as confirmed in a previously presented proof. Such proof can be obtained through executing an interactive identification protocol, which is necessary for justifying the IDS mode. When discussing this combination, we assume that certain unique variables from the current identification session are used in generating the signature. It is important to understand that these variables are ephemeral by design and only have an effect within the current session.<\/p>\n<p>It should be noted that in this <a href=\"https:\/\/habr.com\/ru\/articles\/705266\/\" rel=\"noopener noreferrer nofollow\"><u>publication<\/u><\/a>, we use personal data assurance as an example, which is perhaps the most natural application for the IDS mode.<\/p>\n<p>We demonstrate that the IDS mode is compatible with any known DS scheme. However, it is an open question whether this mode can be used with arbitrary identification protocols. On the other hand, the IDS mode is easily combined with an interactive identification protocol that enables the generation of a shared secret session key, which was created in the development of the protocol presented <a href=\"https:\/\/habr.com\/ru\/articles\/572994\/\" rel=\"noopener noreferrer nofollow\"><u>in this note<\/u><\/a>.<\/p>\n<p>We do not provide formal proofs in this text, but rather present examples to convey the essence of our findings. Unfortunately, we could not avoid using formal notation, but we hope that it will not pose any difficulties, as all necessary notation was introduced in <a href=\"https:\/\/habr.com\/ru\/articles\/572994\/\" rel=\"noopener noreferrer nofollow\"><u>our earlier publication<\/u><\/a>. Additionally, we use standard mathematical notation adopted in specialized literature, such as [Cohen_etc._2006].<\/p>\n<p><strong>Interactive Identification Protocol<\/strong><\/p>\n<p>First of all, let us recall what an interactive identification protocol is. In fact, this is a game of <u>two participants<\/u>, each of which is endowed with its own role. To avoid unnecessary complications, we will deliberately limit the number of subjects of interaction.<\/p>\n<p>There are two distinct roles:  (Prover) and  (Verifier).  provides proof of knowledge, such as a secret, which  then verifies using a decision rule. The verdict can be positive (evidence accepted), negative (evidence rejected), or indeterminate. Typically, upon acceptance or rejection of the evidence, a specific action is initiated. For example, a common scenario is when  requests access to a resource, which is granted if  accepts the proof. There are other applications for this protocol as well.<\/p>\n<p>Identification protocols belong to a more general class of , which were first introduced in [Cramer_1996].  and  are modeled using a probabilistic interactive Turing machine, and the  itself is an interactive proof scheme based on Arthur-Merlin game style [Babai_Moran_1988], in which  always chooses some variable with a random distribution.<\/p>\n<p>Let&#8217;s focus on identification protocols that rely on asymmetric cryptography.\u00a0<\/p>\n<p>The interactive identification protocol can be represented by the following diagram:<\/p>\n<p>It is clear that three messages are transmitted during the protocol: <em>witness, challenge, <\/em>and <em>response<\/em>. In this case,  transmits two messages (<em>witness<\/em> and <em>response<\/em>), and  transmits only one message (<em>challenge<\/em>). The purpose of each message is clear from its name.\u00a0<\/p>\n<p>Let&#8217;s call the independent variables with a random distribution that change from one protocol session to another as the <em>ephemeris<\/em>. In cryptographic terms, ephemeris is equivalent to secret keys. To reveal an unknown ephemeris, it is necessary to find a solution to some computational complexity problem or to undertake a brute force attack.<\/p>\n<p>It is assumed that each participant has a pair of unique keys: a secret key and a public key. Additionally, proper certificates have been issued for the public keys.<\/p>\n<p>The parties do the following:<\/p>\n<ul>\n<li>\n<p> generates a <em>witness<\/em> based on the public key  and at least one ephemeris known only to .<\/p>\n<\/li>\n<li>\n<p> creates a <em>challenge<\/em> using at least one ephemeris known only to .<\/p>\n<\/li>\n<li>\n<p> generates a <em>response<\/em> based on their own private and public keys and the <em>challenge<\/em>.<\/p>\n<\/li>\n<li>\n<p> renders a verdict based on the <em>witness<\/em>, the <em>response<\/em>, the ephemeris involved in the <em>challenge<\/em>, and the public key .<\/p>\n<\/li>\n<\/ul>\n<p>All identification protocols include three messages, which, thanks to ephemeris, are randomly distributed. It is proven that there cannot be fewer messages (there can be more). All of the above messages carry the same semantic load in different identification protocols, but the methods of their computation can vary significantly and depend on the main provisions of the computational complexity problem, as well as the chosen mathematical apparatus.<\/p>\n<p>After some deliberation, we decided to keep the designations used in the interactive identification protocol we developed with the possibility of generating a shared secret session key, which has not yet been made public. Therefore,  is passed as a <em>response<\/em>, where  is some cryptographic hash function known to both parties. To check the proof,  computes . This uses a simple decision rule like . Here . Note that the way  and  are computed is irrelevant in this context.<\/p>\n<p>Since most of the texts we publish are interconnected, we hope that this approach will further simplify the \u201cbridge\u201d between our various posts.<\/p>\n<p><strong>Compatibility with any DS scheme<\/strong><\/p>\n<p>Let there be a pair of keys  and a certificate . Let&#8217;s show how it works taking the well-known Schnorr&#8217;s DS scheme [Schnorr_1990] as an example.<\/p>\n<p> acts as the signer. Given message , secret key , and , the signer performs the following computations:<\/p>\n<ol>\n<li>\n<p>, where ;<\/p>\n<\/li>\n<li>\n<p>;<\/p>\n<\/li>\n<li>\n<p>;<\/p>\n<\/li>\n<li>\n<p>.<\/p>\n<\/li>\n<\/ol>\n<p>Let there be a signature  and a message  such that . Let&#8217;s assume that the authenticity and integrity of the key  is confirmed by checking the valid certificate .  performs the following computations:<\/p>\n<ol>\n<li>\n<p>;<\/p>\n<\/li>\n<li>\n<p>.<\/p>\n<\/li>\n<\/ol>\n<p>If , then , where . Suppose . Therefore,  if . For  with overwhelming probability  and negligible . However, if , then it is  with overwhelming probability and  with negligible probability.<\/p>\n<p>DS verification and verification of personal data are interconnected. Let  be some personal data and . ,  and a valid certificate  are presented for verification. If the DS is valid, in other words , then . If valid,  is verified. The authenticity of personal data arises from .<\/p>\n<p>The IDS mode can be implemented using an arbitrary conventional scheme based on the elliptic curve points arithmetic. This approach is inherent in the vast majority of modern DS schemes [Schnorr_1990, Paterson_2002, Hess_2003, Boneh_Shacham_Lynn_2004, Zhang_Safavi-Naini_Susilo_2004, Boneh_Boyen_2004]. However, this condition is not necessary. For example, without losing the generality, one can replace a subgroup of the group of elliptic curve points with a subgroup of prime order  of the group . Note that the mode is also compatible with DS schemes, which are developed consistent with the provisions of post-quantum cryptography.<\/p>\n<p>This compatibility has a simple explanation. Since in an arbitrary conventional DS scheme the computation of  is normative in nature, that means that it is always present in any DS scheme, then replacing  with  does not lead to negative consequences for the cryptographic strength of this scheme, since in the general case the dependence of the collision probability on the argument of the cryptographic hash function  is unknown. Here, by collision we mean  for  and .<\/p>\n<p>For example, if the DS scheme [Zhang Safavi-Naini_Susilo_2004] is used for this purpose, then for the given message  and secret key  the signer first computes , and then generates the signature .<\/p>\n<p>Let there be a signature  and a message  such that .  first evaluates  and then . Checks  and  if .<\/p>\n<p>Note that at the identification stage,  is transmitted over an insecure communication channel, and to reveal  with an unknown secret message, you must either compute , or find solution of some computational complexity problem.<\/p>\n<p>Let&#8217;s summarize.<\/p>\n<ol>\n<li>\n<p> is unable to forge\/falsify the DS given  is known, because it does not know . He can use the key pair , where , and certificate  has been issued for , but subsequent verification will show that .<\/p>\n<\/li>\n<li>\n<p> (signer) can generate  only if he knows the secret .<\/p>\n<\/li>\n<li>\n<p>DS verification is possible only if there is a positive decision regarding the <em>response<\/em> .<\/p>\n<\/li>\n<\/ol>\n<p>Let&#8217;s list the distinctive features of the IDS mode.<\/p>\n<ol>\n<li>\n<p>The mode is active within the current session and is relevant only for .<\/p>\n<\/li>\n<li>\n<p> cannot convince a third party of the authenticity and integrity of the data received during a particular session.<\/p>\n<\/li>\n<li>\n<p>The IDS can be formed by someone who knows the secret key  and is able to compute <\/p>\n<\/li>\n<li>\n<p>Anyone who knows  and  can check the IDS.<\/p>\n<\/li>\n<li>\n<p>The correctness of the IDS is guaranteed if the proof is accepted.<\/p>\n<\/li>\n<\/ol>\n<p>The IDS mode is ideologically close to the work of [Dwork_Naor_Sahai_1998], in which the problem of <em>deniable authentication<\/em> was first formulated and the authors proposed a specific solution.<\/p>\n<p>Let&#8217;s assume that  verified the authenticity of the signer&#8217;s personal data using the IDS mode with subsequent verification. Now the signer can use the secret key  to generate a signature using an arbitrary conventional DS scheme based on the elliptic curve points arithmetic (or any other). Note that this scheme may differ from the one used to verify personal data. It makes sense to keep such the DS in long-term memory, and you need a valid certificate  to verify it. This means that after authentication in the IDS mode, undeniable authentication is guaranteed for all other data, the certification of which is made within the<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-402160","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/402160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=402160"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/402160\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=402160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=402160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=402160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}