[CFRG] Re: Review of BBS Signatures draft-07

Vasilis Kalos <vasilis.kalos@mattr.global> Thu, 24 October 2024 17:58 UTC

Return-Path: <vasilis.kalos@mattr.global>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0FEFEC14F6E3 for <cfrg@ietfa.amsl.com>; Thu, 24 Oct 2024 10:58:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=mattr.global
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tMOc0CoZVbYU for <cfrg@ietfa.amsl.com>; Thu, 24 Oct 2024 10:58:49 -0700 (PDT)
Received: from AUS01-SY4-obe.outbound.protection.outlook.com (mail-sy4aus01on2062e.outbound.protection.outlook.com [IPv6:2a01:111:f403:201e::62e]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E7D51C14CF18 for <cfrg@irtf.org>; Thu, 24 Oct 2024 10:58:48 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=NNbk7IA5DJwNAmSmc8uZ9o15SMUthk/Rs6+QcHWghmZmQ5jnpUv15voFuP8UpMuNS/MXWS61sFzO51dOE7ihDEFW3T/ABO4Bm2mU6k9NhCUoqqUChcsVUNT3z4L436zJ479HLwcoYyjKunf5gmI0+VZy2lkT4CrFENQdi+RpSTHXoyAvH4JzuKh8uK+mcOhRTy5CP8j2igTCYPdyo2YmquTAm/IoNVuOEv6nfFr1XBIU75G/I5V9lbOhFExDGHEWmW4stt3AiEV08yGO+c1FE1P/Y8jrnBJZ54QdlBtpx5uC+dvQrxwF1uZlSxlmUvF7q6xuaANz/GI+2AlP5Ug0jw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=RcInnIjQyef35VWlfI7oOezmnslHUlgtRV3TaPGKnTM=; b=yQNJJ/rYK7N6ErnAvZxNQMCSSpKpt3WpkqV5B0UOSmAwqtIFqFZunUBizpnlW2HuG2OQWpLK5SPCI5NqCa8kSCDfTWRVAtgP0PzkVTeyEnZmZaOyyuncU54k+OIK0z/KxsHH+DczXq2phyG0UFbfm5ULeQF6IasDVMlXJ41z7ZTnzrQWx2sHNMWBqvVwOFCyi73xhZtYpEoEIvFmRIDfWTgfCzHEEuqUZ2WM39HbQJL4fghpRtxWH0Fare7o0g1MSvG4XrZeXj5iyuiNlzoEomezZLZ5oXI6D1ALKSZybkT4kVTjvCqI9EfoHLIlNF9d6um1ZoHGNkQmhjaKnj2WFQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=mattr.global; dmarc=pass action=none header.from=mattr.global; dkim=pass header.d=mattr.global; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mattr.global; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RcInnIjQyef35VWlfI7oOezmnslHUlgtRV3TaPGKnTM=; b=Xum/iveuATRfjQr8VOivqs9ZXhM56IybGF/fNJxg+8onuFhXMeCTixbjHpp0HX/6d4upajvP7vNAXR7Erj7FNCj1I2EQL/94ZHi3NWLtAOfrwEw0G3+J7wp1Y05Hy1q/qWFJWN0NDjYOHMQfBTBrVepf7D7llPWrRCRnXMoz7NE=
Received: from ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM (2603:10c6:220:91::15) by ME0P282MB4676.AUSP282.PROD.OUTLOOK.COM (2603:10c6:220:222::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8093.17; Thu, 24 Oct 2024 17:58:44 +0000
Received: from ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM ([fe80::a6b6:8ef2:13cc:2cba]) by ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM ([fe80::a6b6:8ef2:13cc:2cba%5]) with mapi id 15.20.8114.007; Thu, 24 Oct 2024 17:58:44 +0000
From: Vasilis Kalos <vasilis.kalos@mattr.global>
To: "cfrg@irtf.org" <cfrg@irtf.org>, Julia Hesse <juliahesse2@gmail.com>
Thread-Topic: [CFRG] Review of BBS Signatures draft-07
Thread-Index: AQHbJi+N1kvVJbFJEkGfz3D2P3gG7A==
Date: Thu, 24 Oct 2024 17:58:43 +0000
Message-ID: <ME4P282MB098470A0350CBCFAD148ED1D8E4E2@ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=mattr.global;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: ME4P282MB0984:EE_|ME0P282MB4676:EE_
x-ms-office365-filtering-correlation-id: 94728ad4-3f11-46b9-7d16-08dcf4558037
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|376014|10070799003|38070700018|8096899003;
x-microsoft-antispam-message-info: rq9E82WNvClpvaYikBurSHr8HU4nxV/u/y5ORNqULrMbYxGDZAAfKxPVoUcWSdXrKqfYe7WGLG9YQGZdHJc1jaDmfHvt6SSVsLAK1cdDm+XxlvRyoiCSr0fN1ztcr4f+RrT6fvcmKjEYrqJxYYn/ul9Jhlojuo1L5ZehNDVe0865uu84lmdXj9tOdpBbIJCfVJLtyXcoIdCcDSVpJ4+9yM3fKSVONehNBb63vbeqyE0p2qb/jQuIbYGB1ObhfAttD1UrZSzxIknWuOiWYb22Uqwg3DVlB/NBQqP0lJRs1VVamXa0fr1NwQfLoT0/ynlQXthPagEYkzrS5AHK5fP4WYBqhnc1TMhbJlM1IFjByPNcnfsJvnoeFfYOP7FoFYlNT7n7jA/aNIXkqk8HMQ8d91+mOsTXfOEDdI7ieqwcq9msP8cVnIRhPBbZoP2333qW8XgQY5blUIY7YYzR8W5YNrA/NnGHWCEkvVQmfh+HSXFRzcq3cuN4ZinSXvsp5uw3tfwD0w9TURk5AHx0iFOYFAWnjGWkQAR3rlEPUDbcb3tHTQOgjdIcaA6txWxINgX3Lsu0Fx3p5PbrNfASSURdGIJ5SLJisD+aSlhInYR6ksn+xau0ykW8tIsD651z04gMlKkRMyjw7lvrClN2XXnltT2NIQAyRD9RMCN0D6oH8q3FuSmQGhDb9Kh+rV0nLnUoxXI45MUWURKYUO6sKoDxZu4OAdbnFmqXKjt6p0loFSKXe4D6l/CKKyXDZ/nKvYCfi4zOV5Ncyd3pwQzo6on0ENW2iDtBr8aTjpnXgxkSu1+j2lIZHwyESmXgHSzp1FYcsG1LgczVFa/rUv7DkWZ9G+q2cpMuP5wln9lyqrndlstsiYJsOHE9GKIy8zwBoQ1EaPy/Ob6soRlQgVmWSfhg75sVo0ZRWya1piGHlnEBsRX0tuLLS81A5EH+4n++ktPJpsgmzTDhp9HEIbmUt47xIqybQHuizERCAA8Zl+vvIIgJIZT8i+ULfpWWO94czO6BxCI7zMzsWg94KKMO76xI5FC5NsVxUFfTcW2Qxx+p75lT/ONh/q2N3pTCx77K2uQTAZXvrjYXn56M8siRHCj8wvVZrWbEpVgX9d67ube9a6hcyRSrTXGeKtIjoSsK7uz87wuAGtKvdK/OVVt6Vxdbgx6awIQQY6JYNustZeTON58crAc5YmP/2ldCwxUXp+HwGbReKK5+gi8FHMs6dp8IGF3PORvVL+xGcWTZ+6vAuGkOw78phWvEYBlUO8Np8ecNYgEAaKlO/Twpclzn2cm8+/+J1gTECiWNA275pLLOu45jLQQeRupri2BkYB4DfVvnkXoOm2KkDYTpBcbNxamnXkHq4mllxZA3DCdejp3hH/4=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(10070799003)(38070700018)(8096899003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: VIfIDTH/jn0rmQLTk0gMxYzolklRxoEXZEwTGXkcyAYYi36K/h6mbSLEKRA0w491qDXQ3qntuwOr6g7EJQLAZMIKwIPkrUPsqv6pCb1x5JPg1y0fP1ndufuTSh0IaLOs/dFFzJrHo/OJTqpbrJ52sIZVIs0Pj+qnU/95yuPajVewR6aXpVRlJtBRiv+HMQvVgUauwHPGtZpYqH20swaVmTO1SQP6tVKvdtC50A00LCYGIRfNuAsW1JL5baRAEpeOZ6T3hOvBRTWeVM/fUNV/NgZ9M3R0H8TAhvOfgbQwArpEUdk9jxdryl6ySfS/SyUzeZl5+JLs3a2mGdMoCBYEVGqR13wkcQO7znwU2paWfggBSJI8twYqpKUIORVkjB+s9Zt+Lys0L15pFXPwnelNzmhfHIvMEnzVrlxJFnsG1ZHONjXUJtcVJuTMNy/BpjtqLdXGfGSZve8NwqNvmTxiNSpRnVyM9x85eI3lSh6gdeYuNLT72Q9glBOEKib/XvJE3968bu4xTOX3Bqd21thf0LyJbio5OQ4arpZQIMMtxUJg5nKd6eB71OerSHxdU1fu3RAl8SB0aSnUnOWt65x27dDcFH4Hp9BT+Uj0MKDO1eUhZrNKcihI0mjaJPn5FM+C9YSCSKWh4J6gyYjTMD9b9lbgWLIXk9xgZPuVGv3BkILJ6IUSHkXfeznn7COoWdiafKHHde0ws+ni2g/sXQ1aguOZ07Kqmn+8TTLhyEEQqTW76HCa83Z1y/H8jo61P6Nt7DWHzoXAXVhsUhQoRxfh482dPtXOkpFPnlIf4GSDXd+bHJtsvVokO34IncRQ5a4iQx3AwxVOPfNsPYmTeQasmJMaq9hKpjuCpYQWsdl/BoLR/ae2I0V2ep9WC9WOoptXx0gWyV254Kz+5ZJJrjxKxS2imGa/NqTLRpQBdas7oQ1BwkMnHEF4x7HwjeBixA6OYBaqMatDUBCArTOpHkz7bK/0namX15zIIVo7mM2WIcRMzAAMGRPp2ARtKxP9v+BNIpSZY8TK8o3wLzx/SfU87l+JQjNqB9Ml9c/os9EESW2vZbbfarbuKCO7LQF8gExLu2oHQJR298Lu488P5pyahWALa/BAn32c58uhhBkHsnAR4gVTqiqeOqVhmu779oUzN5arAqN1Qc7EnzzrucshLGCGJmUAomqJa/18izPiEE2u0JEM6JefEpyLHZ/BUbbc2TwEZVlivHJyu0+o5GybmuJJRyJTJee9UUuPtoIqjIoeajbLRx55bRaeYfomqhNq2xW3+fLI056z636Xx1FDbFpo1/AbIIsOazBy1koPF0PnUiy6CSyKbWK+8CXK8wk4D/vcbPdo9FFDzoarNFWrHQjqyvyEuxNKkHuPdwgPl9ZU0aexdbOmkOcvX9H8ouKPD+aHht4vTL6soAsRo+aUjm4/DeFECX5cTjSe8Y5BOkMfoTwWn2p8a0RKwogIB4jvkRgFKaG6egQfNT8NiOcbt5eu081Rhwxk5WbdGzxlNWCTs4N9qld0BM5kVd07OIcAiOqXJhMJTPzD6hSGSdzL77sTf/cbqmYfWQy94Hy78W9N+bZ4wJCr83YGeFzUTDSdSYwbRjCDQ+nBhciPRHAVeiuMobas5lHo6MTF/A3Z6qT48THSzpnxFbKljn9fO4NfW3bh3/ZavMyRHHXbWBnbyx7BSVfxwfXkLddqKflrV/s=
Content-Type: multipart/alternative; boundary="_000_ME4P282MB098470A0350CBCFAD148ED1D8E4E2ME4P282MB0984AUSP_"
MIME-Version: 1.0
X-OriginatorOrg: mattr.global
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 94728ad4-3f11-46b9-7d16-08dcf4558037
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Oct 2024 17:58:44.0009 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c2c9cf73-6aae-4702-9844-02adab723771
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Pgg93sM4UhvQZJ2SDt+fOwNkNbgNHuP0W+NF7OX4ehZSp3so4yh4KyDjU8bLqnYZe3NbGPx/DrCFXuw5op2F2OZTOY8FGMc8yG7395Yfu1k=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: ME0P282MB4676
Message-ID-Hash: 2STACKP6CR3ILCRR6VXY5G54WUFXWZBR
X-Message-ID-Hash: 2STACKP6CR3ILCRR6VXY5G54WUFXWZBR
X-MailFrom: vasilis.kalos@mattr.global
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Review of BBS Signatures draft-07
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/CQ1p9Wu4AiQ6qvrztSoRlj2IAd8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

Dear Julia,

Thank you very much for the review and invaluable insights! Please find some comments and questions we have inline. For anything not addressed in this email we agree with the review and are currently working to update the document accordingly.

> The draft seems to specify algorithms similar to those in [TesZho23].

We are using the one from Appendix B from the [TesZho23] paper. The only difference is that we use r_2 instead of 1/r_2 when calculating \bar{A} and D and reverse it later to calculate z (or as we call it in our document r_3^).

> Regardless of what version is specified here, I would like to note that (2) and (3) only have sketched security arguments in [TesZho23], and no  proofs of properties such as unlinkability that are claimed in the draft.

Regarding the formal proof of unlinkability, although I agree that it can be made clearer, it seems to me that it does not lack formality. The last paragraph of the paper (page 31) describes how to simulate the BBS proof. The step that is missing is the verification that the simulated BBS proof is valid. The verification equations using U_1 and U_2 (in the paper notation, we call them T_1 and T_2 in our document) hold trivially (by construction). The equation e(\bar{A}, X_2) = e(\bar{B}, g_2) holds given the fact that in the simulated case, \bar{B} = \bar{A} ^ x (again using the exponentiation notation from the paper). Do you think this will be enough to use that proof??

> is there any formal proof of unlinkability of the BBS proofs described in this draft, e.g., using empty headers? [TesZho23] does not mention unlinkability, that's why I'm asking.

We use the term unlinkability as a synonym of zero-knowledge (L-HVZK more specifically). Again, something to clarify in the document.

> What is the motivation behind signing an empty message?

Allowing an application to indicate “absence” of an attribute (note that an “empty” message will be mapped to a non-zero scalar by the hash_to_scalar operation).

> What is the motivation of computing e as hash of SK and the messages,  instead of drawing it uniformly?

To make testing easier by making signatures deterministic, while at the same time limiting the attack surface that can arise from bad entropy sources.

> "each BBS proof is indistinguishable from random" - by whom? Surely not by a verifier who has the header and the message.

The intent was to specify that the proof value itself (as outputted by the ProofGen operation, without the header or the messages) is unlinkable. If the Issuer elects to make use of the header, they should take into account the privacy guarantees the deployment tries to enforce (described briefly in Section 3.3.6). In any case we should make the above clearer in the document.

> For example, if one follows the recommendations of 6.4, the proofs become fully linkable.

Section 6.4., was not targeted to the “header” but the “presentation_header”, chosen by the Prover and “bound” only to the BBS proof. Given that a new one can be chosen each time a proof is generated, unlinkability should be preserved. We should further clarify that.

> Section 6.1 What can happen if the algorithms are run with an invalid serialized PK, i.e., if an implementor decides to skip the recommended PK validity check?

Passing an invalid PK to the pairing operation can have unexpected, implementation specific results (like returning an error or the zero point of the target group etc.).

> Section 6.9 "[CRQC] adversaries will not be able to compromise the data confidentiality property of a BBS signature - I don't understand how

The section refers to the BBS Proof. Although using a signature one could reveal the undisclosed messages as you indicated, doing the same with only a BBS proof should not work.

Kind regards,
Vasilis Kalos