[CFRG] Re: Review of BBS Signatures draft-07
Vasilis Kalos <vasilis.kalos@mattr.global> Fri, 25 October 2024 10:21 UTC
Return-Path: <vasilis.kalos@mattr.global>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 17DA2C1D4A9C for <cfrg@ietfa.amsl.com>; Fri, 25 Oct 2024 03:21:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=mattr.global
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ankt_9VmcF7Z for <cfrg@ietfa.amsl.com>; Fri, 25 Oct 2024 03:21:41 -0700 (PDT)
Received: from AUS01-ME3-obe.outbound.protection.outlook.com (mail-me3aus01on20616.outbound.protection.outlook.com [IPv6:2a01:111:f403:201d::616]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AFA86C1840F4 for <cfrg@irtf.org>; Fri, 25 Oct 2024 03:21:40 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=mwJa543wShGaXrM/CO9pBwWnESqFYWiMpNQu6YxTw4xzaNbdVQdb9p2AIBlZeCxcwT6CL2rrFcebe3AYGodwhOYDkRZqiz2YPR78MnU0aJMMsqZb0avDViufCGnIOabvCHwLs/NLGvrQulF3sbSBxUdIZAwKSds/jftXSFnIjthVMkKwqQLFyPJP4cSMNDRZHuUFOPKhMzhqgUvOVhp/CspgcTXgXNKZFrkm6OIaHq2jBixxijzC/3K4NIcz/RoG/dOB2nBYwxGaHEnmc+79M1Ir33uFB/9k652pwWKduYznfUIoMtOkc/bzCguAdJSVuu6lq7SmJVpIZAPP+0NVbQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=v0rK1LQqT/SLPCtT01hg/9lWcjS1qQKOb1R37JAC/RQ=; b=KmYXgf1fKfBRDd6wAyhaHCsnmiHAH9+/A76/cGRwKiG7DYOl06Mw3fhVx6OB1NcCn0+TZXrJ82R8p5EdKtMsn01mNBL3rxE6+TlHHSxP0h5a+OxfSjLxT9PvytHjnb1UWBmo92d4VKazgL3s1yRqWASdqSs1SjcaQBFTjLEeOJRQLEGmE6k7Ti56XWtBz8yg2usBROpAszdw30u/Fetm83P8/r/8E9rasENj5hCcv4uJWv4nlD/YVzp9BKwQXgjsNlKMeJYtcCcjTrZ4yr4G8btMKd4Vcg9+uA1kr6XSjrYOXLbWpnsw3098WHcVW81llfkiqfsYNIBJ4z2fMlOfKg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=mattr.global; dmarc=pass action=none header.from=mattr.global; dkim=pass header.d=mattr.global; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mattr.global; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=v0rK1LQqT/SLPCtT01hg/9lWcjS1qQKOb1R37JAC/RQ=; b=YWRDP2yElSiX1sf9fTDE4gkk53CpLvk0yi+S4QH3frWHeo9yG/kgkxk04JV2RTqN5mr9QX7ORwLGiSio3ZLOQfRk5Wu8PgncOak5VF7F/PFJmczK0WtkgqKP6zAPaXo0yrAHlP1BF6XYTQ0LUBu2hzVAlWpc6AJCAmWkJIjOi8w=
Received: from ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM (2603:10c6:220:91::15) by SYBP282MB4021.AUSP282.PROD.OUTLOOK.COM (2603:10c6:10:1a4::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8114.11; Fri, 25 Oct 2024 10:21:35 +0000
Received: from ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM ([fe80::a6b6:8ef2:13cc:2cba]) by ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM ([fe80::a6b6:8ef2:13cc:2cba%5]) with mapi id 15.20.8114.007; Fri, 25 Oct 2024 10:21:35 +0000
From: Vasilis Kalos <vasilis.kalos@mattr.global>
To: "cfrg@irtf.org" <cfrg@irtf.org>, Michele Orrù <m@orru.net>
Thread-Topic: [CFRG] Re: Review of BBS Signatures draft-07
Thread-Index: AQHbJsNgZGUFSaMzqUyEnekv6RHMIA==
Date: Fri, 25 Oct 2024 10:21:35 +0000
Message-ID: <ME4P282MB0984F0B8403443FFA0952F718E4F2@ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=mattr.global;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: ME4P282MB0984:EE_|SYBP282MB4021:EE_
x-ms-office365-filtering-correlation-id: 4cbb7f71-dd51-4ea4-2732-08dcf4dece05
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|376014|1800799024|10070799003|8096899003|38070700018;
x-microsoft-antispam-message-info: Ot2u7lIDV9CMaMuO8K4NCo+SFlOz2FQ5dIELyhiAD79ZZhd8kf0nygfFR2L+67wk0PXDX1d4sBId6CgFVtzAxl20QH2tNXPin70zaX3RbkZblgxSN0KDkz5TNWQJlJAHleAaukKNZt8aOVTWTuI9SB+wEQGL0IdjD4x4hh/3e3+IgMzkX3BLT4XSXtR5S7Pzh96zM/pCYV98MYJcNPCTv2d2zk1QhFFTf7ONxIJ8JXoWr0jOUl+obN5+vJoWs+ZEiVJqd8DBfo6fbv59af5D62DaIvSlYC+J+c/gKaIJBUVv0xruEX9KFmozPA7c/C0eoiridlYdl2OrdsHXii0F/K23BizxqvD3egNwDd2L2nEZkc7D766o5tU7VhycRSXLkKk6DtGEtSRx6UkX/JIXsRTuh/h5iIJEBHsK5mGGxhhc8mq9KOX/TtY3NqsdJJQB8HqxDvBI3Cj+ZA7nNksGl18LzsoZhz1eal92J7MOL+mwOK9FsiAHY97zPzkM8tCWeP+i8KVZ5RFB01BSAsBfy32dxR3TGX64x9P6SyQvOhb1rTNps7ayhM53Zda1u4KXUe5RPXLHdOi0OHY9aZjQ1u/lRyJudiGSdAxJ+X7t/Pn2aRVghFY3f5uXRuk2stbqZBiQVnRqTcj0vU4W7N4q+Z1sl88BptJmjiryeJ45jZZQknoAYr4Rw6b0iXTRk7GjTSW/ptBHv4Ii596PjxDz7ZUAaobWm38y/df5Eg1P6w6aro7GqSLL0bQlDllqtPIVK43xAjRRPc+0+cm+C2IP8ZQGmLTIOhxmc/5/eArxfWHWCXt5cRMXoRFKUBoCtQFd1+oi8ASnv50zxllf9p2BPWunGu5hFCFow/EKWUXN+m165Hx06hD+fG3sI6CkSt5qWVlvcHfTimSKp1lXEPquksCQx3W1c+NIluY9aZHUTzdwKKfGi0jvxNDYh1+UiueauH0byYd518O2FLSU/CO60yW2KRshOGqOpjWuZLNmyUnVkOCee9inJHm3fHvdoODgZOvDIGmI7QslDZXc0Q8xhAEUlVPDolyu5+7y5kCd3pQ++M+t5Tcji3T2b+A7VYPHQDo+ju19Po4a2bGxzVBY4a3l2ERrS2mftl6Cfjj8EzbkpTMMv8i1Sn7/gqweMFIYfwJJvkV4q5gnG5ZBh4W4uarrdBXIJBetuNYrd+75L7T6CU6F0xvLvTYx0poihS4aNq50J3EpSg/zrwM3msN23Ne3OyKjRvja6Z2LA7BnXo8IyTU0eCQw6QCD2A26HhIazxrVgNhOx+9QfbmqQnth2uCBUH7RZl7xLKojUdkyftknEzmG4zotWJOk9zO/niqG
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(376014)(1800799024)(10070799003)(8096899003)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: KhabNPFBPTp0N/FQkveWuLNEc/6mKd4Us+F/QeunNuKxNQ4fKfVOVlhf4O6a+OwGJHtcOsbqRpkZ5ywvArh3PnDavbUcwRmijGqaMvhPsAYAcjNYJwBgsIcIyngtNQ2oUkc79R/W2pjJ19cnm43O8bPUrAbVD9gs0Q3XtUiwnQBWYcqJXc1ZhFfEICT6qWxhoiKmNYKFlBW4Mh5mMZe9uHtqdtAZyHsZlCmI10iP40utOELC++k2M5WA50nCj8KBhwWG0pyr9Q1g6y8AEsU5t+gyKiKfT9YtxxwB5EdZBrU1E0KCbqvPPPhT+YgXSX0ekcelI4WFeDA/s7+vee8dOihkWq+xV/kLA9Gd4vdc9uiaPkhh8R9tptdzCzTtfauZPxQhMZWrAjMYo6EqHFfk1czEAD+M97kksVLm8HXZ+npzst6AfePJVF7jynw65Xv7dsjGghurNzG62fFKqbgSWdYEjLoql060I0IAIasoIs7EqXyS/k7kPt9fH18uif/04lWwGZBfwEa7zMxcwnR14M0rEbppSnqNhNDbJeynsd4NJ22hWwl/TKD6kfQ/jCMGDSoIj4dO0/szOckAYBJsjSP1qX08qgzPH1p8mgMdMqqDatuphxfBd52FREdvxLwdHzQkhXn3g94wbcOPZU2S3ppwypsT3fNjPByXOJv88RvkqiK7Rt1E87vMh8hym1nzZWM5gzXLCUN8ebyI8oal46x9EORZ+fNEZWra7du6/4lZZ9PjECMcImP0RnFhzwaJKLxbwxpjEP9p0nT1aPblf0mYHFRPqq6C73ZgWUmjAEz7jQv2ceSLiszmr8JZjAk1xI7G95fX6VxT/RECv0tzT4M3cuXQLCDORqv+4I3fPR6B26tPS1vprgMBRR6l02tddzx/JJM+Lqz6FQq26eWMqrS49VHtB//IIQWEvoZPIROhnI1ixKuM9LEKPFhN8pGhLwg2Bv6wH9FoRmpRF2OYskuClye+CSHWnfpSNgXG2t3NFPdBhv7SrUsUiqSaQy47niQsCgxPOZfdz9iivwyWJeftYzpW9Vcab0QRCFEGg9kMOrKgA97m0DBi/6ObHdyT2KSDzgAS8PZcWIzKOwTylrKpkKinam90f5iiiYCT/PGN6yJ9da0ZzLv0blPb1U7OyCzgzaRDQOEKgr4XUX0n4HDFpPYb4dO5yPnuka/2kjEerg/XRzKKUuh3PrAFy7+mhzpRV+vxC7sjcVAN1NIzv+NDmsUxGAFL7uUQh9eE6OQBMYyHjHG4BmCRPXdbz6WwuhstZ3OqJH/vJOyaWs/mIZyfsTvqZnHZeBFzmPz+VuiBGFsdxNfyg5s0ryvsWHDAgUllnoWpAsVg6zVdcy7xiqZMEKuYohWkEUgsv+5P9SXW4uqgXC5Jermn/CJs7rUiHJ7G24FodaoZW+TJbQdPSeBeExSHyOP+FYWCXZjuiGhX+dYX91VA6N+9+EBEzgQneR3/NHctvssu4W7BNOGrLpym/x/sGZt5IBmY8OxVf1vNqf7dMzaCfJumnrVRdKsyayZ1PGW/2t0lwuANixyOQsYJ+EyTByyANEk7V3MdwXH4Au/8weFds4r1Er7FdmrOLzSTuZxFEnYTfvWIL1xJjp+kBmbbi2NQmk2r9wVg0GYp2WTcbWL9+iYmomdpUolvUiP33AC0oBwq+Pw92O/b3l076xag4QmFi8yhclhl51c=
Content-Type: multipart/alternative; boundary="_000_ME4P282MB0984F0B8403443FFA0952F718E4F2ME4P282MB0984AUSP_"
MIME-Version: 1.0
X-OriginatorOrg: mattr.global
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: ME4P282MB0984.AUSP282.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 4cbb7f71-dd51-4ea4-2732-08dcf4dece05
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Oct 2024 10:21:35.5746 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c2c9cf73-6aae-4702-9844-02adab723771
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ZqewidQVrNImashCfcMc7QWmFoqFwxaOAxbTm2eBQ3ojsjGiU09lBV524ySTUc47oZ6ltbGPGI9jKelgttx5wJ1MAVqyzMf3NFWRQPhEzZ4=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SYBP282MB4021
Message-ID-Hash: LIMCYGI5FJ2SGST3UWUATUHBTHGW7NYW
X-Message-ID-Hash: LIMCYGI5FJ2SGST3UWUATUHBTHGW7NYW
X-MailFrom: vasilis.kalos@mattr.global
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Review of BBS Signatures draft-07
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/lQVSQfjXD9gr0TOh2NbFMYZLcQQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>
Dear Michele and all, Thank you for the review! I do agree with the suggestions. See some comments inline. > *.BBS tokens and keyed-verification* > … the issuer and redeemer are the same person just like in Privacy Pass (this is called "algebraic MAC" in cryptography). In fact, if the verifier has x, then we don't need a pairing map to check signatures: a BBS signature (A, e) for a message commitment C is valid if xA = C - eA. That’s true, but I don’t think the User (Client in pp) will have access to the Issuer's sk. In the algebraic MAC case, it will be the Verifier (Origin I think in pp) that will have the Issuer’s sk. For the Client to verify the signature without pairings, the Issuer will have to generate a ZKP of knowledge for an x so that pk = G * x and A * x = C - A * e. That to say, although I do really like the idea of a DH oracle, making the pairings optional may not be that simple. (We do have a draft on the above here<https://basileioskal.github.io/pairing-free-bbs/draft-vasilis-pairing-free-bbs.html>. Would be open to merging the documents if there is a need) > *.Concrete security of the protocol * > *Suggestion 4: understand the security and efficiency trade-offs with PS signatures* The main advantage of BBS Signatures IMHO is the decoupling of the PK from the number of messages. TMU, in PS each “type” of credentials (with a different number of attributes) will need a different PK. For that reason, BBS Signatures are more suitable for “generic use cases”, providing more flexibility (like hiding the Issuer use cases). > *.Blind BBS multiplicative blinding* > It is possible to have "blind BBS" as a pair (A, e) consistent with the signature using *multiplicative* instead of additive blind. Note that in the last version of blind signatures<https://www.ietf.org/archive/id/draft-kalos-bbs-blind-signatures-03.html> we removed the “signer_blind” and re-introduced it in pseudonyms<https://www.ietf.org/archive/id/draft-kalos-bbs-per-verifier-linkability-00.html> only. So, the blind signature currently is (A, e). > *.Blind BBS API design* > one-more unforgeable tokens. If the user proof can be optional, it's easy to just have another specification say that that function is just a nop We also added `FinalizeBlind<https://www.ietf.org/archive/id/draft-kalos-bbs-blind-signatures-03.html#name-finalize-blind-sign>` (Section 4.3.3 on the blind BBS signatures draft<https://www.ietf.org/archive/id/draft-kalos-bbs-blind-signatures-03.html>) which will sign any point B, without checking any user provided proof. In any case, the documents are far from final. Any proposal and contribution will be extremely appreciated. > *.On the zero-knowledge proofs* > *Suggestion 9: simplify Fiat-Shamir and have a generic framework for future proofs* For a generic ZKP I expressed my thoughts here<https://mailarchive.ietf.org/arch/msg/cfrg/d58lWLAOLN5UgGSvu3VmwsJtG2E/>. I’m still not convinced that the core BBS draft is the best place for such a description. Nevertheless, I will be happy to help with that, no matter where it lands, since I do find it really useful. Kind regards, Vasilis Kalos
- [CFRG] Review of BBS Signatures draft-07 Julia Hesse
- [CFRG] Re: Review of BBS Signatures draft-07 Vasilis Kalos
- [CFRG] Re: Review of BBS Signatures draft-07 Vasilis Kalos
- [CFRG] Re: Review of BBS Signatures draft-07 Michele Orrù
- [CFRG] Re: Review of BBS Signatures draft-07 Watson Ladd
- [CFRG] Re: Review of BBS Signatures draft-07 Michele Orrù
- [CFRG] Re: Review of BBS Signatures draft-07 Vasilis Kalos
- [CFRG] Re: Review of BBS Signatures draft-07 Stanislav V. Smyshlyaev