Cryptology ePrint Archive: Report 2018/610

Hierarchical Attribute-based Signatures

Constantin-Catalin Dragan and Daniel Gardham and Mark Manulis

Abstract: Attribute-based Signatures (ABS) are a powerful tool allowing users with attributes issued by authorities to sign messages while also proving that their attributes satisfy some policy. ABS schemes provide a flexible and privacy-preserving approach to authentication since the signer's identity and attributes remain hidden within the anonymity set of users sharing policy-conform attributes. Current ABS schemes exhibit some limitations when it comes to the management and issue of attributes. In this paper we address the lack of support for hierarchical attribute management, a property that is prevalent in traditional PKIs where certification authorities are organised into hierarchies and signatures are verified along roots of trust. Hierarchical Attribute-based Signatures (HABS) introduced in this work support delegation of attributes along paths from the top-level authority down to the users while also ensuring that signatures produced by these users do not leak their delegation paths, thus extending the original privacy guarantees of ABS schemes. Our generic HABS construction also ensures unforgeability of signatures in the presence of collusion attacks and contains an extended traceability property allowing a dedicated tracing authority to identify the signer and reveal its attribute delegation paths. We include a public verification procedure for the accountability of the tracing authority. We anticipate that HABS will be useful for privacy-preserving authentication in applications requiring hierarchical delegation of attribute-issuing rights and where knowledge of delegation paths might leak information about signers and their attributes, e.g., in intelligent transport systems where vehicles may require certain attributes to authenticate themselves to the infrastructure but remain untrackable by the latter.

Category / Keywords: public-key cryptography / Attribute-based Signatures, delegation, hierarchy, path anonymity, path traceability, non-frameability, privacy

Original Publication (with minor differences): CANS 2018

Date: received 14 Jun 2018, last revised 16 Oct 2018

Contact author: d gardham at surrey ac uk

Available format(s): PDF | BibTeX Citation

Note: Formatting

Version: 20181016:160449 (All versions of this report)

Short URL:

[ Cryptology ePrint archive ]