Paper 2025/1094
Key-Updatable Identity-Based Signature Schemes
Abstract
Identity-based signature (IBS) schemes eliminate the need for certificate management, thereby reducing communication and computational overhead. A major challenge, however, is the efficient update or revocation of compromised keys, as existing approaches such as revocation lists or periodic key renewal incur significant network costs in dynamic settings. We address this challenge by introducing a symmetric element that enables key updates in IBS schemes through a single multicast message. Our approach achieves logarithmic network overhead in the number of keys, with constant computation and memory costs. We further propose a general framework that transforms any IBS scheme into a key-updatable IBS scheme ($\mathsf{KUSS}$), and formalize the associated security requirements, including token security, forward security, and post-compromise security. The versatility of our framework is demonstrated through five instantiations based on Schnorr-type, pairing-based, and isogeny-based IBS, and we provide a detailed security analysis.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published elsewhere. INDOCRYPT 2025
- Keywords
- Identity-Based SignaturesKey RevocationGroup CommunicationECCPairing-basedIsogeny-based Cryptography
- Contact author(s)
-
guggemos @ nm ifi lmu de
farzin renan @ gmail com - History
- 2026-01-19: last of 3 revisions
- 2025-06-11: received
- See all versions
- Short URL
- https://ia.cr/2025/1094
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1094,
author = {Tobias Guggemos and Farzin Renan},
title = {Key-Updatable Identity-Based Signature Schemes},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1094},
year = {2025},
url = {https://eprint.iacr.org/2025/1094}
}