研究了基于一次签名的广播认证协议的可证明安全问题。在通用可组合安全框架下,提出了基于一次签名的广播认证的安全模型。首先,形式化定义了一次签名理想函数FOTS和广播认证理想函数FBAUTH。其次,设计了一次签名算法HORS+。然后,在(FOTS,FREG)-混合模型下设计了广播认证方案πBAUTH。组合协议HORS+,在πBAUTH的基础上可以构造出新的基于一次签名的广播认证协议。结果表明,HORS+能够安全实现FOTS;在(FOTS,FREG)-混合模型下,πBAUTH安全实现理想函数FBAUTH的广播认证方案πBAUTH。根据组合定理,新的广播认证协议具有通用可组合安全性适用于能量受限网络中广播消息的认证。
The provable security of one-time signature based broadcast authentication protocols was investigated.In the UC framework,a one-time signature based broadcast authentication model was proposed.Firstly,the one-time signature ideal functionality FOTS and the broadcast authentication ideal functionality FBAUTH were formally defined in the model.Then,one-time signature protocol HORS+ was proposed.At the same time,a broadcast authentication scheme πBAUTH was designed in the(FOTS,FREG)-hybrid model.Finally,based on the scheme πBAUTH,a new broadcast authentication protocol was then obtained by the combined use of HORS+.The result shows that HORS+ securely realizes the ideal func-tionality FOTS,and πBAUTH also realizes the ideal functionality FBAUTH.According to the composition theorem in the UC framework,the composed broadcast authentication protocol is UC secure and can be applied to broadcast the authenticated message in the resource-limited networks.