Quantum-Resistant Group Signature Scheme Using Merkle Trees

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing post-quantum attestation techniques lack features such as signature-based revocation, a flexible number of signatures, and the ability for group members to generate all information required for signatures, while also being vulnerable to quantum attacks and not resistant to quantum computing.

Innovation Solution

A quantum-resistant group signature scheme using Merkle signatures and a 'mixing' technique with a block cipher to achieve unlinkability and anonymity, allowing for a flexible number of signatures and private-key based revocation, while being resistant to quantum attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Elliptic Curve and Pairing-based cryptography are used for anonymous attestation, then security and anonymity are provided, but the system becomes vulnerable to quantum computer attacks

Engineering Contradiction:
ImprovesecurityVSAvoidquantum attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the cryptographic parameter foundation from Elliptic Curve/Pairing-based cryptography to hash-based cryptography (XMSS, LMS). This parameter change maintains security and anonymity while providing quantum resistance, as hash-based schemes are not vulnerable to quantum attacks like Shor's algorithm that break elliptic curve and pairing-based systems.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If traditional Merkle signature schemes are used, then quantum resistance is achieved, but the number of signatures is limited and revocation capability is lacking

Engineering Contradiction:
Improvequantum attack resistanceVSAvoidflexible number of signatures
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key generation where group members can generate an unlimited number of key pairs on-demand. The system transitions from static Merkle trees with fixed leaf nodes to dynamic structures where new key pairs can be generated and integrated into the Merkle tree as needed, enabling flexible signature counts and dynamic revocation capabilities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses preliminary action by pre-distributing authentication paths and Merkle tree structures to group members before they need to sign. This allows members to have immediate signing capability without waiting for tree reconstruction, while still maintaining the ability to dynamically add new keys and revoke old ones through updated authentication paths.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If group members need to generate all signature information locally, then autonomy is improved, but computational complexity and key management burden increase

Engineering Contradiction:
Improvelocal signature generation capabilityVSAvoidkey management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic key material into authentication paths and Merkle tree structures that are distributed to group members. Each member receives only the specific authentication path needed for their subgroup, rather than managing the entire Merkle tree. This segmentation reduces local storage and computational requirements while maintaining the ability to generate signatures autonomously.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11757656B2Efficient post-quantum anonymous attestation with signature-based join protocol and unlimited signatures
Publication Date: 2023.09.12 INTEL CORP
  • US11757656B2 patent drawing
  • US11757656B2 patent drawing
  • US11757656B2 patent drawing

AI summary

In one example an apparatus comprises a computer readable memory; and a signature module to generate a set of cryptographic keys for attestation of group member devices and a set of leaf nodes in a sub-tree of a Merkle tree corresponding to the set of cryptographic keys, forward the set of leaf nodes to a group manager device, receive, from the group manager device, a subset of intermediate nodes in the Merkle tree, the intermediate nodes being common to all available authentications paths through the Merkel tree for signatures originating in the sub-tree, and determine a cryptographic key that defines an authentication path through the Merkle tree, the authentication path comprising one or more nodes from the set of leaf nodes and one or more nodes from the intermediate nodes received from the group manager device. Other examples may be described.