Transcription of w a ys to implemen - ANF
1 HowtoTime-StampaDigitalDocument , , ,andrequirenorecord-keepingbythetime-sta mpingservice. Appeared,withminoreditorialchanges,inJou rnalofCryptology, , , {111, 'sgloryistocalmcontendingkings,Tounmaskf alsehood,andbringtruthtolight,Tostampthe sealoftimeinagedthings,Towakethemorn,and sentinelthenight, , ,inintellectualpropertymatters,itissomet imescrucialtoverifythedateaninventor rstputinwritingapatentableidea, cideainvolvesdailynotationsofone' , ,sewn-inpagesofthenotebookmakeitdi , 'sideasislaterchallenged,boththephysical evidenceofthenotebookandtheestablishedpr ocedureservetosubstantiatetheinventor'.}
2 Thesemethodsmayensurethattherecordsareha ndledbymorethanoneperson, , ,thereisanotherpartythatviewsthedocument whoseintegrityorimpartialityisseenasvouc hsa ,andthechangeneedn' ,onemust ndawaytotime-stampthedataitself,withouta nyrelianceonthecharacteristicsofthemediu monwhichthedataappears, ,itshouldbeimpossibletostampadocumentwit hatimeanddatedi ,we rstconsideranaivesolutiontotheproblem, ,perhapsrepresentingindividuals,di erentcompanies,ordivisionswithinacompany ; 'schallengetothevalidityofadocument' , ,underreasonableassumptionsaboutthecompu tationalabilitiesoftheusersoftheschemean daboutthecomplexityofacomputationalprobl em,andpossiblyaboutthetrustworthinessoft heusers,itisdi ,theweakertheassumptionsneeded, ,a\digitalsafety-depositbox," ,heorshetransmitsthedocumenttoatime-stam pingservice(TSS).
3 'sdocumentiseverchallenged, , ,thisapproachraisesseveralconcerns:Priva cyThismethodcompromisestheprivacyofthedo cumentintwoways:athirdpartycouldeavesdro pwhilethedocumentisbeingtransmitted,anda ftertransmissionitisavailableinde , ,itcouldbeincorrectlytime-stampedwhenita rrivesattheTSS,oritcouldbecomecorrupted1 Theauthorsrecentlylearnedofasimilarpropo salsketchedbyKanare[14]. ' :nothinginthisschemepreventstheTSSfromco lludingwithaclientinordertoclaimtohaveti me-stampedadocumentforadateandtimedi nalissue,trust, , rstsimpli :f0;1g !
4 F0;1glcompressingbit-stringsofarbitraryl engthtobit-stringsofa xedlengthl, , ,givenoneofthesefunctionsh,to ndapairofdistinctstringsx;x0satisfyingh( x)=h(x0).(Suchapairiscalledacollisionfor h.)Thepracticalimportanceofsuchfunctions hasbeenknownforsometime,andresearchersha veusedtheminanumberofschemes;see,forexam ple,[7,15,16].Damg ardgavethe rstformalde nition,andaconstructiveproofoftheirexist ence,ontheassumptionthatthereexistone-wa y\claw-free"permutations[4].Forthis,any\ one-waygroupaction"issu cient[3].NaorandYungde nedthesimilarnotionof\universalone-wayha shfunctions,"whichsatisfy,inplaceofthese condconditionabove,theslightlyweakerrequ irementthatitbecomputationallyinfeasible ,givenastringx,tocomputeanotherstringx06 =xsatisfyingh(x)=h(x0) [17].
5 Rompelhasrecentlyshownthatsuchfunctionse xistifthereexistone-wayfunctionsatall[20 ]. ,forexamplethatofRivest[19], ,aclientwillsenditshashvalueh(x)= , , ,theremaybeasinglehashfunctionusedbyever ybody,ordi erenthashfunctionsfordi ,wewillspeakoftime-stampinghashvaluesy|r andom-appearingbit-stringsofa esh(x)=y; ,asignatureschemeisanalgorithmforaparty, thesigner,totagmessagesinawaythatuniquel yidenti eandHellman[18,7].Afteralongsequenceofpa persbymanyauthors,Rompel[20]showedthatth eexistenceofone-wayfunctionscanbeusedino rdertodesignasignatureschemesatisfyingth everystrongnotionofsecuritythatwas rstde nedbyGoldwasser,Micali,andRivest[10].
6 Withasecuresignatureschemeavailable,when theTSSreceivesthehashvalue,itappendsthed ateandtime, ,theclientisassuredthattheTSSactuallydid processtherequest,thatthehashwascorrectl yreceived, , , ,webelieve, , ,wewouldlikeamechanismwhichguaranteestha tnomatterhowunscrupuloustheTSSis,thetime sitcerti eswillalwaysbethecorrectones, ,iftheoutputofanalgorithmA,givenasinputa documentxandsometiminginformation ,isabit-stringc=A(x; )thatstandsasalegitimatetime-stampforx,w hatistopreventaforgersometimelaterfromco mputingthesametiminginformation andthenrunningAtoproducethesamecerti catec?
7 , erentapproacheswemighttake, rstapproachistoconstrainacentralizedbutp ossiblyuntrustworthyTSStoproducegenuinet ime-stamps,insuchawaythatfakeonesaredi cate, catealsocanbeusedtosolvetheproblemofcons trainingthetimeintheotherdirection,becau sethetime-stampingcompanycannotissuelate rcerti ;the rstone,slightlysimpler,highlightsourmain idea, ,theTSSwillmakeuseofacollision-freehashf unction, ' c,atime-stampingrequestconsistsofanl-bit stringy(presumablythehashvalueofthedocum ent)andaclientidenti ( ) ,sequentiallynumberedtime-stampcerti (yn;idn)fromourclient,thenthrequestinseq uence, cates= (Cn),wherethecerti cateCn=(n;tn;idn;yn;Ln)consistsofthesequ encenumbern,thetimetn,theclientnumberidn andthehashvalueynfromtherequest,andcerta inlinkinginformation,whichcomesfromthepr eviouslyissuedcerti cate:Ln=(tn 1;idn 1;yn 1.)
8 H(Ln 1)). ,theTSSsendsourclienttheidenti cationnumberidn+ +1fromtheTSS,shechecksthatsisavalidsigna tureofagoodcerti cate, (n;t;idn;yn;Ln), ,thechallenger rstchecksthatthetime-stamp(s;idn+1)isoft hecorrectform(withsbeingasignatureofacer ti catethatindeedcontainsahashofx).Inordert omakesurethatourclienthasnotcolludedwith theTSS,thechallengercancallclientidn+1an daskhimtoproducehistime-stamp(s0;idn+2). Thisincludesasignatures0= (n+1;tn+1;idn+1;yn+1;Ln+1)ofacerti catethatcontainsinitslinkinginformationL n+ (Ln) +2andverifythenexttime-stampinthesequenc e.
9 ,thechallengercanalsofollowthechainoftim e-stampsbackward,beginningwithclientidn ,observethattheuseofthesignaturehasthee ,becausethecerti catemustcontainbitsfromrequeststhatimmed iatelyprecededthedesiredtime, ,becausebitsfromthedocumentinquestionmus tbeembeddedincerti catesimmediatelyfollowingthatearliertime ,yetthesecerti ,correctlyembeddinganewdocumentintotheal ready-existingstreamoftime-stampcerti , ,clientsmustkeepalltheircerti , ,thecerti cateCnisoftheformCn=(n;tn;idn;yn;Ln),whe renowthelinkinginformationLnisoftheformL n=[(tn k;idn k;yn k;H(Ln k));:::;(tn 1;idn 1;yn 1;H(Ln 1))] ,theTSSsendsourclientthelist(idn+1;:::;i dn+k).
10 Aftercheckingthatthisclient'stime-stampi softhecorrectform,asuspiciouschallengerc anaskanyoneofthenextkclientsidn+ ,histime-stampincludesasignatureofacerti catethatcontainsinitslinkinginformationL n+iacopyoftherelevantpartofthechallenged time-stampcerti cateCn,authenticatedbytheinclusionoftheh ashbyHofthechallengedclient' (idn+i+1;:::;idn+i+k),ofwhichthelastiare newones;thechallengercanasktheseclientsf ortheirtime-stamps, cates,thissecondvariantalsohasthepropert ythatcorrectlyembeddinganewdocumentintot healready-existingstreamoftime-stampcert i catesrequiresthecomputationofasimultaneo uslyk-wisecollisionforthehashfunctionH, ,weassumethatthereisasecuresignaturesche mesothateachusercansignmessages, ;inparticular, rststudiedbyBlumandMicali[2]andbyYao[22] ;Impagliazzo,Levin,andLubyhaveshownthatt heyexistifthereexistone-wayfunctions[12] .