Audit logs are one of the most important tools for transparently tracking system events and maintaining continuous oversight in corporate organizations and enterprise business systems. There are many cases where the audit logs contain sensitive data, or the audit logs are enormous. In these situations, dealing with a subset of the data is more practical than the entire data set. To provide a secure solution to handle these issues, a sanitizable signature scheme (SSS) is a viable cryptographic primitive. Herein, we first present the first post-quantum secure multivariate-based SSS, namely Mul-SAN. Our proposed design provides unforgeability, privacy, immutability, signer accountability, and sanitizer accountability under the assumption that the MQ problem is NP-hard. Mul-SAN is very efficient and only requires computing field multiplications and additions over a finite field for its implementation. Mul-SAN presents itself as a practical method to partially delegate control of the authenticated data in avenues like the healthcare industry and government organizations. We also explore using Blockchain to provide a tamper-proof and robust audit log mechanism.
翻译:审计日志是公司组织和企业业务系统中透明跟踪系统事件、维持持续监督的重要工具之一。在许多情况下,审计日志包含敏感数据或数据量庞大。此时,处理数据子集比处理整个数据集更为实用。为安全解决这些问题,可净化签名方案(SSS)是一种可行的密码学原语。本文首先提出首个基于多变量的后量子安全SSS方案——Mul-SAN。在MQ问题为NP困难问题的假设下,本设计具备不可伪造性、隐私性、不可篡改性、签名者问责性和净化者问责性。Mul-SAN高效且仅需在有限域上计算域乘法和加法。该方案为医疗行业和政府机构等场景下部分委托认证数据控制权提供了实用方法。我们还探讨了利用区块链构建防篡改、鲁棒的审计日志机制。