欧州 ETSI TR 119 476-1 V1.3.1 電子署名と信頼基盤(ESI);属性電子証明への選択的開示とゼロ知識証明の適用;第1部:実現可能性調査
こんにちは、丸山満彦です。
2023年8月に発行されたETSI TR 119 476-1 電子署名と信頼基盤(ESI);属性電子証明への選択的開示とゼロ知識証明の適用;第1部:実現可能性調査の第3版です...
● ETSI
目次...
| Intellectual Property Rights | 知的財産権 |
| Foreword | まえがき |
| Modal verbs terminology | 助動詞の用語 |
| Executive summary | エグゼクティブサマリー |
| Introduction | 序論 |
| 1 Scope | 1 範囲 |
| 2 References | 2 参考文献 |
| 2.1 Normative references | 2.1 規範的参考文献 |
| 2.2 Informative references | 2.2 参考資料 |
| 3 Definition of terms, symbols and abbreviations | 3 用語、記号および略語の定義 |
| 3.1 Terms | 3.1 用語 |
| 3.2 Symbols | 3.2 記号 |
| 3.3 Abbreviations | 3.3 略語 |
| 4 Selective disclosure signature schemes | 4 選択的開示署名方式 |
| 4.1 General | 4.1 一般 |
| 4.2 Atomic (Q)EAAs schemes | 4.2 アトミック(Q)EAA方式 |
| 4.3 Salted attribute hashes | 4.3 ソルト付き属性ハッシュ |
| 4.3.1 Overview of salted attribute hashes | 4.3.1 ソルト付き属性ハッシュの概要 |
| 4.3.2 Issuance phase | 4.3.2 発行フェーズ |
| 4.3.3 Presentation and verification phase | 4.3.3 提示および検証フェーズ |
| 4.3.4 Salted attribute hashes and unlinkability | 4.3.4 ソルト付き属性ハッシュと非連結性 |
| 4.3.4.1 General criteria of unlinkability for salted attribute hashes and associated challenges | 4.3.4.1 ソルト付き属性ハッシュの非関連付け可能性に関する一般的な規準と関連する課題 |
| 4.3.4.2 The Asynchronous Remote Key Generation (ARKG) algorithm | 4.3.4.2 非同期遠隔鍵生成(ARKG)アルゴリズム |
| 4.3.4.3 Batch issuance and Proof of Possession / Association | 4.3.4.3 一括発行と所持証明/関連証明 |
| 4.3.5 Cryptographic analysis | 4.3.5 暗号分析 |
| 4.3.6 Predicates based on computational inputs | 4.3.6 計算入力に基づく述語 |
| 4.3.7 HashWires | 4.3.7 HashWires |
| 4.3.7.1 Introduction | 4.3.7.1 序論 |
| 4.3.7.2 Cryptographic analysis of HashWires | 4.3.7.2 HashWiresの暗号分析 |
| 4.3.8 Authentic Chained Data Containers (ACDCs) | 4.3.8 真正連鎖データコンテナ(ACDC) |
| 4.3.9 Gordian Envelopes | 4.3.9 ゴルディアン封筒 |
| 4.4 Multi-message signature schemes | 4.4 マルチメッセージ署名方式 |
| 4.4.1 Camenisch-Lysyanskaya (CL) signatures | 4.4.1 カメニシュ=リシャンスカヤ(CL)署名 |
| 4.4.1.1 Introduction to CL-signatures | 4.4.1.1 CL署名への序論 |
| 4.4.1.2 The CL-signature scheme | 4.4.1.2 CL署名方式 |
| 4.4.1.3 The CL-signature scheme and selective disclosure | 4.4.1.3 CL署名方式と選択的開示 |
| 4.4.1.4 The CL-signature scheme, predicates, and knowledge proofs | 4.4.1.4 CL署名方式、述語、および知識証明 |
| 4.4.1.5 Cryptographic analysis of the CL-signature scheme | 4.4.1.5 CL署名方式の暗号分析 |
| 4.4.2 The BBS, BBS+ and BBS# signature schemes | 4.4.2 BBS、BBS+、およびBBS#署名方式 |
| 4.4.2.1 Background: Boneh-Boyen-Shacham (BBS04) signature scheme | 4.4.2.1 背景:ボネ・ボイエン・シャカム(BBS04)署名方式 |
| 4.4.2.2 Introducing the BBS+ signature scheme | 4.4.2.2 BBS+署名方式の紹介 |
| 4.4.2.3 Overview of BBS+ | 4.4.2.3 BBS+の概要 |
| 4.4.2.4 IRTF CFRG BBS specification | 4.4.2.4 IRTF CFRG BBS仕様 |
| 4.4.2.5 Device Binding Options for BBS+ | 4.4.2.5 BBS+のデバイスバインディングオプション |
| 4.4.2.6 Cryptographic analysis of the BBS+ signature scheme | 4.4.2.6 BBS+署名方式の暗号分析 |
| 4.4.3 The BBS# signature scheme | 4.4.3 BBS#署名方式 |
| 4.4.3.1 Introduction to the BBS# protocol | 4.4.3.1 BBS#プロトコルの序論 |
| 4.4.3.2 BBS# underlying signature schemes | 4.4.3.2 BBS#の基盤となる署名方式 |
| 4.4.3.2.1 General | 4.4.3.2.1 概要 |
| 4.4.3.2.2 Holder's signature scheme | 4.4.3.2.2 保有者の署名方式 |
| 4.4.3.2.3 Issuer's signature scheme | 4.4.3.2.3 発行者の署名方式 |
| 4.4.3.3 Overview of the BBS# protocol | 4.4.3.3 BBS#プロトコルの概要 |
| 4.4.3.3.1 General | 4.4.3.3.1 概要 |
| 4.4.3.3.2 Issuance | 4.4.3.3.2 発行 |
| 4.4.3.3.3 Selective disclosure | 4.4.3.3.3 選択的開示 |
| 4.4.3.3.4 Verification | 4.4.3.3.4 検証 |
| 4.4.3.4 Cryptographic analysis of the BBS# protocol | 4.4.3.4 BBS#プロトコルの暗号分析 |
| 4.4.4 Mercurial signatures | 4.4.4 Mercurial 署名 |
| 4.4.5 Pointcheval-Sanders Multi-Signatures (PS-MS) | 4.4.5 ポワンシュヴァル=サンダース多重署名 (PS-MS) |
| 4.4.6 ISO standardisation of multi-message signature schemes | 4.4.6 マルチメッセージ署名方式のISO標準化 |
| 4.4.6.1 ISO/IEC 20008 - Anonymous digital signatures | 4.4.6.1 ISO/IEC 20008 - 匿名デジタル署名 |
| 4.4.6.2 ISO/IEC 24843 - Privacy-preserving attribute-based credentials | 4.4.6.2 ISO/IEC 24843 - プライバシー保護型属性ベース認証 |
| 4.4.6.3 ISO/IEC CD 27565 - Guidelines on privacy preservation based on ZKP | 4.4.6.3 ISO/IEC CD 27565 - ZKP に基づくプライバシー保護に関するガイドライン |
| 4.4.7 Extensions of multi-messages signature schemes | 4.4.7 マルチメッセージ署名方式の拡張 |
| 4.5 Proofs for arithmetic circuits (programmable ZKPs) | 4.5 算術回路の証明(プログラム可能な完全知識証明) |
| 4.5.1 General | 4.5.1 一般 |
| 4.5.2 zk-SNARKs | 4.5.2 zk-SNARKs |
| 4.5.2.1 Introduction to zk-SNARKs | 4.5.2.1 zk-SNARKs の序論 |
| 4.5.2.2 Trusted setup of zk-SNARKs | 4.5.2.2 zk-SNARKsの信頼されたセットアップ |
| 4.5.2.3 Transparent setup zk-SNARKs | 4.5.2.3 透明なセットアップによるzk-SNARKs |
| 4.5.2.4 Cryptography behind zk-SNARKs | 4.5.2.4 zk-SNARKsの基盤となる暗号技術 |
| 4.5.2.5 Implementations | 4.5.2.5 実装 |
| 4.5.2.6 Cryptographic analysis | 4.5.2.6 暗号学的分析 |
| 4.5.3 zk-STARKs | 4.5.3 zk-STARKs |
| 4.5.3.1 Introduction to zk-STARK | 4.5.3.1 zk-STARK の序論 |
| 4.5.3.2 Setup of zk-STARK | 4.5.3.2 zk-STARKの設定 |
| 4.5.3.3 Cryptography behind zk-STARK | 4.5.3.3 zk-STARKの背後にある暗号技術 |
| 4.5.3.4 Implementations | 4.5.3.4 実装 |
| 4.5.3.5 Cryptographic analysis | 4.5.3.5 暗号分析 |
| 4.5.4 ZK Bulletproofs | 4.5.4 ZK Bulletproofs |
| 5 (Q)EAA formats with selective disclosure | 5 選択的開示を伴う(Q)EAA形式 |
| 5.1 General | 5.1 概要 |
| 5.2 Atomic (Q)EAA formats | 5.2 アトミック(Q)EAAフォーマット |
| 5.2.1 Introduction to atomic (Q)EAA formats | 5.2.1 アトミック(Q)EAA形式の序論 |
| 5.2.2 PKIX X.509 attribute certificate with atomic attribute | 5.2.2 アトミック属性付きPKIX X.509属性証明書 |
| 5.2.3 W3C Verifiable Credential with atomic attribute | 5.2.3 アトミック属性を持つW3C検証可能クレデンシャル |
| 5.3 Formats of (Q)EAAs with salted attribute hashes | 5.3 ソルト付き属性ハッシュを持つ(Q)EAAの形式 |
| 5.3.1 General | 5.3.1 概要 |
| 5.3.2 IETF SD-JWT and SD-JWT VC | 5.3.2 IETF SD-JWT および SD-JWT VC |
| 5.3.2.1 IETF SD-JWT | 5.3.2.1 IETF SD-JWT |
| 5.3.2.2 IETF SD-JWT VC | 5.3.2.2 IETF SD-JWT VC |
| 5.3.3 ISO/IEC 18013-5 Mobile Security Object (MSO) | 5.3.3 ISO/IEC 18013-5 モバイルセキュリティオブジェクト(MSO) |
| 5.4 Multi-message signature (Q)EAA formats | 5.4 マルチメッセージ署名 (Q)EAA フォーマット |
| 5.4.1 W3C VC Data Model with ZKP | 5.4.1 W3C VC データモデルとゼロ知識証明 |
| 5.4.2 W3C VC Data Integrity with BBS Cryptosuite | 5.4.2 W3C VC データ完全性(BBS 暗号スイート付き) |
| 5.4.2.1 W3C BBS Cryptosuite v2023 | 5.4.2.1 W3C BBS 暗号スイート v2023 |
| 5.4.2.2 W3C VC Data Integrity with ISO standardized BBS04/BBS+ | 5.4.2.2 W3C VCデータ完全性(ISO標準BBS04/BBS+) |
| 5.4.3 W3C Data Integrity ECDSA Cryptosuites v1.0 | 5.4.3 W3C データ完全性 ECDSA 暗号スイート v1.0 |
| 5.4.4 Hyperledger AnonCreds (format) | 5.4.4 Hyperledger AnonCreds (フォーマット) |
| 5.4.5 Cryptographic analysis | 5.4.5 暗号分析 |
| 5.5 JSON container formats | 5.5 JSONコンテナ形式 |
| 5.5.1 IETF JSON WebProof (JWP) | 5.5.1 IETF JSON WebProof (JWP) |
| 5.5.2 W3C JSON Web Proofs For Binary Merkle Trees | 5.5.2 W3C JSON Web Proofs For Binary Merkle Trees |
| 5.5.3 JSON Web Zero Knowledge (JWZ) | 5.5.3 JSON Web Zero Knowledge (JWZ) |
| 6 Selective disclosure systems and protocols | 6 選択的開示システムとプロトコル |
| 6.1 General | 6.1 一般 |
| 6.2 Atomic attribute (Q)EAA presentation protocols | 6.2 アトミック属性(Q)EAA提示プロトコル |
| 6.2.1 PKIX X.509 attribute certificates with single attributes | 6.2.1 単一属性付きPKIX X.509属性証明書 |
| 6.2.2 VC-FIDO for atomic (Q)EAAs | 6.2.2 アトミック(Q)EAAのためのVC-FIDO |
| 6.3 Salted attribute hashes protocols | 6.3 ソルト付き属性ハッシュプロトコル |
| 6.3.1 OpenAttestation (Singapore's Smart Nation) | 6.3.1 OpenAttestation(シンガポールのスマートネイション) |
| 6.4 Multi-message signature protocols and solutions | 6.4 マルチメッセージ署名プロトコルとソリューション |
| 6.4.1 Hyperledger AnonCreds (protocols) | 6.4.1 Hyperledger AnonCreds(プロトコル) |
| 6.4.2 Direct Anonymous Attestation (DAA) used with TPMs | 6.4.2 TPMと併用するダイレクト匿名認証(DAA) |
| 6.5 Proofs for arithmetic circuits solutions | 6.5 算術回路ソリューションのための証明 |
| 6.5.1 Anonymous (Q)EAAs from programmable ZKPs and existing digital identities | 6.5.1 プログラム可能なゼロ知識証明と既存のデジタルIDに基づく匿名(Q)EAAs |
| 6.5.1.1 Overview | 6.5.1.1 概要 |
| 6.5.1.2 Setup phase | 6.5.1.2 設定フェーズ |
| 6.5.1.3 Issuance phase | 6.5.1.3 発行フェーズ |
| 6.5.1.4 Proof phase | 6.5.1.4 証明フェーズ |
| 6.5.2 Cinderella: zk-SNARKs to verify the validity of X.509 certificates | 6.5.2 シンデレラ:X.509証明書の妥当性確認を行うzk-SNARKs |
| 6.5.3 zk-creds: zk-SNARKs used with ICAO passports | 6.5.3 zk-creds: ICAOパスポートで使用されるzk-SNARKs |
| 6.5.4 Anonymous credentials from ECDSA | 6.5.4 ECDSA による匿名認証 |
| 6.5.4.1 Overview of the research paper | 6.5.4.1 研究論文の概要 |
| 6.5.4.2 Implementation and standardization | 6.5.4.2 実装と標準 |
| 6.5.5 Crescent: Stronger Privacy for Existing Credentials | 6.5.5 Crescent: 既存の認証情報に対する強化されたプライバシー |
| 6.5.6 Analysis of systems based on programmable ZKPs | 6.5.6 プログラム可能なZKPsに基づくシステムの分析 |
| 6.6 Anonymous attribute based credentials systems | 6.6 匿名属性ベースの認証システム |
| 6.6.1 Idemix (Identity Mixer) | 6.6.1 アイデミックス(アイデンティティ・ミキサー) |
| 6.6.2 U-Prove | 6.6.2 U-Prove |
| 6.6.3 ISO/IEC 18370 (blind digital signatures) | 6.6.3 ISO/IEC 18370(ブラインドデジタル署名) |
| 6.6.4 Keyed-Verification Anonymous Credentials (KVAC) | 6.6.4 鍵付き検証匿名認証情報(KVAC) |
| 6.6.5 Fast IDentity Online with Anonymous Credentials (FIDO-AC) | 6.6.5 匿名認証付きオンライン迅速本人確認 (FIDO-AC) |
| 6.7 ISO mobile driving license (ISO mDL) | 6.7 ISO モバイル運転免許証 (ISO mDL) |
| 6.7.1 Introduction to ISO/IEC 18013-5 (ISO mDL) | 6.7.1 ISO/IEC 18013-5(ISO mDL)の序論 |
| 6.7.2 ISO/IEC 18013-5 (device retrieval flow) | 6.7.2 ISO/IEC 18013-5(デバイス検索フロー) |
| 6.7.3 ISO/IEC 18013-5 (server retrieval flows) | 6.7.3 ISO/IEC 18013-5(サーバー検索フロー) |
| 6.7.4 ISO/IEC 18013-7 (unattended flow) | 6.7.4 ISO/IEC 18013-7 (無人フロー) |
| 6.7.5 ISO/IEC 23220-4 (operational protocols) | 6.7.5 ISO/IEC 23220-4(運用プロトコル) |
| 6.8 OpenID for Verifiable Credentials (OpenID4VC) | 6.8 検証可能クレデンシャル用 OpenID (OpenID4VC) |
| 6.8.1 OpenID for Verifiable Credential Issuance (OpenID4VCI / OID4VCI) | 6.8.1 検証可能クレデンシャル発行のための OpenID (OpenID4VCI / OID4VCI) |
| 6.8.2 OpenID for Verifiable Presentations (OpenID4VP / OID4VP) | 6.8.2 検証可能プレゼンテーション用 OpenID (OpenID4VP / OID4VP) |
| 6.8.3 OpenID4VC High Assurance Interoperability Profile (HAIP) | 6.8.3 OpenID4VC 高保証相互運用性プロファイル (HAIP) |
| 6.9 The Iden3 protocol | 6.9 Iden3プロトコル |
| 6.9.1 Introduction to the Iden3 protocol | 6.9.1 Iden3プロトコルの序論 |
| 6.9.2 Cryptography behind the Iden3 protocol | 6.9.2 Iden3プロトコルを支える暗号技術 |
| 6.9.3 Implementation aspects of the Iden3 protocol | 6.9.3 Iden3プロトコルの実装面 |
| 7 Implications of selective disclosure on standards for (Q)EAA/PID | 7 (Q)EAA/PID 標準に対する選択的開示の影響 |
| 7.1 General implications | 7.1 一般的な影響 |
| 7.2 Implications for mdoc with selective disclosure | 7.2 選択的開示を伴うmdocへの影響 |
| 7.2.1 QTSP/PIDP issuing mdoc | 7.2.1 QTSP/PIDP発行mdoc |
| 7.2.1.1 General | 7.2.1.1 概要 |
| 7.2.1.2 Certificate profiles | 7.2.1.2 証明書プロファイル |
| 7.2.1.3 Trusted Lists | 7.2.1.3 信頼リスト |
| 7.2.1.4 Issuance of mdocs | 7.2.1.4 mdocの発行 |
| 7.2.1.5 Comparison with ETSI certificate profiles for Open Banking (PSD2) | 7.2.1.5 オープンバンキング(PSD2)向けETSI証明書プロファイルとの比較 |
| 7.2.1.6 Mapping of mdoc and eIDAS2 terms | 7.2.1.6 mdocとeIDAS2用語のマッピング |
| 7.2.2 EUDI Wallet mdoc authentication key | 7.2.2 EUDIウォレットのmdoc認証キー |
| 7.2.3 EUDI Wallet used with ISO mDL flows | 7.2.3 ISO mDLフローで使用されるEUDIウォレット |
| 7.3 Implications for SD-JWT selective disclosure | 7.3 SD-JWT選択的開示への影響 |
| 7.3.1 Analysis of using SD-JWT as (Q)EAA format applied to eIDAS2 | 7.3.1 eIDAS2に適用される(Q)EAAフォーマットとしてのSD-JWT使用の分析 |
| 7.4 Feasibility of BBS+ and BBS# applied to eIDAS2 | 7.4 eIDAS2へのBBS+およびBBS#適用可能性 |
| 7.4.1 General | 7.4.1 一般 |
| 7.4.2 Standardization of BBS+ and BBS# | 7.4.2 BBS+ および BBS# の標準 |
| 7.4.2.1 Standardization of BBS+ | 7.4.2.1 BBS+の標準 |
| 7.4.2.2 Standardization of BBS# | 7.4.2.2 BBS#の標準 |
| 7.4.3 Feasibility of using BBS+ or BBS# with W3C VCDM and mdoc | 7.4.3 W3C VCDM および mdoc における BBS+ または BBS# の使用可能性 |
| 7.4.3.1 BBS+ applied to W3C VCDM | 7.4.3.1 W3C VCDMへのBBS+の適用 |
| 7.4.3.2 BBS# applied to mdoc | 7.4.3.2 mdocへのBBS#の適用 |
| 7.4.3.3 BBS# applied to W3C VCDM | 7.4.3.3 W3C VCDMへのBBS#の適用 |
| 7.4.4 Post-quantum considerations for BBS+ and BBS# | 7.4.4 BBS+およびBBS#の耐量子暗号に関する考察 |
| 7.4.5 Conclusions of using BBS+ and BBS# applied to eIDAS2 | 7.4.5 eIDAS2へのBBS+およびBBS#適用に関する結論 |
| 7.4.5.1 Conclusions of applying BBS+ to eIDAS2 | 7.4.5.1 eIDAS2へのBBS+適用に関する結論 |
| 7.4.5.2 Conclusions of applying BBS# to eIDAS2 | 7.4.5.2 eIDAS2へのBBS#適用に関する結論 |
| 7.5 Feasibility of programmable ZKPs applied to eIDAS2 (Q)EAAs | 7.5 eIDAS2 (Q)EAAsへの適用におけるプログラム可能ZKPsの実現可能性 |
| 7.5.1 Background and existing solutions | 7.5.1 背景と既存の解決策 |
| 7.5.2 Extensions to EUDI Wallets, relying parties and protocols | 7.5.2 EUDIウォレット、依存当事者およびプロトコルへの拡張 |
| 7.5.3 Conclusions of programmable ZKPs applied to eIDAS2 (Q)EAAs | 7.5.3 eIDAS2 (Q)EAAへのプログラマブルZKPs適用に関する結論 |
| 7.6 Secure storage of PID/(Q)EAA keys in EUDI Wallet | 7.6 EUDIウォレットにおけるPID/(Q)EAA鍵の安全な保管 |
| 7.6.1 General | 7.6.1 概要 |
| 7.6.2 Key splitting technique (relevant for BBS#) | 7.6.2 鍵分割技術(BBS#に関連) |
| 7.7 The proportionality of privacy goals | 7.7 プライバシーの目標の比例性 |
| 7.7.1 General | 7.7.1 概要 |
| 7.7.2 Issuance | 7.7.2 発行 |
| 7.7.3 Presentation | 7.7.3 提示 |
| 7.7.4 Prioritizing privacy goals given the costs | 7.7.4 コストを考慮したプライバシーの目標の優先順位付け |
| 8 Privacy aspects of revocation and validity checks | 8 失効と妥当性確認のプライバシー面 |
| 8.1 Introduction to revocation and validity checks | 8.1 失効と妥当性確認の序論 |
| 8.2 Online certificate status protocol (OCSP) | 8.2 オンライン証明書ステータスプロトコル(OCSP) |
| 8.3 Revocation lists | 8.3 失効リスト |
| 8.4 Validity status lists | 8.4 妥当性確認ステータスリスト |
| 8.5 Cryptographic accumulators | 8.5 暗号的アキュムレータ |
| 8.6 Using programmable ZKP schemes for revocation checks | 8.6 失効チェックのためのプログラム可能な完全知識証明スキームの利用 |
| 8.7 Conclusions on validity status checks | 8.7 妥当性確認に関する結論 |
| 9 Post-quantum considerations | 9 耐量子に関する考察 |
| 9.1 General remarks | 9.1 総論 |
| 9.2 Post-quantum computing threats | 9.2 耐量子コンピューティングの脅威 |
| 9.3 Post-quantum computing solutions | 9.3 耐量子コンピューティングの解決策 |
| 9.4 Lattice-based anonymous credentials schemes | 9.4 格子ベースの匿名認証スキーム |
| 9.4.1 Background | 9.4.1 背景 |
| 9.4.2 Research on effective lattice-based anonymous credentials | 9.4.2 効果的な格子ベース匿名認証に関する研究 |
| 10 Conclusions | 10 結論 |
| Annex A: Comparison of selective disclosure mechanisms | 附属書A: 選択的開示メカニズムの比較 |
| A.1 Selective disclosure signature schemes | A.1 選択的開示署名スキーム |
| A.2 (Q)EAA formats with selective disclosure | A.2 選択的開示を備えた(Q)EAA形式 |
| A.3 Selective disclosure systems and protocols | A.3 選択的開示システムおよびプロトコル |
| A.4 zk-SNARK protocols | A.4 zk-SNARKプロトコル |
| Annex B: Hash wires | 附属書B:ハッシュワイア |
| B.1 HashWires applied on inequality tests | B.1 不等式テストに適用されるハッシュワイヤー |
| B.1.1 Using a hash chain for inequality tests | B.1.1 不等式テストのためのハッシュチェーンの使用 |
| B.1.2 Using multiple hash chains for inequality tests | B.1.2 不等式テストにおける複数ハッシュチェーンの使用 |
| B.1.3 Protecting optimized HashWires with SD-JWT or MSO | B.1.3 SD-JWTまたはMSOによる最適化ハッシュワイアの防御 |
| B.1.4 Less than or equal to and range proofs | B.1.4 以下の証明および範囲証明 |
| B.2 Hash chain code example | B.2 ハッシュチェーンのコード例 |
| B.3 HashWires for SD-JWT and MSO | B.3 SD-JWTおよびMSO向けHashWires |
| Annex C: Post-quantum safe zero-knowledge proofs and anonymous credentials | 附属書 C: 耐量子ゼロ知識証明と匿名クレデンシャル |
| C.1 General | C.1 概要 |
| C.2 Quantum physics applied on ZKP schemes | C.2 ZKP方式への量子物理学の応用 |
| C.2.1 Background | C.2.1 背景 |
| C.2.2 Quantum Key Distribution (QKD) | C.2.2 量子鍵配送(QKD) |
| C.2.3 Quantum physics applied to the graph 3-colouring ZKP scheme | C.2.3 グラフ3色付けZKP方式への量子物理学の応用 |
| C.2.4 ZKP using the quantum Internet (based on Schnorr's algorithm) | C.2.4 量子インターネットを用いたZKP(シュノールのアルゴリズムに基づく) |
| C.2.5 Conclusions on quantum ZKP schemes | C.2.5 量子ZKPスキームに関する結論 |
| Annex D: EUDI Wallet used with ISO mDL flows | 附属書D:ISO mDLフローで使用されるEUDIウォレット |
| D.1 EUDI Wallet used with ISO mDL device retrieval flow | D.1 ISO mDLデバイス取得フローで使用されるEUDIウォレット |
| D.1.1 Overview of the ISO mDL device retrieval flow | D.1.1 ISO mDLデバイス取得フローの概要 |
| D.1.2 Analysis of the ISO mDL device retrieval flow for eIDAS2 | D.1.2 eIDAS2におけるISO mDLデバイス取得フローの分析 |
| D.2 EUDI Wallet used with ISO mDL server retrieval flow | D.2 ISO mDLサーバー取得フローで使用されるEUDIウォレット |
| D.2.1 Overview of the ISO mDL server retrieval flows | D.2.1 ISO mDLサーバー取得フローの概要 |
| D.2.2 ISO mDL flow initialization | D.2.2 ISO mDLフローの初期化 |
| D.2.3 ISO mDL server retrieval flow initialization | D.2.3 ISO mDLサーバー取得フローの初期化 |
| D.2.4 ISO mDL server retrieval WebAPI flow | D.2.4 ISO mDLサーバー取得WebAPIフロー |
| D.2.5 Analysis of the ISO mDL server retrieval WebAPI flow for eIDAS2 | D.2.5 eIDAS2向けISO mDLサーバー取得WebAPIフローの分析 |
| D.2.6 ISO mDL server retrieval OIDC flow | D.2.6 ISO mDLサーバー検索OIDCフロー |
| D.2.7 Analysis of the ISO mDL OIDC server retrieval flow applied to eIDAS2 | D.2.7 eIDAS2に適用したISO mDL OIDCサーバー取得フローの分析 |
| D.3 EUDI Wallets used with ISO/IEC 18013-7 for unattended flow | D.3 無人フローにおけるISO/IEC 18013-7対応EUDIウォレット |
| D.3.1 Overview of the ISO/IEC 18013-7 flows | D.3.1 ISO/IEC 18013-7フローの概要 |
| D.3.2 ISO/IEC 18013-7 Device Retrieval flow | D.3.2 ISO/IEC 18013-7 デバイス取得フロー |
| D.3.3 ISO/IEC 18013-7 OID4VP/SIOP2 flow | D.3.3 ISO/IEC 18013-7 OID4VP/SIOP2フロー |
| Annex E: A primer on W3C VCDM & SD-JWT VC | 附属書 E: W3C VCDM および SD-JWT VC の基礎 |
| E.1 Overview of W3C Verifiable Credential Data Model (VCDM) | E.1 W3C 検証可能クレデンシャルデータモデル(VCDM)の概要 |
| E.1.1 W3C VC, JSON-LD, data integrity proofs, and linked data signatures | E.1.1 W3C VC、JSON-LD、データ完全性証明、およびリンクデータ署名 |
| E.1.2 W3C VC, JSON-LD, data integrity proofs, and linked data signatures | E.1.2 W3C VC、JSON-LD、データ完全性証明、およびリンクデータ署名 |
| E.1.3 JWT based W3C VC | E.1.3 JWT ベースの W3C VC |
| E.2 SD-JWT based attestations | E.2 SD-JWT ベースの証明 |
| E.2.1 General | E.2.1 概要 |
| E.2.2 SD-JWT VC | E.2.2 SD-JWT VC |
| E.2.3 SD-JWT and multi-show unlinkable disclosures | E.2.3 SD-JWT と複数開示による非関連付け可能な開示 |
| E.2.4 Predicates in SD-JWT | E.2.4 SD-JWT における述語 |
| E.3 W3C VCDM 2.0 with SD-JWT | E.3 SD-JWT を用いた W3C VCDM 2.0 |
| Annex F: Business models and unlinkability | 附属書F: ビジネスモデルと非関連付け可能性 |
| F.1 General | F.1 一般 |
| F.2 ETSI TR 119 479-2 | F.2 ETSI TR 119 479-2 |
| F.3 Anonymous usage data aggregation | F.3 匿名使用データ集計 |
| F.3.1 General | F.3.1 概要 |
| F.3.2 The billing model and private sum process | F.3.2 課金モデルとプライベート・サム処理 |
| F.3.3 Alternative approach optimized for compatibility | F.3.3 互換性に最適化された代替アプローチ |
| Annex G: BBS# applied to ISO mDL | 附属書G:ISO mDLに適用されるBBS# |
| G.1 General | G.1 一般 |
| G.2 Setup | G.2 設定 |
| G.3 Issuance | G.3 発行 |
| G.4 Selective disclosure | G.4 選択的開示 |
| G.5 Verification | G.5 検証 |
| Annex H: Bibliography | 附属書H:参考文献 |
| Annex I: Change history | 附属書 I: 変更履歴 |
| History | 履歴 |
| Executive summary | エグゼクティブサマリー |
| The eIDAS2 regulation [i.103] defines regulatory requirements on selective disclosure and unlinkability for the EUDI Wallet. While the corresponding Architecture and Reference Framework (ARF) is not legally binding, it serves as a reference for the harmonized implementation of the EUDI Wallet. As such, it provides guidance, among other aspects, how to implement selective disclosure. | eIDAS2規制[i.103]は、EUDIウォレットに対する選択的開示と非連結性に関する規制要件を定義している。対応するアーキテクチャおよび参照枠組み(ARF)は法的拘束力を持たないものの、EUDIウォレットの調和的な実装のための参照として機能する。したがって、選択的開示の実装方法を含む様々な側面について指針を提供する。 |
| In contrast, the present document has a broader scope regarding data minimisation. It provides a general yet comprehensive analysis of signature schemes, formats and protocols with different degrees of maturity that cater for selective disclosure, unlinkability, and predicate proofs. More specifically, the present document includes an analysis of how certain data minimisation techniques can be applied to eIDAS2 and the EUDI Wallet. | これに対し、本文書はデータ最小化に関してより広範な範囲を扱う。選択的開示、非関連付け可能性、述語証明に対応する、成熟度の異なる署名方式、フォーマット、プロトコルについて、一般的でありながら包括的な分析を提供する。具体的には、特定のデータ最小化技術をeIDAS2およびEUDIウォレットに適用する方法に関する分析を含む。 |
| The term selective disclosure means that a user should be capable of presenting a subset of attributes from at least one, but potentially multiple, (Qualified) Electronic Attestations of Attributes ((Q)EAAs). For example, a user should be able to only present their birth date from an attestation resembling an ID-card. | 選択的開示とは、ユーザーが少なくとも1つ、場合によっては複数の(適格)電子属性証明((Q)EAA)から属性のサブセットを提示できることを意味する。例えば、IDカードに類似した証明から生年月日のみを提示できるべきである。 |
| The term unlinkability means that different parties should not be able to connect the user's selectively disclosed attributes beyond what is disclosed. There are different categories and degrees of unlinkability, and the present document focuses both on verifier unlinkability and full unlinkability. Verifier unlinkable means that one or more verifiers cannot collude to determine if the selectively disclosed attributes describe the same identity subject, whilst fully unlinkable means that no party can collude to determine if the selectively disclosed attributes describe the same identity subject. | 「非連結性」とは、異なる当事者が、開示された範囲を超えてユーザーの選択的に開示された属性を結びつけることができないことを意味する。非連結性には異なるカテゴリーと程度が存在し、本稿では検証者非連結性と完全非連結性の両方に焦点を当てる。検証者非連結性とは、1人以上の検証者が共謀して選択的に開示された属性が同一の主体を記述しているか否かを判断できないことを意味する。一方、完全非連結性とは、いかなる当事者も共謀して選択的に開示された属性が同一の主体を記述しているか否かを判断できないことを意味する。 |
| Predicate proofs are verifiable computations on information included in attestations, where only the result of the computation and none of the underlying inputs is shared. This includes Boolean assertions (true or false) about properties of attributes in a (Q)EAA without disclosing the attribute value itself. For example, a user could derive a proof that they are above the age of 20 from their birth date and show only this proof as opposed to the birthdate itself. On the other hand, the predicate could also be the sum of two attributes included in a (Q)EAA or a verifiable pseudonym computed from cryptographic metadata associated with the (Q)EAA and information provided by the relying party. Predicate proofs are often employed in Zero-Knowledge Proof (ZKP) systems aimed at limiting information disclosure or fine-tuning it (e.g. in the case of verifiable pseudonyms [i.245]). | 述語証明とは、証明に含まれる情報に対する検証可能な計算であり、計算結果のみが共有され、基礎となる入力は一切共有されない。これには、(Q)EAA内の属性の特性に関するブール値(真または偽)の主張が含まれ、属性値自体は開示されない。例えば、ユーザーは生年月日から20歳以上であることの証明を導出し、生年月日自体ではなくこの証明のみを示すことができる。一方、述語は(Q)EAAに含まれる2つの属性の和や、(Q)EAAに関連する暗号メタデータと依存当事者から提供された情報から計算された検証可能な仮名である場合もある。述語証明は、情報開示を制限または微調整することを目的としたゼロ知識証明(ZKP)システムで頻繁に採用される(例:検証可能仮名[i.245]の場合)。 |
| In general, data minimisation in verifiable presentations is not easy to achieve because the required degree of verifiability relies on digital signatures, which become invalid upon any modification ("blackening") of information in a (Q)EAA. Selective disclosure can be relatively easy to achieve, whereas full unlinkability and predicate proofs require advanced to very advanced cryptographic constructions. | 一般的に、検証可能な提示におけるデータ最小化は容易ではない。なぜなら、必要な検証性はデジタル署名に依存しており、(Q)EAA内の情報が改変(「ブラックニング」)されると無効になるためである。選択的開示は比較的容易に達成できる一方、完全な非関連付け性と述語証明には高度から非常に高度な暗号学的構成が必要となる。 |
| The selective disclosure signature schemes described in the present document are divided in the following categories: | 本文書で説明する選択的開示署名方式は、以下のカテゴリーに分類される: |
| • Atomic (Q)EAA schemes. An atomic electronic attribute attestation is a (Q)EAA with a single attribute claim, which can be issued by a (Q)TSP upon request or as part of a batch to an EUDI Wallet. The atomic (Q)EAAs can be selected by the user and be included in a verifiable presentation to a verifier. | • アトミック(Q)EAA方式。 アトミック電子属性証明(Atomic (Q)EAA)とは、単一の属性主張を含む(Q)EAAであり、(Q)TSPが要求に応じて、またはEUDIウォレットへのバッチの一部として発行できる。 アトミック(Q)EAAはユーザーが選択可能であり、検証者への検証可能提示に含まれる。 |
| • Salted attribute hashes. The general concept of this category is to combine each attribute with a salt, hash the combined values, and insert the resulting salted attribute hashes in a list that is signed. The user presents a selection of attributes to the verifier, which can validate them against the list of salted attribute hashes. The following schemes, based on salted attribute hashes, are described: HashWires, Authentic Chained Data Containers (ACDC), and Gordian Envelopes. | • ソルト付き属性ハッシュ。このカテゴリーの一般的な概念は、各属性をソルトと組み合わせ、結合値をハッシュ化し、その結果であるソルト付き属性ハッシュを署名付きリストに挿入することである。ユーザーは検証者に対して属性の選択を提示し、検証者はソルト付き属性ハッシュのリストと照合してそれらを妥当性確認できる。ソルト付き属性ハッシュに基づく以下の方式を説明する:HashWires、Authentic Chained Data Containers (ACDC)、Gordian Envelopes。 |
| • Multi-message signature schemes. The category of multi-message signature schemes has the capability of proving the knowledge of a signature while selectively disclosing any subset of the signed messages. By definition, multi-message signature schemes also cater for full unlinkability. The following schemes in this category are described: BBS/BBS+/BBS#, Camenisch-Lysyanskaya (CL) signatures, Mercurial signatures, and Pointcheval-Sanders Multi-Signatures (PS-MS). ISO/IEC have standardized parts of BBS and PS-MS in ISO/IEC 20008 [i.184], and have taken the initiative to standardize BBS+ and PS-MS in ISO/IEC 24843 [i.185] and ISO/IEC CD 27565 [i.191]. Furthermore, there are cryptographic research projects, such as MoniPoly, where undisclosed attributes have no impact on the proof size. | • マルチメッセージ署名方式。マルチメッセージ署名方式のカテゴリーは、署名知識を証明しつつ、署名済みメッセージの任意の部分集合を選択的に開示する能力を有する。定義上、マルチメッセージ署名方式は完全な非連結性も保証する。このカテゴリーでは以下の方式を説明する:BBS/BBS+/BBS#、Camenisch-Lysyanskaya (CL) 署名、Mercurial署名、Pointcheval-Sanders多重署名(PS-MS)。ISO/IECはBBSおよびPS-MSの一部をISO/IEC 20008 [i.184]で標準化し、BBS+とPS-MSの標準化をISO/IEC 24843 [i.185]およびISO/IEC CD 27565 [i.191]で主導している。さらに、MoniPolyのような暗号研究プロジェクトでは、非開示属性は証明サイズに影響を与えない。 |
| • Proofs for arithmetic circuits (programmable/general-purpose ZKPs). This category of ZKP protocols enable the user to prove to the verifier that a certain statement is true, without revealing any additional information beyond the truth of the statement itself. The discussion of proofs for arithmetic circuits is currently focused on zk-SNARKs because this type of programmable ZKPs has matured rapidly in recent years, arguably to their broad adoption in cryptocurrencies, decentralised finance and industry blockchain projects. | • 算術回路証明(プログラム可能/汎用 ZKP)。このカテゴリーの ZKP プロトコルは、ユーザーが検証者に対して、特定の命題が真であることを証明することを可能にする。その際、命題自体の真偽以外の追加情報を一切開示しない。算術回路の証明に関する議論は現在、zk-SNARKsに焦点が当てられている。この種のプログラム可能なZKPsは近年急速に成熟し、暗号通貨、分散型金融、産業用ブロックチェーンプロジェクトでの広範な採用につながったと言える。 |
| The present document also includes descriptions of (Q)EAA formats that can be used with selective disclosure. The (Q)EAA formats are divided in the following categories: | 本稿では、選択的開示と併用可能な(Q)EAA形式についても記述する。(Q)EAA形式は以下のカテゴリーに分類される: |
| • Atomic (Q)EAA formats. These (Q)EAA formats are based on the category of atomic (Q)EAA formats. The following (Q)EAA formats in this category are described: PKIX X.509 attribute certificate with atomic attribute and W3C® Verifiable Credential with atomic attribute. | • アトミック(Q)EAA形式。これらの(Q)EAA形式はアトミック(Q)EAA形式のカテゴリーに基づいている。このカテゴリーでは以下の(Q)EAA形式が説明されている:アトミック属性を持つPKIX X.509属性証明書、およびアトミック属性を持つW3C® 検証可能クレデンシャル。 |
| • (Q)EAAs with salted attribute hashes. This category of (Q)EAA formats is based on the concept of salted attribute hashes. These (Q)EAA formats specify in detail how the attributes are combined with the random salts and hashed, inserted in a list, which is signed. The following (Q)EAA formats of this category are described: IETF SD-JWT and ISO/IEC 18013-5 [i.181] Mobile Security Object (MSO). | • ソルト付き属性ハッシュを用いた(Q)EAA。このカテゴリーの(Q)EAAフォーマットは、ソルト付き属性ハッシュの概念に基づいている。これらの(Q)EAAフォーマットは、属性がランダムなソルトと組み合わされハッシュ化され、署名されるリストに挿入される方法を詳細に規定する。このカテゴリーに属する以下の(Q)EAAフォーマットが説明される:IETF SD-JWTおよびISO/IEC 18013-5 [i.181] モバイルセキュリティオブジェクト(MSO)。 |
| • Multi-message signature (Q)EAA formats. This category of (Q)EAA formats is based on multi-message signature schemes. Mainly W3C and Hyperledger have specified such formats to be used for privacy preserving features. The following (Q)EAA formats in this category are described: W3C VC Data Model with ZKP, W3C VC Data Integrity with BBS Cryptosuite, and Hyperledger AnonCreds (format). | • マルチメッセージ署名(Q)EAAフォーマット。このカテゴリーの(Q)EAAフォーマットはマルチメッセージ署名方式に基づいている。主にW3CとHyperledgerが、プライバシー保護機能に使用されるようこうしたフォーマットを規定している。このカテゴリーでは以下の(Q)EAA形式を説明する:W3C VC Data Model with ZKP、W3C VC Data Integrity with BBS Cryptosuite、Hyperledger AnonCreds (format)。 |
| • JSON container formats. This category of generic JSON container formats allows for combining and presenting a mix of selective disclosure signature schemes. The following JSON container formats are described: IETF JSON WebProof (JWP), JSON Web Zero Knowledge (JWZ), W3C Data Integrity ECDSA Cryptosuites v1.0, and W3C JSON Web Proofs For Binary Merkle Trees. | • JSONコンテナ形式。この汎用JSONコンテナ形式カテゴリーは、選択的開示署名スキームの組み合わせと提示を可能にする。以下のJSONコンテナ形式について説明する:IETF JSON WebProof(JWP)、JSON Web Zero Knowledge(JWZ)、W3C Data Integrity ECDSA Cryptosuites v1.0、およびW3C JSON Web Proofs For Binary Merkle Trees。 |
| Furthermore, the present document describes systems and protocols with selective disclosure capabilities. The systems and protocols are divided in the following categories: | さらに、本稿では選択的開示機能を備えたシステムおよびプロトコルについて記述する。これらのシステムとプロトコルは、以下のカテゴリーに分類される: |
| • Atomic attribute (Q)EAA presentation protocols. This category of protocols is designed to present the atomic attribute (Q)EAA formats. The atomic attribute (Q)EAAs may be issued on demand to the user, upon request by a verifier. The following protocols in this category are described: PKIX X.509 attribute certificates with single attributes and VC-FIDO for atomic (Q)EAAs. | • アトミック属性(Q)EAA提示プロトコル。このカテゴリーのプロトコルは、アトミック属性(Q)EAAフォーマットを提示するために設計されている。アトミック属性(Q)EAAは、検証者からの要求に応じて、ユーザーにオンデマンドで発行される。このカテゴリーでは以下のプロトコルが説明される:単一属性付きPKIX X.509属性証明書、およびアトミック(Q)EAA向けVC-FIDO。 |
| • Salted attribute hashes-based protocols. These solutions and protocols are designed to present selectively disclosed attributes based on salted attribute hashes. The OpenAttestation solution of Singapore's Smart Nation is described in the present document. Furthermore, ISO mDL MSOs can be shared over the proximity protocols described in ISO/IEC 18013-5 [i.181] or over the Internet by using ISO/IEC CD 23220-4 [i.187]. The SD-JWTs can be presented with different protocols, such as OID4VP (OpenID for Verifiable Presentations), ISO/IEC CD 18013-7 [i.182] or ISO/IEC CD 23220-4 [i.187]. | • ソルト付き属性ハッシュベースのプロトコル。これらのソリューションおよびプロトコルは、ソルト付き属性ハッシュに基づく選択的に開示された属性を提示するために設計されている。本ドキュメントでは、シンガポール・スマートネイションのOpenAttestationソリューションについて説明する。さらに、ISO mDL MSOは、ISO/IEC 18013-5 [i.181]で規定される近接プロトコル、またはISO/IEC CD 23220-4 [i.187]を使用したインターネット経由で共有可能である。SD-JWTは、OID4VP(OpenID for Verifiable Presentations)、ISO/IEC CD 18013-7 [i.182]、またはISO/IEC CD 23220-4 [i.187]などの異なるプロトコルで提示可能である。 |
| • Multi-message signature protocols and solutions. This category of protocols is based on multi-message signature schemes, such as BBS+ and CL-signatures, and are used to present selected attributes of the (Q)EAAs. The following protocols and solutions in this category are described: Hyperledger AnonCreds (protocols) and Direct Anonymous Attestation (DAA) used with Trusted Platform Modules (TPMs); the TPMs have been deployed in personal computers at a large scale. | • マルチメッセージ署名プロトコルおよびソリューション。このカテゴリーのプロトコルは、BBS+やCL署名などのマルチメッセージ署名方式に基づいており、(Q)EAAの選択された属性を提示するために使用される。このカテゴリーでは以下のプロトコルとソリューションを説明する:Hyperledger AnonCreds(プロトコル)およびTrusted Platform Modules(TPM)と併用するDirect Anonymous Attestation(DAA)。TPMは大規模に個人用コンピュータに展開されている。 |
| • Solutions based on proofs for arithmetic circuits (programmable/general-purpose ZKPs). The solutions that are based on proofs for arithmetic circuits intend to use ZKP schemes such as zero-knowledge non-interactive arguments of knowledge (zk-NARKs) and succinct forms of these (zk-SNARKs) (to facilitate data-minimising verifiable presentations based on existing digital identity infrastructures). In particular, they can provide selective disclosure, unlinkability, and arbitrary predicate proofs. As proof generation involves substantial overhead, these schemes are often combined with new formats for attestations that make ZKP operations relatively efficient. As examples, constructions suggested by [i.14] and the Iden3 protocols are covered. On the other hand, the recent progress in designing and implementing efficient programmable ZKPs now also allows for compatibility with legacy formats. The following projects are covered in the present document: Cinderella (zk-SNARKs used with X.509 certificates), zk-creds (zk-SNARKs used with ICAO passports), FIDO-AC (zk-SNARKs used with the FIDO protocol and ICAO passports), Crescent (zk-SNARKs used with X.509 certificates and JWTs), and anonymous credentials from ECDSA (zk-NARKs used with ISO mdoc). | • 算術回路証明に基づくソリューション(プログラム可能/汎用ゼロ知識証明)。算術回路の証明に基づくソリューションは、ゼロ知識非対話型知識論証(zk-NARK)やその簡潔な形式(zk-SNARK)といったゼロ知識証明スキームを活用する(既存のデジタルIDインフラに基づくデータ最小化検証可能提示を容易にするため)。特に、選択的開示、非連結性、任意述語証明の3つを提供可能なプロバイダである。証明生成には多大なオーバーヘッドを伴うため、これらのスキームはしばしば、ZKP操作を比較的効率化する新たな認証形式と組み合わされる。例として、[i.14]で提案された構成とIden3プロトコルが対象となる。一方、効率的なプログラム可能ZKPsの設計・実装における近年の進展により、従来フォーマットとの互換性も実現可能となった。本稿では以下のプロジェクトを扱う:Cinderella(X.509証明書と併用するzk-SNARKs)、zk-creds(ICAOパスポートと併用するzk-SNARKs)、FIDO-AC(FIDOプロトコルおよびICAOパスポートと併用するzk-SNARKs)、Crescent(X.509証明書およびJWTと併用するzk-SNARKs)、ならびにECDSAからの匿名クレデンシャル(ISO mdocと併用するzk-NARKs)。 |
| • Anonymous attribute-based credentials systems. These solutions are implementations of existing multi-message signature schemes such as BBS+ or CL-signatures, with the purpose to present anonymous credentials ((Q)EAAs) to a verifier. The following solutions in this category are described: Idemix (Identity Mixer), U-Prove, ISO/IEC 18370 [i.183] (blind digital signatures), and Keyed-Verification Anonymous Credentials (KVAC). | • 匿名属性ベース認証システム。これらのソリューションは、検証者に対して匿名認証((Q)EAAs)を提示することを目的とした、BBS+やCL-signaturesなどの既存のマルチメッセージ署名方式の実装である。このカテゴリーでは以下のソリューションを説明する:アイデミックス(Identity Mixer)、U-Prove、ISO/IEC 18370 [i.183](ブラインドデジタル署名)、および鍵付き検証匿名クレデンシャル(KVAC)。 |
| NOTE: In the academic literature, the terms "anonymous credentials" and "attribute-based credentials" are often used synonymously. Both refer to the construction of digital certificates ((Q)EAA) and corresponding presentation protocols that disclose only the minimum amount of information requested by the relying party while still giving assurances of all the expected validity and consistency properties. | 注記: 学術文献では、「匿名クレデンシャル」と「属性ベースクレデンシャル」という用語はしばしば同義語として使用される。いずれも、依存当事者から要求された最小限の情報のみを開示しつつ、期待される有効性および一貫性プロパティの保証を維持するデジタル証明書((Q)EAA)および対応する提示プロトコルの構築を指す。 |
| • ISO mobile driving license (ISO mDL). The ISO mDL standard [i.181]specifies various flows for selective disclosure of attributes. In the present document, the following ISO mDL flows are described: | • ISOモバイル運転免許証(ISO mDL)。ISO mDL標準[i.181]は、属性の選択的開示のための様々なフローを規定している。本文書では、以下のISO mDLフローについて記述する: |
| ISO/IEC 18013-5 [i.181] (device retrieval flow), ISO/IEC 18013-5 [i.181] (server retrieval flows), ISO/IEC 18013-7 [i.182] (unattended flow) and ISO/IEC 23220-4 [i.187] (operational protocols). mDL describes the specific driver's license document or application, whereas mdoc is used to describe the general mechanism for documents or applications residing on a mobile device. For the rest of the present document, mdoc is used to refer to the general mechanism or format for digital identity documents, whereas mDL can be seen as a special case of an mdoc. | ISO/IEC 18013-5 [i.181](デバイス検索フロー)、ISO/IEC 18013-5 [i.181](サーバー検索フロー)、ISO/IEC 18013-7[i.182](無人フロー)、ISO/IEC 23220-4 [i.187](運用プロトコル)。mDLは特定の運転免許証文書またはアプリケーションを記述するのに対し、mdocはモバイルデバイス上に存在する文書またはアプリケーションの一般的なメカニズムを記述するために使用される。本文書の残りの部分では、mdoc はデジタル身分証明書の一般的なメカニズムまたはフォーマットを指すのに対し、mDL は mdoc の特殊なケースと見なすことができる。 |
| The ARF proposes two protection mechanisms for the PID, which support selective disclosure but not unlinkability (unless batch issued): | ARFはPID向けに2つの防御メカニズムを提案しており、これらは選択的開示をサポートするが、非関連付け性(一括発行時を除く)はサポートしない: |
| • ISO/IEC 18013-5 [i.181] (ISO mDL). The mdoc contains 2 general structures, the issuer signed part called, especially the MSO and when presenting a device signed part. During issuance, the issuer provides all attributes of a user in an issuer signed part next to the MSOs whilst the MSO contains the corresponding salted attribute hashes and other information that is signed over by the issuer like a validity period. During presentation, the device signed structure is used to present the attributes that are released. | • ISO/IEC 18013-5 [i.181](ISO mDL)。mdocは2つの基本構造を含む:発行者署名部分(特にMSO)と、提示時に使用されるデバイス署名部分。発行時には、発行者はMSOに隣接する発行者署名部分でユーザーの全属性を提供し、MSOには対応するソルト付き属性ハッシュや有効期間など発行者が署名するその他の情報が含まれる。提示時には、デバイス署名構造が解放された属性の提示に使用される。 |
| • IETF SD-JWT in conjunction with IETF SD-JWT VC. The JWT contains the user attributes, whilst the SD-JWT contains the corresponding salted attribute hashes. | • IETF SD-JWTとIETF SD-JWT VCを併用する。JWTにはユーザー属性が含まれ、SD-JWTには対応するソルト付き属性ハッシュが含まれる。 |
| The present document includes an extensive analysis of mdoc and SD-JWT and how the formats comply with the eIDAS2 requirements on selective disclosure and unlinkability. | 本文書では、mdocおよびSD-JWTの詳細な分析と、これらのフォーマットがeIDAS2の選択的開示および非関連付け性要件にどのように準拠しているかを包括的に扱う。 |
| The mdoc and the SD-JWT formats, and related presentation protocols, cater for selective disclosure based on the concept of salted attribute hashes. Furthermore, the mdoc and SD-JWT formats support SOG-IS approved cryptographic algorithms and can also be used with quantum-safe cryptography for future use. The conclusion is thus that mdoc and SD-JWT meet the eIDAS2 regulatory and technical requirements on selective disclosure. | mdocおよびSD-JWTフォーマット、ならびに関連する提示プロトコルは、ソルト付き属性ハッシュの概念に基づく選択的開示に対応している。さらに、mdocおよびSD-JWTフォーマットはSOG-IS承認の暗号アルゴリズムをサポートし、将来の使用に向けて量子耐性暗号との併用も可能である。したがって結論として、mdocおよびSD-JWTはeIDAS2の選択的開示に関する規制上および技術上の要件を満たしている。 |
| As stated, mdoc and SD-JWT are not fully unlinkable, although they can provide verifier unlinkability with certain operational measures. In order to achieve verifier unlinkability, batches of MSOs or SD-JWTs need to be issued to each EUDI Wallet. In this case, the random salts in the MSO and SD-JWT should be unique, meaning that refreshed MSOs and SD-JWTs are presented to a relying party. Furthermore, the user public keys used for holder binding, if presented (in non-proximity scenarios), need to be unique, too. | 前述の通り、mdocおよびSD-JWTは完全には非関連付け可能ではないが、特定の運用上の措置により検証者非関連付け性をプロバイダできる。検証者非関連付け性を達成するには、各EUDIウォレットに対してMSOまたはSD-JWTのバッチを発行する必要があります。この場合、MSOおよびSD-JWT内のランダムなソルトは一意であるべきであり、更新されたMSOおよびSD-JWTが依存先(relying party)に提示されることを意味する。さらに、保持者紐付けに使用されるユーザー公開鍵(非近接シナリオで提示される場合)も一意である必要がある。 |
| There are many similarities between the ISO mDL issuers and the eIDAS2 compliant PID Providers (PIDPs) or QTSPs. The PIDPs/QTSPs can issue PIDs/(Q)EAAs to EUDI Wallets as follows to cater for selective disclosure: | ISO mDL発行者とeIDAS2準拠のPIDプロバイダ(PIDP)またはQTSPの間には多くの類似点がある。PIDP/QTSPは選択的開示に対応するため、以下のようにEUDIウォレットにPID/(Q)EAAを発行できる: |
| • The PIDP/QTSP issues mdoc and/or JWT as PID/(Q)EAAs to the EUDI Wallet. | • PIDP/QTSPは、EUDIウォレットに対しmdocおよび/またはJWTをPID/(Q)EAAとして発行する。 |
| • The PIDP/QTSP issues MSOs and/or SD-JWTs batchwise to the EUDI Wallet. The MSOs are associated with the mdoc, and the SD-JWTs with the JWT. Random salts are used for the salted attribute hashes in each MSO or SD-JWT. This will cater for verifier unlinkability when the MSOs or SD-JWTs are presented to and validated by a relying party. | • PIDP/QTSPは、MSOおよび/またはSD-JWTをバッチ処理でEUDIウォレットに発行する。MSOはmdocに関連付けられ、SD-JWTはJWTに関連付けられる。各MSOまたはSD-JWT内のソルト付き属性ハッシュにはランダムなソルトが使用される。これにより、MSOまたはSD-JWTが信頼当事者に提示され妥当性確認される際に、検証者による関連付け不可性が確保される。 |
| • The EUDI Wallet selectively discloses certain attribute(s) of an mdoc or JWT. One MSO or SD-JWT is selected from the batch in the EUDI Wallet, and is associated with the disclosed attribute(s). | • EUDIウォレットは、mdocまたはJWTの特定の属性を選択的に開示する。EUDIウォレット内のバッチから1つのMSOまたはSD-JWTが選択され、開示された属性に関連付けられます。 |
| • The relying party can use the eIDAS2 trust list (which is equivalent to an ISO mDL VICAL) to retrieve the QTSP/PIDP trust anchor (which is equivalent to the IACA trust anchor). The relying party validates the MSOs or SD-JWTs signatures by using the QTSP/PIDP trust anchor. The relying party also verifies that the presented selected attribute hash is present in the MSO or SD-JWT. | • 信頼当事者は、eIDAS2トラストリスト(ISO mDL VICALに相当)を使用してQTSP/PIDPトラストアンカー(IACAトラストアンカーに相当)を取得できる。信頼当事者はQTSP/PIDP信頼アンカーを用いてMSOまたはSD-JWTの署名を妥当性確認する。また提示された選択属性ハッシュがMSOまたはSD-JWT内に存在することを確認する。 |
| These recommendations could be considered for the upcoming ETSI TS 119 471 [i.96] and ETSI TS 119 472-1 [i.97] that will standardize the issuance policies and profiles of (Q)EAAs. | これらの推奨事項は、(Q)EAAの発行ポリシーとプロファイルを標準化する予定の今後のETSI TS 119 471 [i.96]およびETSI TS 119 472-1 [i.97]において考慮される可能性がある。 |
| Multi-message signature schemes such as BBS+, BBS#, Camenisch-Lysyanskaya (CL) signatures, Mercurial signatures, and Pointcheval-Sanders Multi-Signatures (PS-MS) cater for full unlinkability, although they are not yet fully standardized. Hence, ISO/IEC 24843 [i.185] intends to standardize BBS+ and PS-MS with blinded signatures, which may allow for a future standard that could be used in compliance with the EUDI Wallet requirements on selective disclosure and unlinkability in eIDAS2. The BBS# scheme can also be implemented for ISO MSO, W3C VCDM and IETF SD-JWT, which caters for full unlinkability for these formats. | BBS+、BBS#、Camenisch-Lysyanskaya (CL) 署名、Mercurial署名、Pointcheval-Sanders Multi-Signatures (PS-MS) などのマルチメッセージ署名方式は完全な非連結性を実現するが、まだ完全に標準化されていない。したがって、ISO/IEC 24843 [i.185] は、ブラインド署名を用いたBBS+およびPS-MSの標準化を意図しており、これにより将来的にeIDAS2におけるEUDIウォレット要件(選択的開示および非関連付け性)に準拠して使用可能な標準が実現される可能性がある。BBS#スキームはISO MSO、W3C VCDM、IETF SD-JWTにも実装可能であり、これらのフォーマットにおける完全な非関連付け性を実現する。 |
| There are also systems based on programmable ZKPs in the form of zk-SNARKs, such as Cinderella, zk-creds, and zk-mdoc, that can achieve both selective disclosure and unlinkability with existing digital identity infrastructures such as X.509 certificates, ISO mDL, or ICAO passports. Such systems can generate pseudo-certificates that share selected attributes from the (Q)EAAs and attest holder binding and non-revocation without exposing linkable cryptographic identifiers, as well as implement arbitrary predicates. Anonymous credentials based on programmable ZKPs can, therefore, in particular be made compatible with deployed secure hardware and are easily extendable. However, these projects are still in the research phase and face a high degree of complexity. On the other hand, they can be considered future-proof as some forms (e.g. the NARKs used in [i.113]) are plausibly post-quantum secure owing to their sole reliance on cryptographic hash functions, and as opposed to established and more efficient multi-message signature schemes, they can flexibly adapt to new (e.g. post-quantum secure) signature schemes and novel (Q)EAA formats. Hence, they may be considered for the EUDI Wallets and eIDAS2 relying parties. | zk-SNARKs形式のプログラム可能ZKPsに基づくシステム(Cinderella、zk-creds、zk-mdocなど)も存在し、X.509証明書、ISO mDL、ICAOパスポートといった既存のデジタルIDインフラと組み合わせて選択的開示と非連結性を両立させられる。こうしたシステムは、(Q)EAAから選択した属性を共有する疑似証明書を生成し、リンク可能な暗号識別子を露出せずに保有者紐付けと非失効を証明できるほか、任意の述語を実装可能である。したがって、プログラム可能なZKPsに基づく匿名クレデンシャルは、特に展開済みのセキュアハードウェアとの互換性を確保しやすく、拡張性も高い。ただし、これらのプロジェクトは依然として研究段階にあり、高度な複雑性に直面している。一方で、一部の形式(例:[i.113]で使用されるNARKs)は暗号ハッシュ関数のみに依存するため耐量子性が期待でき、確立された効率的なマルチメッセージ署名方式とは対照的に、新たな(例:耐量子)署名方式や新規の(Q)EAAフォーマットに柔軟に適応できる点から、将来性があると考えられる。したがって、EUDIウォレットおよびeIDAS2依存当事者向けに検討可能である。 |
| Furthermore, there are recommendations on how to store such (Q)EAA formats in the EUDI Wallet, and how to present selectively disclosed attributes to eIDAS2 relying parties. These recommendations can be considered for the upcoming ETSI TS 119 462 [i.95] on EUDI Wallet interfaces. | さらに、EUDIウォレットにおける(Q)EAA形式の保存方法、およびeIDAS2依存当事者への選択的属性開示方法に関する推奨事項を提示する。これらの推奨事項は、EUDIウォレットインターフェースに関する今後のETSI TS 119 462 [i.95] 規格策定において考慮されるべきである。 |
| The present document also analyses the privacy aspects of revocation schemes and validity status checks. In order to achieve privacy preserving features for revocation and validity status checks it is recommended to use OCSP in Must-Staple mode, implement Revocation Lists or validity Status Lists with additional privacy techniques such as Private Information Retrieval or Private Set Intersection, and use cryptographic accumulators where possible given the associated complexity. If programmable ZKP schemes (such as zk-(S)NARKs) are combined with existing credentials (such as X.509) and revocation or status lists, the status validity checks are performed at the EUDI Wallet, and only the relevant information (revocation state) without any linkable cryptographic identifiers is disclosed to the verifier. | 本稿では、失効スキームおよび有効性ステータスチェックのプライバシー面についても分析する。失効および有効性ステータスチェックにおけるプライバシー保護機能を実現するため、OCSPをMust-Stapleモードで使用すること、失効リストまたは有効性ステータスリストを個人情報検索(Private Information Retrieval)やプライベート共通集合(Private Set Intersection)などの追加的なプライバシー技術と共に実装すること、関連する複雑性を考慮しつつ可能な限り暗号的アキュムレータを使用することが推奨される。プログラム可能なZKP方式(zk-(S)NARKsなど)を既存の認証情報(X.509など)や失効リスト・有効性リストと組み合わせる場合、妥当性確認はEUDI Wallet側で実行され、検証者には関連情報(失効状態)のみが開示され、リンク可能な暗号識別子は一切含まれない。 |
| The present document also includes an analysis of attacks facilitated by a quantum computer on cryptographic schemes with selective disclosure capabilities. More specifically, the salted attribute hashes-based formats, such as mdoc and SD-JWT, can be signed with quantum-safe cryptographic algorithms. Also the atomic (Q)EAA formats can be secured with post-quantum safe signatures. The multi-message signature schemes, such as BBS+ and CL-signatures, have the following characteristics in a post-quantum world: an attacker can use a quantum computer to forge proofs and signatures (i.e. to violate soundness guarantees), but an attacker will not be able to break data minimisation, meaning that undisclosed attributes are safe in a post-quantum world, as are undisclosed signature values etc. This unconditional data minimisation guarantee is also provided by the programmable ZKPs. However, it depends on the design of the arithmetic circuit proof if soundness holds in the presence of a quantum computer. For example, the hash-based NARKs used in [i.113] are considered post-quantum secure in this regard, while others (like the ones used in [i.65], [i.182], [i.269]) are not as they rely on elliptic curves. There are also research projects on lattice-based anonymous credentials schemes, which are plausibly post-quantum safe. | 本稿では、選択的開示機能を備えた暗号スキームに対する量子コンピュータによる攻撃の分析も含まれる。具体的には、mdocやSD-JWTなどのソルト付き属性ハッシュベース形式は、量子耐性暗号アルゴリズムで署名可能である。また、アトミック(Q)EAA形式は耐量子署名で保護できる。BBS+やCL署名などのマルチメッセージ署名方式は、耐量子環境において以下の特性を有する:攻撃者は量子コンピュータを用いて証明や署名を偽造可能(すなわち健全性保証を侵害可能)だが、データ最小化を破ることはできず、非開示属性や非開示署名値などが耐量子環境でも安全である。この無条件のデータ最小化保証は、プログラム可能な零知識証明(ZKPs)のプロバイダとしても提供される。ただし、量子コンピュータの存在下で妥当性が保たれるかどうかは、算術回路証明の設計に依存する。例えば、[i.113]で使用されるハッシュベースのNARKsはこの点で耐量子安全と見なされる一方、楕円曲線に依存する他の方式([i.65]、[i.182]、[i.269]で使用されるものなど)はそうではない。格子ベースの匿名認証スキームに関する研究プロジェクトもあり、これらは耐量子安全である可能性が高い。 |
| Furthermore, there is an annex (annex F) with business models, which discusses how a QTSP can be able to invoice a Relying Party, even if the EUDI Wallet has shared the (Q)EAA/PID anonymously with the Relying Party. ETSI TR 119 479-2 [i.92] and anonymous usage data aggregation propose solutions to this business model. | さらに、附属書Fにはビジネスモデルが記載されており、EUDIウォレットが(Q)EAA/PIDを匿名で依存者に共有した場合でも、QTSPが依存者に請求書を発行する方法を論じている。ETSI TR 119 479-2 [i.92]と匿名使用データ集約はこのビジネスモデルに対する解決策を提案している。 |
| Finally, there is an annex (annex C) with research projects about innovative ZKP schemes. One such approach is to design cryptographic ZKP schemes based on quantum physics. Quantum Key Distribution (QKD), quantum physics applied to the graph 3-colouring ZKP scheme, and ZKPs using the quantum Internet (based on Schnorr's algorithm) are described in annex C. The ZKP schemes based on quantum physics are still in the research phase, but may be considered for the future. There are also cryptographic research initiatives on post-quantum safe (lattice-based) anonymous credentials, which cater for privacy-preserving signature schemes. The most recent research in this field is related to efficient anonymous credentials that are post-quantum safe, yet with small signature sizes. | 最後に、革新的なZKPスキームに関する研究プロジェクトを記載した附属書(附属書C)がある。その一例として、量子物理学に基づく暗号学的ZKPスキームの設計が挙げられる。量子鍵配送(QKD)、グラフ3色問題ZKPスキームへの量子物理学の応用、量子インターネット(シュノールのアルゴリズムに基づく)を用いたZKPが附属書Cで説明されている。量子物理学に基づくZKPスキームは依然として研究段階にあるが、将来的に検討される可能性がある。また、プライバシー保護署名スキームに対応する耐量子安全(格子ベース)匿名クレデンシャルに関する暗号研究も進行中である。この分野における最新の研究は、耐量子安全でありながら署名サイズが小さい効率的な匿名クレデンシャルに関連している。 |
| While the present document aims to comprehensively explore cryptographic techniques to ensure selective disclosure, unlinkability, and predicate proofs, it does not discuss in depth the data-minimising capabilities of authenticated channels facilitated by secure hardware (this approach is prominently used in the German eID) and the corresponding challenges, such as the tradeoff between unique device identifiers and shared risks. Similarly, while selective disclosure, unlinkability, and predicate proofs can be easily implemented via the use of remote attestation in trusted execution environments on the holder or relying party side (see, e.g. [i.121]), corresponding architectures and their risks are not covered regarding trust in manufacturers and side channel attacks. Furthermore, while data minimization in the cryptographic parts of verifiable presentations is necessary to achieve a high degree of data protection and avoid over-identification, it is not sufficient. Yet, the present document does not cover further linkable data, e.g. on the networking layer (IP addresses) or how to determine which identity attributes a relying party should be allowed to request. | 本稿は選択的開示、非関連付け可能性、述語証明を確保するための暗号技術を包括的に検討することを目的とするが、セキュアハードウェアによって実現される認証済みチャネルのデータ最小化機能(この手法はドイツの電子IDで顕著に使用されている)や、固有デバイス識別子と共有リスクのトレードオフといった関連課題については深く論じない。同様に、選択的開示、非連結性、述語証明は、保有者側または依存当事者側の信頼可能な実行環境におけるリモートアテステーションの利用により容易に実装可能である(例:[i.121]参照)。しかしながら、製造事業者への信頼やサイドチャンネル攻撃に関する対応するアーキテクチャとそのリスクについては扱わない。さらに、検証可能提示の暗号部分におけるデータ最小化は、高度なデータ防御の達成と過剰識別回避に必要ではあるが、それだけでは不十分である。しかしながら、本稿では、ネットワーク層(IPアドレス)上の追加のリンク可能なデータや、信頼当事者が要求を許可されるべき識別属性属性をどのように決定するかといった点については扱っていない。 |
« 米国他 中国国家支援のアクターによる世界的なネットワーク侵害への対策:国際的なスパイ活動システムへの供給源 (2025.08.27) | Main | NPO デジタル・フォレンジック研究会のコラム by 丸山満彦 公正な司法におけるデジタル・フォレンジックスの役割 »

Comments