Efficient Convertible Undeniable Signatures with Delegatable Verification

Efficient Convertible Undeniable Signatures with Delegatable Verification
复制标题

DOI:
10.1587/transfun.e94.a.71
复制
发表时间:
2011
期刊:
IEICE Trans. Fundam. Electron. Commun. Comput. Sci.
影响因子:
--
通讯作者:
Jacob C. N. Schuldt;Kanta Matsuura
Jacob C. N. Schuldt;Kanta Matsuura
中科院分区:
其他
文献类型:
--
作者:
Jacob C. N. Schuldt;Kanta Matsuura

文献摘要

被引文献

相似文献

不可否认签名是由Chaum和货车安特卫彭提出的,它要求验证者与签名者进行交互来验证签名,从而允许签名者控制其签名的可验证性。由Boyar、Chaum、Damgard和Pedersen提出的可转换不可否认签名允许签名者通过公开验证令牌将签名转换为可公开验证的签名,无论是针对单个签名还是针对所有签名。此外,原始定义允许签名者通过提供验证密钥将证明有效性和转换签名的能力委托给半信任的第三方。虽然早期的可转换不可否认签名方案实现了这一功能,但大多数最近的方案并不考虑这种形式的授权,尽管它具有实际的吸引力。在本文中,我们提出了一个更新的定义和安全模型的计划,允许委托,并进一步强调了一个新的基本安全属性,令牌健全性,这是没有正式处理在以前的安全模型的可转换不可否认的签名。在此基础上,我们提出了一个新的可转换不可否认签名方案。该方案允许委托验证,并可证明安全的标准模型假设计算co-Diffie-Hellman问题,一个密切相关的问题,和决策线性问题是困难的。此外,与Phong等人和Huang等人最近提出的方案不同,我们的方案可证明满足所有的安全要求,同时提供短签名。
Undeniable signatures, introduced by Chaum and van Antwerpen, require a verifier to interact with the signer to verify a signature, and hence allow the signer to control the verifiability of his signatures. Convertible undeniable signatures, introduced by Boyar, Chaum, Damgard, and Pedersen, furthermore allow the signer to convert signatures to publicly verifiable ones by publicizing a verification token, either for individual signatures or for all signatures universally. In addition, the original definition allows the signer to delegate the ability to prove validity and convert signatures to a semi-trusted third party by providing a verification key. While this functionality is implemented by the early convertible undeniable signature schemes, most recent schemes do not consider this form of delegation despite its practical appeal. In this paper we present an updated definition and security model for schemes allowing delegation, and furthermore highlight a new essential security property, token soundness, which is not formally treated in the previous security models for convertible undeniable signatures. We then propose a new convertible undeniable signature scheme. The scheme allows delegation of verification and is provably secure in the standard model assuming the computational co-Diffie-Hellman problem, a closely related problem, and the decisional linear problem are hard. Furthermore, unlike the recently proposed schemes by Phong et al. and Huang et al., our scheme provably fulfills all security requirements while providing short signatures.