An Efficient Convertible Undeniable Signature Scheme with Delegatable Verification

An Efficient Convertible Undeniable Signature Scheme with Delegatable Verification
复制标题

DOI:
10.1007/978-3-642-12827-1_21
复制
发表时间:
2010-05
期刊:
--
影响因子:
--
通讯作者:
Jacob C. N. Schuldt;Kanta Matsuura
Jacob C. N. Schuldt;Kanta Matsuura
中科院分区:
其他
文献类型:
--
作者:
Jacob C. N. Schuldt;Kanta Matsuura

文献摘要

被引文献

相似文献

不可否认签名是由Chaum和货车安特卫彭提出的,它要求验证者与签名者进行交互来验证签名,从而允许签名者控制其签名的可验证性。由Boyar、Chaum、Damgård和Pedersen提出的可转换不可否认签名进一步允许签名者通过公开验证令牌将签名转换为可公开验证的签名,无论是针对单个签名还是针对所有签名。此外,签名者能够通过提供验证密钥将证明有效性和转换签名的能力委托给半信任的第三方。虽然后者的功能是由早期的可转换不可否认签名方案实现的,但最近的方案并不考虑这一点,尽管它的实际appeal.In本文中,我们提出了一个更新的定义和安全模型的计划允许delegation,并强调了一个新的基本安全属性,令牌健全性,这是没有正式对待在以前的安全模型的可转换不可否认签名。在此基础上,我们提出了一个新的可转换不可否认签名方案。该方案允许委托验证,并可证明安全的标准模型假设计算co-Diffie-Hellman问题,一个密切相关的问题,和决策线性问题是困难的。据我们所知,我们的方案是目前最有效的可转换不可否认签名方案,可证明满足标准模型中的所有安全要求。
Undeniable signatures, introduced by Chaum and van Antwerpen, require a verifier to interact with the signer to verify a signature, and hence allow the signer to control the verifiability of his signatures. Convertible undeniable signatures, introduced by Boyar, Chaum, Damgård, and Pedersen, furthermore allow the signer to convert signatures to publicly verifiable ones by publicizing a verification token, either for individual signatures or for all signatures universally. In addition, the signer is able to delegate the ability to prove validity and convert signatures to a semi-trusted third party by providing a verification key. While the latter functionality is implemented by the early convertible undeniable signature schemes, most recent schemes do not consider this despite its practical appeal.In this paper we present an updated definition and security model for schemes allowing delegation, and highlight a new essential security property, token soundness, which is not formally treated in the previous security models for convertible undeniable signatures. We then propose a new convertible undeniable signature scheme. The scheme allows delegation of verification and is provably secure in the standard model assuming the computational co-Diffie-Hellman problem, a closely related problem, and the decisional linear problem are hard. Our scheme is, to the best of our knowledge, the currently most efficient convertible undeniable signature scheme which provably fulfills all security requirements in the standard model.