Perfect Concurrent Signature Schemes

Perfect Concurrent Signature Schemes
复制标题

DOI:
10.1007/978-3-540-30191-2_2
复制
发表时间:
2004-10
期刊:
--
影响因子:
--
通讯作者:
W. Susilo;Y. Mu;Fangguo Zhang
W. Susilo;Y. Mu;Fangguo Zhang
中科院分区:
其他
文献类型:
--
作者:
W. Susilo;Y. Mu;Fangguo Zhang

文献摘要

被引文献

相似文献

Chen、Kudla 和 Paterson 最近在 [5] 的开创性论文中引入了并发签名的概念。在并发签名方案中,两个实体可以产生两个不具有约束力的签名,直到其中一方发布一条额外的信息(即 keystone)。密钥发布后,两个签名同时对其真正的签名者具有约束力。在本文中,我们通过引入一个新的、更强大的概念(称为完美并发签名)来扩展这个概念。我们要求,尽管已知两个签名者都是值得信赖的,但这两个签名对于任何第三方来说仍然是不明确的(参见[5])。我们提供了两种安全方案来实现基于 Schnorr 签名方案和双线性配对的新概念。这两种结构本质上是相同的。然而,正如我们将在本文中展示的,基于双线性配对的方案比基于 Schnorr 签名方案的方案更有效。
The notion of concurrent signatures was recently introduced by Chen, Kudla and Paterson in their seminal paper in [5]. In concurrent signature schemes, two entities can produce two signatures that arenotbinding, until an extra piece of information (namely thekeystone) is released by one of the parties. Upon release of the keystone, both signatures become binding to their true signers concurrently. In this paper, we extend this notion by introducing a new and stronger notion calledperfectconcurrent signatures. We require that although both signers are known to be trustworthy, the two signatures are still ambiguous to any third party (c.f. [5]). We provide two secure schemes to realize the new notion based on Schnorr’s signature schemes and bilinear pairing. These two constructions are essentially the same. However, as we shall show in this paper, the scheme based on bilinear pairing is more efficient than the one that is based on Schnorr’s signature scheme.