Twin signatures: an alternative to the hash-and-sign paradigm

Twin signatures: an alternative to the hash-and-sign paradigm
复制标题

DOI:
10.1145/501983.501987
复制
发表时间:
2001-11
期刊:
--
影响因子:
--
通讯作者:
D. Naccache;D. Pointcheval;J. Stern
D. Naccache;D. Pointcheval;J. Stern
中科院分区:
其他
文献类型:
--
作者:
D. Naccache;D. Pointcheval;J. Stern

文献摘要

被引文献

相似文献

本文从安全角度介绍了哈希签名范式的一种简单替代方案,但用于签名短消息,称为孪生。孪生签名是通过签名方案对一条短消息进行两次签名而获得的。在不同设置下对概念的分析得出以下结果: 我们证明没有通用算法可以有效地伪造孪生 DSA 签名。尽管通用算法提供的安全形式比标准模型中的计算减少更不严格,但这种成功的证明仍然产生了有利于新范式正确性的积极证据。我们在标准模型中证明了 Gennaro、Halevi 和 Rabin 提出的签名方案的孪生版本的存在伪造(即使在自适应选择消息攻击下)与灵活 RSA 问题的生成存在伪造的难度之间的等价性。因此,我们认为孪生是哈希函数的一个有趣的替代方案,用于消除签名中的存在伪造计划。
This paper introduces a simple alternative to the hash-and-sign paradigm, from the security point of view but for signing short messages, called twinning. A twin signature is obtained by signing twice a short message by a signature scheme. Analysis of the concept in different settings yields the following results: We prove that no generic algorithm can efficiently forge a twin DSA signature. Although generic algorithms offer a less stringent form of security than computational reductions in the standard model, such successful proofs still produce positive evidence in favor of the correctness of the new paradigm.We prove in standard model an equivalence between the hardness of producing existential forgeries (even under adaptively chosen message attacks) of a twin version of a signature scheme proposed by Gennaro, Halevi and Rabin and the Flexible RSA Problem.We consequently regard twinning as an interesting alternative to hash functions for eradicating existential forgery in signature schemes.