New Constructions of Convertible Undeniable Signature Schemes without Random Oracles
نویسندگان
چکیده
In Undeniable Signature, a signature’s validity can only be confirmed or disavowed with thehelp of an alleged signer via a confirmation or disavowal protocol. A Convertible undeniablesignature further allows the signer to release some additional information which can make anundeniable signature become publicly verifiable. In this work we introduce a new kind of attacks,called claimability attacks, in which a dishonest/malicious signer both disavows a signature via thedisavowal protocol and confirms it via selective conversion. Conventional security requirement doesnot capture the claimability attacks. We show that some convertible undeniable signature schemesare vulnerable to this kind of attacks.We then propose a new efficient construction of fully functional convertible undeniable signature,which supports both selective conversion and universal conversion, and is immune to the claimabilityattacks. To the best of our knowledge, it is the most efficient convertible undeniable signaturescheme with provable security in the standard model. A signature is comprised of three elements ofa bilinear group. Both the selective converter of a signature and the universal converter consist ofone group element only. Besides, the confirmation and disavowal protocols are also very simple andefficient. Furthermore, the scheme can be extended to support additional features which includethe delegation of conversion and confirmation/disavowal, threshold conversion and etc.We also propose an alternative generic construction of convertible undeniable signature schemes.Unlike the conventional sign-then-encrypt paradigm, the signer encrypts its (standard) signaturewith an identity-based encryption instead of a public key encryption. It enjoys the advantage ofshort selective converter, which is simply an identity-based user private key, and security againstclaimability attacks.
منابع مشابه
New Approach for Selectively Convertible Undeniable Signature Schemes
In this paper, we propose a new approach for constructing selectively convertible undeniable signature schemes, and present two efficient schemes based on RSA. Our approach allows a more direct selective conversion than the previous schemes, and the security can be proved formally. Further, our disavowal protocols do not require parallelization techniques to reach a significant soundness probab...
متن کامل(Convertible) Undeniable Signatures Without Random Oracles
We propose a convertible undeniable signature scheme without random oracles. Our construction is based on Waters’ and Kurosawa and Heng’s schemes that were proposed in Eurocrypt 2005. The security of our scheme is based on the CDH and the decision linear assumption. Comparing only the part of undeniable signatures, our scheme uses more standard assumptions than the existing undeniable signature...
متن کاملConvertible limited (multi-) verifier signature: new constructions and applications
A convertible limited (multi-) verifier signature (CL(M)VS) provides controlled verifiability and preserves the privacy of the signer. Furthermore, limited verifier(s) can designate the signature to a third party or convert it into a publicly verifiable signature upon necessity. In this proposal, we first present a generic construction of convertible limited verifier signature (CLVS) into which...
متن کاملRelation between Verifiable Random Functions and Convertible Undeniable Signatures, and New Constructions
Verifiable random functions (VRF) and selectively-convertible undeniable signature (SCUS) schemes were proposed independently in the literature. In this paper, we observe that they are tightly related. This directly yields several deterministic SCUS schemes based on existing VRF constructions. In addition, we create a new probabilistic SCUS scheme, which is very compact. The confirmation and di...
متن کاملToward a Generic Construction of Convertible Undeniable Signatures from Pairing-Based Signatures
Undeniable signatures were proposed to limit the verification property of ordinary digital signatures. In fact, the verification of such signatures cannot be attained without the help of the signer, via the confirmation/denial protocols. Later, the concept was refined to give the possibility of converting a selected signature into an ordinary one, or publishing a universal receipt that turns al...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2009 شماره
صفحات -
تاریخ انتشار 2009