On Constructing Optimal One-Time Signatures
نویسندگان
چکیده
One-time signatures (OTS) offer a viable alternative to public keybased digital signatures. OTS security is based only on the strength of the underlying one-way function and does not depend on the conjectured difficulty of a mathematical problem. OTS methods have been proposed in the past but no solid foundation exists for judging their efficiency or optimality. This paper develops a new methodology for evaluating OTS methods and presents optimal OTS techniques for a single OTS or a tree with many OTSs. These techniques can be used in a see-saw mode to obtain desired tradeoff between various parameters such as the cost of signature generation and its subsequent verification and the cost of traditional signature verification and OTS verification.
منابع مشابه
A mathematical model for finding the optimal locations of railway stations
Regarding the importance of competitive advantages among the transportation systems, improving the costumer’s satisfaction is an important factor in attracting them to these systems. In this research, we focus on the effects of constructing new stations on users and a new mathematical model is proposed for this problem. In the proposed model, two simultaneous effects on customers by constructin...
متن کاملOptimal asset control of the diffusion model under consideration of the time value of ruin
In this paper, we consider the optimal asset control of a financial company which can control its liquid reserves by paying dividends and by issuing new equity. We assume that the liquid surplus of the company in the absence of control is modeled by the diffusion model. It is a hot topic to maximize the expected present value of dividends payout minus equity issuance until the time of ba...
متن کاملMore Efficient Structure-Preserving Signatures - Or: Bypassing the Type-III Lower Bounds
Structure-preserving signatures are an important cryptographic primitive that is useful for the design of modular cryptographic protocols. It has been proven that structure-preserving signatures (in the most efficient Type-III bilinear group setting) have a lower bound of 3 group elements in the signature (which must include elements from both source groups) and require at least 2 pairing-produ...
متن کاملLecture 13 Many-time Signatures 1 One-time Signatures
Constructing a scheme that satisfies such a strong security notion is very involved, so we start with an easier goal: unforgeability under a one-time chosen-message attack (uf-1cma). The definition is syntactically identical to the one above, but F is restricted to make (at most) one query to its signing oracle. Here we describe Lamport’s one-time signature scheme OTS for messages of length ` =...
متن کاملRound Optimal Blind Signatures
Constructing round-optimal blind signatures in the standard model has been a long standing open problem. In particular, Fischlin and Schröder recently ruled out a large class of three-move blind signatures in the standard model (Eurocrypt’10). In particular, their result shows that finding security proofs for the well-known blind signature schemes by Chaum, and by Pointcheval and Stern in the s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2003