TY - GEN
T1 - One-Move Convertible Nominative Signature in the Standard Model
AU - Liu, Dennis Y.W.
AU - Wong, Duncan S.
PY - 2012/9
Y1 - 2012/9
N2 - A Nominative Signature (NS) is a non-self-authenticating signature which is jointly generated by a signer (or a nominator) and a user (or a nominee), but once generated, its validity can only be determined by the user. No one else including the signer can tell the signature's validity unless the user confirms or disavows so, while the user cannot cheat either. One-move NS is an efficient type of NS that requires the signer to send only one message to the user during the signature generation stage. Currently, there exists only one one-move NS scheme which is proven secure in the standard model, and is convertible, that is, the user can transform a nominative signature to a publicly verifiable one without the help of the signer. However, the number of elements in the keys of both signer and user grows linearly with the value of the security parameter. In this paper, we propose a new one-move NS which is convertible, can be proven secure in the standard model, and also has a constant number of elements in the keys of both signer and user. We apply the Boneh-Boyen short standard signature in a novel way to build this nominative signature scheme. We show that this new scheme achieves the best performance among all the schemes proven secure in the standard model, and its security relies only on the standard q-SDH and DDH assumptions.
AB - A Nominative Signature (NS) is a non-self-authenticating signature which is jointly generated by a signer (or a nominator) and a user (or a nominee), but once generated, its validity can only be determined by the user. No one else including the signer can tell the signature's validity unless the user confirms or disavows so, while the user cannot cheat either. One-move NS is an efficient type of NS that requires the signer to send only one message to the user during the signature generation stage. Currently, there exists only one one-move NS scheme which is proven secure in the standard model, and is convertible, that is, the user can transform a nominative signature to a publicly verifiable one without the help of the signer. However, the number of elements in the keys of both signer and user grows linearly with the value of the security parameter. In this paper, we propose a new one-move NS which is convertible, can be proven secure in the standard model, and also has a constant number of elements in the keys of both signer and user. We apply the Boneh-Boyen short standard signature in a novel way to build this nominative signature scheme. We show that this new scheme achieves the best performance among all the schemes proven secure in the standard model, and its security relies only on the standard q-SDH and DDH assumptions.
KW - nominative signature
KW - non-self-authenticating signature
KW - undeniable signature
UR - https://www.scopus.com/pages/publications/84866049975
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-84866049975&origin=recordpage
U2 - 10.1007/978-3-642-33272-2_2
DO - 10.1007/978-3-642-33272-2_2
M3 - RGC 32 - Refereed conference paper (with host publication)
SN - 9783642332715
T3 - Lecture Notes in Computer Science
SP - 2
EP - 20
BT - Provable Security
A2 - Takagi, Tsuyoshi
A2 - Wang, Guilin
A2 - Qin, Zhiguang
A2 - Jiang, Shaoquan
A2 - Yu, Yong
PB - Springer Verlag
T2 - 6th International Conference on Provable Security (ProvSec 2012)
Y2 - 26 September 2012 through 28 September 2012
ER -