TY - JOUR
T1 - Short and efficient convertible undeniable signature schemes without random oracles
AU - Huang, Qiong
AU - Wong, Duncan S.
PY - 2013/3/11
Y1 - 2013/3/11
N2 - A convertible undeniable signature allows a signer to confirm or disavow a non-self-authenticating signature and also convert a valid one to a publicly verifiable signature. During the conversion, existing schemes either require the signer to be stateful, or have their security based on the random oracle assumption, or result in getting a large converter. In this work we propose a new construction, which supports both selective conversion and universal conversion, and is provably secure without random oracles. It has the shortest undeniable signature and the smallest converter. A signature consists of three bilinear group elements and just one group element each in a selective converter and a universal converter. The scheme can be extended further to support new features, such as the delegation of conversion and confirmation/disavowal, threshold conversion and others. We also propose an alternative generic construction of stateless convertible undeniable signature. Unlike the conventional 'sign-then-encrypt' paradigm, a signer in this new generic scheme encrypts a signature using identity-based encryption instead of public key encryption. It also enjoys the advantage of a short selective converter.
AB - A convertible undeniable signature allows a signer to confirm or disavow a non-self-authenticating signature and also convert a valid one to a publicly verifiable signature. During the conversion, existing schemes either require the signer to be stateful, or have their security based on the random oracle assumption, or result in getting a large converter. In this work we propose a new construction, which supports both selective conversion and universal conversion, and is provably secure without random oracles. It has the shortest undeniable signature and the smallest converter. A signature consists of three bilinear group elements and just one group element each in a selective converter and a universal converter. The scheme can be extended further to support new features, such as the delegation of conversion and confirmation/disavowal, threshold conversion and others. We also propose an alternative generic construction of stateless convertible undeniable signature. Unlike the conventional 'sign-then-encrypt' paradigm, a signer in this new generic scheme encrypts a signature using identity-based encryption instead of public key encryption. It also enjoys the advantage of a short selective converter.
KW - Convertible undeniable signature
KW - Identity-based encryption
KW - Signature scheme
KW - Standard model
KW - Strong Diffie-Hellman assumption
UR - http://www.scopus.com/inward/record.url?scp=84874741957&partnerID=8YFLogxK
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-84874741957&origin=recordpage
U2 - 10.1016/j.tcs.2013.01.010
DO - 10.1016/j.tcs.2013.01.010
M3 - RGC 21 - Publication in refereed journal
SN - 0304-3975
VL - 476
SP - 67
EP - 83
JO - Theoretical Computer Science
JF - Theoretical Computer Science
ER -