DocumentCode
783509
Title
Two-tier signatures from the Fiat-Shamir transform, with applications to strongly unforgeable and one-time signatures
Author
Bellare, M. ; Shoup, S.
Author_Institution
Dept. of Comput. Sci. & Eng., Univ. of California at San Diego, La Jolla, CA
Volume
2
Issue
2
fYear
2008
fDate
6/1/2008 12:00:00 AM
Firstpage
47
Lastpage
63
Abstract
The authors show how the Fiat-Shamir transform can be used to convert three-move identification protocols into two-tier signature schemes (a primitive that they define) with a proof of security that makes a standard assumption on the hash function rather than modelling it as a random oracle. The result requires security of the starting protocol against concurrent attacks. It is also shown that numerous protocols have the required properties, and thus numerous efficient two-tier schemes are obtained. The first application is an efficient transform of any unforgeable signature scheme into a strongly unforgeable one. (This extends the work of Boneh, Shen and Waters whose transform only applies to a limited class of schemes.) The second application is the new one-time signature schemes that, compared with the one-way function-based ones of the same computational cost, have smaller key and signature sizes.
Keywords
cryptographic protocols; digital signatures; Fiat-Shamir transform; concurrent attacks; identification protocols; one-time signatures; two-tier signatures; unforgeable signature scheme;
fLanguage
English
Journal_Title
Information Security, IET
Publisher
iet
ISSN
1751-8709
Type
jour
DOI
10.1049/iet-ifs:20070089
Filename
4558842
Link To Document