• DocumentCode
    783509
  • Title

    Two-tier signatures from the Fiat-Shamir transform, with applications to strongly unforgeable and one-time signatures

  • Author

    Bellare, M. ; Shoup, S.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Univ. of California at San Diego, La Jolla, CA
  • Volume
    2
  • Issue
    2
  • fYear
    2008
  • fDate
    6/1/2008 12:00:00 AM
  • Firstpage
    47
  • Lastpage
    63
  • Abstract
    The authors show how the Fiat-Shamir transform can be used to convert three-move identification protocols into two-tier signature schemes (a primitive that they define) with a proof of security that makes a standard assumption on the hash function rather than modelling it as a random oracle. The result requires security of the starting protocol against concurrent attacks. It is also shown that numerous protocols have the required properties, and thus numerous efficient two-tier schemes are obtained. The first application is an efficient transform of any unforgeable signature scheme into a strongly unforgeable one. (This extends the work of Boneh, Shen and Waters whose transform only applies to a limited class of schemes.) The second application is the new one-time signature schemes that, compared with the one-way function-based ones of the same computational cost, have smaller key and signature sizes.
  • Keywords
    cryptographic protocols; digital signatures; Fiat-Shamir transform; concurrent attacks; identification protocols; one-time signatures; two-tier signatures; unforgeable signature scheme;
  • fLanguage
    English
  • Journal_Title
    Information Security, IET
  • Publisher
    iet
  • ISSN
    1751-8709
  • Type

    jour

  • DOI
    10.1049/iet-ifs:20070089
  • Filename
    4558842