Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

Confirmer Signature Schemes Secure against Adaptive Adversaries
(Extended Abstract)

Jan CamenischContact Information and Markus MichelsContact Information

(5)  IBM Research, Zürich Research Laboratory, CH-8803 Rüschlikon
(6)  Entrust Technologies (Switzerland), Glatt Tower, CH-8301 Glattzentrum
Abstract
The main difference between confirmer signatures and ordinary digital signatures is that a confirmer signature can be verified only with the assistance of a semitrusted third party, the confirmer. Additionally, the confirmer can selectively convert single confirmer signatures into ordinary signatures.
This paper points out that previous models for confirmer signature schemes are too restricted to address the case where several signers share the same confirmer. More seriously, we show that various proposed schemes (some of which are provably secure in these restricted models) are vulnerable to an adaptive signature-transformation attack. We define a new stronger model that covers this kind of attack and provide a generic solution based on any secure ordinary signature scheme and public key encryption scheme. We also exhibit a concrete instance thereof.

Contact Information Jan Camenisch
Email: jca@zurich.ibm.com

Contact Information Markus Michels
Email: Markus.Michels@entrust.com
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this chapter
Export this chapter as RIS | Text
 
Remote Address: 38.107.191.106 • Server: mpweb24
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)