Universal Designated-Verifier Signatures
نویسندگان
چکیده
Motivated by privacy issues associated with dissemination of signed digital certificates, we definea new type of signature scheme called a ‘Universal Designated-Verifier Signature’ (UDVS). A UDVSscheme can function as a standard publicly-verifiable digital signature but has additional functional-ity which allows any holder of a signature (not necessarily the signer) to designate the signature toany desired designated-verifier (using the verifier’s public key). Given the designated-signature, thedesignated-verifier can verify that the message was signed by the signer, but is unable to convinceanyone else of this fact.We propose an efficient deterministic UDVS scheme constructed using any bilinear group-pair.Our UDVS scheme functions as a standard Boneh-Lynn-Shacham (BLS) signature when no verifier-designation is performed, and is therefore compatible with the key-generation, signing and verifyingalgorithms of the BLS scheme. We prove that our UDVS scheme is secure in the sense of ourunforgeability and privacy notions for UDVS schemes, under the Bilinear Diffie-Hellman (BDH)assumption for the underlying group-pair, in the random-oracle model. We also demonstrate ageneral constructive equivalence between a class of unforgeable and unconditionally-private UDVSschemes having unique signatures (which includes the deterministic UDVS schemes) and a class ofID-Based Encryption (IBE) schemes which contains the Boneh-Franklin IBE scheme but not theCocks IBE scheme.
منابع مشابه
Generic constructions for universal designated-verifier signatures and identitybased signatures from standard signatures
We give a generic construction for universal designated-verifier signature schemes from a large class, C, of signature schemes. The resulting schemes are efficient and have two important properties. Firstly, they are provably DV-unforgeable, non-transferable and also non-delegatable. Secondly, the signer and the designated verifier can independently choose their cryptographic settings. We also ...
متن کاملUniversal designated verifier transitive signatures for graph-based big data
In this paper, we propose a new type of digital signatures which is specifically designed for graph-based big data system. The properties of the proposed signatures are twofold. On one side it possesses the features of transitive signatures: One can sign a graph in such a way that, given two signatures on adjacent edges ði; jÞ and ðj; kÞ, anyone with public information can compute a signature o...
متن کاملConstruction of Universal Designated-Verifier Signatures and Identity-Based Signatures from Standard Signatures
We give a generic construction for universal designated-verifier signature schemes from a large class, C, of signature schemes. The resulting schemes are efficient and have two important properties. Firstly, they are provably DV-unforgeable, non-transferable and also non-delegatable. Secondly, the signer and the designated verifier can independently choose their cryptographic settings. We also ...
متن کاملVerifier-Key-Flexible Universal Designated-Verifier Signatures
Universal Designated-Verifier Signatures (UDVS) are proposed to protect the privacy of a signature holder. Since UDVS schemes reduce to standard signatures when no verifier designation is performed, from the perspective of a signer, it is natural to ask if a UDVS can be constructed from widely used standardized-signatures so that the existing public key infrastructures for these schemes can be ...
متن کاملNew Extensions of Pairing-Based Signatures into Universal (Multi) Designated Verifier Signatures
The concept of universal designated verifier signatures was introduced by Steinfeld, Bull, Wang and Pieprzyk at Asiacrypt 2003. These signatures can be used as standard publicly verifiable digital signatures but have an additional functionality which allows any holder of a signature to designate the signature to any desired verifier. This designated verifier can check that the message was indee...
متن کاملEfficient Extension of Standard Schnorr/RSA Signatures into Universal Designated-Verifier Signatures
Universal Designated-Verifier Signature (UDVS) schemes are digital signature schemes with ad-ditional functionality which allows any holder of a signature to designate the signature to any desireddesignated-verifier such that the designated-verifier can verify that the message was signed by thesigner, but is unable to convince anyone else of this fact.Since UDVS schemes reduce t...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2003 شماره
صفحات -
تاریخ انتشار 2003