Abstract:
Abstract. Secure and authenticated message delivery/storage is one of the major aims of computer and conmmnication security research. The current standard method to hieve this aim is "(digital) signature followed by encryption". In this paper, we address a question on the cost of secure and authenticated message delivery/storage, nasnely, whether it is possible to transport/store messages of varying length in a secure and authenticated way with an expense less than that required by "signa-ture followed by encryption". This question seems to haw never been addressed in the literature since the invention of public key cryptography. We then present a positive answer to the question. In particular, we discover a new cryptographic primitive termed as "signcryption " which simultaneously fulfills both the functions of digital signature aatd public key encryption in a logically single step. and with a cost significantly lower than that required by "signature followed by cncryption". For typical security parameters for high level security applications (size of public moduli = 1536 bits), signcryption costs 50 % (31%, respectively) less in computation time and 85 % (91%, respectively) less in message expan-sion than does "signature followed by encryption " based on the discrete logarithm problem (factorization problem, respectively).
Citations
|
1752
|
New directions in cryptography
– Diffie, Hellman
- 1976
|
|
897
|
Random oracles are practical: A paradigm for designing efficient protocols
– Bellare, Rogaway
- 1993
|
|
788
|
A public key cryptosystem and a signature scheme based on discrete logarithms
– Elgamal
- 1985
|
|
610
|
A digital signature scheme secure against adaptive chosen-message attacks
– Goldwasser, Micali, et al.
- 1988
|
|
386
|
Elliptic curve cryptosystems
– Koblitz
- 1987
|
|
356
|
Undeniable signatures
– Chaum, Antwerpen
|
|
315
|
Keying hash functions for message authentication
– Bellare, Canetti, et al.
- 1996
|
|
210
|
Efficient identification and signatures for smart cards
– Schnorr
|
|
202
|
Authentication and authenticated key exchanges
– Diffie, Oorschot, et al.
- 1992
|
|
172
|
Security proofs for signature schemes
– Pointcheval, Stern
|
|
150
|
Privacy enhancement for Internet electronic mail: Part I | message encipherment and authentication procedures," Network Working Group Request for Comments RFC 1113
– Linn
- 1989
|
|
76
|
Message recovery for signature schemes based on the discrete logarithm problem
– Nyberg, Rueppel
|
|
63
|
Low-exponent RSA with related messages
– Coppersmith, Franklin, et al.
- 1996
|
|
34
|
M.: Meta-ElGamal signature schemes
– Horster, Petersen, et al.
- 1994
|
|
32
|
Round-optimal zero-knowledge arguments based on any one-way function
– Bellare, Jakobsson, et al.
- 1997
|
|
31
|
On the Key Predistribution System: A Practical Solution to the Key Distribution
– Matsumoto, Imai
- 1987
|
|
27
|
The future of integer factorization
– Odlyzko
- 1995
|
|
23
|
Immunizing public key cryptosystems against chosen ciphertext attacks
– Zheng, Seberry
- 1993
|
|
15
|
Asymmetric encryption: evolution and enhancements
– Johnson, Matyas
- 1996
|
|
11
|
The SPEED Cipher
– Zheng
- 1997
|
|
7
|
Interactive identification and digital signatures
– Brickell, McCurley
- 1991
|
|
5
|
Improved public key cryptosystems secure against chosen ciphertext attacks
– Zheng
- 1994
|
|
1
|
R.: Secure transport protocols for high-speed networks
– Basturk, Bellare, et al.
- 1994
|
|
1
|
W.: Algorithms in Number Theory vol. A of Handbook
– Lenstra, Lenstra
- 1990
|
|
1
|
R.: Secure traltsport protocols for high-speed networks
– Basturk, Bellare, et al.
- 1994
|
|
1
|
Random oracles axe practical: A paradigm for designing efficient protocols
– Bellare, Rogaway
- 1993
|
|
1
|
M.: Low-exponent llSA with related messages
– Coppersmith, Franklin, et al.
- 1996
|
|
1
|
M.: Authentication and authenticated key exchaage. Designs, Codes mid Cryptography 2
– Diffie, Oorschot, et al.
- 1992
|
|
1
|
A public key cryptosystem and a signature scheme based on discrete logarithms
– ElGinhal
- 1985
|
|
1
|
W.: Algorithms in Nmnber Theory vol. A of Handbook
– Lenstra, Lenstra
- 1990
|
|
1
|
Efficient identification and signatures for smart caxds
– Schnorr
- 1990
|