机构地区: 西安电子科技大学通信工程学院信息保密研究所
出 处: 《西安电子科技大学学报》 1999年第1期22-24,35,共4页
摘 要: Damgàrd等人提出了一种新的可转换不可否认签名方案,该方案是将ElGa-mal方案的加密形式和签名形式结合在一起,即对签名的结果S进行加密,它有一个缺陷:会话密钥r必须为q阶.该文提出了一个改进方案,实质是用ElGamal加密方案对ElGamal签名的消息m进行加密,从而去掉了这个约束条件.改进方案的签名证实/否认协议是完善/计算零知识的.伪造签名的困难性等价于伪造ElGamal签名,改进方案的签名很容易转换成自验证签名和指定证实者签名. A new convertible undeniable signature scheme which combines ElGamal signature scheme with its encryption form of s was presented by Damgàrd et al., but there is a drawback that the conversation key r has to be of order q. In this paper a new modified scheme of encryption of message m is presented, and its verify/deny protocols are perfectly/computationally zero knowledge. Forging signatures is provably equivalent to forging ElGamal signature. Its signatures can be easily converted into Self authentication Signatures or Confirmed Verifier Signatures.