A practical optimal padding for signature schemes

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

A digital signature scheme that achieves an optimal bandwidth (generating signatures as short as possible) is called an optimal signature scheme. The previous optimal signature schemes all need the random permutations (or the ideal ciphers) with large block size as building blocks. However, the practical cipher with large block size such as Halevi and Rogaway’s CMC-mode should call the underlying secure block cipher with small block size many times each time. This makes the previous optimal signature schemes which use the large domain permutation (or the ideal cipher) less efficient in the real world, even if there exist the methods that can encipher the messages with larger domain. On the other hand, all the practical signature schemes are not optimal in bandwidth including PSS-R, FDH, DSA, etc. Hence, the problem on how to design a practical, efficient and optimal signature scheme remains open. This paper uses two random oracles and an ideal cipher with a smaller block size to design an optimal padding for signature schemes. The ideal cipher in our scheme can be implemented with a truly real block cipher (e.g. AES). Therefore, we provide a perfect solution to the open problem. More precisely, we design a practical, efficient and optimal signature scheme. Particularly, in the case of RSA, the padding leads the signature scheme to achieve not only optimality in bandwidth but also a tight security.

Original languageEnglish
Title of host publicationTopics in Cryptology
Subtitle of host publicationCT-RSA 2007 - The Cryptographers Track at the RSA Conference 2007, Proceedings
EditorsMasayuki Abe
PublisherSpringer Verlag
Pages112-128
Number of pages17
ISBN (Print)9783540693277
DOIs
StatePublished - 2007
EventCryptographers Track at the RSA Conference, CT-RSA 2007 - San Francisco, United States
Duration: 5 Feb 20079 Feb 2007

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4377 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceCryptographers Track at the RSA Conference, CT-RSA 2007
Country/TerritoryUnited States
CitySan Francisco
Period5/02/079/02/07

Keywords

  • Ideal cipher model
  • Optimal signature
  • Random oracle model
  • Short signature
  • Tight security

Fingerprint

Dive into the research topics of 'A practical optimal padding for signature schemes'. Together they form a unique fingerprint.

Cite this