The authenticated encryption scheme allows the specified receiver to simultaneously recover and verify a message. Recently, to protect the receiver’s benefit of a later dispute, Wu and Hsu proposed a convertible authenticated encryption scheme in which the receiver can convert the signature into an ordinary one that can be verified by anyone. However, Wu and Hsu’s scheme doesn’t consider that once the intruder knows the message then the intruder can also easily convert a signature into an ordinary digital signature. In this situation, the intruder may force the signer to be responsible for the terms of agreement of the documents and cause confusion. In this paper, we propose an efficient convertible authenticated encryption scheme which can provide better protection for both the signer and the specified receiver. On the other hand, we also propose an efficient and lower communication convertible authenticated encryption scheme with message linkages. It can be regarded as a variant of the convertible authenticated encryption scheme in that it is designed to link up the message blocks to avoid the message block being reordered, replicated, or partially deleted during the transmission.
[1]
Alfredo De Santis,et al.
Advances in Cryptology — EUROCRYPT'94
,
1994,
Lecture Notes in Computer Science.
[2]
Yuliang Zheng,et al.
Signcryption and Its Applications in Efficient Public Key Solutions
,
1997,
ISW.
[3]
T. Elgamal.
A public key cryptosystem and a signature scheme based on discrete logarithms
,
1984,
CRYPTO 1984.
[4]
Michael Wiener,et al.
Advances in Cryptology — CRYPTO’ 99
,
1999
.
[5]
Claus-Peter Schnorr,et al.
Efficient Identification and Signatures for Smart Cards (Abstract)
,
1990,
EUROCRYPT.
[6]
H. Petersen,et al.
Cryptanalysis and improvement of signcryption schemes
,
1998
.
[7]
Chien-Lung Hsu,et al.
Convertible authenticated encryption scheme
,
2002,
J. Syst. Softw..
[8]
S. Araki,et al.
The Limited Verifier Signature and Its Application
,
1999
.
[9]
Patrick Horster,et al.
Authenticated encryption schemes with low communication costs
,
1994
.
[10]
Rainer A. Rueppel,et al.
Message Recovery for Signature Schemes Based on the Discrete Logarithm Problem
,
1994,
EUROCRYPT.