Convertible Undeniable Standard RSA Signatures

A convertible undeniable signature is issued as an undeniable signature which can provide good privacy service in its early lifecycle. Later when necessary, it can be converted into an ordinary signature by a designated party and thereafter assures good accountability just as an ordinary digital signature does. We propose an RSA-based convertible undeniable signature where, in the stage of undeniable signature veri cation, operations are carried out modulo the square of a standard RSA modulus and thereafter becomes a standard RSA-based undeniable (convertible) signature. This solves the open problem of designing e cient RSA-based undeniable signatures for standard RSA moduli and achieves an e ciency for such schemes suitable for practical applications.