A variant of Schnorr signature scheme with tight security reduction

In 1990, Schnorr proposed a signature scheme that is suitable for smart card interactions. The original Schnorr signature was based on the Discrete Logarithm assumption with a loose security reduction. In 2003, Katz-Wang then proposed a variant of Schnorr's signature scheme based on the Decisional Diffie-Hellman assumption with a tight security reduction. In this paper, we further improve Katz-Wang's work by reducing the number of public keys used, while maintaining the tight security properties of the scheme based on Decisional Square Computational Diffie-Hellman assumption.

[1]  Yannick Seurin,et al.  On the Exact Security of Schnorr-Type Signatures in the Random Oracle Model , 2012, IACR Cryptol. ePrint Arch..

[2]  Robert H. Deng,et al.  Variations of Diffie-Hellman Problem , 2003, ICICS.

[3]  Jean-Sébastien Coron,et al.  A variant of Boneh-Franklin IBE with a tight reduction in the random oracle model , 2009, Des. Codes Cryptogr..

[4]  Eike Kiltz,et al.  Optimal Security Proofs for Signatures from Identification Schemes , 2016, CRYPTO.

[5]  Raghav Bhaskar,et al.  Improved Bounds on Security Reductions for Discrete Log Based Signatures , 2008, CRYPTO.

[6]  Hovav Shacham,et al.  Short Signatures from the Weil Pairing , 2001, J. Cryptol..

[7]  Jacob C. N. Schuldt,et al.  On the Security of the Schnorr Signature Scheme and DSA Against Related-Key Attacks , 2015, ICISC.

[8]  Alfred Menezes,et al.  The random oracle model: a twenty-year retrospective , 2015, Designs, Codes and Cryptography.

[9]  Jonathan Katz,et al.  Efficiency improvements for signature schemes with tight security reductions , 2003, CCS '03.

[10]  Jean-Sébastien Coron,et al.  Optimal Security Proofs for PSS and Other Signature Schemes , 2002, EUROCRYPT.

[11]  Raphael C.-W. Phan,et al.  A Variant of Schnorr Identity-Based Identification Scheme with Tight Reduction , 2011, FGIT.

[12]  Claus-Peter Schnorr E cient Identi cation and Signatures for Smart-Cards , 1990, CRYPTO 1990.

[13]  Matthew K. Franklin,et al.  Identity-Based Encryption from the Weil Pairing , 2001, CRYPTO.

[14]  Stanislaw Jarecki,et al.  A Signature Scheme as Secure as the Diffie-Hellman Problem , 2003, EUROCRYPT.

[15]  Taher ElGamal,et al.  A public key cyryptosystem and signature scheme based on discrete logarithms , 1985 .