摘要
基于不可否认签名和可证实签名的思想 ,提出了一种拥有DSA数字签名的零知识证明新方案 .该方案给出了防止DSA数字签名任意传播的一种新方法———签名者不直接提供对信息M的签名 ,而是提供拥有该信息的数字签名的一个零知识证明 .该方案是不可否认签名功能的扩充———零知识证明签名的有效性 ,也是可证实数字签名的改进 ,比可证实数字签名方案简单且不需要第三方的参与 .在哈希函数在随机神谕的模型下是安全的和计算离散对数是困难的假设下 ,系统是安全的 .
Based on the ideas of undeniable digital signature and confirmer digital signature,a new zero-knowledge proof scheme of possessing a DSA digital signature is proposed which can be used to prevent the arbitrary distribution of digital signature.In the scheme the prover has not to give directly the DSA signature of a message,but to give a zero-knowledge proof of possessing a DSA digital signature of the message.The scheme not only expands the function of undeniable digital signature by verifying a signature without exposing any knowledge,but also improves confirmer digital signature due to its much more simplicity than the latter in practice and the significant feature is that it does not need the participation of the third party.The scheme is proven to be secure under the assumption that Hash function is secure under the random oracle model and the intractability of discrete logarithm problems.
出处
《电子学报》
EI
CAS
CSCD
北大核心
2004年第5期878-880,共3页
Acta Electronica Sinica
基金
国家自然科学基金项目 (No.60 2 730 89)
陕西省自然科学研究计划项目 (No .2 0 0 3F37)
关键词
零知识证明
证实数字签名
DSA
数字签名
zero-knowledge proof
confirmer signature
DSA
undeniable digital signature