The notion of the identity-based(id-based) strong designate verifier signature(SDVS) was extent to the lattice-based cryptography. The authors proposed an id-based SDVS scheme over lattices by using the basis dele...The notion of the identity-based(id-based) strong designate verifier signature(SDVS) was extent to the lattice-based cryptography. The authors proposed an id-based SDVS scheme over lattices by using the basis delegation technical in fixed dimension. The proposed scheme is based on the hardness of the learning with errors(LWE) problem, and the unforgeability against adaptive chosen message and selective identity attack is based on the hardness of the short integer solution(SIS) problem in the random oracle model. If the parameters m, n and q are the same, the signature length of this scheme is only 3mlbq bits shorter than(3m+n) lb q bits which is the signature length of the known lattice-based SDVS scheme in the public key environment. As a result, the proposed scheme is not only id-based but also efficient about the signature length and the computation cost. Moreover, this article also proposed an id-based strong designate verifier ring signature(SDVRS) scheme based on the proposed SDVS scheme, which satisfies anonimity, unforgeability.展开更多
基金supported by the National Natural Science Foundation of China (61303198)Natural Science Foundation of Shandong Province (ZR2013FQ031)supported by the Doctor Foundation of Shandong Jianzhu University
文摘The notion of the identity-based(id-based) strong designate verifier signature(SDVS) was extent to the lattice-based cryptography. The authors proposed an id-based SDVS scheme over lattices by using the basis delegation technical in fixed dimension. The proposed scheme is based on the hardness of the learning with errors(LWE) problem, and the unforgeability against adaptive chosen message and selective identity attack is based on the hardness of the short integer solution(SIS) problem in the random oracle model. If the parameters m, n and q are the same, the signature length of this scheme is only 3mlbq bits shorter than(3m+n) lb q bits which is the signature length of the known lattice-based SDVS scheme in the public key environment. As a result, the proposed scheme is not only id-based but also efficient about the signature length and the computation cost. Moreover, this article also proposed an id-based strong designate verifier ring signature(SDVRS) scheme based on the proposed SDVS scheme, which satisfies anonimity, unforgeability.