TY - JOUR
T1 - Linear and lossy identification schemes derive tightly secure multisignatures
AU - Fukumitsu, Masayuki
AU - Hasegawa, Shingo
N1 - Funding Information:
We would like to thank anonymous reviewers for their valuable comments and suggestions. This work was supported in part by JSPS KAKENHI Grant Numbers JP18K11288 and JP19K20272.
Publisher Copyright:
© 2021 Taiwan Academic Network Management Committee. All rights reserved.
PY - 2021
Y1 - 2021
N2 - For the multisignature schemes, the tight security in the plain public key (PPK) model is considered as one of the desirable features. In this paper, we give a generic construction of multisignature schemes which is tightly secure in the PPK and random oracle model. Our construction can capture the known tightly secure multisignature schemes. The generic construction is derived from the identification (ID) scheme which has two properties called the linearity and the lossiness. Thus, we can obtain new tightly secure multisignature schemes by applying our construction to existing linear and lossy ID schemes. Moreover, we consider the relationship between these two properties to shrink the conditions required for our generic construction. We propose a new property of ID schemes, called the difference soundness, and show that the combination of the linearity and the difference soundness implies the lossiness.
AB - For the multisignature schemes, the tight security in the plain public key (PPK) model is considered as one of the desirable features. In this paper, we give a generic construction of multisignature schemes which is tightly secure in the PPK and random oracle model. Our construction can capture the known tightly secure multisignature schemes. The generic construction is derived from the identification (ID) scheme which has two properties called the linearity and the lossiness. Thus, we can obtain new tightly secure multisignature schemes by applying our construction to existing linear and lossy ID schemes. Moreover, we consider the relationship between these two properties to shrink the conditions required for our generic construction. We propose a new property of ID schemes, called the difference soundness, and show that the combination of the linearity and the difference soundness implies the lossiness.
KW - Linear identification scheme
KW - Lossy identification scheme
KW - Multisignature
KW - Plain public key model
KW - Tight security
UR - http://www.scopus.com/inward/record.url?scp=85117410243&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85117410243&partnerID=8YFLogxK
U2 - 10.53106/160792642021092205018
DO - 10.53106/160792642021092205018
M3 - Article
AN - SCOPUS:85117410243
VL - 22
SP - 1159
EP - 1170
JO - Journal of Internet Technology
JF - Journal of Internet Technology
SN - 1607-9264
IS - 5
ER -