Parallel Signcryption with OAEP, PSS-R, and other Feistel Paddings
Yevgeniy Dodis, Michael J. Freedman, Shabsi Walfish · 2003
We present a new, elegant composition method for joint signature and encryption, also referred to as signcryption. The new method, which we call Padding-based Parallel Signcryption (PbPS), builds an efficient signcryption scheme from any family of trapdoor permutations, such as RSA. Each user U generates a single public/secret key pair fU /f -1 U used for both sending and receiving the data. To signcrypt a message m to a recipient with key f rcv , a sender with key f snd efficiently transforms m into a pair s#, and simply sends f rcv (w)#f -1 snd (s).