Fail-stop Signatures and their Application

Birgit Pfitzmann, Michael Waidner · 1991

. The unforgeability of conventional digital signatures is necessarily based on complexity theoretic assumptions, i.e. even the most secure schemes can be broken by an adversary with unexpected computing abilities. Thus we introduce fail-stop signatures: They are as unforgeable as the best conventional signatures, but if a signature is forged nevertheless, the supposed signer can prove the forgery unconditionally (i.e. without assumptions), with arbitrarily high probability. We construct actual fail-stop signature schemes, called hiding schemes, from arbitrary claw-free pairs of permutations. As a special case, we obtain a rather practical system where forging is as hard as factoring. We also present applications to digital payment systems, and sketch those to reliable broadcast. * Institut für Rechnerentwurf und Fehlertoleranz, Universität Karlsruhe, Postfach 6980, D-W7500 Karlsruhe 1, Fed. Rep. of Germany; Phone: ++49-721-608-4024, Fax: ++49-721370455, E-mail (CSnet): [email protected]...

Read the paper · More papers on PaperTik