A "Paradoxical" Solution To The Signature Problem

S. Goldwasser, Silvio Micali, Ronald L. Rivest · 1984

We present a general signature scheme which uses any pair of trap-door permutations (f0, f1) for which it is infeasible to find any x, y with f0(x) = f1(y). The scheme possesses the novel property of being robust against an adaptive chosen message attack: no adversary who first asks for and then receives sgnatures for messages of his choice (which may depend on previous signatures seen) can later forge the signature of even a singl additional message.

Read the paper · More papers on PaperTik