Confirmer signature scheme
Hongwei Ju · Jisuanji gongcheng yu sheji · 2006
Considering the insecurity [3~5] or inefficiency[6] of currentconfirmer signature schemes,born of the canmenisch-michels formal model and structure,a new confirmer signature scheme based on DSA and RSA is proposed.The confirming protocol and denying protocol are all interactive zero-knowledge protocols,and when confirming and denying aconfirmer signature,the verifieractively parti-cipates in the protocol,and so efficiently avoid the transferability problem of confirm signatures.