On the security of joint signature and encryption revisited
Mridul Nandi, Tapas Pandit · Journal of Mathematical Cryptology · 2016
Abstract In 2002, An et al. [1] proposed three generic conversions of signcryption, ℰ t 𝒮 ${\mathcal{E}t\mathcal{S}}$ , 𝒮 t ℰ ${\mathcal{S}t\mathcal{E}}$ and 𝒞 t ℰ & 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}}$ from the primitive encryption scheme and signature scheme. But, the security proof of confidentiality in the 𝒞 t ℰ & 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}}$ paradigm was ambiguous. In this paper, we revisit these paradigms again and provide a more transparent proof for the aforementioned paradigm. None of these paradigms preserves both stronger securities: strong unforgeability and IND-CCA security. We extend the above paradigms to new signcryption paradigms, ℰ t 𝒮 t 𝒮 ${\mathcal{E}t\mathcal{S}t\mathcal{S}}$ , 𝒮 t ℰ t 𝒮 ${\mathcal{S}t\mathcal{E}t\mathcal{S}}$ and 𝒞 t ℰ & 𝒮 t 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}t\mathcal{S}}$ , by applying one-time signature (OTS) cautiously at the outside layer. In these new paradigms, the stronger security of the primitive encryption and signature schemes are maintained. We also obtain a new paradigm, “Encrypt and Sign then Sign ( ℰ & 𝒮 t 𝒮 ${\mathcal{E}\&\mathcal{S}t\mathcal{S}}$ )”, which is surprisingly better than the 𝒞 t ℰ & 𝒮 t 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}t\mathcal{S}}$ paradigm in all aspects except that ℰ & 𝒮 t