On the security of joint signature and encryption revisited

Mridul Nandi, Tapas Pandit · Journal of Mathematical Cryptology · 2016

Abstract In 2002, An et al. [1] proposed three generic conversions of signcryption, ℰ ⁢ t ⁢ 𝒮 ${\mathcal{E}t\mathcal{S}}$ , 𝒮 ⁢ t ⁢ ℰ ${\mathcal{S}t\mathcal{E}}$ and 𝒞 ⁢ t ⁢ ℰ & 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}}$ from the primitive encryption scheme and signature scheme. But, the security proof of confidentiality in the 𝒞 ⁢ t ⁢ ℰ & 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}}$ paradigm was ambiguous. In this paper, we revisit these paradigms again and provide a more transparent proof for the aforementioned paradigm. None of these paradigms preserves both stronger securities: strong unforgeability and IND-CCA security. We extend the above paradigms to new signcryption paradigms, ℰ ⁢ t ⁢ 𝒮 ⁢ t ⁢ 𝒮 ${\mathcal{E}t\mathcal{S}t\mathcal{S}}$ , 𝒮 ⁢ t ⁢ ℰ ⁢ t ⁢ 𝒮 ${\mathcal{S}t\mathcal{E}t\mathcal{S}}$ and 𝒞 ⁢ t ⁢ ℰ & 𝒮 ⁢ t ⁢ 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}t\mathcal{S}}$ , by applying one-time signature (OTS) cautiously at the outside layer. In these new paradigms, the stronger security of the primitive encryption and signature schemes are maintained. We also obtain a new paradigm, “Encrypt and Sign then Sign ( ℰ & 𝒮 ⁢ t ⁢ 𝒮 ${\mathcal{E}\&\mathcal{S}t\mathcal{S}}$ )”, which is surprisingly better than the 𝒞 ⁢ t ⁢ ℰ & 𝒮 ⁢ t ⁢ 𝒮 ${\mathcal{C}t\mathcal{E}\&\mathcal{S}t\mathcal{S}}$ paradigm in all aspects except that ℰ & 𝒮 ⁢ t

Read the paper · More papers on PaperTik