Partial Signatures and their Applications.
Mihir Bellare, Shanshan Duan · 2009
We introduce Partial Signatures, where a signer, given a message, can compute a “stub ” which preserves her anonymity, yet later she, but nobody else, can complete the stub to a full and verifiable signature under her public key. We provide a formal definition requiring three properties, namely anonymity, unambiguity and unforgeability. We provide schemes meeting our definition both with and without random oracles. Our schemes are surprisingly cheap in both bandwidth and computa-