Signatures and Security Notions
Marc Fischlin · 2022
This chapter describes the interfaces of a digital signature scheme, and the minimal functional requirement that genuine signatures generated by the signer can be verified as correct. It presents two of the most widely deployed signature schemes in practice: digital signature algorithm (DSA) and Schnorr signature scheme. The chapter discusses their security properties after having presented the security notions. The DSA has been proposed by the National Institute of Standards and Technology, first as the only signature algorithm in the digital signature standard in 1994. The Schnorr signature scheme is a discrete logarithm-based variant of the Fiat–Shamir paradigm to turn identification schemes into signature schemes. The chapter discusses basic security properties of signature schemes, especially unforgeability and strong unforgeability under chosen-message attacks.