现有的广义指定验证者签名方案的安全性大都是在随机预言机模型下证明的,但是在该模型下的可证安全并不意味着在现实中是安全的.基于Zhang等人提出的无随机预言机模型下的短签名方案,提出了一个在标准模型下可证安全的广义指定验证者签名方案,其强不可伪造性基于k+1平方根假设和指数知识假设,证明了提出方案在选择公钥和选择消息攻击下是无条件不可传递的.方案的签名长度为1366 bits,比现有方案的签名长度要短.
The security of previously known universal designated verifier signature schemes are mostly proven when the random oracles are assumed, but security in the random oracle model does not imply security in the real world. Based on the short signature scheme without random oracles proposed by Zhang et al, a universal designated verifier signature scheme whose security can be proven without random oracles was proposed, and its security proof was given. Its strong unforgeability relies on k +1 square roots assumption and knowledge-of-exponent assumption. The proposed scheme achieves unconditional non-transferability against adaptive chosen public key attack and chosen message attack. The length of the proposed scheme is 1366 bits, which is shorter than that of most existing schemes.