给出了广播签密的模型与定义,以ECDSA方案为基础,提出了一种可公开验证的广播签密方案ECBSC。方案能向多个用户广播认证单个消息;在不增加系统计算量的前提下,ECBSC还能同时向多个用户广播多个签密消息,用户只能从签密文中提取与自己相应的明文。在协议双方发生争议时,第3方可在ECDSA的模式下公开验证。ECBSC比重复使用SC-BLS的trivialn-recipient方案具有更高的效率,在组播通信中具有广阔的应用前景。
The formal definition of broadcast signcryption was proposed, and based on ECDSA, a verifiable broadcast signcryption ECBSC was constructed which could signcrypt and broadcast messagers to multiple recipients. Without any additional cost, it could also signcrypt multiple messages to multiple recipients. A recipients only obtained relevant messages from the ciphertext. A third party could verify the signcryption text publicly by the method of ECDSA. ECBSC is more efficient than trivial n-recipient scheme which uses SC-BLS repeatedly, and can be used in multicast communication.