Withdrawable signature, the new notion of signature recently introduced, enables the retraction of a digital signature without revealing the signer’s private key or compromising the security of other signatures the signer created before. This concept holds particular significance in decentralized systems where commitments may require revocation. However, a notable limitation of the initial withdrawable signatures is the lack of universal verifiability, primarily due to their reliance on designated-verifier signatures to ensure the withdrawable signature is not verifiable with only the signer’s public key. In this paper, we revisit the concept of withdrawable signature, broaden its scope, and introduce extended withdrawable signature. Rather than limiting verification to a specific entity, the “extended withdrawability” ensures the universal verifiability of the withdrawable signature by employing any signature schemes that can maintain signer ambiguity. After formally extending the definition and security notions for the existing withdrawable signature, we propose a generic construction of the extended withdrawable signature and provide an instantiation based on the Schnorr signature. We provide formal security analyses to demonstrate that our generic construction is unforgeable under insider corruption and satisfies the criteria of extended withdrawability. We envision our new type of withdrawable signature will significantly enhance flexibility and security in digital transactions and communications.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Extended Withdrawable Signature

  • Xin Liu,
  • Willy Susilo,
  • Joonsang Baek

摘要

Withdrawable signature, the new notion of signature recently introduced, enables the retraction of a digital signature without revealing the signer’s private key or compromising the security of other signatures the signer created before. This concept holds particular significance in decentralized systems where commitments may require revocation. However, a notable limitation of the initial withdrawable signatures is the lack of universal verifiability, primarily due to their reliance on designated-verifier signatures to ensure the withdrawable signature is not verifiable with only the signer’s public key. In this paper, we revisit the concept of withdrawable signature, broaden its scope, and introduce extended withdrawable signature. Rather than limiting verification to a specific entity, the “extended withdrawability” ensures the universal verifiability of the withdrawable signature by employing any signature schemes that can maintain signer ambiguity. After formally extending the definition and security notions for the existing withdrawable signature, we propose a generic construction of the extended withdrawable signature and provide an instantiation based on the Schnorr signature. We provide formal security analyses to demonstrate that our generic construction is unforgeable under insider corruption and satisfies the criteria of extended withdrawability. We envision our new type of withdrawable signature will significantly enhance flexibility and security in digital transactions and communications.