Abstract:Signcryption provides confidentiality and authenticity efficiently;it can be used to design compact communication protocol.Arbitration mechanism is used for settling disputes in signcryption,but the information that the judge gets also brings some security problems.This paper points out two problems:in some scheme,the arbitrator can decrypt all the signcryptions of a receiver while he gets some kinds of arbitration message;in another schemes,the arbitration mechanism cannot protect the integrity of plaintext.Analyze the two kinds of problems and concludes their reasons separately,we proposed a resolvent that can solve the two problem by changing a secure arbitration message.Based on the attack and analysis,this paper proposes a secure arbitral signcryption (SASC) scheme and proves its IND-CCA2 security and UF-CMA security in random oracle model.Furthermore,SASC is a securely arbitral signcryption scheme,it can protect the integrity of plaintexts by an arbitration message associated with plaintext;and the scheme can resist decryption attacks of arbitrator,even he gets the arbitration message.SASC does not increase computation nor communication overloads;it has no limitation to the length of plaintext,which makes SASC more convenient.Proofs and analysis show that SASC is an efficient and secure scheme.
粟栗;崔国华;李俊;郑明辉. 签密的仲裁安全与仲裁安全的签密方案[J]. 电子学报, 2007, 35(11): 2117-2122.
SU Li;CUI Guo-hua;LI Jun;ZHENG Ming-hui. Arbitral Security of Signcryptions and A Securely Arbitral Signcryption Scheme. Chinese Journal of Electronics, 2007, 35(11): 2117-2122.