Convertible Authenticated Encryption Scheme Without Using Conventional One‐Way Function

Hung‐Yu Chien
2003 Informatica  
An authenticated encryption allows the designated recipient to verify the authenticity while recovering the message. To protect the recipient's benefit in case of a later dispute, a convertible authenticated encryption scheme allows the recipient to convert the authenticated encryption into an ordinary signature so that it becomes a publicly verifiable. This paper shows a universal forgery attack on Araki et al.'s convertible authenticated encryption scheme, and proposes a new convertible
more » ... ticated encryption scheme. Without using any conventional one-way function, the proposed scheme simplifies its security assumption on only a public hard problem -the discrete logarithm problem.
doi:10.15388/informatica.2003.033 fatcat:u44tegjvfjg4lozdfxcdsqlwbi