Paper 2005/124

Append-Only Signatures

Eike Kiltz, Anton Mityagin, Saurabh Panjwani, and Barath Raghavan

Abstract

We present a new primitive--Append-only Signatures (AOS)--with the property that any party given an AOS signature aossig[M_1] on message M_1 can compute aossig[M_1||M_2] for any message M_2, where M_1||M_2 is the concatenation of M_1 and M_2. We define the security of AOS, present concrete AOS schemes, and prove their security under standard assumptions. In addition, we find that despite its simple definition, AOS is equivalent to Hierarchical Identity-based Signatures (HIBS) through efficient and security-preserving reductions. Finally, we show direct applications of AOS to problems in network security. Our investigations indicate that AOS is both useful in practical applications and worthy of further study as a cryptographic primitive.

Metadata
Available format(s)
PDF PS
Category
Foundations
Publication info
Published elsewhere. An extended abstract will appear at ICALP '05
Keywords
Algebraic SignaturesAppend-only SignaturesHierarchical Identity-based Signatures
Contact author(s)
ekiltz @ cs ucsd edu
History
2005-05-06: last of 2 revisions
2005-04-29: received
See all versions
Short URL
https://ia.cr/2005/124
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2005/124,
      author = {Eike Kiltz and Anton Mityagin and Saurabh Panjwani and Barath Raghavan},
      title = {Append-Only Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2005/124},
      year = {2005},
      url = {https://eprint.iacr.org/2005/124}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.