The Cramer-Shoup Strong-RSA Signature Scheme Revisited

Marc Fischlin

Abstract: We discuss a modification of the Cramer-Shoup strong-RSA signature scheme. Our proposal also presumes the strong RSA assumption (and a collision-intractable hash function for long messages), but -without loss in performance- the size of a signature is almost halved compared to the original scheme. We also show how to turn the signature scheme into a "lightweight" anonymous (but linkable) group identification protocol without random oracles.

Category / Keywords: cryptographic protocols / anonymity, digital signatures, identification protocols, RSA

Date: received 14 Feb 2002

Contact author: marc at mi informatik uni-frankfurt de

Version: 20020214:170156 (All versions of this report)

