Abstract:
The reasons for the appearance of subliminal channels and their applications in digital signature schemes are analyzed. The wideband and narrowband subliminal channels in the Schnorr signature are discussed. And a new subliminal-free protocol is designed. In the new protocol, the warden participates in the generation of session keys in order to guarantee their randomness and privacy. It is shown that the protocol can completely close the subliminal channels existing in the random session keys in the Schnorr signature scheme. In addition, the signature authority of the signer is guaranteed. The security of the proposed protocol is based on both the discrete logarithm intractability assumption and the existence of collision-free hash functions. To generate a signature, it only needs to perform one modular exponentiation for each of the signer and the warden.