An Efficient Convertible Authenticated Encryption Scheme
-
Graphical Abstract
-
Abstract
Most previous authenticated encryption schemes have a problem that the recipient can not prove the dishonesty to any verifier if the signer denies his signatures. An efficient solving scheme has been presented in this paper. The new scheme requires less computational costs and lower communication than other previous convertible authenticated encryption schemes and the conventional signature-then-encryption approaches. In the proposed scheme, if the signer repudiates the signature, the recipient can convert this signature into an ordinary one without the cooperation of the signer. Furthermore, the message is not disclosed to any verifier during verification.
-
-