Qiong Huang, Duncan S. Wong, Yiming Zhao (auth.), Jonathan Katz, Moti Yung (eds.)

This ebook constitutes the refereed lawsuits of the fifth overseas convention on utilized Cryptography and community protection, ACNS 2007, held in Zhuhai, China, in June 2007.

The 31 revised complete papers provided have been conscientiously reviewed and chosen from round 260 submissions. The papers are prepared in topical sections on signature schemes, desktop and community safeguard, cryptanalysis, group-oriented safety, cryptographic protocols, nameless authentication, identity-based cryptography, safeguard in instant, ad-hoc, and peer-to-peer networks, in addition to effective implementation.

D. Pointcheval and J. 361-396, Springer-Verlag, 2000. 21. C. P. 239-252, Springer-Verlag, 1991. 22. A. Shamir and Y. 355-367, Springer-Verlag, 2001. com Abstract. We propose GMSS, a new variant of the Merkle signature scheme. GMSS is the first Merkle-type signature scheme that allows a cryptographically unlimited (280 ) number of documents to be signed with one key pair. Compared to recent improvements of the Merkle signature scheme, GMSS reduces the signature size as well as the signature generation cost.

Since the success probability of A is , it follows that P r[VV K (h, σ) = 1 ∧ h = HHK,kP (m, r) = HHK,ki P (mi , ri )] ≥ . Then we can construct a probabilistic algorithm M to compute a for a randomly given instance (P, aP ) where P is a generator of G as follows: – Let (SK, V K) be the signing/verification key pair of the original signature scheme. Choose a random integer b ∈R Zq , and let HK = Y = bP . Define the chameleon hash value h = b · aP . Run the signing algorithm S with the signing key SK to sign the message h.

6) i=1 Proof. A signature consists of T authentication paths (hi · n bits) and T onetime signatures (twi · n bits), one for each layer i = 1, . . , T . Adding up yields msignature as shown by Equation (6) as the size of a signature. Following the framework of [5], we split the signature generation into two parts. The first part is the online part which computes Sigd and outputs the signature. Merkle Signatures with Virtually Unlimited Signature Capacity 37 The second part is the offline part that precomputes the authentication paths and one-time signatures of the roots required for upcoming signatures.

