Public Key Cryptography — PKC 2003

Volume 2567 of the series Lecture Notes in Computer Science pp 116-129


The Cramer-Shoup Strong-RSA Signature Scheme Revisited

  • Marc FischlinAffiliated withSecurity and Smart Card Technologies (SICA), Fraunhofer-Institute Secure Telecooperation (SIT)


We discuss a modification of the Cramer-Shoup strong-RSA signature scheme. Our proposal also presumes the strong RSA assumption, but allows faster signing and verification and produces signatures of roughly half the size. Then we present a stateful version of our scheme where signing (but not verifying) becomes almost as efficient as with RSA-PSS. We also show how to turn our signature schemes into “lightweight” anonymous yet linkable group identification protocols without random oracles.