Advances in Cryptology — CRYPTO’ 92
Volume 740 of the series Lecture Notes in Computer Science pp 3153
Provably Secure and Practical Identification Schemes and Corresponding Signature Schemes
 Tatsuaki OkamotoAffiliated withNTT Laboratories, Nippon Telegraph and Telephone Corporation
Abstract
This paper presents a threemove interactive identification scheme and proves it to be as secure as the discrete logarithm problem. This provably secure scheme is almost as efficient as the Schnorr identification scheme, while the Schnorr scheme is not provably secure. This paper also presents another practical identification scheme which is proven to be as secure as the factoring problem and is almost as efficient as the GuillouQuisquater identification scheme: the GuillouQuisquater scheme is not provably secure. We also propose practical digital signature schemes based on these identification schemes. The signature schemes are almost as efficient as the Schnorr and GuillouQuisquater signature schemes, while the security assumptions of our signature schemes are weaker than those of the Schnorr and GuillouQuisquater. signature schemes. This paper also gives a theoretically generalized result: a threemove identification scheme can be constructed which is as secure as the randomselfreducible problem. Moreover, this paper proposes a variant which is proven to be as secure as the difficulty of solving both the discrete logarithm problem and the specific factoring problem simultaneously. Some other variants such as an identitybased variant and an elliptic curve variant are also proposed.
