Advances in Cryptology — CRYPTO ’87

Volume 293 of the series Lecture Notes in Computer Science pp 369-378


A Digital Signature Based on a Conventional Encryption Function

  • Ralph C. MerkleAffiliated withElxsi


A new digital signature based only on a conventional encryption function (such as DES) is described which is as secure as the underlying encryption function -- the security does not depend on the difficulty of factoring and the high computational costs of modular arithmetic are avoided. The signature system can sign an unlimited number of messages, and the signature size increases logarithmically as a function of the number of messages signed. Signature size in a ‘typical’ system might range from a few hundred bytes to a few kilobytes, and generation of a signature might require a few hundred to a few thousand computations of the underlying conventional encryption function.