Threshold-Oriented Optimistic Fair Exchange
Fair exchange protocol aims to allow two parties to exchange digital items in a fair manner. It is well-known that fairness can only be achieved with the help of a trusted third party, usually referred to as arbitrator. A fair exchange protocol is optimistic if the arbitrator is not involved in the normal execution of the fair exchange process. That is, its presence is necessary only when one of the exchanging parties is dishonest. Traditionally, the items being exchanged are digital signatures. In this paper, we consider the items to be threshold signatures. Specifically, the signatures are created by a subset of legitimate signers instead of a single signer. We define a security model for this new notion, and provide an concrete instantiation. Our instantiation can be proven secure in the random oracle model. Our definition covers the case when the item being exchanged is a secret key of an identity-based encryption where the master secret key is split amongst a set of authorities.
KeywordsRandom Oracle Secret Sharing Scheme Random Oracle Model Full Signature Fair Exchange
Unable to display preview. Download preview PDF.
- 1.Asokan, N., Schunter, M., Waidner, M.: Optimistic protocols for fair exchange. In: ACM Conference on Computer and Communications Security, pp. 7–17 (1997)Google Scholar
- 8.Dodis, Y., Reyzin, L.: Breaking and repairing optimistic fair exchange from podc 2003. In: DRM 2003, pp. 47–54 (2003)Google Scholar