A note on a signature building block and relevant security reduction in the green-hohenberger ot scheme

Zhengjun Cao, Frederic Lafitte, Olivier Markowitch

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In Asiacrypt’08, Green and Hohenberger presented an adaptive oblivious transfer (OT) scheme which makes use of a signature built from the Boneh-Boyen Identity Based Encryption. In this note, we show that the signature scheme is vulnerable to known-message attacks and the reduction used in the proof of Lemma A.6 is flawed. We also remark that the paradigm of “encryption and proof of knowledge” adopted in the OT scheme is unnecessary because the transferred message must be “recognizable” in practice, otherwise the receiver cannot decide which message to retrieve. However, we would like to stress that this work does not break the OT scheme itself.

Original languageEnglish
Title of host publicationInformation Security and Cryptology - 9th International Conference, Inscrypt 2013, Revised Selected Papers
EditorsMoti Yung, Dongdai Lin, Shouhuai Xu, Moti Yung
PublisherSpringer
Pages282-288
Number of pages7
ISBN (Electronic)9783319120867
DOIs
Publication statusPublished - 2014
Event9th China International Conference on Information Security and Cryptology, Inscrypt 2013 - Guangzhou, China
Duration: 27 Nov 201330 Nov 2013

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8567
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th China International Conference on Information Security and Cryptology, Inscrypt 2013
Country/TerritoryChina
CityGuangzhou
Period27/11/1330/11/13

Keywords

  • Encryption and proof of knowledge
  • Oblivious transfer
  • Recognizable message
  • Selective security
  • Signature

Fingerprint

Dive into the research topics of 'A note on a signature building block and relevant security reduction in the green-hohenberger ot scheme'. Together they form a unique fingerprint.

Cite this