{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T21:06:22Z","timestamp":1784927182912,"version":"3.55.0"},"publisher-location":"Berlin, Heidelberg","reference-count":34,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540140399","type":"print"},{"value":"9783540392002","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2003]]},"DOI":"10.1007\/3-540-39200-9_16","type":"book-chapter","created":{"date-parts":[[2007,8,16]],"date-time":"2007-08-16T07:35:32Z","timestamp":1187249732000},"page":"255-271","source":"Crossref","is-referenced-by-count":416,"title":["A Forward-Secure Public-Key Encryption Scheme"],"prefix":"10.1007","author":[{"given":"Ran","family":"Canetti","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shai","family":"Halevi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan","family":"Katz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2003,5,13]]},"reference":[{"key":"16_CR1","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"116","DOI":"10.1007\/3-540-44448-3_10","volume-title":"Asiacrypt\u201900","author":"M. Abdalla","year":"2000","unstructured":"M. Abdalla and L. Reyzin. A new forward-secure digital signature scheme. Asiacrypt\u201900, LNCS vol. 1976, pp. 116\u2013129, Springer-Verlag, 2000."},{"key":"16_CR2","unstructured":"A. Aho, J. Hopcroft, and J. Ullman. The Design and Analysis of Computer Algorithms. Addison-Wesley, 1975."},{"key":"16_CR3","unstructured":"R. Anderson. Two remarks on public key cryptology. Invited Lecture, ACM-CCS\u201997. http:\/\/www.cl.cam.ac.uk\/ftp\/users\/rja14\/forwardsecure.pdf ."},{"key":"16_CR4","series-title":"Lect Notes Comput Sci","first-page":"307","volume-title":"Eurocrypt\u2019 92","author":"D. Beaver","year":"1992","unstructured":"D. Beaver and S. Haber. Cryptographic protocols provably secure against dynamic adversaries. In Eurocrypt\u2019 92, LNCS vol. 658, pp. 307\u2013323, Springer-Verlag, 1992."},{"key":"16_CR5","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/BFb0052228","volume-title":"Advances in Cryptology \u2014 Crypto\u2019 97","author":"D. Beaver","year":"1997","unstructured":"D. Beaver, Plug and play encryption, Advances in Cryptology \u2014 Crypto\u2019 97, LNCS vol. 1294, pp. 75\u201389, Springer-Verlag, 1997."},{"key":"16_CR6","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"431","DOI":"10.1007\/3-540-48405-1_28","volume-title":"Advances in Cryptology \u2014 Crypto\u2019 99","author":"M. Bellare","year":"1999","unstructured":"M. Bellare and S. K. Miner. A forward-secure digital signature scheme. Advances in Cryptology \u2014 Crypto\u2019 99, LNCS vol. 1666, pp. 431\u2013448, Springer-Verlag, 1999."},{"key":"16_CR7","doi-asserted-by":"crossref","unstructured":"M. Bellare and B. Yee. Forward security in private-key cryptography. Topics in Cryptology \u2014 CT-RSA 2003, to appear. Preliminary version at http:\/\/eprint.iacr.org\/2001\/035\/ .","DOI":"10.1007\/3-540-36563-X_1"},{"key":"16_CR8","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1007\/BFb0055718","volume-title":"Advances in Cryptology \u2014 Crypto\u201998","author":"M. Bellare","year":"1998","unstructured":"M. Bellare, A. Desai, D. Pointcheval, and P. Rogaway, Relations Among Notions of Security for Public-Key Encryption Schemes, Advances in Cryptology \u2014 Crypto\u201998, Lecture Notes in Computer Science Vol. 1462, pp. 26\u201345, Springer-Verlag, 1998."},{"key":"16_CR9","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"213","DOI":"10.1007\/3-540-44647-8_13","volume-title":"Advances in Cryptology \u2014 Crypto 2001","author":"D. Boneh","year":"2001","unstructured":"D. Boneh and M. Franklin. Identity based encryption from the Weil pairing. Advances in Cryptology \u2014 Crypto 2001, LNCS vol. 2139, pp. 213\u2013229, Springer-Verlag, 2001. Full version to appear in SIAM J. Computing and available at http:\/\/eprint.iacr.org\/2001\/090 ."},{"key":"16_CR10","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"514","DOI":"10.1007\/3-540-45682-1_30","volume-title":"Asiacrypt\u2019 01","author":"D. Boneh","year":"2001","unstructured":"D. Boneh, B. Lynn, and H. Shacham. Short signatures from the Weil pairing. Asiacrypt\u2019 01, LNCS vol. 2248, pp. 514\u2013532, Springer-Verlag, 2001."},{"key":"16_CR11","doi-asserted-by":"crossref","unstructured":"R. Canetti, U. Feige, O. Goldreich and M. Naor, Adaptively Secure Computation, STOC\u2019 96, pp. 639\u2013648, ACM, 1996. Also MIT-LCS-TR #682, 1996.","DOI":"10.1145\/237814.238015"},{"key":"16_CR12","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"432","DOI":"10.1007\/3-540-44598-6_27","volume-title":"Advances in Cryptology \u2014 Crypto\u2019 00","author":"I. Damgaard","year":"2000","unstructured":"I. Damgaard and J. B. Nielsen, Improved non-committing encryption schemes based on general complexity assumption, Advances in Cryptology \u2014 Crypto\u2019 00, LNCS vol. 1880, pp. 432\u2013450, Springer-Verlag, 2000."},{"key":"16_CR13","series-title":"Lect Notes Comput Sci","first-page":"307","volume-title":"Advances in Cryptology \u2014 Crypto\u2019 89","author":"Y. Desmedt","year":"1989","unstructured":"Y. Desmedt and Y. Frankel. Threshold cryptosystems. Advances in Cryptology \u2014 Crypto\u2019 89, LNCS vol. 435, pp. 307\u2013315, Springer-Verlag, 1989."},{"key":"16_CR14","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/BF00124891","volume":"2","author":"W. Diffie","year":"1992","unstructured":"W. Diffie, P. C. Van-Oorschot, and M. J. Weiner. Authentication and authenticated key exchanges. Designs, Codes, and Cryptography 2:107\u2013125, 1992.","journal-title":"Designs, Codes, and Cryptography"},{"issue":"2","key":"16_CR15","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1137\/S0097539795291562","volume":"30","author":"D. Dolev","year":"2000","unstructured":"D. Dolev, C. Dwork and M. Naor, Non-malleable cryptography, SIAM. J. Computing, Vol. 30, No. 2, 2000, pp. 391\u2013437. Preliminary version in 23rd Symposium on Theory of Computing (STOC), ACM, 1991.","journal-title":"SIAM. J. Computing"},{"key":"16_CR16","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"537","DOI":"10.1007\/3-540-48405-1_34","volume-title":"Crypto\u2019 99","author":"E. Fujisaki","year":"1999","unstructured":"E. Fujisaki and T. Okamoto. Secure integration of asymmetric and symmetric encryption schemes. Crypto\u2019 99, LNCS 1666, pp. 537\u2013554, Springer-Verlag, 1999."},{"key":"16_CR17","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"548","DOI":"10.1007\/3-540-36178-2_34","volume-title":"Asiacrypt 2002","author":"C. Gentry","year":"2002","unstructured":"C. Gentry and A. Silverberg. Hierarchical identity-based cryptography. Asiacrypt 2002, LNCS vol. 2501, pp. 548\u2013566, Springer-Verlag, 2002."},{"key":"16_CR18","series-title":"Lect Notes Comput Sci","first-page":"29","volume-title":"Advances in Cryptology \u2014 Eurocrypt\u2019 89","author":"C. G. G\u00fcnther","year":"1989","unstructured":"C. G. G\u00fcnther. An identity-based key-exchange protocol. Advances in Cryptology \u2014 Eurocrypt\u2019 89, LNCS vol. 434, pp. 29\u201337, Springer-Verlag, 1989."},{"issue":"2","key":"16_CR19","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1137\/0217017","volume":"17","author":"S. Goldwasser","year":"1988","unstructured":"S. Goldwasser, S. Micali, and R. Rivest. A digital signature scheme secure against adaptive chosen-message attacks. SIAM J. Computing, 17(2):281\u2013308, April 1988.","journal-title":"SIAM J. Computing"},{"key":"16_CR20","doi-asserted-by":"crossref","unstructured":"A. Herzberg, M. Jakobson, S. Jarecki, H. Krawczyk, and M. Yung. Proactive public key and signature systems. Proceedings of 4th Conference on Computer and Communications Security, pp. 100\u2013110, ACM, 1997.","DOI":"10.1145\/266420.266442"},{"key":"16_CR21","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"466","DOI":"10.1007\/3-540-46035-7_31","volume-title":"Eurocrypt\u201902","author":"J. Horwitz","year":"2002","unstructured":"J. Horwitz and B. Lynn. Toward hierarchical identity-based encryption. Eurocrypt\u201902, LNCS vol. 2332, pp. 466\u2013481, Springer-Verlag, 2002."},{"key":"16_CR22","series-title":"Lect Notes Comput Sci","first-page":"499","volume-title":"Crypto\u2019 01","author":"G. Itkis","year":"2001","unstructured":"G. Itkis and L. Reyzin. Forward-secure signatures with optimal signing and verifying. Crypto\u2019 01, LNCS vol. 2139, pp. 499\u2013514, Springer-Verlag, 2001."},{"key":"16_CR23","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1007\/10722028_23","volume-title":"4th International Symposium on Algorithmic Number Theory","author":"A. Joux","year":"2000","unstructured":"A. Joux. A one round protocol for tripartite Diffie-Hellman. 4th International Symposium on Algorithmic Number Theory, LNCS vol. 1838, pp. 385\u2013394, Springer-Verlag, 2000."},{"key":"16_CR24","unstructured":"A. Joux and K. Nguyen. Separating decision diffie-hellman from diffie-hellman in cryptographic groups. Manuscript, January 2001. Available at http:\/\/eprint.iacr.org\/2001\/003\/ ."},{"key":"16_CR25","series-title":"Lect Notes Comput Sci","first-page":"247","volume-title":"Proc. 3rd Conference on Security in Communication Networks","author":"A. Kozlov","year":"2002","unstructured":"A. Kozlov and L. Reyzin. Forward-secure signatures with fast key update. Proc. 3rd Conference on Security in Communication Networks, LNCS vol. 2576, pp. 247\u2013262, Springer-Verlag, 2002."},{"key":"16_CR26","doi-asserted-by":"crossref","unstructured":"H. Krawczyk. Simple forward-secure signatures from any signature scheme. Proc. 7th ACM-CCS, pp. 108\u2013115, ACM, 2000.","DOI":"10.1145\/352600.352617"},{"key":"16_CR27","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"400","DOI":"10.1007\/3-540-46035-7_27","volume-title":"Advances in Cryptology \u2014 Eurocrypt 2002","author":"T. Malkin","year":"2002","unstructured":"T. Malkin, D. Micciancio, and S. K. Miner. Efficient generic forward-secure signatures with an unbounded number of time periods. Advances in Cryptology \u2014 Eurocrypt 2002, LNCS vol. 2332, pp. 400\u2013417, Springer-Verlag, 2002."},{"key":"16_CR28","doi-asserted-by":"crossref","unstructured":"M. Naor and M. Yung, Public key cryptosystems provably secure against chosen ciphertext attacks, 22nd STOC, 427\u2013437, 1990.","DOI":"10.1145\/100216.100273"},{"key":"16_CR29","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1007\/3-540-45708-9_8","volume-title":"Crypto\u2019 02","author":"J. B. Nielsen","year":"2002","unstructured":"J. B. Nielsen. Separating random oracle proofs from complexity theoretic proofs: The non-committing encryption case. Crypto\u2019 02, LNCS vol. 2442, pp. 111\u2013126, Springer-Verlag, 2002."},{"key":"16_CR30","doi-asserted-by":"crossref","unstructured":"R. Ostrovsky and M. Yung. How to withstand mobile virus attacks. 10th Annual Symposium on Principles of Distributed Computing, pages 51\u201359, ACM, 1991.","DOI":"10.1145\/112600.112605"},{"key":"16_CR31","series-title":"Lect Notes Comput Sci","first-page":"433","volume-title":"Crypto\u2019 91","author":"C. Rackoff","year":"1991","unstructured":"C. Rackoff and D. Simon, Non-interactive zero-knowledge proof of knowledge and chosen ciphertext attack, Crypto\u2019 91, LNCS vol. 576, pp. 433\u2013444, Springer-Verlag, 1991."},{"key":"16_CR32","doi-asserted-by":"crossref","unstructured":"A. Sahai. Non-malleable non-interactive zero-knowledge and adaptive chosenciphertext security. Proc. of the 40th Annual Symposium on Foundations of Computer Science, pages 543\u2013553, IEEE, 1999.","DOI":"10.1109\/SFFCS.1999.814628"},{"issue":"11","key":"16_CR33","doi-asserted-by":"publisher","first-page":"612","DOI":"10.1145\/359168.359176","volume":"22","author":"A. Shamir","year":"1979","unstructured":"A. Shamir. How to share a secret. Comm. of the ACM 22(11):612\u2013613, 1979.","journal-title":"Comm. of the ACM"},{"key":"16_CR34","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1007\/3-540-45682-1_31","volume-title":"Asiacrypt 2001","author":"E. R. Verheul","year":"2001","unstructured":"E. R. Verheul. Self-blindable credential certificates from the Weil pairing. Asiacrypt 2001, LNCS vol. 2248, pp. 533\u2013551, Springer-Verlag, 2001."}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2014 EUROCRYPT 2003"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/3-540-39200-9_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,20]],"date-time":"2025-01-20T11:24:06Z","timestamp":1737372246000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/3-540-39200-9_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003]]},"ISBN":["9783540140399","9783540392002"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/3-540-39200-9_16","relation":{},"ISSN":["0302-9743"],"issn-type":[{"value":"0302-9743","type":"print"}],"subject":[],"published":{"date-parts":[[2003]]}}}