{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T16:47:35Z","timestamp":1784306855402,"version":"3.55.0"},"publisher-location":"Berlin, Heidelberg","reference-count":44,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540633846","type":"print"},{"value":"9783540695288","type":"electronic"}],"license":[{"start":{"date-parts":[[1997,1,1]],"date-time":"1997-01-01T00:00:00Z","timestamp":852076800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[1997]]},"DOI":"10.1007\/bfb0052240","type":"book-chapter","created":{"date-parts":[[2006,8,17]],"date-time":"2006-08-17T18:37:31Z","timestamp":1155839851000},"page":"249-263","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":105,"title":["A key recovery attack on discrete log-based schemes using a prime order subgroup"],"prefix":"10.1007","author":[{"given":"Chae Hoon","family":"Lim","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pil Joong","family":"Lee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2006,5,17]]},"reference":[{"key":"17_CR1","doi-asserted-by":"crossref","unstructured":"R.Anderson and R.Needham, Robustness principles for public key protocols, In Advances in Cryptology \u2014 CRYPTO'95, LNCS 963, Springer-Verlag, 1995, pp.236\u2013247.","DOI":"10.1007\/3-540-44750-4_19"},{"key":"17_CR2","unstructured":"R.Anderson and S.Vaudenay, Minding your p's and q's, In Advances in Cryptology \u2014 ASIACRYPT'96, LNCS 1163, Springer-Verlag, 1996, pp.15\u201325."},{"key":"17_CR3","unstructured":"A.Aziz, T.Markson and H.Prafullchandra, Simple key-management for Internet protocols (SKIP), draft-ietf-ipsec-skip-07.txt, Aug. 1996. (see also the SKIP home page http: \/\/skip.incog.com\/ for more information.)"},{"key":"17_CR4","doi-asserted-by":"crossref","unstructured":"D.Bleichenbacher, Generating ElGamal signatures without knowing the secret, In Advances in Cryptology \u2014 EUROCRYPT'96, LNCS 1070, Springer-Verlag, 1996, pp.10\u201318.","DOI":"10.1007\/3-540-68339-9_2"},{"key":"17_CR5","doi-asserted-by":"crossref","unstructured":"C.Boyd and W.Mao, Design and analysis of key exchange protocols via secure channel identification, In Advances in Cryptology \u2014 ASIACRYPT'94, LNCS 917, Springer-Verlag, 1995, pp.171\u2013181.","DOI":"10.1007\/BFb0000433"},{"key":"17_CR6","doi-asserted-by":"crossref","unstructured":"S.Brands, Untraceable off-line cash in wallet with observers, In Advances in Cryptology \u2014 CRYPTO'93, LNCS 773, Springer-Verlag, 1994, pp.302\u2013318.","DOI":"10.1007\/3-540-48329-2_26"},{"key":"17_CR7","volume-title":"Technical Report CS-R9323","author":"S. Brands","year":"1993","unstructured":"S.Brands, An efficient off-line electronic cash system based on the representation problem, Technical Report CS-R9323, CWI, Amsterdam, 1993."},{"key":"17_CR8","doi-asserted-by":"crossref","unstructured":"J.Boyar, D.Chaum, I.Damgard and T.Pedersen, Convertible undeniable signatures, In Advances in Cryptology \u2014 CRYPTO'90, LNCS 537, Springer-Verlag, 1991, pp.189\u2013205.","DOI":"10.1007\/3-540-38424-3_14"},{"key":"17_CR9","doi-asserted-by":"crossref","unstructured":"M.Burmester, A remark on the efficiency of identification schemes, In Advances in Cryptology \u2014 EUROCRYPT'90, LNCS 473, Springer-Verlag, 1991, pp.493\u2013495.","DOI":"10.1007\/3-540-46877-3_47"},{"key":"17_CR10","doi-asserted-by":"crossref","unstructured":"M.Burmester, On the risk of opening distributed keys, In Advances in Cryptology \u2014 CRYPTO'94, LNCS 839, Springer-Verlag, 1994, pp.308\u2013317.","DOI":"10.1007\/3-540-48658-5_29"},{"key":"17_CR11","doi-asserted-by":"crossref","unstructured":"A.Chan, Y.Prankel and Y.Tsiounis, Mis-representation of identities in E-cash schemes and how to prevent it, In Advances in Cryptology \u2014 ASIACRYPT'96, LNCS 1163, Springer-Verlag, 1996, pp.276\u2013285.","DOI":"10.1007\/BFb0034854"},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"D.Chaum, Zero-knowledge undeniable signatures, In Advances in Cryptology \u2014 EUROCRYPT90, LNCS 473, Springer-Verlag, 1991, pp.458\u2013464.","DOI":"10.1007\/3-540-46877-3_41"},{"key":"17_CR13","doi-asserted-by":"crossref","unstructured":"D.Chaum and T.Pedersen, Wallet databases with observers, In Advances in Cryptology \u2014 CRYPTO'92, LNCS 740, Springer-Verlag, 1993, pp.89\u2013105.","DOI":"10.1007\/3-540-48071-4_7"},{"key":"17_CR14","doi-asserted-by":"crossref","unstructured":"R.Cramer and T.Pedersen, Improved privacy in wallets with observers, In Advances in Cryptology \u2014 EUROCRYPT'93, LNCS 765, Springer-Verlag, 1994, pp.329\u2013343.","DOI":"10.1007\/3-540-48285-7_29"},{"key":"17_CR15","doi-asserted-by":"crossref","unstructured":"Y.Desmedt and Y.Prankel, Threshold cryptosystems, In Advances in Cryptology \u2014 CRYPTO'89, LNCS 435, Springer-Verlag, 1990, pp.307\u2013315.","DOI":"10.1007\/0-387-34805-0_28"},{"issue":"6","key":"17_CR16","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W. Diffie","year":"1976","unstructured":"W.Diffie and M.E.Hellman, New directions in cryptography, IEEE Trans. Info. Theory, 22(6), 1976, pp.644\u2013654.","journal-title":"IEEE Trans. Info. Theory"},{"key":"17_CR17","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/BF00124891","volume":"2","author":"W. Diffie","year":"1992","unstructured":"W.Diffie, P.vanOorschot and M.Wiener, Authentication and authenticated key exchange, Designs, Codes and Cryptography, 2, 1992, pp.107\u2013125.","journal-title":"Designs, Codes and Cryptography"},{"key":"17_CR18","doi-asserted-by":"publisher","first-page":"469","DOI":"10.1109\/TIT.1985.1057074","volume":"IT-31","author":"T. ElGamal","year":"1985","unstructured":"T.ElGamal, A public key cryptosystem and a signature scheme based on discrete logarithms, IEEE Trans. Inform. Theory, IT-31, 1985, pp.469\u2013472.","journal-title":"IEEE Trans. Inform. Theory"},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"M.Jakobsson and M.Yung, Proving without knowing: on oblivious, agnostic and blindfolded provers, In Advances in Cryptology \u2014 CRYPTO'96, LNCS 1109, Springer-Verlag, 1996, pp.186\u2013200.","DOI":"10.1007\/3-540-68697-5_15"},{"key":"17_CR20","doi-asserted-by":"crossref","unstructured":"M.Just and S.Vaudenay, Authenticated multi-party key agreement, In Advances in Cryptology \u2014 ASIACRYPT'96, LNCS 1163, Springer-Verlag, 1996, pp.36\u201349.","DOI":"10.1007\/BFb0034833"},{"key":"17_CR21","unstructured":"H.Krawczyk, SKEME: A versatile secure key exchange mechanisms for Internet, In Proc. of 1996 Symp. on Network and Distributed Systems Security."},{"key":"17_CR22","doi-asserted-by":"crossref","unstructured":"A.K.Lenstra, P.Winkler and Y.Yacobi, A key escrow system with warrant bounds, In Advances in Cryptology \u2014 CRYPTO'95, LNCS 963, Springer-Verlag, 1995, pp.197\u2013207.","DOI":"10.1007\/3-540-44750-4_16"},{"key":"17_CR23","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1016\/0020-0190(94)00178-2","volume":"53","author":"C.H. Lim","year":"1995","unstructured":"C.H.Lim and P.J.Lee, Several practical protocols for authentication and key exchange, Information Processing Letters, 53, 1995, pp.91\u201396.","journal-title":"Information Processing Letters"},{"key":"17_CR24","volume-title":"Directed signatures and application to threshold cryptosystems","author":"C.H. Lim","year":"1996","unstructured":"C.H.Lim and P.J.Lee, Directed signatures and application to threshold cryptosystems, In Pre-Proc. of 1996 Cambridge Workshop on Security Protocols, The Isaac Newton Institute, Cambridge, April 1996."},{"key":"17_CR25","unstructured":"C.H.Lim and P.J.Lee, Generating efficient primes for discrete log cryptosystems, submitted for publication (also presented at ASIACRYPT'96 Rump Session)."},{"key":"17_CR26","first-page":"99","volume":"E69","author":"T. Matsumoto","year":"1986","unstructured":"T.Matsumoto, Y.Takashima and H.Imai, On seeking smart public-key distribution systems, The Transactions of the IEICE of Japan, E69, 1986, pp.99\u2013106.","journal-title":"The Transactions of the IEICE of Japan"},{"key":"17_CR27","first-page":"22","volume-title":"Proc. SAC'95","author":"A.J. Menezes","year":"1995","unstructured":"A.J.Menezes, M.Qu and S.A.Vanstone, Some new key agreement protocols providing implicit authentication, In Proc. SAC'95, Carleton Univ., Ottawa, Ontario, May 1995, pp.22\u201332."},{"key":"17_CR28","doi-asserted-by":"crossref","unstructured":"M.Michels, H.Petersen and P.Horster, Breaking and repairing a convertible undeniable signature scheme, Proc. of 3rd ACM Conference on Computer and Communications Security, Mar. 1996.","DOI":"10.1145\/238168.238207"},{"key":"17_CR29","doi-asserted-by":"crossref","unstructured":"T.Okamoto, Designated confirmer signatures and public-key encryption are equivalent, In Advances in Cryptology \u2014 CRYPTO'94, LNCS 839, Springer-Verlag, 1995, pp.61\u201374.","DOI":"10.1007\/3-540-48658-5_8"},{"key":"17_CR30","doi-asserted-by":"crossref","unstructured":"C.S.Park, K.Itoh and K.Kurosawa, Efficient anonymous channel and all\/nothing election scheme, In Advances in Cryptology \u2014 EUROCRYPT'93, LNCS 765, Springer-Verlag, 1994, pp.248\u2013259.","DOI":"10.1007\/3-540-48285-7_21"},{"key":"17_CR31","doi-asserted-by":"crossref","unstructured":"T.Pedersen, Distributed provers with applications to undeniable signatures, In Advances in Cryptology \u2014 EUROCRYPT'91, LNCS 547, Springer-Verlag, 1991, pp.221\u2013242.","DOI":"10.1007\/3-540-46416-6_20"},{"key":"17_CR32","doi-asserted-by":"crossref","unstructured":"B.Pfitzmann, Breaking an efficient anonymous channel, In Advances in Cryptology \u2014 EUROCRYPT'94, LNCS 950, Springer-Verlag, 1995, pp.332\u2013340.","DOI":"10.1007\/BFb0053448"},{"issue":"1","key":"17_CR33","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1109\/TIT.1978.1055817","volume":"IT-24","author":"S.C. Pohlig","year":"1978","unstructured":"S.C.Pohlig and M.E.Hellman, An improved algorithm for computing logarithms over GF(p) and its cryptographic significance, IEEE Trans. Inform. Theory, IT-24 (1), 1978, pp.106\u2013110.","journal-title":"IEEE Trans. Inform. Theory"},{"key":"17_CR34","doi-asserted-by":"crossref","unstructured":"D.Pointcheval and J.Stern, Security proofs for signature schemes, In Advances in Cryptology \u2014 EUROCRYPT'96, LNCS 1070, Springer-Verlag, 1996, pp.387\u2013398.","DOI":"10.1007\/3-540-68339-9_33"},{"issue":"143","key":"17_CR35","first-page":"918","volume":"32","author":"J.M. Pollard","year":"1978","unstructured":"J.M.Pollard, Monte Carlo methods for index computation (mod p), Math. Comp., 32(143), 1978, pp.918\u2013924.","journal-title":"Math. Comp."},{"key":"17_CR36","doi-asserted-by":"crossref","unstructured":"K.Sako and J.Kilian, Receipt-free mix-type voting scheme, In Advances in Cryptology \u2014 EUROCRYPT'95, LNCS 921, Springer-Verlag, 1995, pp.pp.393\u2013403.","DOI":"10.1007\/3-540-49264-X_32"},{"key":"17_CR37","doi-asserted-by":"publisher","first-page":"612","DOI":"10.1145\/359168.359176","volume":"22","author":"A. Shamir","year":"1979","unstructured":"A.Shamir, How to share a secret, Commun. ACM, 22, 1979, pp.612\u2013613.","journal-title":"Commun. ACM"},{"key":"17_CR38","unstructured":"C.P.Schnorr, Efficient identification and signatures for smart cards, In Advances in Cryptology \u2014 CRYPTO'89, LNCS 435, Springer-Verlag, 1990, pp.235\u2013251."},{"key":"17_CR39","doi-asserted-by":"crossref","unstructured":"J.Stern, The validation of cryptographic algorithms, In Advances in Cryptology \u2014 ASIACRYPT'96, LNCS 1163, Springer-Verlag, 1996, pp.301\u2013310.","DOI":"10.1007\/BFb0034856"},{"key":"17_CR40","doi-asserted-by":"crossref","unstructured":"P.C.van Oorschot and M.J.Wiener, Parallel collision search with applications to hash functions and discrete logarithms, In Proc. 2nd ACM Conference on Computer and Communications Security, Fairfax, Virginia, Nov. 1994, pp.210\u2013218.","DOI":"10.1145\/191177.191231"},{"key":"17_CR41","doi-asserted-by":"crossref","unstructured":"P.C.van Oorschot and M.J.Wiener, On Diffie-Hellman key agreement with short exponents, In Advances in Cryptology \u2014 EUROCRYPT'96, LNCS 1070, Springer-Verlag, 1996, pp.332\u2013343.","DOI":"10.1007\/3-540-68339-9_29"},{"key":"17_CR42","doi-asserted-by":"crossref","unstructured":"S.Vaudenay, Hidden collisions on DSS, In Advances in Cryptology \u2014 CRYPTO'96, LNCS 1109, Springer-Verlag, 1996, pp.83\u201388.","DOI":"10.1007\/3-540-68697-5_7"},{"key":"17_CR43","doi-asserted-by":"crossref","unstructured":"Y.Yacobi, A key distribution paradox, In Advances in Cryptology \u2014 CRYPTO'90, LNCS 537, Springer-Verlag, 1991, pp.268\u2013273.","DOI":"10.1007\/3-540-38424-3_19"},{"key":"17_CR44","unstructured":"ISO\/IEC JTC1\/SC27, Information technology \u2014 Security techniques \u2014 Key management \u2014 Part 3: Mechanisms using asymmetric techniques."}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2014 CRYPTO '97"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/BFb0052240","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,1,30]],"date-time":"2020-01-30T03:26:06Z","timestamp":1580354766000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/BFb0052240"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[1997]]},"ISBN":["9783540633846","9783540695288"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/bfb0052240","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[1997]]},"assertion":[{"value":"17 May 2006","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}