{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T18:29:22Z","timestamp":1761676162478},"reference-count":65,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2014,4,18]],"date-time":"2014-04-18T00:00:00Z","timestamp":1397779200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2015,4]]},"DOI":"10.1007\/s00145-014-9182-0","type":"journal-article","created":{"date-parts":[[2014,4,18]],"date-time":"2014-04-18T02:02:32Z","timestamp":1397786552000},"page":"351-395","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["Computing on Authenticated Data"],"prefix":"10.1007","volume":"28","author":[{"given":"Jae Hyun","family":"Ahn","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Boneh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jan","family":"Camenisch","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Susan","family":"Hohenberger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abhi","family":"Shelat","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Brent","family":"Waters","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,4,18]]},"reference":[{"key":"9182_CR1","unstructured":"G. Ateniese, D.H. Chou, B. de Medeiros, G. Tsudik, Sanitizable signatures, in ESORICS \u201905. LNCS, vol. 3679 (2005), pp. 159\u2013177"},{"key":"9182_CR2","unstructured":"N. Attrapadung, B. Libert, Homomorphic network coding signatures in the standard model, in Public Key Cryptography\u2014PKC 2011, vol. 6571 (2011), p. 17"},{"key":"9182_CR3","unstructured":"N. Attrapadung, B. Libert, T. Peters, Computing on authenticated data: New privacy definitions and constructions, in ASIACRYPT (2012), pp. 367\u2013385"},{"key":"9182_CR4","unstructured":"N. Attrapadung, B. Libert, T. Peters, Efficient completely context-hiding quotable and linearly homomorphic signatures, in Public Key Cryptography (2013), pp. 386\u2013404"},{"key":"9182_CR5","unstructured":"A. Beimel, Secure Schemes for Secret Sharing and Key Distribution. PhD thesis, Israel Institute of Technology, Technion, Haifa, Israel (1996)"},{"key":"9182_CR6","unstructured":"M. Bellare, O. Goldreich, S. Goldwasser, Incremental cryptography: the case of hashing and signing, in CRYPTO \u201994. LNCS, vol. 839 (1994), pp. 216\u2013233"},{"key":"9182_CR7","unstructured":"M. Bellare, D. Micciancio, B. Warinschi, Foundations of group signatures: formal definitions, simplified requirements, and a construction based on general assumptions, in EUROCRYPT (2003), pp. 614\u2013629"},{"key":"9182_CR8","unstructured":"M. Bellare, G. Neven, Transitive signatures based on factoring and RSA, in ASIACRYPT \u201902. LNCS, vol. 2501 (2002), pp. 397\u2013414"},{"key":"9182_CR9","doi-asserted-by":"crossref","first-page":"2133","DOI":"10.1109\/TIT.2005.847697","volume":"51","author":"M. Bellare","year":"2005","unstructured":"M. Bellare, G. Neven, Transitive signatures: new schemes and proofs. IEEE Transactions on Information Theory, 51:2133\u20132151 (2005)","journal-title":"IEEE Transactions on Information Theory"},{"key":"9182_CR10","unstructured":"J. Bethencourt, A. Sahai, B. Waters, Ciphertext-policy attribute-based encryption, in IEEE Symposium on Security and Privacy (2007), pp. 321\u2013334"},{"issue":"6","key":"9182_CR11","doi-asserted-by":"crossref","first-page":"1084","DOI":"10.1137\/0220068","volume":"20","author":"M. Blum","year":"1991","unstructured":"M. Blum, A. De Santis, S. Micali, G. Persiano, Noninteractive zero-knowledge. SIAM J. Comput., 20(6):1084\u20131118 (1991)","journal-title":"SIAM J. Comput."},{"key":"9182_CR12","unstructured":"D. Boneh, X. Boyen, Efficient selective-ID secure identity-based encryption without random oracles, in Advances in Cryptology\u2014EUROCRYPT \u201904. vol. 3027 (2004), pp. 223\u2013238"},{"key":"9182_CR13","unstructured":"D. Boneh, X. Boyen, H. Shacham, Short group signatures, in CRYPTO \u201904. LNCS, vol. 3152 (2004), pp. 45\u201355"},{"key":"9182_CR14","doi-asserted-by":"crossref","unstructured":"D. Boneh, M.K. Franklin, Identity-based encryption from the Weil pairing. SIAM J. Comput., 32(3) (2003)","DOI":"10.1137\/S0097539701398521"},{"key":"9182_CR15","doi-asserted-by":"crossref","unstructured":"D. Boneh, D. Freeman, Homomorphic signatures for polynomial functions, in Proc. of Eurocrypt. Cryptology ePrint Archive, Report 2011\/018 (2011)","DOI":"10.1007\/978-3-642-20465-4_10"},{"key":"9182_CR16","unstructured":"D. Boneh, D. Freeman, Linearly homomorphic signatures over binary fields and new tools for lattice-based signatures, in Proc. of PKC. LNCS, Cryptology ePrint Archive, Report 2010\/453. vol. 6571 (2011), pp. 1\u201316"},{"key":"9182_CR17","doi-asserted-by":"crossref","unstructured":"D. Boneh, D. Freeman, J. Katz, B. Waters, Signing a linear subspace: signature schemes for network coding, in Public-Key Cryptography\u2014PKC \u201909. LNCS, vol. 5443 (Springer, Berlin, 2009), pp. 68\u201387","DOI":"10.1007\/978-3-642-00468-1_5"},{"key":"9182_CR18","unstructured":"D. Boneh, M. Hamburg. Generalized identity based and broadcast encryption schemes, in ASIACRYPT. (2008), pp. 455\u2013470"},{"key":"9182_CR19","doi-asserted-by":"crossref","unstructured":"C. Brzuska, H. Busch, O. Dagdelen, M. Fischlin, M. Franz, S. Katzenbeisser, M. Manulis, C. Onete, A. Peter, B. Poettering, D. Schr\u00f6der, Redactable signatures for tree-structured data: definitions and constructions, in Applied Cryptography and Network Security (ACNS) \u201908. LNCS, vol. 6123 (2010), pp. 87\u2013104","DOI":"10.1007\/978-3-642-13708-2_6"},{"key":"9182_CR20","unstructured":"C. Brzuska, M. Fischlin, T. Freudenreich, A. Lehmann, M. Page, J. Schelbert, D. Schr\u00f6der, F. Volk, Security of sanitizable signatures revisited, in Public Key Cryptography. LNCS, vol. 5443 (2009), pp. 317\u2013336"},{"key":"9182_CR21","unstructured":"C. Brzuska, M. Fischlin, A. Lehmann, D. Schr\u00f6der, Santizable signatures: how to partially delegate control for authenticated data, in BIOSIG 2009 (2009), pp. 117\u2013128"},{"key":"9182_CR22","unstructured":"C. Brzuska, M. Fischlin, A. Lehmann, D. Schr\u00f6der, Unlinkability of sanitizable signatures, in Public Key Cryptography (PKC) \u201910. LNCS, vol. 6056 (2010), pp. 444\u2013461"},{"key":"9182_CR23","unstructured":"J. Camenisch, A. Lysyanskaya, Signature schemes and anonymous credentials from bilinear maps, in Advances in Cryptology\u2014CRYPTO \u201904. vol. 3152 (2004), pp. 56\u201372"},{"key":"9182_CR24","unstructured":"R. Canetti, S. Halevi, J. Katz, A forward-secure public-key encryption scheme, in EUROCRYPT (2003), pp. 255\u2013271"},{"key":"9182_CR25","unstructured":"E. Chang, C.L. Lim, J. Xu, Short redactable signatures using random trees, in CT-RSA \u201909: Proceedings of the The Cryptographers\u2019 Track at the RSA Conference 2009 on Topics in Cryptology (2009), pp. 133\u2013147"},{"issue":"1","key":"9182_CR26","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1504\/IJICOT.2009.024044","volume":"1","author":"D. Charles","year":"2009","unstructured":"D. Charles, K.J. K. Lauter, Signatures for network coding. International Journal of Information and Coding Theory, 1(1):3\u201314 (2009)","journal-title":"International Journal of Information and Coding Theory"},{"key":"9182_CR27","unstructured":"M. Chase, M. Kohlweiss, A. Lysyanskaya, S. Meiklejohn, Malleable signatures: complex unary transformations and delegatable anonymous credentials. Cryptology ePrint Archive, Report 2013\/179 (2013). \n                    http:\/\/eprint.iacr.org\/\n                    \n                  . Accessed 17 Mar 2014"},{"key":"9182_CR28","unstructured":"D. Chaum, E. van Heyst, Group signatures, in EUROCRYPT. LNCS, vol. 547 (1991), pp. 257\u2013265"},{"key":"9182_CR29","unstructured":"B. Deiseroth, V. Fehr, M. Fischlin, M. Maasz, N.F. Reimers, R. Stein, Computing on authenticated data for adjustable predicates. Cryptology ePrint Archive, Report 2013\/217 (2013). \n                    http:\/\/eprint.iacr.org\/\n                    \n                  . Accessed 17 Mar 2014"},{"key":"9182_CR30","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W. Diffie","year":"1976","unstructured":"W. Diffie, M. Hellman, New directions in cryptography. IEEE Transactions on Information Theory, 22:644\u2013654 (1976)","journal-title":"IEEE Transactions on Information Theory"},{"key":"9182_CR31","doi-asserted-by":"crossref","unstructured":"C. Fragouli, E. Soljanin, Network Coding Fundamentals (Now Publishers Inc., Hanover, MA, 2007)","DOI":"10.1561\/9781601980335"},{"key":"9182_CR32","doi-asserted-by":"crossref","unstructured":"R. Gennaro, J. Katz, H. Krawczyk, T. Rabin, Secure network coding over the integers, in Public Key Cryptography\u2014PKC \u201910. LNCS, vol. 6056 (Springer, Berlin, 2010), pp. 142\u2013160","DOI":"10.1007\/978-3-642-13013-7_9"},{"key":"9182_CR33","doi-asserted-by":"crossref","unstructured":"C. Gentry, A fully homomorphic encryption scheme. PhD thesis, Stanford University (2009)","DOI":"10.1145\/1536414.1536440"},{"key":"9182_CR34","unstructured":"O. Goldreich, S. Goldwasser, S. Micali, How to construct random functions (extended abstract), in FOCS (1984), pp. 464\u2013479"},{"issue":"2","key":"9182_CR35","doi-asserted-by":"crossref","first-page":"281","DOI":"10.1137\/0217017","volume":"17","author":"S. Goldwasser","year":"1988","unstructured":"S. Goldwasser, S. Micali, R.L. Rivest, A digital signature scheme secure against adaptive chosen-message attacks. SIAM J. Comput., 17(2):281\u2013308 (1988)","journal-title":"SIAM J. Comput."},{"key":"9182_CR36","unstructured":"S. Haber, Y. Hatano, Y. Honda, W. Horne, K. Miyazaki, T. Sander, S. Tezoku, D. Yao. Efficient signature schemes supporting redaction, pseudonymization, and data deidentification, in ASIACCS \u201908 (2008), p. 353\u2013362"},{"key":"9182_CR37","unstructured":"A. Hevia, D. Micciancio, The provable security of graph-based one-time signatures and extensions to algebraic signature schemes, in ASIACRYPT \u201902. LNCS, vol. 2501 (2002), pp. 379\u2013396"},{"key":"9182_CR38","unstructured":"S. Hohenberger, B. Waters, Realizing hash-and-sign signatures under standard assumptions, in EUROCRYPT \u201909. LNCS, vol. 5479 (2009), pp. 333\u2013350"},{"key":"9182_CR39","doi-asserted-by":"crossref","unstructured":"R. Johnson, D. Molnar, D. Song, D. Wagner, Homomorphic signature schemes, in CT-RSA (Springer, Berlin, 2002), pp. 244\u2013262","DOI":"10.1007\/3-540-45760-7_17"},{"key":"9182_CR40","unstructured":"M. Krohn, M. Freedman, D. Mazieres. On-the-fly verification of rateless erasure codes for efficient content distribution, in Proc. of IEEE Symposium on Security and Privacy (2004), pp. 226\u2013240"},{"key":"9182_CR41","doi-asserted-by":"crossref","unstructured":"A.B. Lewko, T. Okamoto, A. Sahai, K. Takashima, B. Waters. Fully secure functional encryption: attribute-based encryption and (hierarchical) inner product encryption, in EUROCRYPT (2010)","DOI":"10.1007\/978-3-642-13190-5_4"},{"key":"9182_CR42","unstructured":"A.B. Lewko, B. Waters, New techniques for dual system encryption and fully secure HIBE with short ciphertexts, in TCC \u201910. LNCS, vol. 5978 (2010), pp. 455\u2013479"},{"key":"9182_CR43","unstructured":"A. Lysyanskaya, Unique signatures and verifiable random functions from the DH-DDH separation, in CRYPTO (2002), pp. 597\u2013612"},{"issue":"4","key":"9182_CR44","doi-asserted-by":"crossref","first-page":"1253","DOI":"10.1137\/S0097539795284959","volume":"30","author":"S. Micali","year":"2000","unstructured":"S. Micali, Computationally sound proofs. SIAM J. Comput., 30(4):1253\u20131298 (2000)","journal-title":"SIAM J. Comput."},{"key":"9182_CR45","unstructured":"S. Micali, R.L. Rivest, Transitive signature schemes, in CT-RSA \u201902. LNCS, vol. 2271 (2002), pp. 236\u2013243"},{"key":"9182_CR46","unstructured":"K. Miyazaki, G. Hanaoka, H. Imai, Digitally signed document sanitizing scheme based on bilinear maps, in ASIACCS \u201906: Proceedings of the 2006 ACM Symposium on Information, computer and communications security (2006), pp. 343\u2013354"},{"issue":"1","key":"9182_CR47","doi-asserted-by":"crossref","first-page":"239","DOI":"10.1093\/ietfec\/E88-A.1.239","volume":"E88-A","author":"K. Miyazaki","year":"2005","unstructured":"K. Miyazaki, M. Iwamura, T. Matsumoto, R. Sasaki, H. Yoshiura, S. Tezuka, H. Imai, Digitally signed document sanitizing scheme with disclosure condition control. IEICE Trans. Fundam., E88-A(1):239\u2013246 (2005)","journal-title":"IEICE Trans. Fundam."},{"key":"9182_CR48","unstructured":"K. Miyazaki, S. Susaki, M. Iwamura, T. Matsumoto, R. Sasaki, H. Yoshiura, Digital document sanitizing problem. IEICE Technical, Report, 103:61\u201367 (2003)"},{"key":"9182_CR49","unstructured":"D. Naccache, Is theoretical cryptography any good in practice? CHES 2010 invited talk (2010). \n                    www.iacr.org\/workshops\/ches\/ches2010\n                    \n                  . Accessed 13 Jun 2012"},{"issue":"1\u20133","key":"9182_CR50","doi-asserted-by":"crossref","first-page":"277","DOI":"10.1016\/j.tcs.2008.01.042","volume":"396","author":"G. Neven","year":"2008","unstructured":"G. Neven, A simple transitive signature scheme for directed trees. Theor. Comput. Sci., 396(1\u20133):277\u2013282 (2008)","journal-title":"Theor. Comput. Sci."},{"key":"9182_CR51","unstructured":"R. Rivest, Two signature schemes. Slides from talk given at Cambridge University (2000). \n                    http:\/\/people.csail.mit.edu\/rivest\/Rivest-CambridgeTalk.pdf\n                    \n                  . Accessed 13 Jun 2012"},{"issue":"2","key":"9182_CR52","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1145\/359340.359342","volume":"21","author":"R.L. Rivest","year":"1978","unstructured":"R.L. Rivest, A. Shamir, L. Adleman, A method for obtaining digital signatures and public-key cryptosystems. Commun. ACM, 21(2):120\u2013126 (1978)","journal-title":"Commun. ACM"},{"key":"9182_CR53","unstructured":"R.L. Rivest, A. Shamir, Y. Tauman, How to leak a secret: theory and applications of ring signatures, in Essays in Memory of Shimon Even (2006), pp. 164\u2013186"},{"key":"9182_CR54","unstructured":"S.F. Shahandashti, M. Salmasizadeh, J. Mohajeri, A provably secure short transitive signature scheme from bilinear group pairs, in Security and Communication Networks. LNCS, vol. 3352 (2005), pp. 60\u201376"},{"key":"9182_CR55","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1145\/357353.357357","volume":"1","author":"A. Shamir","year":"1983","unstructured":"A. Shamir, On the generation of cryptographically strong pseudorandom sequences. ACM Trans Comput Syst, 1:38\u201344 (1983)","journal-title":"ACM Trans Comput Syst"},{"key":"9182_CR56","doi-asserted-by":"crossref","unstructured":"N.P. Smart, F. Vercauteren, Fully homomorphic encryption with relatively small key and ciphertext sizes, in Public Key Cryptography\u2014PKC \u201910. LNCS, vol. 6056 (Springer Berlin, 2010), pp. 420\u2013443","DOI":"10.1007\/978-3-642-13013-7_25"},{"key":"9182_CR57","unstructured":"N. Smart. ECRYPT2 Yearly Report on Algorithms and Keysizes (2008\u20132009), Revision 1.0. Edited by Smart (2009). \n                    http:\/\/people.csail.mit.edu\/rivest\/Rivest-CambridgeTalk.pdf\n                    \n                  . Accessed 13 Jun 2012"},{"key":"9182_CR58","unstructured":"R. Steinfeld, L. Bull, Y. Zheng, Context extraction signatures, in Information Security and Cryptology (ICISC). LNCS, vol. 2288 (2001), pp. 285\u2013304"},{"key":"9182_CR59","doi-asserted-by":"crossref","unstructured":"M. van Dijk, C. Gentry, S. Halevi, V. Vaikuntanathan, Fully homomorphic encryption over the integers, in Advances in Cryptology\u2014EUROCRYPT \u201910. LNCS, vol. 6110 (Springer, Berlin, 2010), pp. 24\u201343","DOI":"10.1007\/978-3-642-13190-5_2"},{"key":"9182_CR60","unstructured":"B. Waters, Efficient identity-based encryption without random oracles, in Advances in Cryptology\u2014EUROCRYPT \u201905. vol. 3494 (2005), pp. 320\u2013329"},{"key":"9182_CR61","unstructured":"B. Waters, Dual system encryption: realizing fully secure IBE and HIBE under simple assumptions, in Advances in Cryptology\u2014CRYPTO \u201909. vol. 5677 (2009), pp. 619\u2013636"},{"key":"9182_CR62","unstructured":"B. Waters, Ciphertext-policy attribute-based encryption: an expressive, efficient, and provably secure realization, in Public Key Cryptography\u2014PKC \u201911 (2011), pp. 53\u201370"},{"key":"9182_CR63","unstructured":"L. Wei, S.E. Coull, M.K. Reiter, Bounded vector signatures and their applications, in ASIACCS \u201911. (2011), pp. 277\u2013285"},{"key":"9182_CR64","unstructured":"X. Yi, Directed transitive signature scheme, in CT-RSA \u201907. LNCS, vol. 4377 (2007), pp. 129\u2013144"},{"key":"9182_CR65","doi-asserted-by":"crossref","unstructured":"F. Zhao, T. Kalker, M. M\u00e9dard, K. Han, Signatures for content distribution with network coding, in Proc. Intl. Symp. Info. Theory (ISIT) (2007)","DOI":"10.1109\/ISIT.2007.4557283"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-014-9182-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-014-9182-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-014-9182-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-014-9182-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,8]],"date-time":"2020-04-08T08:14:36Z","timestamp":1586333676000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-014-9182-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,4,18]]},"references-count":65,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,4]]}},"alternative-id":["9182"],"URL":"https:\/\/doi.org\/10.1007\/s00145-014-9182-0","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,4,18]]},"assertion":[{"value":"13 June 2012","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 April 2014","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}