{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T20:03:44Z","timestamp":1778789024358,"version":"3.51.4"},"reference-count":64,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2018,2,28]],"date-time":"2018-02-28T00:00:00Z","timestamp":1519776000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2019,1]]},"DOI":"10.1007\/s00145-018-9283-2","type":"journal-article","created":{"date-parts":[[2018,2,28]],"date-time":"2018-02-28T18:06:20Z","timestamp":1519841180000},"page":"84-150","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["On the Tightness of Forward-Secure Signature Reductions"],"prefix":"10.1007","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2447-4329","authenticated-orcid":false,"given":"Michel","family":"Abdalla","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8300-1820","authenticated-orcid":false,"given":"Fabrice","family":"Benhamouda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6668-683X","authenticated-orcid":false,"given":"David","family":"Pointcheval","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,2,28]]},"reference":[{"key":"9283_CR1","doi-asserted-by":"crossref","unstructured":"M.\u00a0Abdalla, J.H. An, M.\u00a0Bellare, C.\u00a0Namprempre, From identification to signatures via the Fiat\u2013Shamir transform: minimizing assumptions for security and forward-security, in EUROCRYPT\u00a02002. LNCS, vol. 2332 (Springer, Heidelberg, 2002), pp. 418\u2013433","DOI":"10.1007\/3-540-46035-7_28"},{"issue":"8","key":"9283_CR2","doi-asserted-by":"publisher","first-page":"3631","DOI":"10.1109\/TIT.2008.926303","volume":"54","author":"M Abdalla","year":"2008","unstructured":"M. Abdalla, J.H. An, M. Bellare, C. Namprempre, From identification to signatures via the Fiat-Shamir transform: Necessary and sufficient conditions for security and forward-security. IEEE Trans. Inf. Theory \n                           54(8), 3631\u20133646 (2008)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"9283_CR3","doi-asserted-by":"crossref","unstructured":"M.\u00a0Abdalla, F.\u00a0Ben Hamouda, D.\u00a0Pointcheval, Tighter reductions for forward-secure signature schemes, in PKC\u00a02013. LNCS, vol. 7778 (Springer, Heidelberg, 2013), pp. 292\u2013311","DOI":"10.1007\/978-3-642-36362-7_19"},{"key":"9283_CR4","doi-asserted-by":"crossref","unstructured":"M.\u00a0Abe, B.\u00a0David, M.\u00a0Kohlweiss, R.\u00a0Nishimaki, M.\u00a0Ohkubo, Tagged one-time signatures: Tight security and optimal tag size, in PKC\u00a02013. LNCS, vol. 7778 (Springer, Heidelberg, 2013), pp. 312\u2013331","DOI":"10.1007\/978-3-642-36362-7_20"},{"key":"9283_CR5","doi-asserted-by":"crossref","unstructured":"M.\u00a0Abdalla, P.-A. Fouque, V.\u00a0Lyubashevsky, M.\u00a0Tibouchi, Tightly-secure signatures from lossy identification schemes, in EUROCRYPT\u00a02012. LNCS, vol. 7237 (Springer, Heidelberg, 2012), pp. 572\u2013590","DOI":"10.1007\/978-3-642-29011-4_34"},{"issue":"3","key":"9283_CR6","doi-asserted-by":"publisher","first-page":"597","DOI":"10.1007\/s00145-015-9203-7","volume":"29","author":"M Abdalla","year":"2016","unstructured":"M. Abdalla, P.-A. Fouque, V. Lyubashevsky, M. Tibouchi, Tightly-secure signatures from lossy identification schemes. J. Cryptol.\n                           29(3), 597\u2013631 (2016)","journal-title":"J. Cryptol."},{"key":"9283_CR7","unstructured":"R.\u00a0Anderson, Two remarks on public-key cryptology. Manuscript. Relevant material presented by the author in an invited lecture at the 4th ACM Conference on Computer and Communications Security, CCS 1997, Zurich, Switzerland, 1\u20134 Apr 1997, Sept 2000"},{"key":"9283_CR8","doi-asserted-by":"crossref","unstructured":"D.\u00a0Boneh, X.\u00a0Boyen, H.\u00a0Shacham, Short group signatures, in CRYPTO\u00a02004. LNCS, vol. 3152 (Springer, Heidelberg, 2004), pp. 41\u201355","DOI":"10.1007\/978-3-540-28628-8_3"},{"issue":"2","key":"9283_CR9","doi-asserted-by":"publisher","first-page":"519","DOI":"10.1007\/s00145-016-9229-5","volume":"20","author":"F Benhamouda","year":"2017","unstructured":"F.\u00a0Benhamouda, J.\u00a0Herranz, M.\u00a0Joye, B.\u00a0Libert, Efficient cryptosystems from \n                    \n                      \n                    \n                    $$2^k$$\n                    \n                      \n                        \n                          2\n                          k\n                        \n                      \n                    \n                  -th power residue symbols. J. Cryptol.\n                           20(2), 519\u2013549 (2017)","journal-title":"J. Cryptol."},{"key":"9283_CR10","doi-asserted-by":"crossref","unstructured":"C.\u00a0Bader, T.\u00a0Jager, Y.\u00a0Li, S.\u00a0Sch\u00e4ge, On the impossibility of tight cryptographic reductions, in EUROCRYPT\u00a02016, Part\u00a0II. LNCS, vol. 9666 (Springer, Heidelberg, 2016), pp. 273\u2013304","DOI":"10.1007\/978-3-662-49896-5_10"},{"key":"9283_CR11","doi-asserted-by":"crossref","unstructured":"M.\u00a0Bellare, S.K. Miner, A forward-secure digital signature scheme, in CRYPTO\u201999. LNCS, vol. 1666 (Springer, Heidelberg, 1999), pp. 431\u2013448","DOI":"10.1007\/3-540-48405-1_28"},{"key":"9283_CR12","doi-asserted-by":"crossref","unstructured":"M.\u00a0Bellare, S.\u00a0Micali, R.\u00a0Ostrovsky, The (true) complexity of statistical zero knowledge, in 22nd ACM STOC (ACM Press, New York, 1990), pp. 494\u2013502","DOI":"10.1145\/100216.100285"},{"key":"9283_CR13","doi-asserted-by":"crossref","unstructured":"M.\u00a0Bellare, C.\u00a0Namprempre, G.\u00a0Neven, Unrestricted aggregate signatures, in ICALP 2007. LNCS, vol. 4596 (Springer, Heidelberg, 2007), pp. 411\u2013422","DOI":"10.1007\/978-3-540-73420-8_37"},{"key":"9283_CR14","doi-asserted-by":"crossref","unstructured":"N.\u00a0Bari, B.\u00a0Pfitzmann, Collision-free accumulators and fail-stop signature schemes without trees, in EUROCRYPT\u201997. LNCS, vol. 1233 (Springer, Heidelberg, 1997), pp. 480\u2013494","DOI":"10.1007\/3-540-69053-0_33"},{"key":"9283_CR15","doi-asserted-by":"crossref","unstructured":"M.\u00a0Bellare, B.\u00a0Poettering, D.\u00a0Stebila, From identification to signatures, tightly: a framework and generic transforms, in ASIACRYPT\u00a02016, Part\u00a0II. LNCS, vol. 10032 (Springer, Heidelberg, 2016), pp. 435\u2013464","DOI":"10.1007\/978-3-662-53890-6_15"},{"key":"9283_CR16","doi-asserted-by":"crossref","unstructured":"M.\u00a0Bellare, P.\u00a0Rogaway, Random oracles are practical: a paradigm for designing efficient protocols, in ACM CCS 93 (ACM Press, New York, 1993), pp. 62\u201373","DOI":"10.1145\/168588.168596"},{"key":"9283_CR17","doi-asserted-by":"crossref","unstructured":"M.\u00a0Bellare, P.\u00a0Rogaway, The security of triple encryption and a framework for code-based game-playing proofs, in EUROCRYPT\u00a02006. LNCS, vol. 4004 (Springer, Heidelberg, 2006), pp. 409\u2013426","DOI":"10.1007\/11761679_25"},{"key":"9283_CR18","volume-title":"Algorithmic Number Theory","author":"E Bach","year":"1996","unstructured":"E.\u00a0Bach, J.\u00a0Shallit, Algorithmic Number Theory. MIT Press, Cambridge (1996)"},{"key":"9283_CR19","doi-asserted-by":"crossref","unstructured":"R.\u00a0Cramer, I.\u00a0Damg\u00e5rd, Escure signature schemes based on interactive protocols, in CRYPTO\u201995. LNCS, vol. 963 (Springer, Heidelberg, 1995), pp. 297\u2013310","DOI":"10.1007\/3-540-44750-4_24"},{"issue":"2","key":"9283_CR20","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1016\/j.dam.2005.03.028","volume":"154","author":"J Camenisch","year":"2006","unstructured":"J.\u00a0Camenisch, M.\u00a0Koprowski, Fine-grained forward-secure signature schemes without random oracles. Discrete Appl. Math. \n                           154(2), 175\u2013188 (2006)","journal-title":"Discrete Appl. Math."},{"key":"9283_CR21","doi-asserted-by":"crossref","unstructured":"C.\u00a0Cachin, S.\u00a0Micali, M.\u00a0Stadler, Computationally private information retrieval with polylogarithmic communication, in EUROCRYPT\u201999. LNCS, vol. 1592 (Springer, Heidelberg, 1999), pp. 402\u2013414","DOI":"10.1007\/3-540-48910-X_28"},{"key":"9283_CR22","doi-asserted-by":"crossref","unstructured":"J.-S. Coron, Optimal security proofs for PSS and other signature schemes, in EUROCRYPT\u00a02002. LNCS, vol. 2332 (Springer, Heidelberg, 2002), pp. 272\u2013287","DOI":"10.1007\/3-540-46035-7_18"},{"key":"9283_CR23","unstructured":"R.\u00a0Cramer, Modular design of secure yet practical cryptographic protocols. Ph.D. thesis, CWI and University of Amsterdam, Amsterdam, The Netherlands (Nov 1996)"},{"key":"9283_CR24","unstructured":"P.\u00a0Dusart, Autour de la fonction qui compte le nombre de nombres premiers. Thesis, Universit\u00e9 de Limoges (1998)"},{"key":"9283_CR25","unstructured":"ECRYPT II yearly report on algorithms and keysizes (2011)"},{"issue":"2","key":"9283_CR26","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/BF02351717","volume":"1","author":"U Feige","year":"1988","unstructured":"U.\u00a0Feige, A.\u00a0Fiat, A.\u00a0Shamir, Zero-knowledge proofs of identity. J. Cryptol. \n                           1(2), 77\u201394 (1988)","journal-title":"J. Cryptol."},{"key":"9283_CR27","doi-asserted-by":"crossref","unstructured":"E.\u00a0Fujisaki, T.\u00a0Okamoto, Statistical zero knowledge protocols to prove modular polynomial relations, in CRYPTO\u201997. LNCS, vol. 1294 (Springer, Heidelberg, 1997), pp. 16\u201330","DOI":"10.1007\/BFb0052225"},{"key":"9283_CR28","doi-asserted-by":"crossref","unstructured":"A.\u00a0Fiat, A.\u00a0Shamir, How to prove yourself: Practical solutions to identification and signature problems, in CRYPTO\u201986. LNCS, vol. 263 (Springer, Heidelberg, 1987), pp. 186\u2013194","DOI":"10.1007\/3-540-47721-7_12"},{"key":"9283_CR29","doi-asserted-by":"crossref","unstructured":"S.\u00a0Garg, R.\u00a0Bhaskar, S.V. Lokam, Improved bounds on security reductions for discrete log based signatures, in CRYPTO\u00a02008. LNCS, vol. 5157 (Springer, Heidelberg, 2008), pp. 93\u2013107","DOI":"10.1007\/978-3-540-85174-5_6"},{"key":"9283_CR30","doi-asserted-by":"crossref","unstructured":"S.\u00a0Goldwasser, S.\u00a0Micali, R.L. Rivest, A \u201cparadoxical\u201d solution to the signature problem (extended abstract), in 25th FOCS (IEEE Computer Society Press, Washington, 1984), pp. 441\u2013448","DOI":"10.1109\/SFCS.1984.715946"},{"issue":"1","key":"9283_CR31","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1137\/0218012","volume":"18","author":"S Goldwasser","year":"1989","unstructured":"S.\u00a0Goldwasser, S.\u00a0Micali, C.\u00a0Rackoff, The knowledge complexity of interactive proof systems. SIAM J. Comput. \n                           18(1), 186\u2013208 (1989)","journal-title":"SIAM J. Comput."},{"issue":"2","key":"9283_CR32","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/s00145-005-0307-3","volume":"19","author":"JA Garay","year":"2006","unstructured":"J.A. Garay, P.D. MacKenzie, K.\u00a0Yang, Strengthening zero-knowledge protocols using signatures. J. Cryptol. \n                           19(2), 169\u2013209 (2006)","journal-title":"J. Cryptol."},{"key":"9283_CR33","doi-asserted-by":"crossref","unstructured":"O.\u00a0Goldreich, Two remarks concerning the Goldwasser\u2013Micali\u2013Rivest signature scheme, in CRYPTO\u201986. LNCS, vol. 263 (Springer, Heidelberg, 1987), pp. 104\u2013110","DOI":"10.1007\/3-540-47721-7_8"},{"key":"9283_CR34","doi-asserted-by":"crossref","unstructured":"L.C. Guillou, J.-J. Quisquater, A practical zero-knowledge protocol fitted to security microprocessor minimizing both trasmission and memory, in EUROCRYPT\u201988. LNCS, vol. 330 (Springer, Heidelberg, 1988), pp. 123\u2013128","DOI":"10.1007\/3-540-45961-8_11"},{"key":"9283_CR35","doi-asserted-by":"crossref","unstructured":"J.\u00a0Groth, Simulation-sound NIZK proofs for a practical language and constant size group signatures, in ASIACRYPT\u00a02006. LNCS, vol. 4284 (Springer, Heidelberg, 2006), pp. 444\u2013459","DOI":"10.1007\/11935230_29"},{"key":"9283_CR36","doi-asserted-by":"crossref","unstructured":"J.\u00a0Groth, A.\u00a0Sahai, Efficient non-interactive proof systems for bilinear groups, in EUROCRYPT\u00a02008. LNCS, vol. 4965 (Springer, Heidelberg, 2008), pp. 415\u2013432","DOI":"10.1007\/978-3-540-78967-3_24"},{"key":"9283_CR37","unstructured":"K.\u00a0Haralambiev, Efficient cryptographic primitives for non-interactive zero-knowledge proofs and applications. Ph.D. thesis, New York University (2011)"},{"key":"9283_CR38","doi-asserted-by":"crossref","unstructured":"D.\u00a0Hofheinz, T.\u00a0Jager, Tightly secure signatures and public-key encryption, in CRYPTO\u00a02012. LNCS, vol. 7417 (Springer, Heidelberg, 2012), pp. 590\u2013607","DOI":"10.1007\/978-3-642-32009-5_35"},{"key":"9283_CR39","doi-asserted-by":"crossref","unstructured":"S.\u00a0Hohenberger, B.\u00a0Waters, Short and stateless signatures from the RSA assumption, in CRYPTO\u00a02009. LNCS, vol. 5677 (Springer, Heidelberg, 2009), pp. 654\u2013670","DOI":"10.1007\/978-3-642-03356-8_38"},{"issue":"4","key":"9283_CR40","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/s001459900012","volume":"9","author":"R Impagliazzo","year":"1996","unstructured":"R.\u00a0Impagliazzo, M.\u00a0Naor, Efficient cryptographic schemes provably as secure as subset sum. J. Cryptol. \n                           9(4), 199\u2013216 (1996)","journal-title":"J. Cryptol."},{"key":"9283_CR41","doi-asserted-by":"crossref","unstructured":"G.\u00a0Itkis, L.\u00a0Reyzin, Forward-secure signatures with optimal signing and verifying, in CRYPTO\u00a02001. LNCS, vol. 2139 (Springer, Heidelberg, 2001), pp. 332\u2013354","DOI":"10.1007\/3-540-44647-8_20"},{"key":"9283_CR42","doi-asserted-by":"crossref","unstructured":"M.\u00a0Joye, B.\u00a0Libert, Efficient cryptosystems from \n                    \n                      \n                    \n                    $$2^k$$\n                    \n                      \n                        \n                          2\n                          k\n                        \n                      \n                    \n                  -th power residue symbols, in EUROCRYPT\u00a02013. LNCS, vol. 7881 (Springer, Heidelberg, 2013), pp. 76\u201392","DOI":"10.1007\/978-3-642-38348-9_5"},{"key":"9283_CR43","doi-asserted-by":"crossref","unstructured":"C.S. Jutla, A.\u00a0Roy, Shorter quasi-adaptive NIZK proofs for linear subspaces, in ASIACRYPT\u00a02013, Part\u00a0I. LNCS, vol. 8269 (Springer, Heidelberg, 2013), pp. 1\u201320","DOI":"10.1007\/978-3-642-42033-7_1"},{"key":"9283_CR44","doi-asserted-by":"crossref","unstructured":"S.A. Kakvi, E.\u00a0Kiltz, Optimal security proofs for full domain hash, revisited, in EUROCRYPT\u00a02012. LNCS, vol. 7237 (Springer, Heidelberg, 2012), pp. 537\u2013553","DOI":"10.1007\/978-3-642-29011-4_32"},{"key":"9283_CR45","doi-asserted-by":"crossref","unstructured":"E.\u00a0Kiltz, A.\u00a0O\u2019Neill, A.\u00a0Smith, Instantiability of RSA-OAEP under chosen-plaintext attack, in CRYPTO\u00a02010. LNCS, vol. 6223 (Springer, Heidelberg, 2010), pp. 295\u2013313","DOI":"10.1007\/978-3-642-14623-7_16"},{"key":"9283_CR46","doi-asserted-by":"crossref","unstructured":"H.\u00a0Krawczyk, Simple forward-secure signatures from any signature scheme, in ACM CCS 00 (ACM Press, New York, 2000), pp. 108\u2013115","DOI":"10.1145\/352600.352617"},{"key":"9283_CR47","doi-asserted-by":"crossref","unstructured":"J.\u00a0Katz, V.\u00a0Vaikuntanathan, Signature schemes with bounded leakage resilience, in ASIACRYPT\u00a02009. LNCS, vol. 5912 (Springer, Heidelberg, 2009), pp. 703\u2013720","DOI":"10.1007\/978-3-642-10366-7_41"},{"key":"9283_CR48","doi-asserted-by":"crossref","unstructured":"J.\u00a0Katz, N.\u00a0Wang, Efficiency improvements for signature schemes with tight security reductions, in ACM CCS 03 (ACM Press, New York, 2003), pp. 155\u2013164","DOI":"10.1145\/948109.948132"},{"key":"9283_CR49","doi-asserted-by":"crossref","unstructured":"V.\u00a0Lyubashevsky, D.\u00a0Micciancio, Generalized compact Knapsacks are collision resistant, in ICALP 2006, Part\u00a0II. LNCS, vol. 4052 (Springer, Heidelberg, 2006), pp. 144\u2013155","DOI":"10.1007\/11787006_13"},{"key":"9283_CR50","unstructured":"S.\u00a0Micali, A secure and efficient digital signature algorithm. Technical Memo MIT\/LCS\/TM-501b, Massachusetts Institute of Technology, Laboratory for Computer Science, Apr 1994"},{"key":"9283_CR51","doi-asserted-by":"crossref","unstructured":"D.\u00a0Micciancio, P.\u00a0Mol, Pseudorandom knapsacks and the sample complexity of LWE search-to-decision reductions, in CRYPTO\u00a02011. LNCS, vol. 6841 (Springer, Heidelberg, 2011), pp. 465\u2013484","DOI":"10.1007\/978-3-642-22792-9_26"},{"key":"9283_CR52","doi-asserted-by":"crossref","unstructured":"T.\u00a0Malkin, D.\u00a0Micciancio, S.K. Miner, Efficient generic forward-secure signatures with an unbounded number of time periods, in EUROCRYPT\u00a02002. LNCS, vol. 2332 (Springer, Heidelberg, 2002), pp. 400\u2013417","DOI":"10.1007\/3-540-46035-7_27"},{"issue":"1","key":"9283_CR53","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s00145-001-0005-8","volume":"15","author":"S Micali","year":"2002","unstructured":"S.\u00a0Micali, L.\u00a0Reyzin, Improving the exact security of digital signature schemes. J. Cryptol. \n                           15(1), 1\u201318 (2002)","journal-title":"J. Cryptol."},{"issue":"3","key":"9283_CR54","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1023\/B:DESI.0000036250.18062.3f","volume":"33","author":"A Menezes","year":"2004","unstructured":"A.\u00a0Menezes, N.\u00a0Smart, Security of signature schemes in a multi-user setting. Des. Codes Cryptogr. \n                           33(3), 261\u2013274 (2004)","journal-title":"Des. Codes Cryptogr."},{"key":"9283_CR55","doi-asserted-by":"crossref","unstructured":"K.\u00a0Ohta, T.\u00a0Okamoto, A modification of the Fiat\u2013Shamir scheme, in CRYPTO\u201988. LNCS, vol. 403 (Springer, Heidelberg, August 1990), pp. 232\u2013243","DOI":"10.1007\/0-387-34799-2_17"},{"key":"9283_CR56","doi-asserted-by":"crossref","unstructured":"H.\u00a0Ong, C.-P. Schnorr, Fast signature generation with a Fiat\u2013Shamir-like scheme, in EUROCRYPT\u201990. LNCS, vol. 473 (Springer, Heidelberg, 1991), pp. 432\u2013440","DOI":"10.1007\/3-540-46877-3_38"},{"key":"9283_CR57","doi-asserted-by":"crossref","unstructured":"P.\u00a0Paillier, Public-key cryptosystems based on composite degree residuosity classes, in EUROCRYPT\u201999. LNCS, vol. 1592 (Springer, Heidelberg, 1999), pp. 223\u2013238","DOI":"10.1007\/3-540-48910-X_16"},{"key":"9283_CR58","doi-asserted-by":"crossref","unstructured":"C.\u00a0Peikert, A.\u00a0Rosen, Efficient collision-resistant hashing from worst-case assumptions on cyclic lattices, in TCC\u00a02006. LNCS, vol. 3876 (Springer, Heidelberg, 2006), pp. 145\u2013166","DOI":"10.1007\/11681878_8"},{"key":"9283_CR59","doi-asserted-by":"crossref","unstructured":"S.\u00a0Patel, G.S. Sundaram, An efficient discrete log pseudo random generator, in CRYPTO\u201998. LNCS, vol. 1462 (Springer, Heidelberg, 1998), pp. 304\u2013317","DOI":"10.1007\/BFb0055737"},{"issue":"3","key":"9283_CR60","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/s001450010003","volume":"13","author":"D Pointcheval","year":"2000","unstructured":"D.\u00a0Pointcheval, J.\u00a0Stern, Security arguments for digital signatures and blind signatures. J. Cryptol. \n                           13(3), 361\u2013396 (2000)","journal-title":"J. Cryptol."},{"key":"9283_CR61","doi-asserted-by":"crossref","unstructured":"P.\u00a0Paillier, D.\u00a0Vergnaud, Discrete-log-based signatures may not be equivalent to discrete log, in ASIACRYPT\u00a02005. LNCS, vol. 3788 (Springer, Heidelberg, 2005), pp. 1\u201320","DOI":"10.1007\/11593447_1"},{"key":"9283_CR62","doi-asserted-by":"crossref","unstructured":"C.-P. Schnorr, Efficient identification and signatures for smart cards (abstract) (rump session), in EUROCRYPT\u201989. LNCS, vol. 434 (Springer, Heidelberg, 1990), pp. 688\u2013689","DOI":"10.1007\/3-540-46885-4_68"},{"key":"9283_CR63","doi-asserted-by":"crossref","unstructured":"Y.\u00a0Seurin, On the exact security of Schnorr-type signatures in the random oracle model, in EUROCRYPT\u00a02012. LNCS, vol. 7237 (Springer, Heidelberg, 2012), pp. 554\u2013571","DOI":"10.1007\/978-3-642-29011-4_33"},{"key":"9283_CR64","doi-asserted-by":"crossref","unstructured":"P.C. van Oorschot, M.J. Wiener, On Diffie\u2013Hellman key agreement with short exponents, in EUROCRYPT\u201996. LNCS, vol. 1070 (Springer, Heidelberg, 1996), pp. 332\u2013343","DOI":"10.1007\/3-540-68339-9_29"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-018-9283-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-018-9283-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-018-9283-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,8]],"date-time":"2020-04-08T08:10:28Z","timestamp":1586333428000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-018-9283-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,2,28]]},"references-count":64,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,1]]}},"alternative-id":["9283"],"URL":"https:\/\/doi.org\/10.1007\/s00145-018-9283-2","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,2,28]]},"assertion":[{"value":"28 June 2013","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 January 2018","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 February 2018","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}