{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T02:40:48Z","timestamp":1779936048839,"version":"3.53.1"},"reference-count":55,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2005,4,1]],"date-time":"2005-04-01T00:00:00Z","timestamp":1112313600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Des Codes Crypt"],"published-print":{"date-parts":[[2005,4]]},"DOI":"10.1007\/s10623-003-6154-z","type":"journal-article","created":{"date-parts":[[2005,2,28]],"date-time":"2005-02-28T20:01:45Z","timestamp":1109620905000},"page":"119-152","source":"Crossref","is-referenced-by-count":82,"title":["Generic Groups, Collision Resistance, and ECDSA"],"prefix":"10.1007","volume":"35","author":[{"given":"Daniel R. L.","family":"Brown","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"CR1","unstructured":"M. Abdalla, M. Bellare and P. Rogaway, The oracle Diffie-Hellman assumptions and an analysis of DHIES, In Topics in Cryptology CT-RSA 2001, D. Naccache, (ed.), Vol. 2020 of Lecture Notes in Computer Science, Springer-Verlag, (2001) pp. 143?158."},{"key":"CR2","unstructured":"ANSI X9.62. Public Key Cryptography for the Financial Services Industry: the Elliptic Curve Digital Signature Algorithm (ECDSA). American National Standards Institute, (1999)."},{"key":"CR3","unstructured":"M. Bellare, S. Goldwasser and D. Micciancio, ??Pseudo-Random?? number generation within cryptographic algorithms: The DSS case, In Advances in Cryptology EUROCRYPT?97, W. Fumy (ed.), Vol. 1233 of Lecture Notes in Computer Science, Springer-Verlag, (1997) pp. 277?291."},{"key":"CR4","unstructured":"M. Bellare and P. Rogaway, The exact security of digital signatures?-how to sign with RSA and Rabin. In Advances in Cryptology EUROCRYPT ?96, U. Maurer, (ed.), Vol. 1070 of Lecture Notes in Computer Science, Springer-Verlag, (1996) pp. 399?416."},{"key":"CR5","doi-asserted-by":"crossref","unstructured":"M. Bellare and P. Rogaway, Random oracles are practical: A paradigm for designing efficient protocols, In First ACM Conference on Computer and Communications Security, ACM, (1993) pp. 62?73.","DOI":"10.1145\/168588.168596"},{"key":"CR6","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9781107360211","volume-title":"Elliptic Curves in Cryptography","author":"I. Blake","year":"1999"},{"key":"CR7","doi-asserted-by":"crossref","unstructured":"S. Blake-Wilson, D. B. Johnson and A. J. Menezes, Key agreement protocols and their security analysis, In Proceedings of the 6th IMA International Conference on Cryptography and Coding, Vol. 1355 of Lecture Notes in Computer Science, Springer-Verlag, (1997) pp. 30?45.","DOI":"10.1007\/BFb0024447"},{"key":"CR8","unstructured":"D. Bleichenbacher, On the generation of one-time keys in DSS, Presented at the Monteverta workshop, (2001)."},{"key":"CR9","unstructured":"D. Boneh and R. J. Lipton, Algorithms for black-box fields and their application to cryptography, In Advances in Cryptology ?- EUROCRYPT ?96 N. Koblitz (ed.), Vol. 1109 of Lecture Notes in Computer Science, (1996) pp. 283?297."},{"key":"CR10","unstructured":"D. K. Branstad and M. E. Smid, Response to comments on the NIST proposed digital signature standard, In Advances in Cryptology ?- EUROCRYPT ?92 E. F. Brickell, (ed.), Vol. 740 of Lecture Notes in Computer Science, Springer-Verlag, (1992) pp. 76?88."},{"key":"CR11","doi-asserted-by":"crossref","unstructured":"E. F. D. Brickell, S. Pointcheval, S. Vaudenay and M. Yung, Design validations for discrete logarithm based signature schemes, In Proceedings of Third International Workshop on Practice and Theory in Public Key Cryptosystems, PKC 2000, H. Imai and Y. Zheng, (ed.), Vol. 1751 of Lecture Notes in Computer Science, Springer-Verlag, (2000) pp. 276?292.","DOI":"10.1007\/978-3-540-46588-1_19"},{"key":"CR12","unstructured":"D. R. L. Brown and D. B. Johnson, Formal security proofs for a signature scheme with partial message recovery, In Topics in Cryptology ?- CT-RSA 2001, D. Naccache, (ed.), Vol. 2020 of Lecture Notes in Computer Science, Springer-Verlag, (2001) pp. 126?142."},{"key":"CR13","doi-asserted-by":"crossref","unstructured":"R. Canetti, O. Goldreich and S. Halevi, The random oracle methodology, revisited, In Proceedings of the 30th Annual ACM Symposium on the Theory of Computing, (1998).","DOI":"10.1145\/276698.276741"},{"key":"CR14","unstructured":"Certicom ECC challenge, November 1997. http:\/\/www.certicom.com\/resources\/eccchall\/challenge. html."},{"key":"CR15","unstructured":"J.-S. Coron, On the exact security of full domain hash, In Advances in Cryptology ?- CRYPTO 2000, M. Bellare, (ed.), Vol. 1880 of Lecture Notes in Computer Science, Springer-Verlag, (2000) pp. 229?235."},{"issue":"3","key":"CR16","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1145\/357830.357847","volume":"3","author":"R. Cramer","year":"2000","journal-title":"ACM Transactions on Information and System Security"},{"key":"CR17","unstructured":"I. B. Damgaard, Collision free hash functions and public key signatures schemes, In Advances in Cryptology ?- EUROCRYPT ?87 D. Chaum and W. L. Price, (ed), Vol. 304 of Lecture Notes in Computer Science, Springer-Verlag, (1987) pp. 203?216."},{"key":"CR18","unstructured":"I. B. Damgaard, A design principle for hash functions, In Advances in Cryptology ?- CRYPTO ?89 G. Brassard, (ed.), Vol. 435 of Lecture Notes in Computer Science, Springer-Verlag, (1989) pp. 416?427."},{"key":"CR19","unstructured":"B. Den boer, Diffie-Hellman is a strong as discrete log for certain primes, In Advances in Cryptology ?- CRYPTO ?88 S. Goldwasser, (ed.), Vol. 403 of Lecture Notes in Computer Science. Springer-Verlag. (1988)."},{"key":"CR20","doi-asserted-by":"crossref","first-page":"187","DOI":"10.1007\/s001459900043","volume":"11","author":"C. Dwork","year":"1998","journal-title":"Journal of Cryptology"},{"key":"CR21","unstructured":"FIPS 186-2. Digital Signature Standard, National Institute of Standards and Technology (2000)."},{"key":"CR22","unstructured":"M. Fischlin, A note on security proofs in the generic model, In Advances in Cryptology ?- ASIACRYPTO 2000 T. Okamoto, (ed.), Vol. 1976 of Lecture Notes in Computer Science, Springer-Verlag, (2000) pp. 458?469."},{"key":"CR23","unstructured":"P. Flajolet and A. M. Odlyzko, Random mapping statistics, In Advances in Cryptology ?- EUROCRYPTO ?89 J.-J. Quisquater and J. Vandewalle, (ed.), Vol. 434 of Lecture Notes in Computer Science, Springer-Verlag, (1989) pp. 329?354."},{"key":"CR24","unstructured":"R. Gennaro, S. Halevi and T. Rabin, Secure hash-and-sign without the random oracle, In Advances in Cryptology ?- EUROCRYPTO ?99 J. Stern (ed.), Vol. 1592 of Lecture Notes in Computer Science, Springer-Verlag, (1999) pp. 123?139."},{"issue":"2","key":"CR25","doi-asserted-by":"crossref","first-page":"281","DOI":"10.1137\/0217017","volume":"17","author":"S. Goldwasser","year":"1998","journal-title":"SIAM Journal of Computing"},{"key":"CR26","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1023\/A:1011214926272","volume":"23","author":"N.A. Howgrave-Graham","year":"2001","journal-title":"Designs, Codes and Cryptography"},{"key":"CR27","unstructured":"IEEE Std 1363-2000, Standard Specifications for Public Key Cryptography, Institute of Electrical and Electronics Engineers, (2000)."},{"key":"CR28","unstructured":"ISO\/IEC 14888-3, Information Technology?-Security Techniques?-Digital Sigantures with Appendix?-Part 3: Certificate Based Mechanisms, International Standards Organization, (1998)."},{"key":"CR29","doi-asserted-by":"crossref","unstructured":"M.. Jakobsson and C. P. Schnorr, Security of signed ElGamal encryption, In Advances in Cryptology?-ASIACRYPTO 2000 T. Okamoto, (ed.), Vol. 1976 of Lecture Notes in Computer Science, Springer-Verlag, (2000) pp. 73?89. Available at http:\/\/www.mi.informatik.uni-frankfurt.de\/research\/papers.html.","DOI":"10.1007\/3-540-44448-3_7"},{"key":"CR30","unstructured":"D. Johnson and A. Menezes, The elliptic curve digital signature algorithm (ECDSA), Technical Report CORR 99?34, Deptartment of Combinatorics and Optimization, University of Waterloo, Waterloo, (1999). Available at http:\/\/www.cacr.math.uwaterloo.ca."},{"key":"CR31","unstructured":"B. S. Kaliski, A pseudo-random bit generator based on elliptic logarithms, In Advances in Cryptology ?- CRYPTO ?86 A. M. Odlyzko, (ed.), Vol. 263 of Lecture Notes in Computer Science, Springer-Verlag, (1986) pp. 84?103."},{"key":"CR32","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1090\/S0025-5718-1987-0866109-5","volume":"48","author":"N. Koblitz","year":"1987","journal-title":"Mathematics of Computation"},{"key":"CR33","doi-asserted-by":"crossref","unstructured":"N. Koblitz, Algebraic Aspects of Cryptography, Vol. 3 of Algorithms and Computation in Mathematics. Springer-Verlag, (1998).","DOI":"10.1007\/978-3-662-03642-6"},{"key":"CR34","unstructured":"J. Malone-Lee, D. Pointcheval, N. P. Smart and J. Stern, Flaws in applying proof methodologies to signature schemes, In Advances in Cryptology?-CRYPTO 2002 M. Yung, (ed.), Vol. 2442 of Lecture Notes in Computer Science, Springer-Verlag, (2002) pp. 93?110. Available at http:\/\/www.di.ens.fr\/ pointche\/pub.php?reference=MaPoSmSt02."},{"key":"CR35","unstructured":"U. Maurer, Towards the equivalence of breaking the diffie-hellman protocol and computing discrete logarithms, In Advances in Cryptology?-CRYPTO ?94 Y. Desmedt, (ed.), Vol. 839 of Lecture Notes in Computer Science, Springer-Verlag, (1994) pp. 271?281."},{"key":"CR36","unstructured":"U. Maurer and S. Wolf, Lower bounds on generic algorithms in groups, In Advances in Cryptology ?- EUROCRYPTO ?98 K. Nyberg, (ed.), Vol. 1403 of Lecture Notes in Computer Science, Springer-Verlag, pp. 72?84."},{"key":"CR37","doi-asserted-by":"crossref","first-page":"1689","DOI":"10.1137\/S0097539796302749","volume":"28","author":"U. Maurer","year":"1999","journal-title":"SIAM Journal on Computing"},{"key":"CR38","unstructured":"A. Menezes and N. Smart, Security of signature schemes in a multi-user setting. preprint, (2001)."},{"key":"CR39","doi-asserted-by":"crossref","unstructured":"A. J. Menezes, Elliptic Curve Public Key Cryptosystems, Communications and Information Theory, Kluwer Academic Press, (1993).","DOI":"10.1007\/978-1-4615-3198-2"},{"key":"CR40","volume-title":"Handbook of Applied Cryptography, Discrete Mathematics and Its Applications","author":"A.J. Menezes","year":"1997"},{"key":"CR41","doi-asserted-by":"crossref","unstructured":"V. S. Miller, Uses of elliptic curves in cryptography, In Advances in Cryptology ?- CRYPTO ?85 H. C. Williams, (ed.), Vol. 218 of Lecture Notes in Computer Science, Springer-Verlag, pp. 417?426. (1985).","DOI":"10.1007\/3-540-39799-X_31"},{"issue":"2","key":"CR42","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1007\/BF02113297","volume":"55","author":"V.I. Nechaev","year":"1994","journal-title":"Mathematical Notes"},{"key":"CR43","doi-asserted-by":"crossref","unstructured":"P. Q. Nguyen and I. E. Shparlinski, The insecurity of the digital signature algorithm with partially known nonces, Journal of Cryptology, to appear.","DOI":"10.1007\/s00145-002-0021-3"},{"key":"CR44","unstructured":"T. Okamoto. Provably secure and practical identification schemes and corresponding signature schemes, In Advances in Cryptology ?- CRYPTO ?92 E. F. Brickell, (ed.), Vol. 740 of Lecture Notes in Computer Science, Springer-Verlag, (1992) pp. 31?53."},{"issue":"3","key":"CR45","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1007\/s001450010003","volume":"13","author":"D. Pointcheval","year":"2000","journal-title":"Journal of Cryptology"},{"key":"CR46","doi-asserted-by":"crossref","unstructured":"B. Preneel, The state of cryptographic hash functions, In Lectures on Data Security, I. Damgaard (ed.), Lectures on Data Security, Vol. 1561 of Lecture Notes in Computer Science, pp. 158?182. (1999).","DOI":"10.1007\/3-540-48969-X_8"},{"key":"CR47","unstructured":"T. Schweinberger and V. Shoup. ACE: The advanced cryptographic engine. Submission to NESSIE, aug 2000. Available at http:\/\/shoup.net\/papers\/."},{"key":"CR48","unstructured":"SEC 1, Elliptic Curve Cryptography. Standards for Efficient Cryptography, Available at www.secg.org. (2000)."},{"key":"CR49","unstructured":"V. Shoup, Lower bounds for discrete logarithms and related problems, In Advances in Cryptology ?- EUROCRYPTO ?97 W. Fumy, (ed.), Vol. 1233 of Lecture Notes in Computer Science, Springer-Verlag, (1997) pp. 256?266."},{"key":"CR50","unstructured":"V. Shoup, A proposal for an ISO standard for public key encryption (version 2.0), Sept. 2001. Available at http:\/\/shoup.net\/papers\/."},{"key":"CR51","unstructured":"D. R. Simon, Finding collisions on a one-way street: Can secure hash functions be based on general assumptions? In Advances in Cryptology ?- EUROCRYPTO ?98 K. Nyberg, (ed.), Vol. 1403 of Lecture Notes in Computer Science, Springer-Verlag, (1998) pp. 334?345."},{"key":"CR52","volume-title":"Cryptography: Theory and Practice, Discrete Mathematics and Its Applications","author":"D.R. Stinson","year":"1995"},{"key":"CR53","unstructured":"D. R. Stinson, Some observations on the theory of cryptographic hash functions. Cryptology ePrint Archive, Report 2001\/020, (2001). Available at http:\/\/eprint.iacr.org\/."},{"key":"CR54","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1145\/138859.138865","volume":"35","author":"S. A. Vanstone","year":"1992","journal-title":"Communications of the ACM"},{"key":"CR55","unstructured":"S. Vaudenay, Hidden collisions on DSS, In Advances in Cryptology ?- CRYPTO ?96 N. Koblitz, (ed.), Vol. 1109 of Lecture Notes in Computer Science, Springer-Verlag, (1996) pp. 83?87."}],"container-title":["Designs, Codes and Cryptography"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-003-6154-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10623-003-6154-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-003-6154-z","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,6]],"date-time":"2020-04-06T02:03:29Z","timestamp":1586138609000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10623-003-6154-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,4]]},"references-count":55,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2005,4]]}},"alternative-id":["6154"],"URL":"https:\/\/doi.org\/10.1007\/s10623-003-6154-z","relation":{},"ISSN":["0925-1022","1573-7586"],"issn-type":[{"value":"0925-1022","type":"print"},{"value":"1573-7586","type":"electronic"}],"subject":[],"published":{"date-parts":[[2005,4]]}}}