Posterior Security: Anonymity and Message Hiding of Standard Signatures
Tsz Hon Yuen, Ying-Teng Chen, Shimin Pan, Jiangshan Yu, Joseph K. Liu
Abstract
We introduce posterior security of digital signatures, the additional security features after the original signature is generated. It is motivated by the scenario that some people store their secret keys in secure hardware and can only obtain a standard signature through a standardized interface. In this paper, we consider two different posterior security features: anonymity and message hiding.
We first introduce incognito signature, a new mechanism to anonymize a standard signature. Different from other ring or group signatures, the signer generates a standard (non-anonymous) signature first. The signature is then anonymized by a converter before sending to the verifier, by hiding the signer public key with a set of decoy public keys. We then introduce concealed signature which hides the message in a commitment. The standard signature is converted such that it can be verified with the commitment. The models of posterior anonymity and posterior message hiding capture the separation of the signer and the converter. Anonymity or message hiding is provided by the converter after the creation of a standard signature by the signer. It is useful in applications like two-tier central bank digital currency, where users want to hide their addresses (public keys) and transaction amounts (messages) when the payment is settled in the interbank layer.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 82e97025-d42b-42c3-96c2-21ba0c2bd340Builds on8
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Fast Multiparty Threshold ECDSA with Fast Trustless SetupRosario Gennaro, Steven GoldfederCCS 2018 · 264 citations
- Lattice-Based Zero-Knowledge Proofs and Applications: Shorter, Simpler, and More GeneralVadim Lyubashevsky, Ngoc Khanh Nguyen, Maxime PlançonCRYPTO 2022 · 125 citations
- DualRing: Generic Construction of Ring Signatures with Efficient InstantiationsTsz Hon Yuen, Muhammed F. Esgin, Joseph K. Liu, Man Ho Au et al.CRYPTO 2021 · 83 citations
- Time- and Space-Efficient Arguments from Groups of Unknown OrderAlexander R. Block, Justin Holmgren, Alon Rosen, Ron D. Rothblum et al.CRYPTO 2021 · 67 citations
Related papers
- Anonymous Tokens with Designated-Reader Metadata BitAisha Tu, Meng Jia, Kun He, Jing Chen et al.USENIX Security 2026
- A Unified Treatment of Anamorphic EncryptionWonseok Choi, Daniel Collins, Xiangyu Liu, Roy Stracovsky et al.CRYPTO 2026
- Foundations of Adaptor SignaturesPaul Gerhart, Dominique Schröder, Pratik Soni, Sri Aravinda Krishnan ThyagarajanEUROCRYPT 2024 · 21 citations
- Bifurcated Signatures: Folding the Accountability vs. Anonymity Dilemma into a Single Private Signing SchemeBenoît Libert, Khoa Nguyen, Thomas Peters, Moti YungEUROCRYPT 2021 · 23 citations
- Multimodal Private SignaturesKhoa Nguyen, Fuchun Guo, Willy Susilo, Guomin YangCRYPTO 2022 · 19 citations
