A preliminary version of this paper appears in the proceedings of ESORICS 2014 [PS14]. The full version appears in the International Journal of Information Security [PS15]. This is the author's copy of the full version. The final publication is available at Springer via http://dx.doi.org/10.1007/s10207-015-0307-8. Double-authentication-preventing signatures Bertram Poettering1 and Douglas Stebila2 1 Foundations of Cryptography, Ruhr University Bochum, Germany 2 School of Electrical Engineering and Computer Science and School of Mathematical Sciences, Queensland University of Technology, Brisbane, Australia
[email protected] [email protected] January 18, 2016 Abstract Digital signatures are often used by trusted authorities to make unique bindings between a subject and a digital object; for example, certificate authorities certify a public key belongs to a domain name, and time-stamping authorities certify that a certain piece of information existed at a certain time. Traditional digital signature schemes however impose no uniqueness conditions, so a trusted authority could make multiple certifications for the same subject but different objects, be it intentionally, by accident, or following a (legal or illegal) coercion. We propose the notion of a double-authentication-preventing signature, in which a value to be signed is split into two parts: a subject and a message. If a signer ever signs two different messages for the same subject, enough information is revealed to allow anyone to compute valid signatures on behalf of the signer. This double-signature forgeability property discourages signers from misbehaving|a form of self-enforcement|and would give binding authorities like CAs some cryptographic arguments to resist legal coercion.