摘要

Online/offline signatures are used in a particular scenario where the signer must respond quickly once the message to be signed is presented. In this paper, we present a general method to efficiently convert a trapdoor hash family into an online/offline signature scheme without resorting to any additional signature scheme. We prove that the new scheme is secure in the random oracle model if the underlying trapdoor hash family is collision resistant. Compared to Shamir and Tauman's paradigm, there is an almost 50% reduction in overall computational cost by using the new scheme.