摘要

The notion of optimal online/online signature (O-3 signature) is an extension to the notion of online/online signature, where all necessary computations are carried out in the offline phase before the message is available and the signer does not need to conduct any computation to construct the final signature in the online phase. We present a practical O-3 signature scheme secure under the stateful signatures of Hohenberger and Waters (HW signature). The advantages of our scheme can be listed as follows: firstly, the heavy computation of offline phase can be carried out on multiple machines, and does not need them to work synchronously; secondly, the public key of our scheme is very short, which makes the scheme is very convenient to be used. We proved that it is secure under computational Diffie-Hellman problems in the standard model. Our proof is not with the help of chameleon hash function, but fully uses the characteristic of bit-structure in O-3 signature.