Unidirectional Identity-Based Proxy Re-Signature
To construct a suitable and secure proxy re-signature scheme is not an easy job. Up to now, there exist only a few schemes. None of these schemes is unidirectional identity-based proxy re-signature, where a semi-trusted proxy can transform a signature under an identity to another signature under another identity on the same message, while the proxy cannot generate any signature on behalf of any of these two identities. In this paper, based on Schnorr's signature and Libert-Vergnaud proxy re-signature, the authors propose the first unidirectional identity-based proxy re-signature, which is existentially unforgeable in the random oracle model based on the extended computational Diffie-Hellman assumption.