Gradually releasable commitment scheme allows a party to transfer, bit by bit, his committed secret to his counterpart. It can be applicable to many cryptographic protocols. This paper proposes two types of gradually releasable commitment schemes: one is computationally secure and information-theoretically unambiguous. and the other is information-theoretically secure and computationally unambiguous, which are based oa one-way permutation and claw-free permutation pair, respectively. Moreover we describe their applications to cryptographic protocols.
展开▼