Abstract. In this paper, we propose a signcryption scheme which provides all the following properties at the same time. (1) forward security: the private key of a sender does not help any attack to break the confidentiality of any signcrypted message generated by the sender. (2) signature verification on the signcrypted message: this is done without revealing the original message. (3) a standardized signature mechanism: in our scheme, both the non-repudiation of the message and the signcrypted message can be done using the standardized digital signature algorithm; ECDSA. The efficiency and features of our scheme are compared with other schemes and the security is proved in the random oracle model.