An efficient signcryption scheme based on elliptic curve is proposed in this paper. The signcryption scheme combines digital signature and encryption functions. The proposed scheme takes lower computation and communication cost to provide security functions. It not only provides message confidentiality, authentication, integrity, unforgeability, and non-repudiation, but also forward secrecy for message confidentiality and public verification. In the proposed scheme, the judge can verify sender s signature directly without the sender s private key when dispute occurs. Our scheme can be applied to mobile communication environment more efficiently because of the low computation and communication cost. 2004 Elsevier Inc. All rights reserved.