Definition and Implementation of Accountable-Subgroup Multisignatures

Yujun Pang · 2002

A multi-signature scheme, accountable-subgroup multisignature (ASM) was defined. ASM scheme enables any subgroup S of a given group of potential signers G to sign efficiently a message M, and the signature can prove the identities of the signers to any verifier. The first formal model of security for multisignature scheme explicitly includes key generation (without trusted third party). A protocol based on Schnorr's signature scheme must be both provable and efficient: only three rounds of communication are needed in each signature. The signing time per signer is as the same as that in single-signer Schnorr scheme, regardless of the number of signers. The verification time is only slightly greater than that for the single-signer Schnorr scheme. The signature length is the same as for the single-signer Schnorr scheme, regardless of the number of signers. The proof of security relies on Random oracles and the hardness of the discrete log problem.

Read the paper · More papers on PaperTik