A Short Group Signature with IND-CCA2 Full-Anonymity

Yue Zhang · Chinese Journal of Computers · 2007

In CRYPTO 2004,a short group signature is proposed by Boneh,Boyen and Shacham, which is based on strong Diffie-Hellman(SDH) assumption and Decision Linear assumption.Thereafter it is denoted BBS.Only chosen plaintext attack(CPA) full-anonymity is achieved in BBS short group signature for CPA secure in linear encryption.In this case,adversary could not query an open oracle.However, when adversaries try to break the notion of chosen ciphertext attack(IND-CCA2) full-anonymity,they have the ability to query an open oracle in the current and strongest security model for group signatures.Hence adversaries can obtain the signer identity of the queried signature.This paper presents a new zero-knowledge protocol for SDH,which based on Cramer-Shoup encryption from the linear assumption.Using this protocol as a building block,a new short group signature is constructed in this paper,which is provable secure in the Bellare-Micciancio-Warinshi model.The scheme is of IND-CCA2-full-anonymity,which allows adversary querying open oracle when trying to attack the anonymity notion.And the signature is only 1704 bits in size.

Read the paper · More papers on PaperTik