Separability and Eciency for Generic Group Signature Schemes (Extended Abstract)
Jan L. Camenisch, Markus Michels · 1999
A cryptographic protocol possesses separability if the par- ticipants can choose their keys independently of each other. This is ad- vantageous from a key-management as well as from a security point of view. This paper focuses on separability in group signature schemes. Such schemes allow a group member to sign messages anonymously on the group's behalf. However, in case of this anonymity's misuse, a trustee can reveal the originator of a signature. We provide a generic fully separa- ble group signature scheme and present an ecient instantiation thereof. The scheme is suited for large groups; the size of the group's public key and the length of signatures do not depend on the number of group member. Its eciency is comparable to the most ecient schemes that do not oer separability and is an order of magnitude more ecient than a previous scheme that provides partial separability. As a side result, we provide ecient proofs of the equality of two discrete logarithms from dierent groups and, more general, of the validity of polynomial relations in among discrete logarithms from dierent groups.