Linkable Democratic Group Signatures.
Mark Manulis, Ahmad‐Reza Sadeghi, Jörg Schwenk · 2006
For many mutli-party applications group signatures are important cryptographic primitives that can be used for the purpose of anonymity and privacy. Group signatures can be used by employees of a company to sign documents on behalf of the company, or in electronic voting and bidding scenarios. In classical group signatures members of a group are able to sign messages anonymously on behalf of the group. However, there exists a designated authority, called group manager, that initializes the scheme, adds new group members, and is able to open group signatures, i.e., identify the signer. Some group signature schemes distinguish between two management authorities: a membership manager that sets up the scheme and controls admission to the group, and a revocation manager that opens the signatures. Obviously, in classical group signatures the group manager is given enormous power compared to other group members and is required to be trusted to act as predestinated. On the other hand there exist multi-party applications where such centralized control (trust) is undesirable, e.g., distributed or federated systems. For this kind of applications it is desirable to have a group signature scheme which provides similar properties but is independent of any centralized control. In this talk we summarize research results concerning this issue. In particular we have proposed a