Two-Layer Group Signature and Application to E-Cash

Hanwen Feng, Jianwei Liu, Qianhong Wu, Tongge Xu · 2019

We propose a novel variant of group signature schemes called two-layer group signature (TL-GS) scheme. In a TL-GS scheme, each user is equipped with two layer identities, long-term identity for traceability and short-term identity for linkability, while the short-term identity is bound to the long-term one. A signature by a signer convinces a verifier both facts, that (i) the singer has a registered long-term identity which belongs to a dynamic group; and (ii) he has a short-term identity which belongs to a specific spontaneous group. We provide formalized security definitions for TL-GS schemes and propose an secure asymptotic efficient lattice-based TL-GS scheme under the LWE and SIS assumptions. We then propose a post-quantum secure decentralized anonymous E-cash scheme with effective real world identity traceability, by combining the proposed TL-GS scheme with the design principle of CryptoNote protocol. Our scheme is secure against double spending attacks and provides anonymity for both payers and payees. All coin transferring behaviors can only be accomplished through creating transactions, and there is a special authority that can trace the identity of traders from transactions. In addition, the transaction is compact, which means the number of possible inputs has at most logarithmic impacts on the transaction's size.

Read the paper · More papers on PaperTik