Practical Group Signatures without Random Oracles.
Giuseppe Ateniese, Jan L. Camenisch, Susan Hohenberger, Breno de Medeiros · 2005
We present the first practical group signature scheme that is provably secure in the standard model without the need for relaxed setup assumptions. The proof follows a new ideal/real-world definition of security for group signatures that encapsulates all the standard properties of unforgeability, anonymity, unlinkability, and exculpability. Security of our constructions require certain cryptographic assumptions, namely the Strong LRSW, EDH, and Strong SXDH assumptions. Evidence for the newly introduced assumptions is provided by proving them secure in the generic group model.