Short Threshold Dynamic Group Signatures

Traditional group signatures feature a single issuer who can add users to the group of signers and a single opening authority who can reveal the identity of the group member who computed a signature. Interestingly, despite being designed for privacy-preserving applications, they require strong trust...

Full description

Saved in:
Bibliographic Details
Published inSecurity and Cryptography for Networks Vol. 12238; pp. 401 - 423
Main Authors Camenisch, Jan, Drijvers, Manu, Lehmann, Anja, Neven, Gregory, Towa, Patrick
Format Book Chapter
LanguageEnglish
Published Switzerland Springer International Publishing AG 2020
Springer International Publishing
SeriesLecture Notes in Computer Science
Subjects
Online AccessGet full text

Cover

Loading…
Abstract Traditional group signatures feature a single issuer who can add users to the group of signers and a single opening authority who can reveal the identity of the group member who computed a signature. Interestingly, despite being designed for privacy-preserving applications, they require strong trust in these central authorities who constitute single points of failure for critical security properties. To reduce the trust placed on authorities, we introduce dynamic group signatures which distribute the role of issuer and opener over several entities, and support $$ t _I$$ -out-of- $$n_I$$ issuance and $$ t _O$$ -out-of- $$n_O$$ opening. We first define threshold dynamic group signatures and formalize their security. We then give an efficient construction relying on the pairing-based Pointcheval–Sanders (PS) signature scheme (CT-RSA 2018), which yields very short group signatures of two first-group elements and three field elements. We also give a simpler variant of our scheme in which issuance requires the participation of all $$n_I$$ issuers, but still supports $$ t _O$$ -out-of- $$n_O$$ opening. It is based on a new multi-signature variant of the PS scheme which allows for efficient proofs of knowledge and is a result of independent interest. We prove our schemes secure in the random-oracle model under a non-interactive q-type of assumption.
AbstractList Traditional group signatures feature a single issuer who can add users to the group of signers and a single opening authority who can reveal the identity of the group member who computed a signature. Interestingly, despite being designed for privacy-preserving applications, they require strong trust in these central authorities who constitute single points of failure for critical security properties. To reduce the trust placed on authorities, we introduce dynamic group signatures which distribute the role of issuer and opener over several entities, and support $$ t _I$$ -out-of- $$n_I$$ issuance and $$ t _O$$ -out-of- $$n_O$$ opening. We first define threshold dynamic group signatures and formalize their security. We then give an efficient construction relying on the pairing-based Pointcheval–Sanders (PS) signature scheme (CT-RSA 2018), which yields very short group signatures of two first-group elements and three field elements. We also give a simpler variant of our scheme in which issuance requires the participation of all $$n_I$$ issuers, but still supports $$ t _O$$ -out-of- $$n_O$$ opening. It is based on a new multi-signature variant of the PS scheme which allows for efficient proofs of knowledge and is a result of independent interest. We prove our schemes secure in the random-oracle model under a non-interactive q-type of assumption.
Author Towa, Patrick
Drijvers, Manu
Lehmann, Anja
Neven, Gregory
Camenisch, Jan
Author_xml – sequence: 1
  givenname: Jan
  surname: Camenisch
  fullname: Camenisch, Jan
– sequence: 2
  givenname: Manu
  surname: Drijvers
  fullname: Drijvers, Manu
– sequence: 3
  givenname: Anja
  surname: Lehmann
  fullname: Lehmann, Anja
– sequence: 4
  givenname: Gregory
  surname: Neven
  fullname: Neven, Gregory
– sequence: 5
  givenname: Patrick
  surname: Towa
  fullname: Towa, Patrick
  email: tow@zurich.ibm.com
BookMark eNotkDFPwzAQhQ0URFv6DxgyshjOPjuOR1SgIFViaJktJ3GaQomDnQ78e9yW6U7v3Xe6exMy6nznCLllcM8A1INWBUUKCFQqrYHmhsMZmWBSjoI8J2OWM0YRhb4gszT_7xUaRmScek61EnhFJoxpKYRGll-TWYyfAMAFz4HJMblbtT4M2boNLrZ-V2dPv5393lbZIvh9n622m84O-2TekMvG7qKb_dcp-Xh5Xs9f6fJ98TZ_XNKeCxyoqlEJCeC0FQ2wshSVVSh5jYVVjVWa1SK33CGv0slCihJt2eim0pxDyRhOCT_tjX3YdhsXTOn9VzQMzCEYkyiDJr1njjmYQzAJEieoD_5n7-Jg3IGqXDcEu6ta2w8uRJOjACkToaURUOAfjuxhhw
ContentType Book Chapter
Copyright Springer Nature Switzerland AG 2020
Copyright_xml – notice: Springer Nature Switzerland AG 2020
DBID FFUUA
DEWEY 005.82
DOI 10.1007/978-3-030-57990-6_20
DatabaseName ProQuest Ebook Central - Book Chapters - Demo use only
DatabaseTitleList
DeliveryMethod fulltext_linktorsrc
Discipline Computer Science
EISBN 3030579905
9783030579906
EISSN 1611-3349
Editor Galdi, Clemente
Kolesnikov, Vladimir
Editor_xml – sequence: 1
  fullname: Galdi, Clemente
– sequence: 2
  fullname: Kolesnikov, Vladimir
EndPage 423
ExternalDocumentID EBC6340556_295_408
GroupedDBID 38.
AABBV
ACGCR
AEDXK
AEJLV
AEJNW
AEKFX
ALMA_UNASSIGNED_HOLDINGS
APEJL
AVCSZ
AZTDL
BBABE
CYNQG
CZZ
DACMV
ESBCR
FFUUA
I4C
IEZ
OAOFD
OPOMJ
SBO
TPJZQ
TSXQS
Z7R
Z7U
Z7X
Z7Z
Z81
Z83
Z84
Z88
-DT
-GH
-~X
1SB
29L
2HA
2HV
5QI
875
AASHB
ABMNI
ACGFS
ADCXD
AEFIE
EJD
F5P
FEDTE
HVGLF
LAS
LDH
P2P
RIG
RNI
RSU
SVGTG
VI1
~02
ID FETCH-LOGICAL-p243t-7d374500e9a4f01bb4ca7352d38a7fa791d46a2e32c978454b3abf9fc9220b113
ISBN 9783030579890
3030579891
ISSN 0302-9743
IngestDate Tue Jul 29 20:36:02 EDT 2025
Thu May 29 16:21:27 EDT 2025
IsPeerReviewed true
IsScholarly true
LCCallNum QA268
Language English
LinkModel OpenURL
MergedId FETCHMERGED-LOGICAL-p243t-7d374500e9a4f01bb4ca7352d38a7fa791d46a2e32c978454b3abf9fc9220b113
Notes Original Abstract: Traditional group signatures feature a single issuer who can add users to the group of signers and a single opening authority who can reveal the identity of the group member who computed a signature. Interestingly, despite being designed for privacy-preserving applications, they require strong trust in these central authorities who constitute single points of failure for critical security properties. To reduce the trust placed on authorities, we introduce dynamic group signatures which distribute the role of issuer and opener over several entities, and support \documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$ t _I$$\end{document}-out-of-\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$n_I$$\end{document} issuance and \documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$ t _O$$\end{document}-out-of-\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$n_O$$\end{document} opening. We first define threshold dynamic group signatures and formalize their security. We then give an efficient construction relying on the pairing-based Pointcheval–Sanders (PS) signature scheme (CT-RSA 2018), which yields very short group signatures of two first-group elements and three field elements. We also give a simpler variant of our scheme in which issuance requires the participation of all \documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$n_I$$\end{document} issuers, but still supports \documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$ t _O$$\end{document}-out-of-\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$n_O$$\end{document} opening. It is based on a new multi-signature variant of the PS scheme which allows for efficient proofs of knowledge and is a result of independent interest. We prove our schemes secure in the random-oracle model under a non-interactive q-type of assumption.
OCLC 1195449316
PQID EBC6340556_295_408
PageCount 23
ParticipantIDs springer_books_10_1007_978_3_030_57990_6_20
proquest_ebookcentralchapters_6340556_295_408
PublicationCentury 2000
PublicationDate 2020
PublicationDateYYYYMMDD 2020-01-01
PublicationDate_xml – year: 2020
  text: 2020
PublicationDecade 2020
PublicationPlace Switzerland
PublicationPlace_xml – name: Switzerland
– name: Cham
PublicationSeriesSubtitle Security and Cryptology
PublicationSeriesTitle Lecture Notes in Computer Science
PublicationSeriesTitleAlternate Lect.Notes Computer
PublicationSubtitle 12th International Conference, SCN 2020, Amalfi, Italy, September 14-16, 2020, Proceedings
PublicationTitle Security and Cryptography for Networks
PublicationYear 2020
Publisher Springer International Publishing AG
Springer International Publishing
Publisher_xml – name: Springer International Publishing AG
– name: Springer International Publishing
RelatedPersons Hartmanis, Juris
Gao, Wen
Bertino, Elisa
Woeginger, Gerhard
Goos, Gerhard
Steffen, Bernhard
Yung, Moti
RelatedPersons_xml – sequence: 1
  givenname: Gerhard
  surname: Goos
  fullname: Goos, Gerhard
– sequence: 2
  givenname: Juris
  surname: Hartmanis
  fullname: Hartmanis, Juris
– sequence: 3
  givenname: Elisa
  surname: Bertino
  fullname: Bertino, Elisa
– sequence: 4
  givenname: Wen
  surname: Gao
  fullname: Gao, Wen
– sequence: 5
  givenname: Bernhard
  orcidid: 0000-0001-9619-1558
  surname: Steffen
  fullname: Steffen, Bernhard
– sequence: 6
  givenname: Gerhard
  orcidid: 0000-0001-8816-2693
  surname: Woeginger
  fullname: Woeginger, Gerhard
– sequence: 7
  givenname: Moti
  surname: Yung
  fullname: Yung, Moti
SSID ssj0002426015
ssj0002792
Score 2.1381667
Snippet Traditional group signatures feature a single issuer who can add users to the group of signers and a single opening authority who can reveal the identity of...
SourceID springer
proquest
SourceType Publisher
StartPage 401
SubjectTerms Group signatures
Threshold cryptography
Title Short Threshold Dynamic Group Signatures
URI http://ebookcentral.proquest.com/lib/SITE_ID/reader.action?docID=6340556&ppg=408
http://link.springer.com/10.1007/978-3-030-57990-6_20
Volume 12238
hasFullText 1
inHoldings 1
isFullTextHit
isPrint
link http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwnV1La9wwEBab7aX00DdNX_jQQ2Fx0cuvY9ikhKXZSzYlNyHJUrOBOGHtLaS_viNLfuw2l_RijBGWNJ8YjUbzzSD0RVtZakt4bIlkMSfSxIoREhtWprYwLPUJTM-W6ekFX1wml5PJ_Shqaduob_rPg7yS_0EVvgGujiX7CGT7n8IHeAd84QkIw3PP-N11s3oOR6g817r_55v7uyZkn24jB5c-vLu3mOfyxlTr2hd-WgxL4nizvv4d6qSdyWo7BOhc3YT6yUfVda-7ly7h05jbMlpx51dgys9WsDhqd6c1O_bF7oO_63z9yycR9UNy8jE1dOOvMJa3TRsZNuuqTHRKZ-yVoHjPK9F5Jff8moNrbecYy5zWyYrcFw7t6FygquGw47Wf8do5dTkXmc9xGjQuD736zZt78vI_-8I4FAT-HENvBRybBcUH6CDLkyl6cnSy-PGzd885y6W1lMKm7vIs-gspPypHE-pGTXwip2EWI4rmQ13uHGb27t9bs2b1Aj1zVJfIcVBAfi_RxFSv0PMOgihA8Bp9baGNemijAG3UQhsN0L5BF99PVvPTOJTYiO8oZ02clSzjCcamkNxiohTXMgObvGS5zKzMClLyVFLDqIaZ8IQrJpUtrC4oxYoQ9hZNq9vKvEOR5soQC-ayppbnihYqxZqqJLPOBVHiQxR3sxZtIECIPtZ-jrVIGXeZnQQtEsFxfohmnWiEa16LLsM2jEQwATIVrUyFk-n7R7X-gJ4Oi_YjmjabrfkExmWjPoeF8BeQaXDV
linkProvider Library Specific Holdings
openUrl ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rft.genre=bookitem&rft.title=Security+and+Cryptography+for+Networks&rft.au=Camenisch%2C+Jan&rft.au=Drijvers%2C+Manu&rft.au=Lehmann%2C+Anja&rft.au=Neven%2C+Gregory&rft.atitle=Short+Threshold+Dynamic+Group+Signatures&rft.series=Lecture+Notes+in+Computer+Science&rft.date=2020-01-01&rft.pub=Springer+International+Publishing&rft.isbn=9783030579890&rft.issn=0302-9743&rft.eissn=1611-3349&rft.spage=401&rft.epage=423&rft_id=info:doi/10.1007%2F978-3-030-57990-6_20
thumbnail_s http://utb.summon.serialssolutions.com/2.0.0/image/custom?url=https%3A%2F%2Febookcentral.proquest.com%2Fcovers%2F6340556-l.jpg