1. Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions
- Author
-
Takahiro Matsuda, Yusuke Sakai, Kazuma Ohara, Kazumasa Omote, Keita Emura, Yutaka Kawai, and Goichiro Hanaoka
- Subjects
Theoretical computer science ,Article Subject ,Computer Networks and Communications ,Computer science ,business.industry ,020206 networking & telecommunications ,02 engineering and technology ,Group signature ,Encryption ,Signature (logic) ,Random oracle ,Set (abstract data type) ,lcsh:Technology (General) ,0202 electrical engineering, electronic engineering, information engineering ,Identity (object-oriented programming) ,lcsh:T1-995 ,020201 artificial intelligence & image processing ,lcsh:Science (General) ,business ,lcsh:Q1-390 ,Information Systems ,Standard model (cryptography) ,Anonymity - Abstract
This paper introduces a new capability for group signatures called message-dependent opening. It is intended to weaken the high trust placed on the opener; i.e., no anonymity against the opener is provided by an ordinary group signature scheme. In a group signature scheme with message-dependent opening (GS-MDO), in addition to the opener, we set up an admitter that is not able to extract any user’s identity but admits the opener to open signatures by specifying messages where signatures on the specified messages will be opened by the opener. The opener cannot extract the signer’s identity from any signature whose corresponding message is not specified by the admitter. This paper presents formal definitions of GS-MDO and proposes a generic construction of it from identity-based encryption and adaptive non-interactive zero-knowledge proofs. Moreover, we propose two specific constructions, one in the standard model and one in the random oracle model. Our scheme in the standard model is an instantiation of our generic construction but the message-dependent opening property is bounded. In contrast, our scheme in the random oracle model is not a direct instantiation of our generic construction but is optimized to increase efficiency and achieves the unbounded message-dependent opening property. Furthermore, we also demonstrate that GS-MDO implies identity-based encryption, thus implying that identity-based encryption is essential for designing GS-MDO schemes.
- Published
- 2019