We provide definitions for the new notion and construct a scheme that is provably secure given the existence of a family of trapdoor permutations.
We also present a construction which is relatively practical, and prove its security in the random oracle model under the strong RSA assumption and the DDH assumption.
Category / Keywords: cryptographic protocols / group signatures Publication Info: Presented at ICALP 2005. This is the full version. Date: received 16 Nov 2004, last revised 8 Apr 2005 Contact author: marten at nada kth se Available format(s): Postscript (PS) | Compressed Postscript (PS.GZ) | PDF | BibTeX Citation Note: The notion of cross-indistinguishability in the first version matches anonymity / key-privacy by Bellare et.al (Asiacrypt 2001), which is now referenced. Added efficiency analysis. Corrected minor mistakes. Version: 20050408:091618 (All versions of this report) Short URL: ia.cr/2004/311 Discussion forum: Show discussion | Start new discussion