To do this, we start by proposing a new stateful signature scheme for signing vectors of exponents that is F-unforgeable under weak chosen message attacks. This signature scheme is of independent interest as it is compatible with Groth-Sahai proofs and secure under a computational assumption implied by DLIN. Then we give a general transformation for signing group elements based on signatures (for signing exponents) with efficient non-interactive zero-knowledge proofs. This transform also removes any dependence on state in the signature used to sign exponents. Finally, we obtain our result by instantiating this transformation with the above signature scheme and Groth-Sahai proofs.
Category / Keywords: public-key cryptography / structure preserving signatures Date: received 23 Jun 2011 Contact author: melissac at microsoft com Available format(s): PDF | BibTeX Citation Version: 20110627:075419 (All versions of this report) Short URL: ia.cr/2011/342 Discussion forum: Show discussion | Start new discussion