We also investigate the case of fully structure-preserving signatures where it is required that the secret signing key consists of group elements only. We show a variant of our signature scheme allowing the signer to pick part of the verification key at the time of signing is still secure. This gives us both randomizable and strongly existentially unforgeable fully structure-preserving signatures. In the fully structure preserving scheme the verification key is a single group element, signatures contain m+n+1 group elements and verification requires evaluating n+1 pairing product equations.
Category / Keywords: public-key cryptography / Digital signatures, pairing-based cryptography, full structure-preservation Date: received 22 Aug 2015 Contact author: j groth at ucl ac uk Available format(s): PDF | BibTeX Citation Version: 20150824:144809 (All versions of this report) Short URL: ia.cr/2015/824 Discussion forum: Show discussion | Start new discussion