Paper 2002/173

Efficient Group Signatures without Trapdoors

Giuseppe Ateniese and Breno de Medeiros


Group signature schemes enable unlinkably anonymous authentication, in the same fashion that digital signatures provide the basis for strong authentication protocols. This paper introduces the first group signature scheme with constant-size parameters that does not require any group member, including group managers, to know trapdoor secrets. This novel type of group signature scheme allows public parameters to be shared among organizations, and are useful when several distinct groups must interact and exchange information about individuals while protecting their privacy.

Note: This revised version corrects the proof of security of the modified Nyberg-Rueppel signature and contains some changes in the writing and presentation of the results.

Published elsewhere. This is a REVISED version of the paper that appeared in ASIACRYPT 2003.
ateniese @ cs jhu edu
2004-04-21: last of 6 revisions
2002-11-13: received
