Cryptology ePrint Archive: Report 2019/221

Group Signatures without NIZK: From Lattices in the Standard Model

Shuichi Katsumata and Shota Yamada

Abstract: In a group signature scheme, users can anonymously sign messages on behalf of the group they belong to, yet it is possible to trace the signer when needed. Since the first proposal of lattice-based group signatures in the random oracle model by Gordon, Katz, and Vaikuntanathan (ASIACRYPT 2010), the realization of them in the standard model from lattices has attracted much research interest, however, it has remained unsolved. In this paper, we make progress on this problem by giving the first such construction. Our schemes satisfy CCA-selfless anonymity and full traceability, which are the standard security requirements for group signatures proposed by Bellare, Micciancio, and Warinschi (EUROCRYPT 2003) with a slight relaxation in the anonymity requirement suggested by Camenisch and Groth (SCN 2004). We emphasize that even with this relaxed anonymity requirement, all previous group signature constructions rely on random oracles or NIZKs, where currently NIZKs are not known to be implied from lattice-based assumptions. We propose two constructions that provide tradeoffs regarding the security assumption and efficiency:

- Our first construction is proven secure assuming the standard LWE and the SIS assumption. The sizes of the public parameters and the signatures grow linearly in the number of users in the system. - Our second construction is proven secure assuming the standard LWE and the subexponential hardness of the SIS problem. The sizes of the public parameters and the signatures are independent of the number of users in the system.

Technically, we obtain the above schemes by combining a secret key encryption scheme with additional properties and a special type of attribute-based signature (ABS) scheme, thus bypassing the utilization of NIZKs. More specifically, we introduce the notion of \emph{indexed} ABS, which is a relaxation of standard ABS. The above two schemes are obtained by instantiating the indexed ABS with different constructions. One is a direct construction we propose and the other is based on previous work.

Category / Keywords: cryptographic protocols / Group signatures, Lattices, Attribute-based signatures

Original Publication (with major differences): IACR-EUROCRYPT-2019

Date: received 25 Feb 2019, last revised 24 Apr 2019

Contact author: shuichi katsumata000 at gmail com, shota yamada enc@gmail com, yamada-shota@aist go jp

Available format(s): PDF | BibTeX Citation

Version: 20190425:055004 (All versions of this report)

Short URL: ia.cr/2019/221


[ Cryptology ePrint archive ]