Paper 2024/1942

DGMT: A Fully Dynamic Group Signature From Symmetric-key Primitives

Mojtaba Fadavi, Department of Computer Science, University of Calgary, Canada
Sabyasachi Karati, Cryptology and Security Research Unit, Indian Statistical Institute, Kolkata, India
Aylar Erfanian, Department of Computer Science, University of Calgary, Canada
Reihaneh Safavi-Naini, Department of Computer Science, University of Calgary, Canada
Abstract

A group signatures allows a user to sign a message anonymously on behalf of a group and provides accountability by using an opening authority who can ``open'' a signature and reveal the signer's identity. Group signatures have been widely used in privacy-preserving applications including anonymous attestation and anonymous authentication. Fully dynamic group signatures allow new members to join the group and existing members to be revoked if needed. Symmetric-key based group signature schemes are post-quantum group signatures whose security rely on the security of symmetric-key primitives such as cryptographic hash functions and pseudorandom functions. In this paper, we design a symmetric-key based fully dynamic group signature scheme, called DGMT, that redesigns DGM (Buser et al. ESORICS 2019) and removes its two important shortcomings that limit its application in practice: (i) interaction with the group manager for signature verification, and (ii) the need for storing and managing an unacceptably large amount of data by the group manager. We prove security of DGMT (unforgeability, anonymity, and traceability) and give a full implementation of the system. Compared to all known post-quantum group signature schemes with the same security level, DGMT has the shortest signature size. We also analyze DGM signature revocation approach and show that despite its conceptual novelty, it has significant hidden costs that makes it much more costly than using traditional revocation list approach.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
Post-quantum cryptographyPrivacy-preserving protocolsGroup Signature SchemesHash-based signature schemes
Contact author(s)
mojt fadavi @ gmail com
skarati @ isical ac in
aylar erfanianazadso @ ucalgary ca
rei @ ucalgary ca
History
2024-12-02: approved
2024-11-29: received
See all versions
Short URL
https://ia.cr/2024/1942
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/1942,
      author = {Mojtaba Fadavi and Sabyasachi Karati and Aylar Erfanian and Reihaneh Safavi-Naini},
      title = {{DGMT}: A Fully Dynamic Group Signature From Symmetric-key Primitives},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1942},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1942}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.