Anonymous Identification in Ad Hoc Groups
Anonymous Identification in Ad Hoc Groups
复制标题
DOI:
10.1007/978-3-540-24676-3_36
复制
发表时间:
2004-05
期刊:
影响因子:
--
通讯作者:
Y. Dodis;A. Kiayias;Antonio Nicolosi;V. Shoup
中科院分区:
文献类型:
--
作者:
Y. Dodis;A. Kiayias;Antonio Nicolosi;V. Shoup
We introduceAd hocAnonymous Identification schemes, a new multi-user cryptographic primitive that allows participants from a user population to formad-hocgroups, and then prove membership anonymously in such groups. Our schemes are based on the notion ofaccumulator with one-way domain, a natural extension of cryptographic accumulators we introduce in this work. We provide a formal model forAd hocAnonymous Identification schemes and design secure such schemes both generically (based on any accumulator with one-way domain) and for a specific efficient implementation of such an accumulator based on the Strong RSA Assumption. A salient feature of our approach is that all the identification protocols take time independent of the size of the ad-hoc group. All our schemes and notions can be generally and efficiently amended so that they allow the recovery of the signer’s identity by an authority, if the latter is desired.Using the Fiat-Shamir transform, we also obtainconstant-size, signer-ambiguous group and ring signatures (provably secure in the Random Oracle Model). For ring signatures, this is the first such constant-size scheme, as all the previous proposals had signature size proportional to the size of the ring. For group signatures, we obtain schemes comparable in performance with state-of-the-art schemes, with the additional feature that the role of the group manager during key registration is extremely simple and essentially passive: all it does is accept the public key of the new member (and update the constant-size public key of the group).