Group Signatures with Message-Dependent Opening

Group Signatures with Message-Dependent Opening
复制标题

DOI:
10.1007/978-3-642-36334-4_18
复制
发表时间:
2012-05
期刊:
--
影响因子:
--
通讯作者:
Yusuke Sakai;K. Emura;Goichiro Hanaoka;Yutaka Kawai;Takahiro Matsuda;Kazumasa Omote
Yusuke Sakai;K. Emura;Goichiro Hanaoka;Yutaka Kawai;Takahiro Matsuda;Kazumasa Omote
中科院分区:
其他
文献类型:
--
作者:
Yusuke Sakai;K. Emura;Goichiro Hanaoka;Yutaka Kawai;Takahiro Matsuda;Kazumasa Omote

文献摘要

相似文献

本文介绍了群签名的一种新的能力--消息相关开放性。它的目的是削弱对开放者的较高信任,即普通的群签名不提供对开放者的匿名性。在消息相关开放的群签名系统(GS-MDO)中,除了开放器之外,我们还设置了不能打开任何用户身份的接纳器,但通过指定应打开签名的消息来接纳开放器来打开签名。对于任何签名,如果其对应的消息不是由被签名者指定的,则打开器不能从中提取签名者的身份。此外,我们还表明,GS-MDO意味着基于身份的加密,因此对于设计GS-MDO方案,基于身份的加密是至关重要的。实际上,我们提出了一个通用的建设GS-MDO基于身份的加密和自适应NIZK证明,其具体的实例从Groth-Sahai证明系统,通过构建一个新的(k-弹性)基于身份的加密方案,这是兼容的Groth-Sahai证明。
This paper introduces a new capability of the group signature, calledmessage-dependent opening. It is intended to weaken the higher trust put on an opener, that is, no anonymity against an opener is provided by ordinary group signature. In a group signature system with message-dependent opening (GS-MDO), in addition to the opener, we set up theadmitterwhich is not able to open any user’s identity butadmitsthe opener to open signatures by specifying messages whose signatures should be opened. For any signature whose corresponding message is not specified by the admitter, the opener cannot extract the signer’s identity from it. In this paper, we present formal definitions and constructions of GS-MDO. Furthermore, we also show that GS-MDO implies identity-based encryption, and thus for designing a GS-MDO scheme, identity-based encryption is crucial. Actually, we propose a generic construction of GS-MDO from identity-based encryption and adaptive NIZK proofs, and its specific instantiation from the Groth-Sahai proof system by constructing a new (k-resilient) identity-based encryption scheme which is compatible to the Groth-Sahai proof.