ACM Home Page
Please provide us with feedback. Feedback
Practical forward secure group signature schemes
Full text PdfPdf (291 KB)
Source Conference on Computer and Communications Security archive
Proceedings of the 8th ACM conference on Computer and Communications Security table of contents
Philadelphia, PA, USA
Session: Group Key Management and Signatures table of contents
Pages: 225 - 234  
Year of Publication: 2001
ISBN:1-58113-385-5
Author
Dawn Xiaodong Song  University of California, Berkeley, CA
Sponsor
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): n/a,   Downloads (12 Months): n/a,   Citation Count: 13
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/501983.502015
What is a DOI?

ABSTRACT

A group signature scheme allows a group member to sign messages anonymously on behalf of the group, while in case of a dispute, a designated entity can reveal the identity of a signature's originator. Group signature schemes can be used as a basic building block for many security applications such as electronic banking systems and electronic voting. Two important issues -- forward security and efficient revocation -- have not been addressed by prior schemes. We construct the first forward-secure group signature schemes. While satisfying all the security properties proposed in previous group signature schemes, our schemes provide a new desired security property, forward-security: while the group public key stays fixed, a group signing key of a group member evolves over time such that compromise of a group signing key of the current time period does not enable an attacker to forge group signatures pertaining to the past time periods. Such forward-security is important to mitigate the damage caused by key exposure and particularly desirable for group signature schemes because the risk of signing key exposure escalates as the size of the group increases. Our schemes are provably secure in the random oracle model and under the strong RSA and decisional Diffie Hellman assumptions.Furthermore, we extend our forward-secure group signature scheme to provide a solution for the problem of group member exclusion without the need to re-key all other group members. When a group member is excluded, he should not be able to generate valid signatures any more and yet his previous signatures remain anonymous. We provide the first solutions which support both retroactive public revocation and backward unlinkability and the signature size is independent of the number of revoked members.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
Ross Anderson.Invited Lecture,4th ACM Computer and Communications Security,1997.
 
3
 
4
 
5
N.Baric and B.P .tzman.Collision-free accumulators and fail-stopsignature schemes without trees.In Advances in Cryptology - EUROCRYPT 1997 pages 480 -494. Springer-Verlag,1997.Lecture Notes in Computer Science Volume 1233.
 
6
 
7
 
8
F.Boudot.E .cient proofs that committed number lies in an interval.In B.Preneel,editor,Advances in Cryptology - EUROCRYPT 2000 pages 431 -444,Berlin, 2000.Springer-Verlag.Lecture Notes in Computer Science Volume 1807.
 
9
 
10
 
11
 
12
 
13
 
14
 
15
D.Chaum,J.H.Evertse,and J.van de Graaf.An improved protocol for demonstrating possession of discrete logarithms nd some generalizations.In D vid Chaum nd Wyn L.Price,editors,Advances in Cryptology - EuroCrypt '87 pages 127 -142,Berlin,1987.Springer-Verlag.Lecture Notes in Computer Science Volume 304.
 
16
D.Chaum nd E.v n Heyst.Groupsignatures.In Donald W.Davies,editor,Advances in Cryptology -EuroCrypt '91 pages 257 -265,Berlin,1991. Springer-Verlag.Lecture Notes in Computer Science Volume 547.
 
17
 
18
L.Chen and T.P.Pedersen.New groupsignature schemes. In Alfredo De Santis,editor,Advances in Cryptology -EuroCrypt '94 pages 171 -181,Berlin,1995. Springer-Verlag.Lecture Notes in Computer Science Volume 950.
 
19
I.Damgard.E .cient concurrent zero-knowledge in the auxiliary string model.In B.Preneel,editor,Advances in Cryptology - EUROCRYPT 2000 pages 431 -444,Berlin, 2000.Springer-Verlag.Lecture Notes in Computer Science Volume 1807.
 
20
W.Difie and M.E.Hellman.New directions in cryptography.IEEE Transactions on Information Theory 6(IT-22):644 -654,1976.
 
21
 
22
 
23
 
24
 
25
26
 
27
 
28
Chanathip Namprempre Michel Abdalla,Sara Miner. Forward security in threshold signature schemes.In RSA 2001 2001.
 
29

CITED BY  13