A Group Signature Scheme Based on an RSA-Variant

Jan Camenisch
Markus Michels

November 1998


The concept of group signatures allows a group member to sign messages anonymously on behalf of the group. However, in the case of a dispute, the identity of a signature's originator can be revealed by a designated entity. In this paper we propose a new group signature scheme that is well suited for large groups, i.e., the length of the group's public key and of signatures do not depend on the size of the group. Our scheme is based on a variation of the RSA problem called strong RSA assumption. It is also more efficient than previous ones satisfying these requirements

Available as PostScript, PDF, DVI.


Last modified: 2003-06-08 by webmaster.