On the Security of A Group Signature Scheme

Jianhong Zhang, Qin Geng
2008 2008 IEEE International Conference on Networking, Sensing and Control  
As a special digital signature, a group signature scheme allows a group member to sign message on behalf of the group in an anonymous and unlinkability way, In case of a dispute, the group manager can reveal the actual identity of signer. Anonymity and unlinkability are basic properties of group signature, which distinguish other signature scheme. Recently, based on the work of Camenisch and Lysyanskaya, which is known to be the most efficient scheme so far, E.Y.Choi et.al propose an efficient
more » ... roup signature scheme with member revocation at TrustBus 2005. Unfortunately, in this work we show that the scheme has linkability, Namely, any one can distinguish whether two different group signatures are produced by the same signer, and that the revocation manager cannot trace the actual identity of a signer by a group signature. Finally, we give the corresponding attack to the scheme.
doi:10.1109/icnsc.2008.4525420 dblp:conf/icnsc/ZhangG08a fatcat:2c6kp6xswndjhbfmpoc4sl4434