Advances in Cryptology — ASIACRYPT’98

Volume 1514 of the series Lecture Notes in Computer Science pp 160-174


A Group Signature Scheme with Improved Efficiency (Extended Abstract)

  • Jan CamenischAffiliated withBRICS Department of Computer Science, University of Aarhus
  • , Markus MichelsAffiliated withr3 security engineering ag, Entrust Technology


The concept of group signatures allows a group member to sign messages anonymously on behalf of the group. However, in the case of a dispute, the identity of a signature’s originator can be revealed by a designated entity. In this paper we propose a new group signature scheme that is well suited for large groups, i.e., the length of the group’s public key and of signatures do not depend on the size of the group. Our solution based on a variation of the RSA problem is more efficient than previous ones satisfying these requirements.


Group signature scheme for large groups digital signature schemes revocable anonymity