TCS Journal 2025 Journal Article
A linkable ring signature scheme with unconditional anonymity in the standard model
- Keisuke Hara
Ring signatures allow a user to sign messages as a member of a set of users, which is called a ring. This primitive ensures that anybody can check that one of the members in a ring generate a signature, but cannot detect which member does. Linkable ring signature is a novel extension of ring signature in the sense that anyone can verify whether two signatures were generated by the same user or not. One of the desirable features on (linkable) ring signature is unconditional anonymity which provides signers everlasting anonymity. In 2014, Liu, Au, Susilo, and Zhou proposed the first linkable ring signature scheme with unconditional anonymity. Their scheme is only secure in the random oracle model and leaves to construct a scheme in the standard model as an open problem. In this paper, we solve their open problem and propose the first linkable ring signature scheme with unconditional anonymity in the standard model. Our scheme is constructed based on a non-interactive proof of knowledge, a (standard) signature scheme, a commitment scheme, and a vector commitment scheme with specializable universal common reference string.