MoneroResearch.info |
Resource type: Unpublished Work BibTeX citation key: Aranha2021 View all bibliographic details |
Categories: Monero-focused Keywords: anonymity, Ring Signature, Traceability Creators: Aranha, Hall-Anderson, Nitulescu, Pagnin, Yakoubov |
Views: 18/2610
|
Attachments 2021-1240.pdf [6/1222] | URLs Cryptology ePrint Archive |
Abstract |
[..] a limitation of existing threshold ring signature constructions is that all of the signers must agree on the group on whose behalf they are signing, which implicitly assumes some coordination amongst them. The need to agree on a group before generating a signature also prevents others - from outside that group - from endorsing a message by adding their signature to the statement post-factum. We overcome this limitation by introducing extendability for ring signatures, same-message linkable ring signatures, and threshold ring signatures. [..] we formalize the syntax and provide a meaningful security model which includes different flavors of anonymous extendability. In addition, we present concrete realizations of each primitive and formally prove their security relying on signatures of knowledge and the hardness of the discrete logarithm problem. We also describe a generic transformation to obtain extendable threshold ring signatures from same-message-linkable extendable ring signatures. Finally, we implement and benchmark our constructions. |
Musings |
As far as I can tell this relies on size-linear constructions, which are less efficient than Grootle proofs.
Added by: koe000
(2022-03-09 17:28:53)
Keywords: anonymity Ring Signature Traceability |
p.3, Section a generic transformation
Jeffro256 "IIUC, if this could be applied to Monero, then all the rings signatures in a block could be combined non-interactively for much better anonymity sets It even has a notion of key-images, although they call them "same-message linkable extendable ring signatures" " Added by: Plowsof (2022-03-04 17:18:33)Keywords: anonymity Ring Signature Traceability |