Paper: Mesh Signatures : How to Leak a Secret with Unwitting and Unwilling Participants

Xavier Boyen
Abstract: We introduce the mesh signature primitive as an anonymous signature that borrows from ring signatures, but with added modularity and a much richer language for expressing signer ambiguity. The language can represent complex access structures, and in particular allows individual signature components to be replaced with modular certificate chains. As a result, withholding one's public key from view is no longer a shield against being named as a possible cosignatory; and hence, a mesh signature may be used as a ring signature substitute with compulsory enrollment. We give an efficient construction based on bilinear maps in the common random string model. Our mesh signatures have linear size, achieve everlasting perfect anonymity, and as a special case induce the most efficient and first unconditionally anonymous ring signatures without random oracles or trusted setup authorities. We prove non-repudiation from a mild extension of the SDH assumption, which we introduce and justify meticulously.
  title={Mesh Signatures : How to Leak a Secret with Unwitting and Unwilling Participants},
  booktitle={IACR Eprint archive},
  keywords={public-key cryptography / ring signatures, perfect anonymity, modularity},
  note={Full version of an extended abstract to appear in EUROCRYPT 2007 13633 received 13 Mar 2007, last revised 30 Apr 2007},
  author={Xavier Boyen},