Bifurcated Signatures: Folding the Accountability vs. Anonymity Dilemma into a Single Private Signing Scheme
Benoît Libert, Khoa Nguyen, Thomas Peters, Moti Yung
摘要
Over the development of modern cryptography, often, alternative cryptographic schemes are developed to achieve goals that in some important respect are orthogonal. Thus, we have to choose either a scheme which achieves the first goal and not the second, or vice versa. This results in two types of schemes that compete with each other. In the basic area of user privacy, specifically in anonymous (multi-use credentials) signing, such an orthogonality exists between anonymity and accountability. The conceptual contribution of this work is to reverse the above orthogonality by design, which essentially typifies the last 25 years or so, and to suggest an alternative methodology where the opposed properties are carefully folded into a single scheme. The schemes will support both opposing properties simultaneously in a bifurcated fashion, where:
-First, based on rich semantics expressed over the message's context and content, the user, etc., the relevant property is applied point-wise per message operation depending on a predicate; and -Secondly, at the same time, the schemes provide what we call "branchhiding;" namely, the resulting calculated value hides from outsiders which property has actually been locally applied. Specifically, we precisely define and give the first construction and security proof of a "Bifurcated Anonymous Signature" (BiAS): A scheme which supports either absolute anonymity or anonymity with accountability, based on a specific contextual predicate, while being branch-hiding. This novel signing scheme has numerous applications not easily implementable or not considered before, especially because: (i) the conditional traceability does not rely on a trusted authority as it is (non-interactively) encapsulated into signatures; and (ii) signers know the predicate value and can make a conscious choice at each signing time. Technically, we realize BiAS from homomorphic commitments for a general family of predicates that can be represented by bounded-depth circuits. Our construction is generic and can be instantiated in the standard model from lattices and, more efficiently, from bilinear maps. In particular, the signature length is independent of the circuit size when we use commitments with suitable efficiency properties.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- Multi-Holder Anonymous Credentials from BBS SignaturesAndrea Flamini, Eysa Lee, Anna LysyanskayaCRYPTO 2025 · 被引用 6 次
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 被引用 52 次
- Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous CredentialsOmid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya 等CCS 2023 · 被引用 29 次
- Threshold BBS+ Signatures for Distributed Anonymous Credential IssuanceJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi Shelat 等S&P 2023
- Doubly Aggregatable SignaturesGeorg Fuchsbauer, Pranav Garimidi, Joachim Neu, Guru-Vamsi Policharla 等CCS 2026
