We construct efficient ring signatures (RS) from isogeny and lattice assumptions. Our ring signatures are based on a logarithmic OR proof for group actions. We instantiate this group action by either the CSIDH group action or an MLWE-based group action to obtain our isogeny-based or lattice-based RS scheme, respectively. Even though the OR proof has a binary challenge space and therefore requires a number of repetitions which is linear in the security parameter, the sizes of our ring signatures are small and scale better with the ring size N than previously known post-quantum ring signatures. We also construct linkable ring signatures (LRS) that are almost as efficient as the non-linkable variants. The isogeny-based scheme produces signatur...
Ring signatures enable a user to anonymously sign a message on behalf of group of users. In this pap...
In this paper, we construct a Lattice-based one-time Linkable Ring Signature (L2RS) scheme, which en...
Abstract. A ring signature scheme can be viewed as a group signature scheme with no anonymity revoca...
We construct efficient ring signatures (RS) from isogeny and lattice assumptions. Our ring signature...
Ring signatures allow for creating signatures on behalf of an ad hoc group of signers, hiding the ...
Deniable ring signature can be regarded as group signature without group manager, in which a singer ...
Unique ring signatures (URS) were introduced by Franklin and Zhang (FC 2012) as a unification of lin...
We introduce a lattice-based group signature scheme that provides several noticeable improvements ov...
A ring signature (RS) scheme enables a group member to sign messages on behalf of its group without ...
In order to solve the problem of large key size and low efficiency in the linkable ring signature sc...
ISBN : 978-3-642-38615-2International audienceWe present in this paper an improvement of the lattice...
Abstract. A ring signature scheme is a group signature scheme with no group manager to setup a group...
International audienceBasing signature schemes on strong lattice problems has been a long standing o...
While ring signatures can provide unconditional anonymity to the signing user, they are vulnerable t...
In a ring signature scheme, a user selects an arbitrary ring to be able to sign a message on behalf ...
Ring signatures enable a user to anonymously sign a message on behalf of group of users. In this pap...
In this paper, we construct a Lattice-based one-time Linkable Ring Signature (L2RS) scheme, which en...
Abstract. A ring signature scheme can be viewed as a group signature scheme with no anonymity revoca...
We construct efficient ring signatures (RS) from isogeny and lattice assumptions. Our ring signature...
Ring signatures allow for creating signatures on behalf of an ad hoc group of signers, hiding the ...
Deniable ring signature can be regarded as group signature without group manager, in which a singer ...
Unique ring signatures (URS) were introduced by Franklin and Zhang (FC 2012) as a unification of lin...
We introduce a lattice-based group signature scheme that provides several noticeable improvements ov...
A ring signature (RS) scheme enables a group member to sign messages on behalf of its group without ...
In order to solve the problem of large key size and low efficiency in the linkable ring signature sc...
ISBN : 978-3-642-38615-2International audienceWe present in this paper an improvement of the lattice...
Abstract. A ring signature scheme is a group signature scheme with no group manager to setup a group...
International audienceBasing signature schemes on strong lattice problems has been a long standing o...
While ring signatures can provide unconditional anonymity to the signing user, they are vulnerable t...
In a ring signature scheme, a user selects an arbitrary ring to be able to sign a message on behalf ...
Ring signatures enable a user to anonymously sign a message on behalf of group of users. In this pap...
In this paper, we construct a Lattice-based one-time Linkable Ring Signature (L2RS) scheme, which en...
Abstract. A ring signature scheme can be viewed as a group signature scheme with no anonymity revoca...