Traceable Ring Signatures: Logarithmic-Size, Without Any Setup, from Standard Assumptions
摘要
A traceable ring signature is a variant of ring signatures that allows public traceability of a user’s identity if they have produced two signatures for the same issue. Fujisaki and Suzuki first proposed traceable ring signatures at PKC’2007. They have numerous applications in e-coupons, e-voting, and blockchain. While several traceable ring signatures exist in both classical and post-quantum settings, most are proven in the (quantum) random oracle or common reference string models. These models require impractical or inefficient assumptions, such as the heuristic of random oracles or a trusted setup. In this paper, we present the first generic construction of traceable ring signature schemes that do not rely on a trusted setup or the random oracle heuristic. Specifically, our scheme can be instantiated from standard assumptions, and the size of the signatures is only logarithmic in the number of ring members.