Designated-Verifier Ring Signatures: Strong Definitions, Generic Constructions and Efficient Instantiations
摘要
Ring signatures play crucial roles in cryptographic toolkits, providing the signer with both anonymity and unforgeability. Over the years, numerous advancements in ring signatures have been developed to address a wide range of application scenarios. However, most of them do not consider that disclosed message-signature pairs are publicly verifiable, resulting in a loss of privacy. To tackle this dilemma, we focus on the notion of Designated-Verifier Ring Signatures (DVRS), in which only a designated verifier can ascertain the signature’s origin and validity, while others cannot. Unlike directly encrypting a signature to prevent verification, DVRS remain effective even if the designated verifier’s secret key is leaked or stolen, enabling enhanced privacy. After clarifying the necessities and strong definitions of DVRS, we provide a generic construction based on the Extended Type-T* Canonical Identification. This newly defined three-move Canonical Identification can be instantiated from different hardness assumptions. Subsequently, we present two settings. The first one is based on the discrete logarithm (DL) and Decisional Diffie-Hellman (DDH) assumptions. A novel zero-knowledge argument system, Minus Argument, is also devised to reduce signature sizes to logarithmic while not requiring any trusted setup. The second one is based on lattice, which is believed to be quantum-resistant.