Abstract:
Abstract. We introduce the notion of a dynamic accumulator. An accumulator scheme allows one to hash a large set of inputs into one short value, such that there is a short proof that a given input was incorporated into this value. A dynamic accumulator allows one to dynamically add and delete a value, such that the cost of an add or delete is independent of the number of accumulated values. We provide a construction of a dynamic accumulator and an efficient zero-knowledge proof of knowledge of an accumulated value. We prove their security under the strong RSA assumption. We then show that our construction of dynamic accumulators enables efficient revocation of anonymous credentials, and membership revocation for recent group signature and identity escrow schemes.
Citations
|
352
|
A paractical public-key cryptosystem provably secure against adaptive chosen ciphertext attack
– Cramer, Shoup
- 1998
|
|
261
|
Security and Composition of Multiparty Cryptographic Protocols
– Canetti
- 2000
|
|
169
|
Efficient group signature schemes for large groups
– Camenisch, Stadler
- 1997
|
|
159
|
Tsudik: A Practical and Provably Secure Coalition-Resistant Group Signature Scheme
– Ateniese, Camenisch, et al.
- 2000
|
|
133
|
Pfitzmann: Collision-free Accumulators and Fail-Stop Signature Schemes Without Trees
– Barić, B
- 1997
|
|
104
|
Rethinking Public Key Infrastructures and Digital Certificates; Building in Privacy
– Brands
- 2000
|
|
103
|
Statistical zero knowledge protocols to prove modular polynomial relations
– Fujisaki, Okamoto
- 1997
|
|
95
|
Secure hash-andsign signature without the random oracle
– Gennaro, Halevi, et al.
- 1999
|
|
95
|
Composition and integrity preservation of secure reactive systems
– Pfitzmann, Waidner
- 2000
|
|
80
|
A group signature scheme with improved efficiency
– Camenisch, Michels
- 1998
|
|
75
|
One-way accumulators: A decentralized alternative to digital sinatures
– Benaloh, Mare
- 1993
|
|
71
|
Identity escrow
– Kilian, Petrank
- 1998
|
|
68
|
Efficient and generalized group signatures
– Camenisch
- 1997
|
|
68
|
New group signature schemes
– Chen, Pedersen
- 1995
|
|
68
|
Pseudonym systems
– Lysyanskaya, Rivest, et al.
- 1999
|
|
62
|
Separability and Efficiency for Generic Group Signature Schemes
– Camenisch, Michels
- 1998
|
|
58
|
On the Generation of Cryptographically Strong Pseudorandom Sequences
– Shamir
- 1983
|
|
53
|
Efficient non-transferable anonymous multi-show credential system with optional anonymity revocation
– Camenisch, Lysyanskaya
- 2001
|
|
41
|
An integer commitment scheme based on groups with hidden order
– Damgard, Fujisaki
- 2001
|
|
37
|
Quasi-efficient revocation of group signatures
– Ateniese, Song, et al.
- 2002
|
|
27
|
Practical forward secure group signature schemes
– Song
- 2001
|
|
20
|
How to prove all np statements in zero knowledge and a methodology of cryptographic protocol design
– Goldreich, Micali, et al.
- 1987
|
|
18
|
An identity escrow scheme with appointed verifiers
– Camenisch, Lysyanskaya
|
|
9
|
Efficient and secure member deletion in group signature schemes
– Kim, Lim, et al.
- 2001
|
|
6
|
Group signatures with efficient revocation
– Bresson, Stern
- 2001
|
|
3
|
auditable membership proofs
– Blind
- 2000
|