Taming Delegations in Anonymous Signatures: k-Times Anonymity for Proxy and Sanitizable Signatures
Seminar AMAC: CASC
30/01/2025 - 09:30 Charles Olivier-Anclin (Université Clermont-Auvergne) IMAG 106
Fully traceable k-times anonymity is a security property concerning anonymous signatures: if a user produces more than k anonymous signatures, its identity is disclosed and all its previous signatures can be identified. We show how this property can be achieved for delegation-supported signature schemes, especially proxy signatures, where the signer allows a delegate to sign on its behalf, and sanitizable signatures, where a signer allows a delegate to modify certain parts of the signed messages. In both cases, we formalize the primitive, give a suitable security model, provide a scheme and then prove its security under the DDH assumption. The size of the keys/signatures is logarithmic in k in our two schemes, making them suitable for practical applications, even for large k.