Improvement of A Lattice-Based Revocable Ring Signature
Abstract
Revocable ring signatures protect signer anonymity. A trusted authority can revoke signing rights when necessary. This makes them attractive for blockchains and vehicular networks. Existing lattice-based ring signature schemes are only traceable. They can de-anonymize a malicious signer, yet fail to stop the revoked signer from creating a valid signature. This contradicts the very notion of revocation. We introduce a polynomial-based revocation list. It is enforced with non-interactive zero-knowledge proofs of knowledge. Our protocol implicitly verifies the up-to-date revocation list during signature generation. Consequently, revoked signers cannot authenticate and are effectively excluded. Integrating this mechanism into a lattice setting, we obtain a compact revocable ring signature. The scheme is correct, anonymous, unforgeable, and truly revocable under the random oracle model. No costly key updates are required. Compared with prior trace-and-update schemes, our construction offers a practical post-quantum primitive. It guarantees both privacy and accountable revocation. Overhead analysis shows that we have added very little cost while ensuring true revocation.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.