Re: group signature



vedaal wrote:
[...]
pgp has implemented this by using Blakely-Shamir key splitting to
'split'
a 'group' key into shares, and encrypting each shared key fragment to
the pre-existing public key of the individual group member

This doesn't sound like a true group signature. For one, the first time
a subset of the group colludes to sign a message, they get the true
group key and therefore never need to collude again to sign other
messages. I'm sure this has been noticed before though...

--Aaron

.


Quantcast