A lattice-based ring signature scheme with gradual revelation of non-signers
摘要
A ring signature scheme (RSS) is a way to leak secrets anonymously. If the verifier (e.g. journalist) does not trust some of the ring members then the ring signature with gradual revelation provides a way for the real signer to reveal the identities of the non-signers to make the verifier convinced that the signature is not generated by someone he does not trust. In this article, we design the first lattice-based RSS with the gradual revelation of non-signers which is convertible also. Our scheme provides unforgeability against insider corruption, anonymity against full key exposure under the difficulty of solving short integer solution problem over lattices.