Group Certificate Extension for Anonymous Transaction Auditing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital signature schemes, particularly those used in anonymous transactions, face challenges in auditing and regulatory compliance, as they lack mechanisms to trace signer identities and link signatures to specific group members, which is crucial for preventing duplicate transactions and ensuring regulatory requirements in applications like electronic voting and cryptocurrencies.
Innovation Solution
The introduction of a group certificate extension that allows for anonymous transactions while enabling the group manager to open or link signatures using a secret master key, providing traceability and anonymity, and facilitating regulatory compliance through a system comprising a network interface circuit, key generation circuit, opener circuit, and linking base circuit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional digital signature schemes are used, then signer anonymity is maintained, but the ability to audit and trace signer identities is lost
Solution Approach 1:
The system segments the signature verification capability into two distinct functions: public verification (maintaining anonymity) and private opening (enabling traceability). The group signature scheme allows anyone to verify that a signature comes from a group member, while the secret opening key held by authorized entities enables identification of the specific signer when needed. This segmentation resolves the contradiction by separating the anonymous verification function from the traceable identification function.
Solution Approach 2:
The group signature scheme acts as an intermediary mechanism between complete anonymity and complete traceability. It introduces a trusted group manager or authorized entity that holds the secret opening key, enabling them to reveal signer identities when necessary for auditing or dispute resolution, while maintaining anonymity for normal operations. This intermediary structure allows the system to provide both anonymity and conditional traceability.
2Adaptability or versatility
If signer identities are always revealed, then regulatory compliance is achieved, but transaction privacy and anonymity are compromised
Solution Approach 1:
The system dynamically adjusts between anonymity and traceability based on operational needs. During normal transactions, signer identities remain anonymous to protect privacy. When regulatory compliance requires audit or dispute resolution occurs, authorized entities can dynamically switch to traceable mode by using the secret opening key to reveal signer identities. This dynamic adaptability allows the system to meet regulatory requirements without permanently compromising transaction privacy.
3Ease of operation
If group signature schemes are implemented, then anonymous transactions are enabled, but the complexity of managing signing keys and audit functions increases
Solution Approach 1:
The system extracts the complex key management and audit functions into a separate trusted component (the group manager or authorized entity holding the secret opening key). Individual group members only need to manage their own signing keys for creating anonymous signatures, while the complex functions of key generation, distribution, and signature opening are handled by the external trusted component. This extraction reduces the complexity burden on individual users while maintaining the necessary audit capabilities.
Data Source
AI summary
Systems and methods relating to an extension of a group signature scheme certificate that allows group users to conduct anonymous transactions in public, with the ability to subsequently audit and confirm signer identity. Auditing and confirmatory functions may include group signature openers that are configured to reveal the identity of a signer that is a member of a group by their signature. Auditing and confirmatory functions may also include group signature linkers that are configured to link two signatures to the same signer using a linking key or linking base.


