Group Signature System Using Pairing-Based Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing group signature schemes are inefficient due to high calculation amounts and slow speeds, particularly in large groups, as they are proportional to the number of members, making them unsuitable for practical use.

Innovation Solution

A group signature system using a multiplicative cyclic group of prime order q, with a group manager device, signer device, and verifier device, employing a member secret key representation (ki1, ki2) and Cramer-Shoup encryption for efficient signature generation and verification, based on the DDH problem for security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional group signature schemes are used, then signature generation and verification can be performed, but the calculation amount is high and calculation speed is slow

Engineering Contradiction:
Improvecalculation speedVSAvoidcalculation amount
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent changes the mathematical parameters from RSA-based schemes to pairing-based cryptographic schemes. Specifically, it uses bilinear pairings on elliptic curves with carefully selected parameters (group orders, generator points, pairing-friendly curves) to achieve faster computation. The signature generation complexity is reduced from O(n) in conventional schemes to O(1) by leveraging the properties of bilinear pairings and pre-computed values.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical RSA exponentiation operations with pairing-based cryptographic operations. Instead of performing multiple modular exponentiations as in RSA-based group signatures, the system uses elliptic curve point operations and bilinear pairings, which are computationally more efficient and provide the same security level with smaller key sizes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If the number of group members increases, then the group signature functionality remains the same, but the signature length and calculation amount increase proportionally

Engineering Contradiction:
Improvegroup size adaptabilityVSAvoidsignature length
Core Design Contradiction:
Adaptability or versatilityVSLength of stationary object

Solution Approach 1:

The patent fundamentally changes the parameter dependency by using pairing-based cryptography where signature length becomes independent of group size. The signature consists of a constant number of group elements regardless of how many members are in the group, achieving O(1) signature length instead of O(n) in conventional schemes.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the signature into fixed-size components that do not scale with group membership. Each signature contains a constant number of pairing verification equations and group elements, separating the verification complexity from the group size parameter.

Inventive Principle:
Principle #1Segmentation

3Reliability

If RSA-based group signature schemes are used, then security is maintained, but the calculation amount is about 200 times that of RSA signature

Engineering Contradiction:
ImprovesecurityVSAvoidcalculation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent substitutes RSA-based cryptographic mechanisms with pairing-based cryptographic mechanisms. Instead of relying on RSA's modular exponentiation and factorization hardness, the system uses elliptic curve discrete logarithm problems and bilinear pairing properties, which provide equivalent security with dramatically improved computational efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the cryptographic parameter foundation from RSA modulus sizes (typically 2048 bits) to pairing-friendly elliptic curve parameters (typically 256-512 bits for equivalent security). This parameter change reduces the computational burden while maintaining security levels, achieving calculation amounts closer to standard RSA signatures rather than 200 times higher.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8200977B2Group signature system, device, and program
Publication Date: 2012.06.12 TOSHIBA DIGITAL SOLUTIONS CORP
  • US8200977B2 patent drawing
  • US8200977B2 patent drawing
  • US8200977B2 patent drawing

AI summary

A group signature system includes a group manager device, a signer device and a verifier device capable of communicating with each other, each device using a group signature scheme. The group manager device generates a group secret key, a group public key, a member secret key and a signer tracing information. The signer device generates an encrypted text data of the signer tracing information, and a zero-knowledge proof showing that the signer device knows the member secret key and the encrypted text data is correctly generated based on the signer tracing information. The signer device transmits, to the verifier device, a group signature composed of the encrypted text data and the zero knowledge proof, and the message. The verifier device verifies correctness of the group signature and transmits the verified result to the signer device.