Author :
Wei, Puwen ; Wang, Mingqiang ; Wang, Wei
Abstract :
In 2007, Shacham and Waters [9] propose the first effi- cient ring signature scheme, without random oracles, based on standard assumptions. And the signature size is linear in the size of the ring. In this paper, we analyze the security of Shacham and Waters ring signature [9] when using the structure of ring signature proposed by [6]. We claim that, in some cases, Shacham and Waters ring signature can be applied in a more efficient way, i.e., the size of the ring sig- nature can be constant. Moreover, the signer can decide whether to provide linkability by herself.