Communications in Cryptology IACR CiC

Multi Designated Verifier Ring Signatures


Sebastian Kolby, Elena Pagnin, Sophia Yakoubov
Sebastian Kolby ORCID
Aarhus University, Aarhus, Denmark
sk at cs dot au dot dk
Elena Pagnin ORCID
Chalmers University of Technology and University of Gothenburg, Gothenburg, Sweden
elenap at chalmers dot se
Sophia Yakoubov ORCID
Aarhus University, Aarhus, Denmark
sophia dot yakoubov at cs dot au dot dk


We study signatures well suited for sensitive applications (e.g. whistleblowing) where both the signer's anonymity and deniability are important. Two independent lines of work have tackled these two goals: ring signatures ensure the signer's anonymity (within a set of signers, called a ring), and — separately — multi designated verifier signatures ensure that all the intended recipients agree on whether a signature is valid, while maintaining the signer's deniability by preventing the intended recipients from convincing an outsider of the validity of the signature. In this paper, we introduce multi designated verifier ring signatures (MDVRS), which simultaneously offer both signer anonymity and deniability. This makes MDVRS uniquely suited for sensitive scenarios.

Following the blueprint of Damgård et al (TCC'20) for multi designated verifier signatures, we introduce provably simulatable designated verifier ring signatures (PSDVRS) as an intermediate building block which we then compile into an MDVRS. We instantiate PSDVRS in a concretely efficient way from discrete logarithm based sigma protocols, encryption and commitments.


Submitted: 2024-07-08
Accepted: 2024-09-02
Published: 2024-10-07
Sebastian Kolby, Elena Pagnin, and Sophia Yakoubov, Multi Designated Verifier Ring Signatures. IACR Communications in Cryptology, vol. 1, no. 3, Oct 07, 2024, doi: 10.62056/a33zivrzn.


