On Thu, Apr 3, 2014 at 4:11 PM, Michael Rogers <[email protected]> wrote: > > in Pond, does the > recipient have some trapdoor information that the server doesn't have, > allowing the recipient to tell which contact made the group signature?
Yes: http://www.robotics.stanford.edu/~xb/crypto04a/groupsigs.pdf Pond's group signatures are actually very cool, and (according to Boneh) VLR group signatures are also worth taking a look at, since they handle revocation better: http://cseweb.ucsd.edu/~hovav/dist/preteripsistic.pdf Trevor _______________________________________________ Messaging mailing list [email protected] https://moderncrypto.org/mailman/listinfo/messaging
