A redactable signature scheme allows removing parts of a signed message without invalidating the signature. Currently, the need to prove the validity of digital documents issued by governments and enterprises is increasing. However, when disclosing documents, governments and enterprises must remove privacy information concerning individuals. A redactable signature scheme is useful for such a situation. In this paper, we introduce the new notion of the t-out-of-n redactable signature scheme. This scheme has a signer, n redactors, a combiner, and a verifier. The signer designates n redactors and a combiner in advance and generates a signature of a message M. Each redactor decides parts that he or she wants to remove from the message and generates a piece of redaction information. The combiner collects pieces of redaction information from all redactors, extracts parts of the message that more than t redactors want to remove, and generate a redacted message. We consider the one-time redaction model which allows redacting signatures generated by the signer only once. We formalize the one-time redaction t-out-of-n redactable signature scheme, define security, and give a construction using the pairing based aggregate signature scheme in the random oracle model.
翻译:编辑签名方案允许删除签名信件的部分内容, 但不取消签名 。 目前, 证明政府和企业签发的数字文件有效性的必要性正在增加 。 但是, 当披露文件时, 政府和企业必须删除个人隐私信息 。 一个可编辑的签名方案对这种情况有用 。 在本文中, 我们引入了签名人、 编辑器、 组合器和验证器的新概念 。 签名人提前指定了 n 编辑器和组合器, 并生成了 M 信息的签名 。 每个编辑者决定他( 她)想从信件中删除的部分内容, 并生成一个编辑信息 。 合并者收集了所有编辑器的修改信息, 提取的信息中比编辑者想要删除的部分, 并生成了一条编辑信息 。 我们考虑一次性的修改模式, 允许签名人只用一次时间来进行修改签名 。 我们正式了一次性的编辑模式, 使用基于随机的构建模式或共享的签名方案, 来定义一个安全性 。