Group signatures á la carte

A group signature scheme allows any member of a potentially large group to sign on behalf of the group. Group signatures are anonymous and unlinkable. Only a designated group manager can co-relate signatures and/or reveal the identity of the actual signer. At the same time, no one (including a group manager) can misattribute a valid signature. In this paper we construct a very efficient and provably secure group