Group Signatures for Hierarchical Multigroups

At Eurocrypt'91, D. Chaum and E. Heyst introduced the notion of group signatures, which allow members of a group to make signatures on behalf of the group while remaining anonymous. This paper first presents a new type of group signatures for hierarchical multigroups. In group signatures for hierarchical multigroups, a user who is a member of a higher group is not only able to make a group signature of his higher group, but also able to make a group signature of lower affiliated group without disclosing his higher membership, while the size of the secret data is independent of the number of the groups in which the user participates. Furthermore, if necessary, the group authority identifies a signer from the given group signature.