Overview
ISO/IEC 20008-2:2013/Amd 2:2023 - "Information technology - Security techniques - Anonymous digital signatures - Part 2: Mechanisms using a group public key (Amendment 2)" updates the Part 2 specification of anonymous/group-based digital signature mechanisms. The amendment introduces new mechanisms (Mechanism 8 and Mechanism 9), clarifies symbols (e.g., Fp()), and refines clauses describing signature, verification, linking and revocation processes. This document is intended for implementers and evaluators of privacy-preserving signature systems that use a group public key and pairing-based cryptography.
Key Topics
- Anonymous digital signatures (group signatures / DAA-like schemes):
- Mechanisms provide anonymity for signers within a group while enabling verification under a group public key.
- The amendment lists mechanisms that include list signatures, pre-DAA, and DAA-style schemes.
- New mechanisms (Mechanism 8 and Mechanism 9):
- Detailed key generation, signature, verification, linking and revocation processes for each mechanism.
- Mechanism 8 uses bilinear (pairing-based) groups, independent generator proofs, hash-to-group and hash-to-Z constructions, and supports linking bases for selective linkability.
- Mechanism 9 specifies group issuer/opener keys and an interactive issuer-to-member enrollment protocol.
- Linking capability: allows signatures to be linked when signed under the same linking base (e.g., for abuse tracking) while preserving anonymity otherwise.
- Revocation models: supports both private key revocation (issuer-maintained lists) and verifier blacklist revocation (verifier-maintained local blacklists); notes trade-offs in anonymity when revocation reveals member keys.
- Cryptographic building blocks: bilinear group pairs, pairing functions, hash functions mapping to groups and integers, and security assumptions such as Pointcheval‑Sanders or q‑MSDH cited in the amendment.
Applications
- Implementers of privacy-preserving authentication, anonymous credential systems and group-signature services.
- Designers of systems requiring selective linkability (e.g., anonymous reporting, reputation systems, e‑voting primitives, or privacy-aware logging).
- Security engineers and cryptographers who need standardized, audit-ready specifications for group public key digital signatures and revocation strategies.
- Standards bodies and evaluators assessing compliance, security proofs, and interoperability of anonymous signature schemes.
Related standards
- Part of the ISO/IEC 20008 series on anonymous digital signatures; consult other parts of the series for complementary specifications, implementation notes and normative references.
Keywords: ISO/IEC 20008-2:2013/Amd 2:2023, anonymous digital signatures, group public key, DAA, pairing-based cryptography, linking, revocation, Pointcheval‑Sanders, q‑MSDH.