Research Article

Group Signatures with Message-Dependent Opening: Formal Definitions and Constructions

Box 3

The proposed construction in the random oracle model. The functions and are cryptographic hash functions and , which are modeled as random oracles in the security proof. is the parameter generation algorithm, which is defined in Section 2.5.
GKg:
, ,
, , , ,
; ; ;
 For :
 For :
 Output .
GSig:
, , ,
, , , , , , , ,
;
;
;
;
 Output .
GVf:
 If
Output
 Else output .
Td:
 Output .
Open:
 If
Output
 If :
 Output ;
 Else output .