A Domain Transformation for Structure-Preserving Signatures on Group Elements
The authors present a generic transformation that allows one to use a large class of pairing-based signatures to construct schemes for signing group elements in a structure preserving way. As a result of the transformation they obtain a new efficient signature scheme for signing a vector of group elements that are based only on the well established Decisional LINear assumption (DLIN). Moreover, the public keys and signatures of the scheme consist of group elements only, and a signature is verified by evaluating a set of pairing-product equations. In combination with the Groth-Sahai proof system, such a signature scheme is an ideal building block for many privacy-enhancing protocols.