Provided by: AICIT
In the linkable ring signature schemes, the signer can link all the signature they signed while still remain the anonymity, i.e. the verifier can determine whether the arbitrary signatures are signed by the same signer or not. Under the PKI model, the signer generates the identification to link the signature, but using the same method, it is unlikely possible to construct a linkable ring signature scheme under the identity-based model. How to construct a linkable ring signature in the identity based model is one of the open problem proposed in. In this paper, using the accumulator scheme, the authors give a general short constant-size identity-based ring signature scheme satisfying linkable requirement.