Group-Signature Schemes on Constrained Devices: The Gap Between Theory and Practice

Raphael Spreitzer, Jörn-Marc Schmidt

Research output: Chapter in Book/Report/Conference proceedingConference paperpeer-review


Group-signature schemes allow members within a predefined group to prove specific properties without revealing more information than necessary. Potential areas of application include electronic IDs (eIDs) and smartcards, i.e., resource-constrained environments. Though literature provides many theoretical proposals for group-signature schemes, practical evaluations regarding the applicability of such mechanisms in resource-constrained environments are missing. In this work, we investigate four different group-signature schemes in terms of mathematical operations, signature length, and the proposed revocation mechanisms. We also use the RELIC toolkit to implement the two most promising of the investigated group-signature schemes---one of which is going to be standardized in ISO/IEC 20008---for the AVR microcontroller. This allows us to give practical insights into the applicability of pairings on the AVR microcontroller in general and the applicability of group-signature schemes in particular on the very same. Contrary to the general recommendation of precomputing and storing pairing evaluations if possible, we observed that the evaluation of pairings might be faster than computations on cached pairings.
Original languageEnglish
Title of host publicationCS2'14 Proceedings
PublisherAssociation of Computing Machinery
ISBN (Print)978-1-4503-2484-7
Publication statusPublished - 2014
EventWorkshop on Cryptography and Security in Computing Systems - Wien, Austria
Duration: 20 Jan 201422 Jan 2014


ConferenceWorkshop on Cryptography and Security in Computing Systems

Fields of Expertise

  • Information, Communication & Computing

Treatment code (Nähere Zuordnung)

  • Application


Dive into the research topics of 'Group-Signature Schemes on Constrained Devices: The Gap Between Theory and Practice'. Together they form a unique fingerprint.

Cite this