<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.0 20120330//EN" "JATS-journalpublishing1.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article">
	<front>
		<journal-meta>
			<journal-id journal-id-type="publisher-id">INFORMATICA</journal-id>
			<journal-title-group>
				<journal-title>Informatica</journal-title>
			</journal-title-group>
			<issn pub-type="epub">0868-4952</issn>
			<issn pub-type="ppub">0868-4952</issn>
			<publisher>
				<publisher-name>VU</publisher-name>
			</publisher>
		</journal-meta>
		<article-meta>
			<article-id pub-id-type="publisher-id">inf14106</article-id>
			<article-id pub-id-type="doi">10.15388/Informatica.2003.006</article-id>
			<article-categories>
				<subj-group subj-group-type="heading">
					<subject>Research article</subject>
				</subj-group>
			</article-categories>
			<title-group>
				<article-title>On the Linkability of Some Group Signature Schemes</article-title>
			</title-group>
			<contrib-group>
				<contrib contrib-type="Author">
					<name>
						<surname>Sun</surname>
						<given-names>Hung‐Min</given-names>
					</name>
					<email xlink:href="mailto:hmsun@cs.nthu.edu.tw">hmsun@cs.nthu.edu.tw</email>
					<xref ref-type="aff" rid="j_INFORMATICA_aff_000"/>
				</contrib>
				<aff id="j_INFORMATICA_aff_000">Department of Computer Science, National Tsing Hua University, Hsinchu, Taiwan 300</aff>
			</contrib-group>
			<contrib-group>
				<contrib contrib-type="Author">
					<name>
						<surname>Yeh</surname>
						<given-names>Her‐Tyan</given-names>
					</name>
					<email xlink:href="mailto:htyeh@ismail.csie.ncku.edu.tw">htyeh@ismail.csie.ncku.edu.tw</email>
					<xref ref-type="aff" rid="j_INFORMATICA_aff_001"/>
				</contrib>
				<contrib contrib-type="Author">
					<name>
						<surname>Hwang</surname>
						<given-names>Tzonelih</given-names>
					</name>
					<xref ref-type="aff" rid="j_INFORMATICA_aff_001"/>
				</contrib>
				<aff id="j_INFORMATICA_aff_001">Department of Computer Science and Information Engineering, National Cheng Kung University, Tainan, Taiwan 701</aff>
			</contrib-group>
			<pub-date pub-type="epub">
				<day>01</day>
				<month>01</month>
				<year>2003</year>
			</pub-date>
			<volume>14</volume>
			<issue>1</issue>
			<fpage>85</fpage>
			<lpage>94</lpage>
			<history>
				<date date-type="received">
					<day>01</day>
					<month>03</month>
					<year>2003</year>
				</date>
			</history>
			<abstract>
				<p>A group signature scheme is a digital signature scheme that allows a group member to sign messages anonymously on behalf of the group. Recently, Tseng and Jan proposed two group signature schemes based on self‐certified and ID‐based public keys respectively. However, these two schemes were shown to be insecure against forgery due to Joye et al. Later, Sun et al. showed that Tseng and Jan's self‐certified group signature scheme is linkable. In this paper, we first point out that the proposed linking equation, which is used to check the linkability of Tseng and Jan's self‐certified scheme, cannot work because the inverse problem of RSA is hard. A repaired linking equation is consequently proposed to fix this problem. Then, we show that Tseng and Jan's ID‐based scheme is still linkable because given any two valid group signatures it is easy to decide whether these two group signatures are generated by the same group member or not.</p>
			</abstract>
			<kwd-group>
				<label>Keywords</label>
				<kwd>cryptography</kwd>
				<kwd>group signatures</kwd>
				<kwd>digital signatures</kwd>
				<kwd>ID‐based</kwd>
				<kwd>self‐certified</kwd>
				<kwd>data security</kwd>
			</kwd-group>
		</article-meta>
	</front>
</article>