A group signature allows a group member lo sign messages anonymously on behalf of the group. Only can a designated entity determine the identity of the group member who issued a given signature. In this paper we propose a new group signature scheme, suitable for large groups. i.e. the length of the group's public key and of signatures does not depend on the size of the group. Our group signature scheme is based on the difficulty of computation of approximate e-th roots modulo a composite number and is more efficient than the previous ones.
Group signature scheme, large groups, membership certificate, discrete logarithms, signature of knowledge.