A novel group signature scheme with subliminal channel
The conventional group signature scheme allows a group member to anonymously sign a message on behalf of the group, but only the group manager can identify the signer. Sometimes, a group member may send a subliminal message to the special receiver on behalf of the group, while others cannot obtain this subliminal message but can verify this signature's validity. In this paper, we extend the conventional group signature and propose a novel signature type, namely the group signature scheme with subliminal channel, to realize this functionality. In this scheme, the size of signature and public key is independent of the size of the group.