Check out the new USENIX Web site.
Next: Second Solution. Up: First Solution. Previous: Security.

Efficiency Considerations.

This is a generic solution with a constant size of signature. In fact, the size of the signature is the same as that of the underlying signature scheme. From a computational point of view, there is a number of equality tests that is proportional to the number of revoked members, which can be considered as negligible, and the verification of only one signature. Another advantage of this solution is that the verifier does not have any extra computation to do. His work is no greater than that of the verifier in the underlying signature scheme. The work during the revocation phase is also constant. The group manager only has to add a value in the revocation list and to modify the resulting signature.