W.-B.Lee and C.-C.Chang (1998) proposed a very efficient group signature scheme based on the discrete logarithm problem. This scheme was subsequently improved by Y.-M.Tseng and J.-K.Jan (1999) so that the resulting group signatures are unlinkable. In this paper, we show that any obvious attempt to make unlinkable the Lee-Chang signatures would likely fail. More importnatly, we show that both the original Lee-Chang signature scheme and its improved version are universally forgeable.
展开▼