International Association for Cryptologic Research

International Association
for Cryptologic Research

Eurocrypt 2026

DGSP: An Efficient Scalable Fully Dynamic Group Signature Scheme Using SPHINCS+


Mojtaba Fadavi
Department of Combinatorics & Optimization, University of Waterloo, Canada

Seyyed Arash Azimi
CPS2 Lab, Electrical Engineering Department, Shahid Rajaee Teacher Training University, Tehran, Iran

Sabyasachi Karati
Cryptology and Security Research Unit, Indian Statistical Institute, Kolkata, India

Samuel Jaques
Department of Combinatorics & Optimization, University of Waterloo, Canada


Keywords: post-quantum cryptography, group signatures, dynamic group signatures, SPHINCS+, hash-based signatures


Abstract

A group signature scheme enables users of a group to anonymously sign messages on behalf of the group, while a designated authority can revoke anonymity when needed to ensure user accountability. In this paper, we build a post-quantum fully dynamic group signature scheme from only symmetric encryption and hash functions.

Our protocol, DGSP, achieves the following: (i) the set-up time is effectively constant in the number of signatures that may be issued, with support for up to $2^{64}$ signatures; (ii) the tracing algorithm run by the authority has constant runtime in the number of users; (iii) the set of users is fully dynamic and users can be revoked or added as needed without system-wide updates; and (iv) forward anonymity, where if a user's secrets are compromised they cannot be used to de-anonymize previous signatures. DGSP is the first group signature based only on symmetric primitives to achieve all of these properties: the previous state-of-the-art in this area is SPHINX-in-the-Head (SITH), which does not achieve (ii) or (iv), and DGMT, which does not achieve (i) and may not achieve (iv). Like DGMT, but unlike SITH, DGSP is stateful and users must refresh a local storage of certificates to issue new signatures.

We provide a full Rust implementation, showing that our signatures are roughly 5 times larger than DGMT but nearly 100 times smaller than SITH, and all basic operations run in under 2 milliseconds. We prove security in the standard model based on typical assumptions for symmetric primitives. DGSP is a compelling solution for applications requiring large-scale user support, efficient operations, and conservative post-quantum security.

Publication

EUROCRYPT 2026, LNCS 16545

Paper

Artifact

Artifact number
eurocrypt/2026/a7

Artifact published
July 25, 2026

Badge
🏆 IACR EUROCRYPT Results Reproduced

README

ZIP (75.3 KB)  

View on Github

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Mojtaba Fadavi, Seyyed Arash Azimi, Sabyasachi Karati, and Samuel Jaques. (2026). DGSP: An Efficient Scalable Fully Dynamic Group Signature Scheme Using SPHINCS+. In Advances in Cryptology – EUROCRYPT 2026, Lecture Notes in Computer Science vol. 16545, pp. 454–485, Springer. https://doi.org/10.1007/978-3-032-25330-9_16. Artifact at https://artifacts.iacr.org/eurocrypt/2026/a7.