K. Maneva-Jakimoska

The anonymity provided by the threshold ring signature scheme proposed by Bres-son et al (Crypto'02) is perfect. However, its complexity is prohibitively large even for relatively small sets of signers. We propose use of threshold schemes based on covering designs that are efficient for large groups of signers. The cost we pay is non-perfect anonymity.
