author="H. Poehls, K. Samelin, J. Posegga, H. de Meer"
title="Transparent Mergeable Redactable Signatures with Signer Commitment and Applications"
institution="Fakult{\"a}t f{\"u}r Informatik und Mathematik, Universit{\"a}t Passau",


State-of-the-art private redactable schemes (RSS) allow the signer to un-detectably add new elements to signed data after signature generation. We introduce a RSS with a signer commitment: it prohibits adding new elements after signature generation. This protects against a malicious signer and allows using RSS for applications like time-stamping. Moreover, we introduce another practically useful property: private mergeability. It allows merging two redacted versions of the same signed document into a single document with one signature. We show that neither mergeability nor signer commitment negatively impacts the existing security properties. We present a committing and mergeable redactable signature scheme that is provably secure, i.e., it is unforgeable, private and transparent. The performance analysis of our implementation shows its practicality.

