A cryptographic method and apparatus for anonymously signing a message.
Added to the anonymous signature is another signature which is calculated
(operation 13) using a private key common to all the members of a group
authorized to sign and unknown to all revoked members. The private key is
updated (operations 8, 11) at group level on each revocation within the
group and at member level only on anonymous signing of a message by the
member.