Batch Signatures, Revisited

Batch Signatures, Revisited
复制标题

重新审视批量签名

DOI:
--
复制
发表时间:
2023
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Marcos Manzano
Marcos Manzano
中科院分区:
--
文献类型:
--
作者:
C. A. Melchor;Martin R. Albrecht;Thomas Bailleux;Nina Bindel;James Howe;Andreas Hülsing;David Joseph;Marcos Manzano

文献摘要

被引文献

相似文献

我们重新审视批签名(以前在RFC草案中考虑过,并在最近的多个作品中使用),其中单个可能昂贵的“内部”数字签名验证了从许多消息构建的Merkle树。我们正式的建设,并证明其不可伪造性和隐私属性。我们还表明,批量签名使我们能够扩展缓慢的签名算法,如最近选择的标准化作为NIST的后量子项目的一部分,以高吞吐量,延迟略有增加。我们证明了批量签名的TLS的上下文中的实际效率。以TLS中的Falcon-512为例,我们可以将每秒的连接量增加3.2倍,代价是签名大小增加了1.14%,中值延迟增加了1.25%,两者都运行在同一个30核服务器上。我们还讨论了批签名的应用程序,使我们能够增加吞吐量和节省带宽。例如,同样对于Falcon-512,一旦有一个批签名可用,其余每个批签名的额外带宽是多少?-1只有82个字节。
We revisit batch signatures (previously considered in a draft RFC, and used in multiple recent works), where a single, potentially expensive, “inner” digital signature authenticates a Merkle tree constructed from many messages. We formalise a construction and prove its unforgeability and privacy properties. We also show that batch signing allows us to scale slow signing algorithms, such as those recently selected for standardisation as part of NIST’s post-quantum project, to high throughput, with a mild increase in latency. We demonstrate the practical efficiency of batch signing in the context of TLS. For the example of Falcon-512 in TLS, we can increase the amount of connections per second by a factor 3.2x, at the cost of an increase in the signature size by ∼ 14% and the median latency by ∼ 25% , where both are ran on the same 30 core server. We also discuss applications where batch signatures allow us to increase throughput and to save bandwidth. For example, again for Falcon-512, once one batch signature is available, the additional bandwidth for each of the remaining ? − 1 is only 82 bytes.