Batch Signatures, Revisited
Batch Signatures, Revisited
复制标题
重新审视批量签名
DOI:
--
复制
发表时间:
2023
期刊:
影响因子:
--
通讯作者:
Marcos Manzano
中科院分区:
文献类型:
--
作者:
C. A. Melchor;Martin R. Albrecht;Thomas Bailleux;Nina Bindel;James Howe;Andreas Hülsing;David Joseph;Marcos Manzano
We revisit batch signatures (previously considered in a draft RFC, and used in multiple recent works), where a single, potentially expensive, “inner” digital signature authenticates a Merkle tree constructed from many messages. We formalise a construction and prove its unforgeability and privacy properties. We also show that batch signing allows us to scale slow signing algorithms, such as those recently selected for standardisation as part of NIST’s post-quantum project, to high throughput, with a mild increase in latency. We demonstrate the practical efficiency of batch signing in the context of TLS. For the example of Falcon-512 in TLS, we can increase the amount of connections per second by a factor 3.2x, at the cost of an increase in the signature size by ∼ 14% and the median latency by ∼ 25% , where both are ran on the same 30 core server. We also discuss applications where batch signatures allow us to increase throughput and to save bandwidth. For example, again for Falcon-512, once one batch signature is available, the additional bandwidth for each of the remaining ? − 1 is only 82 bytes.