Aggregate and Verifiably Encrypted Signatures from Bilinear Maps
Aggregate and Verifiably Encrypted Signatures from Bilinear Maps
复制标题
DOI:
10.1007/3-540-39200-9_26
复制
发表时间:
2003-05
期刊:
影响因子:
--
通讯作者:
D. Boneh;Craig Gentry;Ben Lynn;H. Shacham
中科院分区:
文献类型:
--
作者:
D. Boneh;Craig Gentry;Ben Lynn;H. Shacham
An aggregate signature scheme is a digital signature that supports aggregation: Givennsignatures onndistinct messages fromndistinct users, it is possible to aggregate all these signatures into a single short signature. This single signature (and thenoriginal messages) will convince the verifier that thenusers did indeed sign thenoriginal messages (i.e., userisigned messageMifori= 1,...,n). In this paper we introduce the concept of an aggregate signature, present security models for such signatures, and give several applications for aggregate signatures. We construct an efficient aggregate signature from a recent short signature scheme based on bilinear maps due to Boneh, Lynn, and Shacham. Aggregate signatures are useful for reducing the size of certificate chains (by aggregating all signatures in the chain) and for reducing message size in secure routing protocols such as SBGP. We also show that aggregate signatures give rise to verifiably encrypted signatures. Such signatures enable the verifier to test that a given ciphertextCis the encryption of a signature on a given messageM. Verifiably encrypted signatures are used in contract-signing protocols. Finally, we show that similar ideas can be used to extend the short signature scheme to give simple ring signatures.