Aggregate and verifiably encrypted signatures from bilinear maps

被引:0
作者
Boneh, D [1 ]
Gentry, C [1 ]
Lynn, B [1 ]
Shacham, H [1 ]
机构
[1] Stanford Univ, Stanford, CA 94305 USA
来源
ADVANCES IN CRYPTOLOGY-EUROCRYPT 2003 | 2003年 / 2656卷
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
An aggregate signature scheme is a digital signature that supports aggregation: Given n signatures on n distinct messages from n distinct users, it is possible to aggregate all these signatures into a single short signature. This single signature (and the n original messages) will convince the verifier that the n users did indeed sign the n original messages (i.e., user i signed message M-i for i = 1,. . ., n). In this paper we introduce the concept of an aggregate signature, present security models for such signatures, and give several applications for aggregate signatures. We construct an efficient aggregate signature from a recent short signature scheme based on bilinear maps due to Boneh, Lynn, and Shacham. Aggregate signatures are useful for reducing. the size of certificate chains (by aggregating all signatures in the chain) and for reducing message size in secure routing protocols such as SBGP. We also show that aggregate signatures give rise to verifiably encrypted signatures. Such signatures enable the verifier to test that a given ciphertext C is the encryption of a signature on a given message M. Verifiably encrypted signatures are used in contract-signing protocols. Finally, we show that similar ideas can be used to extend the short signature scheme to give simple ring signatures.
引用
收藏
页码:416 / 432
页数:17
相关论文
共 28 条
[1]   Optimistic fair exchange of digital signatures [J].
Asokan, N ;
Shoup, V ;
Waidner, M .
IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2000, 18 (04) :593-610
[2]   Efficient and practical fair exchange protocols with off-line TTP [J].
Bao, F ;
Deng, RH ;
Mao, WB .
1998 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1998, :77-85
[3]  
Bellare M, 1996, LECT NOTES COMPUT SC, V1070, P399
[4]  
Boldyreva A, 2003, LECT NOTES COMPUT SC, V2567, P31
[5]  
Boneh D., 2001, LNCS, P514, DOI [DOI 10.1007/3-540-45682-1_30, DOI 10.1007/3-540-45682-130]
[6]  
BONEH D, 2001, LNCS, V2139
[7]  
BONEH D, 2002, AGGREGATE VERIFIABLY
[8]  
Dodis Y, 2003, LECT NOTES COMPUT SC, V2567, P1
[9]  
FIAT A, 1990, LECT NOTES COMPUT SC, V435, P175
[10]  
Garay J. A., 1999, Advances in Cryptology - CRYPTO'99. 19th Annual International Cryptology Conference. Proceedings, P449