## Cryptology ePrint Archive: Report 2019/1177

Aggregatable Signatures from an Inner Pairing Product Argument

Mary Maller and Noah Vesely

Abstract: We present a new public-coin setup protocol for aggregating BLS signatures on distinct messages. For $n$ messages the verifier computes just $6$ pairings and $6(n+\textrm{log}(n))$ exponentiations—an improvement on previous aggregate schemes in which the verifier computes $n+1$ pairings. Our aggregate signature is logarithmic in size. This result uses an $\textit{inner pairing product argument}$ of knowledge that can be used to prove membership in pairing-based languages.

Category / Keywords: public-key cryptography / Inner Pairing Product Argument, Aggregatable Signatures, Bilinear Pairings