Paper 2025/1955
Aggregate Signatures Tightly Secure under Adaptive Corruptions
Abstract
Aggregate signatures allow compressing multiple single-signer signatures into a single short aggregate signature. This primitive has attracted new attention due to applications in blockchains and cryptocurrencies. In multisig addresses, which is one of such applications, aggregate signatures reduce the sizes of transactions from multisig addresses. Security of aggregate signatures under adaptive corruptions of signing keys is important, since one of the motivations of multisig addresses was a countermeasure against signing key exposures. We propose the first aggregate signature scheme tightly secure under adaptive corruptions using pairings. An aggregate signature includes two source group elements of bilinear groups plus a bit vector whose length is equal to the number of single-signer signatures being aggregated. To construct a scheme, we employ a technique from quasi-adaptive non-interactive zero-knowledge arguments. Our construction can be seen as modularization and tightness improvement of Libert et al.'s threshold signature scheme supporting signature aggregation (Theoretical Computer Science 645) in a non-threshold setting.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2025
- Keywords
- aggregate signaturestight securityadaptive corruptions
- Contact author(s)
- yusuke sakai @ aist go jp
- History
- 2025-10-20: approved
- 2025-10-20: received
- See all versions
- Short URL
- https://ia.cr/2025/1955
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1955,
author = {Yusuke Sakai},
title = {Aggregate Signatures Tightly Secure under Adaptive Corruptions},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1955},
year = {2025},
url = {https://eprint.iacr.org/2025/1955}
}