Paper 2025/1955

Aggregate Signatures Tightly Secure under Adaptive Corruptions

Yusuke Sakai, National Institute of Advanced Industrial Science and Technology (AIST)
Abstract

Aggregate signatures allow compressing multiple single-signer signatures into a single short aggregate signature. This primitive has attracted new attention due to applications in blockchains and cryptocurrencies. In multisig addresses, which is one of such applications, aggregate signatures reduce the sizes of transactions from multisig addresses. Security of aggregate signatures under adaptive corruptions of signing keys is important, since one of the motivations of multisig addresses was a countermeasure against signing key exposures. We propose the first aggregate signature scheme tightly secure under adaptive corruptions using pairings. An aggregate signature includes two source group elements of bilinear groups plus a bit vector whose length is equal to the number of single-signer signatures being aggregated. To construct a scheme, we employ a technique from quasi-adaptive non-interactive zero-knowledge arguments. Our construction can be seen as modularization and tightness improvement of Libert et al.'s threshold signature scheme supporting signature aggregation (Theoretical Computer Science 645) in a non-threshold setting.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A major revision of an IACR publication in ASIACRYPT 2025
Keywords
aggregate signaturestight securityadaptive corruptions
Contact author(s)
yusuke sakai @ aist go jp
History
2025-10-20: approved
2025-10-20: received
See all versions
Short URL
https://ia.cr/2025/1955
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1955,
      author = {Yusuke Sakai},
      title = {Aggregate Signatures Tightly Secure under Adaptive Corruptions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1955},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1955}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.