Paper 2026/2292
Nonstop Multihop? Constructions and Lower Bounds for Re-Aggregatable Multisignatures
Abstract
Multisignatures compress many signatures on a common message into a single aggregate. In large distributed systems, aggregation occurs over multiple hops, where partial aggregates may overlap. The recent hint-free multisignatures of Hofheinz, Reichle, and Wagner (TCC~2026) eliminate aggregation-topology hints, but verification still requires the complete set of participating public keys. This leaves open whether the signer-set information itself can be eliminated. We answer this question negatively. We introduce idempotent multisignatures to capture unrestricted aggregation of overlapping aggregates and prove that any such scheme has a signature size linear in the number of signers. To circumvent this lower bound, we introduce unique multisignatures, a sequential alternative that eliminates this metadata and retains constant-size signatures. We construct unique multisignatures using incrementally verifiable computations. Finally, replacing signature chains in authenticated Dolev-Strong Byzantine Broadcast with our primitive enables two-round termination when the sender is honest and reduces communication from $O(n^3)$ to $O(n^2)$ against $t<n$ adaptive corruptions.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Multisignatures
- Contact author(s)
-
hanzlik @ cispa de
julian loss @ rub de
omar renawi @ cispa de - History
- 2026-10-04: approved
- 2026-10-01: received
- See all versions
- Short URL
- https://ia.cr/2026/2292
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2292,
author = {Lucjan Hanzlik and Julian Loss and Omar Renawi},
title = {Nonstop Multihop? Constructions and Lower Bounds for Re-Aggregatable Multisignatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2292},
year = {2026},
url = {https://eprint.iacr.org/2026/2292}
}