Paper 2026/836

Privacy-Preserving Aggregate-Signatures: Generic Constructions and Practical Instantiations

Xiaoyang Wei, Shanghai Jiao Tong University
Shuai Han, Shanghai Jiao Tong University
Shengli Liu, Shanghai Jiao Tong University
Abstract

Aggregate signatures allow a set of signers to compress individual signatures on distinct messages into a short signature, offering significant savings in storage and verification time. However, existing aggregate signatures neither support key aggregation nor achieve strong privacy guarantees for signers. In a very recent work, Nick, Ruffing and Seurin (EUROCRYPT’26) proposed DahLIAS, a pairing-free aggregate signature scheme with constant size signatures. Unfortunately, DahLIAS fails to provide aggregated verification and privacy properties. As a side contribution, they also constructed a generic transformation from multi-signatures to aggregate-signatures. However, the transformed schemes cannot satisfy unrestrictedness and privacy. In this paper, we formally introduce the notion of aggregate signatures with verifiable key aggregation (ASvKA), along with new unforgeability and privacy definitions. We then present a generic transformation that turns any multi-signature (MS) scheme into aggregate signature scheme with verifiable key aggregation and privacy properties, which also lifts weaker unforgeability of the underlying MS to stronger unforgeability of ASvKA. Finally, we instantiate our transformation with two concrete multi-signature schemes. For pairing-free schemes, we propose PP-SpeedyASvKA, a two-round privacy-preserving aggregate signature derived from the multi-signature SpeedyMuSig, achieving the strongest unforgeability and privacy while preserving the efficiency. For pairing-based schemes, we construct PP-BAS-0 and PP-BAS-1 from a BLS multi-signature, offering different trade-offs between unforgeability and privacy.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Aggregate-signaturesPrivacy-preservingGeneric TransformationKey Aggregation
Contact author(s)
weixy02 @ sjtu edu cn
dalen17 @ sjtu edu cn
slliu @ sjtu edu cn
History
2026-05-03: approved
2026-04-28: received
See all versions
Short URL
https://ia.cr/2026/836
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/836,
      author = {Xiaoyang Wei and Shuai Han and Shengli Liu},
      title = {Privacy-Preserving Aggregate-Signatures: Generic Constructions and Practical Instantiations},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/836},
      year = {2026},
      url = {https://eprint.iacr.org/2026/836}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.