Locally Verifiable Signature and Key Aggregation
Rishab Goyal, Vinod Vaikuntanathan
Abstract
Aggregate signatures (Boneh, Gentry, Lynn, Shacham, Eurocrypt 2003) enable compressing a set of N signatures on N different messages into a short aggregate signature. This reduces the space complexity of storing the signatures from linear in N to a fixed constant (that depends only on the security parameter). However, verifying the aggregate signature requires access to all N messages, resulting in the complexity of verification being at least Ω(N ).
In this work, we introduce the notion of locally verifiable aggregate signatures that enable efficient verification: given a short aggregate signature σ (corresponding to a set M of N messages), the verifier can check whether a particular message m is in the set, in time independent of N . Verification does not require knowledge of the entire set M. We demonstrate many natural applications of locally verifiable aggregate signature schemes: in the context of certificate transparency logs; in blockchains; and for redacting signatures, even when all the original signatures are produced by a single user.
We provide two constructions of single-signer locally verifiable aggregate signatures, the first based on the RSA assumption and the second on the bilinear Diffie-Hellman inversion assumption, both in the random oracle model.
As an additional contribution, we introduce the notion of compressing cryptographic keys in identity-based encryption (IBE) schemes, show applications of this notion, and construct an IBE scheme where the secret keys for N identities can be compressed into a single aggregate key, which can then be used to decrypt ciphertexts sent to any of the N identities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d74c4d25-ed48-41eb-93ad-bab1cb7ba657Cited by top-tier papers2
- Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous CredentialsOmid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya et al.CCS 2023 · 29 citations
- Pairing-Based Registered ABE for Boolean Formulas with a Linear-Size CRSRoy Stracovsky, Brent Waters, David J. WuCRYPTO 2026
Related papers
- Monotone-Policy Aggregate SignaturesMaya Farber Brodsky, Arka Rai Choudhuri, Abhishek Jain, Omer PanethEUROCRYPT 2024 · 14 citations
- Compact Certificates of Collective KnowledgeSilvio Micali, Leonid Reyzin, Georgios Vlachos, Riad S. Wahby et al.S&P 2021 · 15 citations
- Chipmunk: Better Synchronized Multi-Signatures from LatticesNils Fleischhacker, Gottfried Herold, Mark Simkin, Zhenfei ZhangCCS 2023 · 10 citations
- DahLIAS: Discrete Logarithm-Based Interactive Aggregate SignaturesJonas Nick, Tim Ruffing, Yannick SeurinEUROCRYPT 2026
- Squirrel: Efficient Synchronized Multi-Signatures from LatticesNils Fleischhacker, Mark Simkin, Zhenfei ZhangCCS 2022 · 33 citations
