T-Spoon: Tightly Secure Two-Round Multi-signatures with Key Aggregation
Renas Bacho, Benedikt Wagner
摘要
Multi-signatures over pairing-free cyclic groups have seen significant advancements in recent years, including achieving two-round protocols and supporting key aggregation. Key aggregation enables the combination of multiple public keys into a single succinct aggregate key for verification and has essentially evolved from an optional feature to a requirement.
To enhance the concrete security of two-round schemes, Pan and Wagner (Eurocrypt 2023, 2024) introduced the first tightly secure constructions in this setting. However, their schemes do not support key aggregation, and their approach inherently precludes a single short aggregate public key. This leaves the open problem of achieving tight security and key aggregation simultaneously.
In this work, we solve this open problem by presenting the first tightly secure two-round multi-signature scheme in pairing-free groups supporting key aggregation. As for Pan and Wagner's schemes, our construction is based on the DDH assumption. In contrast to theirs, it also has truly compact signatures, with signature size asymptotically independent of the number of signers.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- Earpicks: Tightly Secure Two-Round Multi and Threshold SignaturesRenas Bacho, Yanbo ChenEUROCRYPT 2026 · 被引用 1 次
- Chopsticks: Fork-Free Two-Round Multi-signatures from Non-interactive AssumptionsJiaxin Pan, Benedikt WagnerEUROCRYPT 2023 · 被引用 24 次
- Putting Multi Into Multi-signatures: Tight Security for Multiple SignersAnja Lehmann, Cavit ÖzbayEUROCRYPT 2026
- Toothpicks: More Efficient Fork-Free Two-Round Multi-signaturesJiaxin Pan, Benedikt WagnerEUROCRYPT 2024 · 被引用 10 次
- DahLIAS: Discrete Logarithm-Based Interactive Aggregate SignaturesJonas Nick, Tim Ruffing, Yannick SeurinEUROCRYPT 2026
