Comparing two pairing-based aggregate signature schemes
This paper describes detailed security and performance comparisons of two aggregate signature schemes. The first (BGLS), due to \textit{D. Boneh, C. Gentry, B. Lynn} and \textit{H. Shacham} [Eurocrypt 2003, Lect. Notes Comput. Sci. 2656, 416--432 (2003; Zbl 1038.94553)], uses bilinear pairings and has a reductionist security proof assuming the random oracle model. The second (LOSSW), due to \textit{S. Lu, R. Ostrovsky, A. Sahai, H. Shacham} and \textit{B. Waters} [Eurocrypt 2006, Lect. Notes Comput. Sci. 4004, 465--485 (2006; Zbl 1140.94358)], also uses bilinear pairings but does not make use of the random oracle model for its security result. The schemes are compared when realized with a particular elliptic curve offering 128 bits of security due to \textit{P. S. L. M. Barreto} and \textit{M. Naehrig} [SAC 2005, Lect. Notes Comput. Sci. 3897, 319--331 (2006; Zbl 1151.94479)], and the protocol specifications and parameter selections are based on the best-known reductionist security arguments. The authors show that both signature schemes can be described using so-called Type 3 pairings (asymmetric pairings \(e: \mathbb{G}_1 \times \mathbb{G}_2 \rightarrow \mathbb{G}_T\) for which no efficiently-computable isomorphism between \(\mathbb{G}_1\) and \(\mathbb{G}_2\) is known) as opposed to the original setting of Type 2 pairings (an efficiently-computable isomorphism does exist). They argue that Type 3 pairings offer at least as much security in this context and that Type 2 pairings offer no performance benefits over Type 3 pairings using the the Barreto-Naehrig curves. Finally, the authors demonstrate that the BGLS scheme outperforms the LOSSW scheme with respect to size of public keys and signatures as well as signature generation and verification time.
- Unrestricted Aggregate Signatures
- Security of BLS and BGLS signatures in a multi-user setting
- Cryptology and Network Security
- Identity based aggregate signcryption schemes
- Information Security and Cryptology
- Universal signature aggregators
- Novel efficient certificateless aggregate signatures
- How to aggregate the CL signature scheme
- Advances in Cryptology – CRYPTO 2004
- Algorithmic Number Theory
- Algorithms for black-box fields and their application to cryptography
- Discrete logarithms and local units
- Discrete Logarithms in $GF ( P )$ Using the Number Field Sieve
- Efficient and Generalized Pairing Computation on Abelian Varieties
- Efficient Identity-Based Encryption Without Random Oracles
- Efficient pairing computation on supersingular abelian varieties
- Exponentiation in Pairing-Friendly Groups Using Homomorphisms
- scientific article; zbMATH DE number 1643939 (Why is no real title available?)
- scientific article; zbMATH DE number 5532069 (Why is no real title available?)
- scientific article; zbMATH DE number 2009971 (Why is no real title available?)
- scientific article; zbMATH DE number 1842492 (Why is no real title available?)
- scientific article; zbMATH DE number 2114384 (Why is no real title available?)
- scientific article; zbMATH DE number 1406786 (Why is no real title available?)
- Implementing cryptographic pairings
- Implementing Cryptographic Pairings over Barreto-Naehrig Curves
- Information Security and Cryptology - ICISC 2005
- Integer Variable χ–Based Ate Pairing
- Monte Carlo Methods for Index Computation (mod p)
- On computable isomorphisms in efficient asymmetric pairing-based systems
- On the relationship between squared pairings and plain pairings
- Pairing-Friendly Elliptic Curves of Prime Order
- Pairings for cryptographers
- Sequential Aggregate Signatures and Multisignatures Without Random Oracles
- The Equivalence between the DHP and DLP for Elliptic Curves Used in Practical Applications
- The Eta Pairing Revisited
- The number field sieve for integers of low weight
- Topics in Cryptology – CT-RSA 2005
- Unrestricted Aggregate Signatures
- Using number fields to compute logarithms in finite fields
- Converting pairing-based cryptosystems from composite to prime order setting -- a comparative analysis
- More efficient structure-preserving signatures -- or: bypassing the type-III lower bounds
- On cryptographic protocols employing asymmetric pairings -- the role of \(\Psi \) revisited
- Short signatures from Diffie-Hellman: realizing almost compact public key
- Key-homomorphic signatures: definitions and applications to multiparty signatures and non-interactive zero-knowledge
- Design in type-I, run in type-III: fast and scalable bilinear-type conversion using integer programming
- Subgroup security in pairing-based cryptography
- On the efficiency and security of pairing-based protocols in the type 1 and type 4 settings
- Sequential aggregate signatures with lazy verification from trapdoor permutations
- Information Security and Cryptology
- Rai-Choo! Evolving blind signatures to the next level
- Generalised asynchronous remote key generation for pairing-based cryptosystems
- Security of BLS and BGLS signatures in a multi-user setting
- NEST: strong key-insulated password-based shared-custodial blockchain wallets
- DahLIAS: discrete logarithm-based interactive aggregate signatures
- A comparison of MNT curves and supersingular curves
This page was built for publication: Comparing two pairing-based aggregate signature schemes
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q970534)