In this paper, we propose a new BLS multi-signature (MS) scheme that offers advantages compared to the state-of-the-art Boneh-Drijvers-Neven MS (BDN-MS) scheme. Firstly, the proposed scheme is provably secure without a forking lemma. Specifically, we show that it is unforgeable under chosen message attack (uf-cma) in the plain public key model if BLS signature is uf-cma. Moreover, the security against the rogue public key attacks of our MS scheme can be reduced to the binding security of a multi-set commitment scheme, stemming from the commit-and-verify technique underlying the proposed BLS-MS which is of independent interest. Secondly, the proposed scheme supports incremental signing, that is, a new BLS signature can be added to an existing multi-signature of the same message. Thirdly, the proposed MS scheme has a more efficient public key aggregation algorithm, resulting in approximately 42 times faster verification process than BDN-MS when considering 10,000 signers. Finally, we also show that the proposed MS scheme can be extended into an aggregate MS (AMS) scheme as in that of BDN-MS.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Efficient Fork-Free BLS Multi-signature Scheme with Incremental Signing

  • Syh-Yuan Tan,
  • Tiong-Sik Ng,
  • Swee-Huay Heng

摘要

In this paper, we propose a new BLS multi-signature (MS) scheme that offers advantages compared to the state-of-the-art Boneh-Drijvers-Neven MS (BDN-MS) scheme. Firstly, the proposed scheme is provably secure without a forking lemma. Specifically, we show that it is unforgeable under chosen message attack (uf-cma) in the plain public key model if BLS signature is uf-cma. Moreover, the security against the rogue public key attacks of our MS scheme can be reduced to the binding security of a multi-set commitment scheme, stemming from the commit-and-verify technique underlying the proposed BLS-MS which is of independent interest. Secondly, the proposed scheme supports incremental signing, that is, a new BLS signature can be added to an existing multi-signature of the same message. Thirdly, the proposed MS scheme has a more efficient public key aggregation algorithm, resulting in approximately 42 times faster verification process than BDN-MS when considering 10,000 signers. Finally, we also show that the proposed MS scheme can be extended into an aggregate MS (AMS) scheme as in that of BDN-MS.