Short signatures from the Weil pairing

被引:1664
作者
Boneh, D [1 ]
Lynn, B [1 ]
Shacham, H [1 ]
机构
[1] Stanford Univ, Dept Comp Sci, Stanford, CA 94305 USA
关键词
digital signatures; short signatures; elliptic curves; pairings; bilinear maps;
D O I
10.1007/s00145-004-0314-9
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We introduce a short signature scheme based on the Computational Diffie-Hellman assumption on certain elliptic and hyperelliptic curves. For standard security parameters, the signature length is about half that of a DSA signature with a similar level of security. Our short signature scheme is designed for systems where signatures are typed in by a human or are sent over a low-bandwidth channel. We survey a number of properties of our signature scheme such as signature aggregation and batch verification.
引用
收藏
页码:297 / 319
页数:23
相关论文
共 55 条
[1]  
[Anonymous], LNCS
[2]  
ANSI, 1998, X962 ANSI
[3]  
*ANSI X9 COMM, X9592000 DSTU ANSI X
[4]   The improbability that an elliptic curve has subexponential discrete log problem under the Menezes-Okamoto-Vanstone algorithm [J].
Balasubramanian, R ;
Koblitz, N .
JOURNAL OF CRYPTOLOGY, 1998, 11 (02) :141-145
[5]  
BARRETO P, 2003, LNCS, V2576
[6]  
Barreto PSLM, 2002, LECT NOTES COMPUT SC, V2442, P354
[7]  
Bellare M, 1998, LECT NOTES COMPUT SC, V1403, P236, DOI 10.1007/BFb0054130
[8]  
Bellare M, 1996, LECT NOTES COMPUT SC, V1070, P399
[9]  
Blake I.F., 1999, LONDON MATH SOC LECT, V265
[10]  
Boldyreva A, 2003, LECT NOTES COMPUT SC, V2567, P31