Multi-signatures allow to combine individual signatures from different signers on the same message into a short aggregated signature. Newer schemes further allow to aggregate the individual public keys, such that the combined signature gets verified against a short aggregated key. This makes them a versatile alternative to threshold or distributed signatures: the aggregated key can serve as group key, and signatures under that key can only be computed with the help of all signers. What makes multi-signatures even more attractive is their simple key management, as users can re-use the same secret key in several and ad-hoc formed groups. In that context, it will be desirable to not sacrifice privacy as soon as keys get re-used and ensure that...
Traditional single-user security models do not necessarily capture the power of real-world attackers...
Traditional single-user security models do not necessarily capture the power of real-world attackers...
Aggregate signatures provide bandwidth-saving aggregation of ordinary signatures. We present the fir...
We describe a new Schnorr-based multi-signature scheme (i.e., a protocol which allows a group of sig...
A multisignature scheme is used to aggregate signatures by multiple parties on a common message $m$ ...
A multi-signature scheme allows a group of signers to collaboratively sign a message, creating a si...
We propose a variant of the original Boneh, Drijvers, and Neven (Asiacrypt \u2718) BLS multi-signatu...
Multi-signature is a protocol where a set of signatures jointly sign a message so that the final sig...
The work presents a new signature scheme, called the multi-threshold signature, which generalizes th...
Aggregate signatures are a useful primitive which allows to aggregate into a single and constant-len...
2019 IEEE. A multi signature scheme allows a group of signers to produce a joint signature on a comm...
Multi-signatures allow for compressing many signatures for the same message that were generated unde...
A group signature is a basic privacy mechanism. The group joining operation is a critical component ...
A multi-signature scheme allows a group of signers to collaboratively sign a message, creating a sin...
We survey two recent signature constructions that support signature aggregation: Given n signatures ...
Traditional single-user security models do not necessarily capture the power of real-world attackers...
Traditional single-user security models do not necessarily capture the power of real-world attackers...
Aggregate signatures provide bandwidth-saving aggregation of ordinary signatures. We present the fir...
We describe a new Schnorr-based multi-signature scheme (i.e., a protocol which allows a group of sig...
A multisignature scheme is used to aggregate signatures by multiple parties on a common message $m$ ...
A multi-signature scheme allows a group of signers to collaboratively sign a message, creating a si...
We propose a variant of the original Boneh, Drijvers, and Neven (Asiacrypt \u2718) BLS multi-signatu...
Multi-signature is a protocol where a set of signatures jointly sign a message so that the final sig...
The work presents a new signature scheme, called the multi-threshold signature, which generalizes th...
Aggregate signatures are a useful primitive which allows to aggregate into a single and constant-len...
2019 IEEE. A multi signature scheme allows a group of signers to produce a joint signature on a comm...
Multi-signatures allow for compressing many signatures for the same message that were generated unde...
A group signature is a basic privacy mechanism. The group joining operation is a critical component ...
A multi-signature scheme allows a group of signers to collaboratively sign a message, creating a sin...
We survey two recent signature constructions that support signature aggregation: Given n signatures ...
Traditional single-user security models do not necessarily capture the power of real-world attackers...
Traditional single-user security models do not necessarily capture the power of real-world attackers...
Aggregate signatures provide bandwidth-saving aggregation of ordinary signatures. We present the fir...