2021
DOI: 10.1007/978-3-030-75539-3_24
|View full text |Cite
|
Sign up to set email alerts
|

Non-interactive Half-Aggregation of EdDSA and Variants of Schnorr Signatures

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 16 publications
(4 citation statements)
references
References 45 publications
0
4
0
Order By: Relevance
“…In order to prevent again rogue-type attacks, we use a linear combination (instead of the simple sum), where the coefficients come from some random oracle (which was queried on all signatures that are aggregated). This technique is also used in the Schnorr-analogue by Chalkias et al [Cha+21]. We formally present our aggregate signature scheme and the rogue-attack for the simple-sum solution in the full version [BR21, Sec.…”
Section: Contributionsmentioning
confidence: 99%
See 2 more Smart Citations
“…In order to prevent again rogue-type attacks, we use a linear combination (instead of the simple sum), where the coefficients come from some random oracle (which was queried on all signatures that are aggregated). This technique is also used in the Schnorr-analogue by Chalkias et al [Cha+21]. We formally present our aggregate signature scheme and the rogue-attack for the simple-sum solution in the full version [BR21, Sec.…”
Section: Contributionsmentioning
confidence: 99%
“…This is the main reason of our failure in constructing aggregate signatures schemes on lattices that are shorter than the trivial concatenation. Note that in the discrete-logarithm setting of the Schnorr aggregate signature in [Cha+21], the challenge c and the commitment u are elements of the same space. This explains why there is a real improvement for Schnorr signatures, but not for FSwA signatures.…”
Section: Contributionsmentioning
confidence: 99%
See 1 more Smart Citation
“…Chalkias, Garillot, Kondi, and Nikolaenko [10] proposed the notion of half-aggregation. Halfaggregation allows compressing signatures into an aggregate signature that has half size of the total signature size.…”
Section: Related Workmentioning
confidence: 99%