Practical Certificateless Aggregate Signatures From Bilinear Maps
Zheng Hu Gong, Yu Long, Xuan Hong, Kefei Chen · University of Twente Research Information · 2008
Abstract. In some restrictive environments, such as sensor networks, each sensor submits the newest information to the server, every message must be authenticated to immune forgery and replay attacks. But the regular signatures need to be saved and verified individually, which will heavily add the costs of the computation, storage and communication than the plain text mode in the constraint devices. Aggregate signature (AS) makes towards solving the above problem because anyone can aggregate n individual signatures on n distinct messages which are signed by n distinct signers, into a single compact signature σ. In this paper, two practical certificateless aggregate signature schemes, which are the first aggregate signature schemes in the CL-PKC, are proposed from bilinear maps. The first scheme CAS-1 reduces the costs of communication and signer-side computation but loses on the storage, while CAS-2 minimizes the storage but sacrifices the communication. One can choose either of the above schemes by the consideration of the implementation requirement. Our schemes do not need the public key certificate anymore and achieve the trust level 3, the same level with traditional PKI. Both of the schemes are proven secure in the random oracle model (ROM) by assuming the intractability of the computational Diffie-Hellman (CDH) problem over the groups with bilinear maps.