Short Signatures from the Weil Pairing

By Dan Boneh, Ben Lynn, and Hovav Shacham.

J. Cryptology, 17(4):297–319, Sep. 2004.


We introduce a short signature scheme based on the Computational Diffie-Hellman assumption on certain elliptic and hyper-elliptic curves. For standard security parameters, the signature length is about half that of a DSA signature with a similar level of security. Our short signature scheme is designed for systems where signatures are typed in by a human or are sent over a low-bandwidth channel. We survey a number of properties of our signature scheme such as signature aggregation and batch verification.



@Article{BLS04, author = {Dan Boneh and Ben Lynn and Hovav Shacham}, title = {Short Signatures from the {Weil} Pairing}, journal = {J. Cryptology}, year = 2004, volume = 17, number = 4, pages = {297-319}, month = sep }

