Generalized Multi-Public-Key Signature Schemes
- Generalized multi-public-key signature schemes are cryptographic frameworks that combine independent public keys to jointly create a single, verifiable signature on a common message with strong security guarantees.
- These schemes use polynomial-time algorithms for setup, key generation, aggregation, signing, and verification across various algebraic structures, achieving constant-size keys and signatures regardless of the number of signers.
- They are crucial in applications such as blockchain, distributed ledgers, and post-quantum cryptography, offering efficient, robust protection against rogue-key attacks and enabling scalable multi-party authentication.
A generalized multi-public-key signature scheme enables a set of independently generated public keys to be combined so that multiple parties jointly produce a single, compact, and verifiably aggregated signature on a common message. This framework unifies and extends the notions of multi-signatures, aggregate signatures, and group signatures, supporting advanced features such as order integrity, key-and-signature compactness, aggregation correctness, and post-quantum security. These schemes have become foundational in distributed systems, blockchains, and threshold cryptography due to their efficiency, robustness to rogue-key attacks, and adaptability to new algebraic and security models (Tezuka et al., 22 Sep 2025, Jiang et al., 2023, Rahmati et al., 2024, Xiao et al., 2022).
1. Formal Models and Essential Algorithms
Generalized multi-public-key signature schemes are defined by a suite of polynomial-time algorithms operating over a specified algebraic structure (group, ring, or module):
- Setup: Establishes global parameters, sometimes including bilinear groups (pairings) or lattice parameters.
- Key Generation (KGen): Each signer independently generates a secret/public key pair. Some constructions require non-interactive Proof-of-Possession (PoP) to thwart rogue-key attacks (Xiao et al., 2022).
- Key Verification (KVerify): Validates public key correctness, again often via PoP.
- Public-Key Aggregation (KAgg/AggKey/AggregatePK): Compresses a set or sequence of public keys into a single aggregated public key , capturing signers’ identities and, in ordered settings, their order (Tezuka et al., 22 Sep 2025).
- Signing (Sign): Parties jointly or sequentially produce partial signatures that are finally combined into a single signature .
- Verification (SVerify/Verify): Checks that is a valid multi-signature for both the message and the exact set (and possibly order) of participating keys under the aggregated public key.
These algorithms must guarantee correctness (every honest aggregated signature verifies) and strong security notions (existential unforgeability, order integrity, aggregation correctness).
2. Security Models and Attack Resistance
Security for multi-public-key signature schemes is framed in variants of existential unforgeability under chosen-message attack (EUF-CMA). Common enhancements include:
- Certified-Key (CK) Model: Requires all signers register verifiable keys (often with PoP) (Tezuka et al., 22 Sep 2025, Xiao et al., 2022).
- Rogue-Key Attack Resistance: Enforced via PoP and the aggregation function’s independence from other participants' keys. AGMS/GMS implement strict PoP-based verification (Xiao et al., 2022).
- Order Integrity: In ordered multi-signature schemes, the verification must ensure not just authenticity and aggregation, but also proof that the signers participated in exactly the claimed sequence (Tezuka et al., 22 Sep 2025).
- Aggregation Correctness: The aggregated public key and the signature must be unambiguously linked to a specific key set (or sequence) (Tezuka et al., 22 Sep 2025, Jiang et al., 2023).
- Quantum Resistance: Achieved in lattice-based schemes by security reductions to Module-LWE/MSIS (Rahmati et al., 2024, Jiang et al., 2023).
The security proofs commonly employ random oracle models, forking lemmas (including “nested-forking” (Jiang et al., 2023)), and, for non-pairing-based schemes, reductions to group or lattice hardness assumptions.
3. Constructions: Algebraic and Protocol Variants
3.1 Pairing-Based and Sequential-Aggregate Constructions
The scheme in "Ordered Multi-Signatures with Public-Key Aggregation from SXDH Assumption" (Tezuka et al., 22 Sep 2025) operates over asymmetric-bilinear groups with the SXDH assumption. The sequential signing protocol allows each to extend a partial signature, maintaining verifiable order. Public key aggregation is realized using accumulation in as , , and verification relies on specific pairing equations. The final multi-signature and aggregated key sizes remain constant, independent of the number of signers.
3.2 Linear ID-Scheme Compiler and Group-Based Schemes
"Key-and-Signature Compact Multi-Signatures for Blockchain" (Jiang et al., 2023) introduces a generic compiler transforming any linear identification scheme (ID) into a multi-signature with both key and signature sizes independent of the number of signers. Instantiations include Schnorr-based and lattice-based ID schemes, employing randomness-derived scalars () to assemble the aggregate public key and signature. This design efficiently resists rogue-key attacks by hashing each key into a weight, enforcing tight dependency between the aggregated key and the signature.
3.3 Lattice-Based Quantum-Resistant Designs
Quantum-resistant schemes such as Razhi-ms (Rahmati et al., 2024) generalize multi-signatures to the lattice setting. Each signer possesses a lattice-based key pair and generates partial signatures encapsulating masked and encrypted shares. Communication requires only a single parallel round. The final aggregate signature and aggregated public key have the same size as single-user signatures (e.g., Dilithium), with security against lattice attacks (MLWE/MSIS). This architecture achieves UF-ESA (unforgeability even given all individual partial signatures) and enables truly post-quantum blockchains.
3.4 Tree-Structured Schemes for Scalability
GMS/AGMS (Xiao et al., 2022) are designed for scalable enterprise blockchains and support tree-structured communication for large numbers of signers. The advanced AGMS protocol moves expensive commitment and challenge steps offline, minimizing online latency to a single scalar multiplication per signer.
4. Efficiency and Complexity
Generalized multi-public-key schemes achieve significant efficiency compared to naïve multi-signature techniques:
| Scheme | Aggregated PK Size | Signature Size | Verification Complexity |
|---|---|---|---|
| Pairing-based | Constant | Constant | Constant pairings (e.g., 3 pairings) |
| Linear-ID | Constant | Constant | 2 exponentiations (Schnorr) |
| Lattice-based | Constant | Constant | 1-2 ring multiplications + 1 hash |
| GMS/AGMS (ECC) | Constant | Constant | 2 exponentiations + 1 inversion |
Public key and signature sizes are independent of the number of participants (). Verification workloads are minimal (constant group/ring operations). Offline/online splits as in AGMS allow precomputation, further reducing signing latency for real-time applications (Xiao et al., 2022).
5. Rogue-Key and 0-Sum Problem Countermeasures
To defend against rogue-key attacks, leading schemes require:
- Non-interactive proof-of-possession mechanisms at key registration, ensuring private key knowledge for every public key (Xiao et al., 2022).
- Aggregation functions that are order-sensitive or hash-dependent, binding aggregated signing data to explicitly verified sets (Jiang et al., 2023).
- Additional measures against 1-sum (birthday-style) attacks, such as separating challenge and message hashes, to prevent adversarial manipulation via repeated protocol runs (Xiao et al., 2022).
These protections are central for trustless, decentralized deployments such as public blockchains.
6. Applications and Generalizations
Generalized multi-public-key signature protocols are deployed in:
- Blockchain and Distributed Ledgers: Compact authorization of payments or consensus commitments in Bitcoin, Fabric, and other platforms (Xiao et al., 2022, Rahmati et al., 2024).
- Threshold and Group Signatures: Schemes are extensible to 2-of-3 threshold settings, though some constructions (e.g., (Tezuka et al., 22 Sep 2025)) note this as a target for future work.
- Aggregate and Sequential Signatures: Ordered schemes (e.g., (Tezuka et al., 22 Sep 2025)) embed additional metadata such as signer sequences; linear-ID approaches generalize to various algebraic settings (Jiang et al., 2023).
- Post-Quantum Cryptography: Lattice-based designs are essential for long-term viability as new quantum adversary models emerge (Rahmati et al., 2024).
The offline/online partitioning and constant-size features make these schemes suitable for high-throughput, bandwidth-constrained, and latency-sensitive environments.
7. Open Problems and Prospective Directions
Current limitations and directions for further research include:
- Extending order and aggregation properties to dynamic groups and threshold variants (e.g., generalized inner-product aggregation (Tezuka et al., 22 Sep 2025)).
- Broadening message space flexibility, especially in pairing-based constructions restricted to modular messages (Tezuka et al., 22 Sep 2025).
- Further optimizing communication rounds, especially for settings demanding near-zero latency (Rahmati et al., 2024).
- Realizing efficient quantum-resistant schemes with provable UF-ESA security for a wider class of applications (Rahmati et al., 2024).
- Investigating new algebraic frameworks (beyond groups/rings/modules) and more expressive policy enforcement (e.g., attribute-based or function-based aggregation).
The rapid evolution of multi-public-key signature schemes points to continued foundational impact in both theory and applied cryptography.