---
title: Generalized Multi-Public-Key Signature Schemes
url: https://www.emergentmind.com/topics/generalized-multi-public-key-signature-schemes
type: topic
---

# Generalized Multi-Public-Key Signature Schemes

A generalized multi-public-key signature scheme enables a set of independently generated public keys to be combined so that multiple parties jointly produce a single, compact, and verifiably aggregated signature on a common message. This framework unifies and extends the notions of multi-signatures, aggregate signatures, and group signatures, supporting advanced features such as order integrity, key-and-signature compactness, aggregation correctness, and post-quantum security. These schemes have become foundational in distributed systems, blockchains, and threshold cryptography due to their efficiency, robustness to rogue-key attacks, and adaptability to new algebraic and security models [2509.17709][2301.08668][2404.17787][2210.10294].

## 1. Formal Models and Essential Algorithms

Generalized multi-public-key signature schemes are defined by a suite of polynomial-time algorithms operating over a specified algebraic structure (group, ring, or module):

- **Setup**: Establishes global parameters, sometimes including bilinear groups (pairings) or lattice parameters.
- **Key Generation (KGen)**: Each signer independently generates a secret/public key pair. Some constructions require non-interactive Proof-of-Possession (PoP) to thwart rogue-key attacks [2210.10294].
- **Key Verification (KVerify)**: Validates public key correctness, again often via PoP.
- **Public-Key Aggregation (KAgg/AggKey/AggregatePK)**: Compresses a set or sequence of public keys \((pk_1,\dots,pk_n)\) into a single aggregated public key \(\mathit{APK}\), capturing signers’ identities and, in ordered settings, their order [2509.17709].
- **Signing (Sign)**: Parties jointly or sequentially produce partial signatures that are finally combined into a single signature \(\sigma\).
- **Verification (SVerify/Verify)**: Checks that \(\sigma\) is a valid multi-signature for both the message and the exact set (and possibly order) of participating keys under the aggregated public key.

These algorithms must guarantee correctness (every honest aggregated signature verifies) and strong security notions (existential unforgeability, order integrity, aggregation correctness).

## 2. Security Models and Attack Resistance

Security for multi-public-key signature schemes is framed in variants of existential unforgeability under chosen-message attack (EUF-CMA). Common enhancements include:

- **Certified-Key (CK) Model**: Requires all signers register verifiable keys (often with PoP) [2509.17709][2210.10294].
- **Rogue-Key Attack Resistance**: Enforced via PoP and the aggregation function’s independence from other participants' keys. AGMS/GMS implement strict PoP-based verification [2210.10294].
- **Order Integrity**: In ordered multi-signature schemes, the verification must ensure not just authenticity and aggregation, but also proof that the signers participated in exactly the claimed sequence [2509.17709].
- **Aggregation Correctness**: The aggregated public key and the signature must be unambiguously linked to a specific key set (or sequence) [2509.17709][2301.08668].
- **Quantum Resistance**: Achieved in lattice-based schemes by security reductions to Module-LWE/MSIS [2404.17787][2301.08668].

The security proofs commonly employ random oracle models, forking lemmas (including “nested-forking” [2301.08668]), and, for non-pairing-based schemes, reductions to group or lattice hardness assumptions.

## 3. Constructions: Algebraic and Protocol Variants

### 3.1 Pairing-Based and Sequential-Aggregate Constructions

The scheme in "Ordered Multi-Signatures with Public-Key Aggregation from SXDH Assumption" [2509.17709] operates over asymmetric-bilinear groups with the SXDH assumption. The sequential signing protocol allows each \(P_i\) to extend a partial signature, maintaining verifiable order. Public key aggregation is realized using accumulation in \(\widetilde G\) as \(\widetilde K_1=\prod_{i=1}^n \widetilde V_{i,1}\), \(\widetilde K_2=\prod_{i=1}^n \widetilde V_{i,2}^{\,i}\), and verification relies on specific pairing equations. The final multi-signature and aggregated key sizes remain constant, independent of the number of signers.

### 3.2 Linear ID-Scheme Compiler and Group-Based Schemes

"Key-and-Signature Compact Multi-Signatures for Blockchain" [2301.08668] introduces a generic compiler transforming any linear identification scheme (ID) into a multi-signature with both key and signature sizes independent of the number of signers. Instantiations include Schnorr-based and lattice-based ID schemes, employing randomness-derived scalars (\(\alpha_i\)) to assemble the aggregate public key and signature. This design efficiently resists rogue-key attacks by hashing each key into a weight, enforcing tight dependency between the aggregated key and the signature.

### 3.3 Lattice-Based Quantum-Resistant Designs

Quantum-resistant schemes such as Razhi-ms [2404.17787] generalize multi-signatures to the lattice setting. Each signer possesses a lattice-based key pair and generates partial signatures encapsulating masked and encrypted shares. Communication requires only a single parallel round. The final aggregate signature and aggregated public key have the same size as single-user signatures (e.g., Dilithium), with security against lattice attacks (MLWE/MSIS). This architecture achieves UF-ESA (unforgeability even given all individual partial signatures) and enables truly post-quantum blockchains.

### 3.4 Tree-Structured Schemes for Scalability

GMS/AGMS [2210.10294] are designed for scalable enterprise blockchains and support tree-structured communication for large numbers of signers. The advanced AGMS protocol moves expensive commitment and challenge steps offline, minimizing online latency to a single scalar multiplication per signer.

## 4. Efficiency and Complexity

Generalized multi-public-key schemes achieve significant efficiency compared to naïve multi-signature techniques:

| Scheme         | Aggregated PK Size | Signature Size     | Verification Complexity                 |
|----------------|-------------------|--------------------|-----------------------------------------|
| Pairing-based  | Constant          | Constant           | Constant pairings (e.g., 3 pairings)    |
| Linear-ID      | Constant          | Constant           | 2 exponentiations (Schnorr)             |
| Lattice-based  | Constant          | Constant           | 1-2 ring multiplications + 1 hash       |
| GMS/AGMS (ECC) | Constant          | Constant           | 2 exponentiations + 1 inversion         |

Public key and signature sizes are independent of the number of participants (\(n\)). Verification workloads are minimal (constant group/ring operations). Offline/online splits as in AGMS allow precomputation, further reducing signing latency for real-time applications [2210.10294].

## 5. Rogue-Key and \(k\)-Sum Problem Countermeasures

To defend against rogue-key attacks, leading schemes require:

- Non-interactive proof-of-possession mechanisms at key registration, ensuring private key knowledge for every public key [2210.10294].
- Aggregation functions that are order-sensitive or hash-dependent, binding aggregated signing data to explicitly verified sets [2301.08668].
- Additional measures against \(k\)-sum (birthday-style) attacks, such as separating challenge and message hashes, to prevent adversarial manipulation via repeated protocol runs [2210.10294].

These protections are central for trustless, decentralized deployments such as public blockchains.

## 6. Applications and Generalizations

Generalized multi-public-key signature protocols are deployed in:

- **Blockchain and Distributed Ledgers**: Compact authorization of payments or consensus commitments in Bitcoin, Fabric, and other platforms [2210.10294][2404.17787].
- **Threshold and Group Signatures**: Schemes are extensible to \(t\)-of-\(n\) threshold settings, though some constructions (e.g., [2509.17709]) note this as a target for future work.
- **Aggregate and Sequential Signatures**: Ordered schemes (e.g., [2509.17709]) embed additional metadata such as signer sequences; linear-ID approaches generalize to various algebraic settings [2301.08668].
- **Post-Quantum Cryptography**: Lattice-based designs are essential for long-term viability as new quantum adversary models emerge [2404.17787].

The offline/online partitioning and constant-size features make these schemes suitable for high-throughput, bandwidth-constrained, and latency-sensitive environments.

## 7. Open Problems and Prospective Directions

Current limitations and directions for further research include:

- Extending order and aggregation properties to dynamic groups and threshold variants (e.g., generalized inner-product aggregation [2509.17709]).
- Broadening message space flexibility, especially in pairing-based constructions restricted to modular messages [2509.17709].
- Further optimizing communication rounds, especially for settings demanding near-zero latency [2404.17787].
- Realizing efficient quantum-resistant schemes with provable UF-ESA security for a wider class of applications [2404.17787].
- Investigating new algebraic frameworks (beyond groups/rings/modules) and more expressive policy enforcement (e.g., attribute-based or function-based aggregation).

The rapid evolution of multi-public-key signature schemes points to continued foundational impact in both theory and applied cryptography.

Source: https://www.emergentmind.com/topics/generalized-multi-public-key-signature-schemes