Journal of Cryptology

, Volume 17, Issue 4, pp 297–319

Short Signatures from the Weil Pairing


DOI: 10.1007/s00145-004-0314-9

Cite this article as:
Boneh, D., Lynn, B. & Shacham, H. J Cryptology (2004) 17: 297. doi:10.1007/s00145-004-0314-9


We introduce a short signature scheme based on the Computational Diffie–Hellman assumption on certain elliptic and hyperelliptic curves. For standard security parameters, the signature length is about half that of a DSA signature with a similar level of security. Our short signature scheme is designed for systems where signatures are typed in by a human or are sent over a low-bandwidth channel. We survey a number of properties of our signature scheme such as signature aggregation and batch verification.

Digital signaturesShort signaturesElliptic curvesPairingsBilinear maps

Copyright information

© International Association for Cryptological Research 2004

Authors and Affiliations

  1. 1.Computer Science Department, Stanford University, Stanford, CA 94305USA