Skip to main content

Short Signatures from the Weil Pairing


We introduce a short signature scheme based on the Computational Diffie–Hellman assumption on certain elliptic and hyperelliptic curves. For standard security parameters, the signature length is about half that of a DSA signature with a similar level of security. Our short signature scheme is designed for systems where signatures are typed in by a human or are sent over a low-bandwidth channel. We survey a number of properties of our signature scheme such as signature aggregation and batch verification.

Author information

Authors and Affiliations


Corresponding authors

Correspondence to Dan Boneh, Ben Lynn or Hovav Shacham.

Rights and permissions

Reprints and Permissions

About this article

Cite this article

Boneh, D., Lynn, B. & Shacham, H. Short Signatures from the Weil Pairing. J Cryptology 17, 297–319 (2004).

Download citation

  • Received:

  • Revised:

  • Published:

  • Issue Date:

  • DOI:

  • Digital signatures
  • Short signatures
  • Elliptic curves
  • Pairings
  • Bilinear maps