Short signatures from the Weil pairing

Authors: D. Boneh, H. Shacham, and B. Lynn

We introduce a short signature scheme based on the Computational Diffie-Hellman assumption on certain elliptic and hyper-elliptic curve groups. The signature length is half the size of a DSA signature for a similar level of security. Our short signature scheme is designed for systems where signatures are typed in by a human or signatures are sent over a low bandwidth channel.

J. of Cryptology, Vol. 17, No. 4, pp. 297-319, 2004
Extended abstract in Asiacrypt 2001

Full paper: postscript