Question: Let ( S 1 , R 1 ) , . . . , ( Sn , Rn ) be n distinct Schnorr signatures computed on

Let (S1,R1),...,(Sn,Rn) be n distinct Schnorr signatures computed on distinct messages M1,M2,...,Mn under the same private key Ks. Is it possible to aggregate these signatures and then broadcast it as one single-compact (constant-size) signature to be verified by all the signers? If your answer is YES, show mathematically (and algorithmically) how it can do. If your answer is NO, similarly, how mathematically (and algorithmically) why not. Your answer should not be handwaving verbal descriptions, and it must include necessary mathematical rigor to showcase possibility or impossibility result. Note that in the class, we showed in detail how Schnorr signature is computed with a correctness verification. You can recall these equations to deduce your conclusions.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!