Bilinear pairing ⇒ DS

Bilinear pairing implies DS.

Statement

Migrated verbatim from digital-signature § BLS signatures:

BLS signatures (Boneh-Lynn-Shacham) use a bilinear pairing to achieve unique, deterministic, and aggregatable signatures. To sign : output (where is a hash-to-curve function). Verification checks .

Notes

source: folklore: the claim carried no citation on the page it was migrated from, and none was invented.

class: unstated: no citing page says which notion of reduction is meant. Recording a class the wiki does not state would add a claim.

Recorded during migration and not fixed — these are claims about the source text, not changes to it:

  • No citation — the BLS paper (Boneh-Lynn-Shacham, Asiacrypt 2001) has no reference page in content/References/.
  • [[pairings]] (glossary) exists but is not wikilinked; ‘pairings’ as a hypothesis is a structure, not a hardness assumption (the assumption, co-CDH, is stated separately at line 153).