0

In the BLS signature the subgroup $G$ of elliptic curve constructed with point $P$ with prime order $q$ by $G=\langle P\rangle $. The $h(x)$ is a hash function. The point $S$ is map (image) of $h(m)$ on elliptic curve. The signature is multiplying the private key in the point $S$.

Is the point $S$, also in $G$ and a multiple of point $P$ such as $kP$?

Amirhnr
  • 87
  • 4

1 Answers1

1

It depends on whether the pairing is a type 1 pairing or some other type of pairing. In a type 1 pairing, $S$ is a multiple of $P$. In any other type of pairing, $S$ is not a multiple of $P$.

djao
  • 796
  • 9
  • 11