BLS Signature Scheme

Document Type Replaced Internet-Draft (cfrg RG)
Authors Dan Boneh  , Sergey Gorbunov  , Hoeteck Wee  , Zhenfei Zhang 
Last updated 2019-08-12 (latest revision 2019-02-08)
Replaced by draft-irtf-cfrg-bls-signature
Stream Internet Research Task Force (IRTF)
Intended RFC status (None)
Expired & archived
pdf htmlized (tools) htmlized bibtex
Stream IRTF state Replaced
Consensus Boilerplate Unknown
Document shepherd No shepherd assigned
IESG IESG state Replaced by draft-irtf-cfrg-bls-signature
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


The BLS signature scheme was introduced by Boneh-Lynn-Shacham in 2001. The signature scheme relies on pairing-friendly curves and supports non-interactive aggregation properties. That is, given a collection of signatures (sigma_1, ..., sigma_n), anyone can produce a short signature (sigma) that authenticates the entire collection. BLS signature scheme is simple, efficient and can be used in a variety of network protocols and systems to compress signatures or certificate chains. This document specifies the BLS signature and the aggregation algorithms.


Dan Boneh (
Sergey Gorbunov (
Hoeteck Wee (
Zhenfei Zhang (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)