0

If there is a message $m_1$ that $H(m_1) \rightarrow g^r$ and there is another message $m_2$ that $H(m_2) \rightarrow g^k$, where $g^k$ is also a generator of $G$, is this possible? then $g^r$ could equal $(g^k)^m$, where $m < p$, $p$ is the order of $G$. Then any message could be expressed in this form $(g^k)^m$, so if we allow aggregating duplicate messages from one same signer, it is not safe in BLS?

kelalaka
  • 48,443
  • 11
  • 116
  • 196
Ray James
  • 45
  • 5

0 Answers0