Let , and be positive integers and be a Gaussian parameter. Let be a message space and let be hash functions that are modeled as random oracles. We construct an interactive aggregate signature scheme as follows:
Theorem (Compactness). Let be a positive integer, or , and suppose that the parameters are set as polynomial functions over Then, the aggregate signature scheme above is compact .
Theorem (Correctness). Suppose that the parameters of Construction above are set such that the ring is instantiated as either or for a positive integer , and that the inequality holds. Then, Construction above is correct .
Theorem (Security). Suppose that the parameters of Construction above are instantiated such that the ring is instantiated with either or for a positive integer , and that the parameters satisfy the conditions of the leftover hash lemma . With these parameter settings, assume that the SIS problem for is hard. Then, the interactive aggregate signature scheme in Construction above satisfies unforgeability.