A BLS Signature (Boneh–Lynn–Shacham signature) is a cryptographic signature scheme built on bilinear pairings over elliptic curves that permits multiple individual signatures to be aggregated into a single constant-size signature, which can be verified against the aggregate of the corresponding public keys in a single pairing operation. This aggregation property drastically reduces bandwidth and verification cost when many parties must co-sign a message or attest to a block.

Content

  • The BLS signature scheme was introduced by Dan Boneh, Ben Lynn, and Hovav Shacham in 2001, building on the bilinear Weil and Tate pairing constructions that had been developed for cryptographic applications in the late 1990s. The initial motivation was short signatures—BLS produces 48-byte signatures over BLS12-381, compared to 64 bytes for ECDSA. The aggregation breakthrough became apparent later: because pairing bilinearity implies e(aG, bH) = e(G, H)^{ab}, signatures from multiple signers collapse into a single verifiable element.
  • Technically, BLS operates over a pairing-friendly elliptic curve. The BLS12-381 curve, defined by the Zcash team in 2017 and now standard across Ethereum and Filecoin, has a 381-bit prime field. A private key is a scalar; a public key is a curve point; a signature is the hash-to-curve of the message multiplied by the private key. Aggregation simply sums the signature curve points (and public key points) via elliptic curve addition. The pairing-based verification equation e(sig, G) = e(H(m), pk) holds for the aggregate as for any individual signer, provided the Proof of Possession protocol is followed to prevent rogue-key attacks.
  • Ethereum’s Beacon Chain, launched in 2020, uses BLS12-381 signatures throughout: each validator signs attestations and block proposals with BLS, and the chain aggregates thousands of attestations per slot into a few hundred bytes. Filecoin similarly uses BLS for message signing. Outside blockchains, BLS is being adopted in threshold cryptography libraries (e.g., BLST, MCL), distributed key generation protocols (DKG), and privacy-preserving systems where succinct multi-party authentication is needed.
  • In 2024–2025 BLS signatures are becoming a standard primitive across the proof-of-stake ecosystem. Ethereum’s Pectra upgrade introduced EIP-2537 (BLS12-381 precompile), reducing gas cost of on-chain BLS verification by roughly 10×. Work on BLS-based distributed validator technology (DVT) by projects such as Obol and SSV Network enables fault-tolerant validator clusters without custodial risk. Research into BLS-based recursive SNARK aggregation and post-quantum hybrid schemes is active, though BLS itself is vulnerable to sufficiently large quantum computers, prompting work on migration paths.