A construction of attribute-based aggregate signatures

For the identity-based aggregate signatures, Hohenberger, Sahai and Waters proposed the first scheme that admits unrestricted aggregation, using multilinear maps. On the other hand, for the attribute based-signatures, which is an extended notion of the identity-based signatures, the ones with aggregation are not known to exist so far. This paper studies the attribute-based aggregate signatures. We introduce a rigorous definition of the attribute-based aggregate signatures and propose a construction. Our scheme is the first attribute-based aggregate signature although it admits only conjunctive predicates.