freecoding.school100% FREE · NO SIGNUP
Proof PeaksISSUE #4 of 38

bls signatures · aggregation · validator keys

ZeekaVSThe Collision
Zeeka saysBLS signatures can be added together: thousands of validators signing the same block collapse into one short signature checked with a single pairing.

BLS signatures have a superpower: they aggregate. A signature is σ = H(m)^sk and a public key is g^sk. Multiply all the signatures together and you get one short signature; multiply all the public keys and you get one aggregate key. A single pairing equation then verifies that the whole crowd signed — which is why Ethereum's consensus layer can fold tens of thousands of validator attestations into something checkable.

The catch is rogue-key attacks: a malicious validator can craft a key that cancels others unless you require proof of possession or message-distinct aggregation. The toy demo shows the aggregation arithmetic — the product of signatures equals H(m) raised to the sum of the secret keys — which is the exact identity a pairing checks at full scale.

Power-ups you unlock

The Collision attacks — common mistakes

Boss battleShow that the product of three BLS signatures on one message equals H(m) raised to the sum of the three secret keys.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// ILLUSTRATIVE BLS aggregation (toy): real BLS needs pairings. We show the
// arithmetic that lets ONE short signature verify many signers.
const p = 1009, g = 11;
const pw=(a,e,m)=>{ let r=1; a%=m; while(e>0){ if(e&1) r=(r*a)%m; a=(a*a)%m; e>>=1; } return r; };
const Hm = 7;                                      // H(message) mapped to an exponent
const sk = [3, 5, 9];                              // three validators' secret keys
const sig = sk.map(s => pw(Hm, s, p));             // σᵢ = H(m)^skᵢ
const aggSig = sig.reduce((a,b)=>(a*b)%p, 1);      // ∏ σᵢ
const sumSk  = sk.reduce((a,b)=>a+b, 0);           // Σ skᵢ
document.getElementById('o').textContent = [
  '3 validators sign the same block',
  'individual σ = ' + sig.join(', '),
  'aggregate σ (one value!) = ' + aggSig,
  'H(m)^(Σ sk) = H(m)^' + sumSk + ' = ' + pw(Hm, sumSk, p) + '   ← equals aggregate σ',
  'match? ' + (aggSig === pw(Hm, sumSk, p)) + '  → one sig + one agg key verifies all 3'
].join('\n');
</script></body></html>
▶ Open the interactive comic issue
‹ Pairing-Based Crypto · Bilinear MapsSchnorr Signatures · Linearity · Musig2 ›