    "A study on provably secure multi-signature schemes with signers' intentions"

    In this paper, we propose a multi-signature scheme, in which each signer can express her intention in the message to be signed.
    An intention is a piece of information which can be attached to a signature. However, no multi-signature scheme dealing with intentions without loss of efficiency has been introduced. First, we consider a multi-signature scheme realizing the concept of signers' intentions by utilizing existing schemes, and name it {\it primitive method}.
    After that, we introduce the proposed multi-signature scheme which is more efficient than the primitive method in view of the computational cost for verification and in view of the signature size. The proposed multi-signature scheme is shown to be secure even against adaptive chosen message insider attacks.

