A blind signature scheme is an interactive protocol that enables a user to obtain a signature on a message without revealing any information about the message–signature pair to the signer. Despite more than 40 years of research, all existing constructions suffer from at least two of the following limitations. The protocol is not round-optimal, requiring more than two messages to be exchanged during the signature phase.There is only game-based security and/or lack of composability with global and observable setup (i.e., there is a need for trusted parameters or to program random oracles).Security (unlike regular signatures) is based on demanding hardness assumptions, especially when considering quantum attacks. The protocol is not round-optimal, requiring more than two messages to be exchanged during the signature phase. There is only game-based security and/or lack of composability with global and observable setup (i.e., there is a need for trusted parameters or to program random oracles). Security (unlike regular signatures) is based on demanding hardness assumptions, especially when considering quantum attacks. In this work, we show how to blindly sign a message, simultaneously overcoming all of the above three limitations. Specifically, we construct a Universally Composable (UC), two-round (optimal) blind signature protocol that relies only on one-way functions (optimal), without trusted parameters. The only deviation3 from the plain model is the need for a global non-programmable random oracle (NPRO). Nicely, our scheme can be instantiated from a variety of assumptions believed to be post-quantum secure (e.g., AES). A central technical component of our scheme is the construction of a novel commitment scheme that enjoys a special (mild) form of composability, which may be of independent interest. We also discuss a concrete instantiation of our scheme that is suitable for practical applications. (A deviation is anyway necessary in light of known impossibility results [53].)
Round-Optimal GUC-Secure Blind Signatures From Minimal Computational and Setup Assumptions: From Minimal Computational and Setup Assumptions / Ciampi, M., Della Monica, P., Visconti, I.. - 16806:(2026), pp. 522-554. (46th Annual International Cryptology Conference, CRYPTO 2026 usa ) [10.1007/978-3-032-35415-0_17].
Round-Optimal GUC-Secure Blind Signatures From Minimal Computational and Setup Assumptions: From Minimal Computational and Setup Assumptions
Della Monica P.;Visconti I.
2026
Abstract
A blind signature scheme is an interactive protocol that enables a user to obtain a signature on a message without revealing any information about the message–signature pair to the signer. Despite more than 40 years of research, all existing constructions suffer from at least two of the following limitations. The protocol is not round-optimal, requiring more than two messages to be exchanged during the signature phase.There is only game-based security and/or lack of composability with global and observable setup (i.e., there is a need for trusted parameters or to program random oracles).Security (unlike regular signatures) is based on demanding hardness assumptions, especially when considering quantum attacks. The protocol is not round-optimal, requiring more than two messages to be exchanged during the signature phase. There is only game-based security and/or lack of composability with global and observable setup (i.e., there is a need for trusted parameters or to program random oracles). Security (unlike regular signatures) is based on demanding hardness assumptions, especially when considering quantum attacks. In this work, we show how to blindly sign a message, simultaneously overcoming all of the above three limitations. Specifically, we construct a Universally Composable (UC), two-round (optimal) blind signature protocol that relies only on one-way functions (optimal), without trusted parameters. The only deviation3 from the plain model is the need for a global non-programmable random oracle (NPRO). Nicely, our scheme can be instantiated from a variety of assumptions believed to be post-quantum secure (e.g., AES). A central technical component of our scheme is the construction of a novel commitment scheme that enjoys a special (mild) form of composability, which may be of independent interest. We also discuss a concrete instantiation of our scheme that is suitable for practical applications. (A deviation is anyway necessary in light of known impossibility results [53].)I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


