Foundations of Adaptor Signatures
Paul Gerhart, Dominique Schröder, Pratik Soni, Sri Aravinda Krishnan Thyagarajan
Abstract
Adaptor signatures extend the functionality of regular signatures through the computation of pre-signatures on messages for statements of NP relations. Presignatures are publicly verifiable; they simultaneously hide and commit to a signature of an underlying signature scheme on that message. Anybody possessing a corresponding witness for the statement can adapt the pre-signature to obtain the "regular" signature. Adaptor signatures have found numerous applications for conditional payments in blockchain systems, like payment channels (CCS'20, CCS'21), private coin mixing (CCS'22, SP'23), and oracle-based payments (NDSS'23). In our work, we revisit the state of the security of adaptor signatures and their constructions. In particular, our two main contributions are:
• Security Gaps and Definitions: We review the widely-used security model of adaptor signatures due to Aumayr et al. (ASIACRYPT'21) and identify gaps in their definitions that render known protocols for private coin-mixing and oracle-based payments insecure. We give simple counterexamples of adaptor signatures that are secure w.r.t. their definitions but result in insecure instantiations of these protocols. To fill these gaps, we identify a minimal set of modular definitions that align with these practical applications.
• Secure Constructions: Despite their popularity, all known constructions are (1) derived from identification schemes via the Fiat-Shamir transform in the random oracle model or (2) require modifications to the underlying signature verification algorithm, thus making the construction useless in the setting of cryptocurrencies. More concerningly, all known constructions were proven secure w.r.t. the insufficient definitions of Aumayr et al., leaving us with no provably secure adaptor signature scheme to use in applications. Firstly, in this work, we salvage all current applications by proving the security of the widely-used Schnorr adaptor signatures under our proposed definitions. We then provide several new constructions, including presenting the first adaptor signature schemes for Camenisch-Lysyanskaya (CL), Boneh-Boyen-Shacham (BBS+), and Waters signatures, all of which are proven secure in the standard model. Our new constructions rely on a new abstraction of digital signatures, called dichotomic signatures, which covers the essential properties we need to build adaptor signatures. Proving the security of all constructions (including identification-based schemes) relies on a novel nonblack-box proof technique. Both our digital signature abstraction and the proof technique could be of independent interest to the community.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 166566a0-4384-4cb0-a018-2e390a4c2c42Cited by top-tier papers1
Ask how each one uses itBuilds on5
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- Foundations of Coin Mixing ServicesNoemi Glaeser, Matteo Maffei, Giulio Malavolta, Pedro Moreno-Sanchez et al.CCS 2022 · 37 citations
- LedgerLocks: A Security Framework for Blockchain Protocols Based on Adaptor SignaturesErkan Tairi, Pedro Moreno-Sanchez, Clara SchneidewindCCS 2023 · 10 citations
- Cryptographic Oracle-based Conditional PaymentsVarun Madathil, Sri Aravinda Krishnan Thyagarajan, Dimitrios Vasilopoulos, Lloyd Fournier et al.NDSS 2023
- BlindHub: Bitcoin-Compatible Privacy-Preserving Payment Channel Hubs Supporting Variable AmountsXianrui Qin, Shimin Pan, Arash Mirzaei, Zhimei Sui et al.S&P 2023
Related papers
- Functional Adaptor Signatures: Beyond All-or-Nothing Blockchain-based PaymentsNikhil Vanjani, Pratik Soni, Sri Aravinda Krishnan ThyagarajanCCS 2024 · 4 citations
- Adaptively Secure 5 Round Threshold Signatures from MLWE/MSIS and DL with RewindingShuichi Katsumata, Michael Reichle, Kaoru TakemureCRYPTO 2024 · 34 citations
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 1 citation
- A Plausible Attack on the Adaptive Security of Threshold Schnorr SignaturesElizabeth C. Crites, Alistair StewartCRYPTO 2025 · 11 citations
- On the Adaptive Security of Key-Unique Threshold SignaturesMichele Ciampi, Elizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2026
