Round-Optimal Blind Signatures in the Plain Model from Classical and Quantum Standard Assumptions
Shuichi Katsumata, Ryo Nishimaki, Shota Yamada, Takashi Yamakawa
Abstract
Blind signatures, introduced by Chaum (Crypto’82), allows a user to obtain a signature on a message without revealing the message itself to the signer. Thus far, all existing constructions of round-optimal blind signatures are known to require one of the following: a trusted setup, an interactive assumption, or complexity leveraging. This state-of-the-affair is somewhat justified by the few known impossibility results on constructions of round-optimal blind signatures in the plain model (i.e., without trusted setup) from standard assumptions. However, since all of these impossibility results only hold under some conditions, fully (dis)proving the existence of such round-optimal blind signatures has remained open.
In this work, we provide an affirmative answer to this problem and construct the first round-optimal blind signature scheme in the plain model from standard polynomial-time assumptions. Our construction is based on various standard cryptographic primitives and also on new primitives that we introduce in this work, all of which are instantiable from classical and post-quantum standard polynomial-time assumptions. The main building block of our scheme is a new primitive called a blind-signature-conforming zero-knowledge (ZK) argument system. The distinguishing feature is that the ZK property holds by using a quantum polynomial-time simulator against non-uniform classical polynomial-time adversaries. Syntactically one can view this as a delayed-input three-move ZK argument with a reusable first message, and we believe it would be of independent interest.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers4
- Short Pairing-Free Blind Signatures with Exponential SecurityStefano Tessaro, Chenzhi ZhuEUROCRYPT 2022 · 47 citations
- Pairing-Free Blind Signatures from Standard Assumptions in the ROMJulia Kastner, Ky Nguyen, Michael ReichleCRYPTO 2024 · 11 citations
- Security-Preserving Distributed Samplers: How to Generate Any CRS in One Round Without Random OraclesDamiano Abram, Brent Waters, Mark ZhandryCRYPTO 2023 · 10 citations
- Hecate: Abuse Reporting in Secure Messengers with Sealed SenderRawane Issa, Nicolas Alhaddad, Mayank VariaUSENIX Security 2022
Related papers
- A New Framework for More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor SamplingRafaël del Pino, Shuichi KatsumataCRYPTO 2022 · 50 citations
- Round-Optimal GUC-Secure Blind Signatures From Minimal Computational and Setup Assumptions - From Minimal Computational and Setup AssumptionsMichele Ciampi, Pierpaolo Della Monica, Ivan ViscontiCRYPTO 2026 · 1 citation
- Rai-Choo! Evolving Blind Signatures to the Next LevelLucjan Hanzlik, Julian Loss, Benedikt WagnerEUROCRYPT 2023 · 23 citations
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 52 citations
- On the Impossibility of Round-Optimal Pairing-Free Blind Signatures in the ROMMarian Dietz, Julia Kastner, Stefano TessaroCRYPTO 2026 · 1 citation
