Pairing-Free Blind Signatures from Standard Assumptions in the ROM
Julia Kastner, Ky Nguyen, Michael Reichle
Abstract
Blind Signatures are a useful primitive for privacy preserving applications such as electronic payments, e-voting, anonymous credentials, and more. However, existing practical blind signature schemes based on standard assumptions require either pairings or lattices. We present the first practical construction of a round-optimal blind signature in the random oracle model based on standard assumptions without resorting to pairings or lattices. In particular, our construction is secure under the strong RSA assumption and DDH (in pairingfree groups). For our construction, we provide a NIZK-friendly signature based on strong RSA, and efficiently instantiate a variant of Fischlin's generic framework (CRYPTO'06). Our Blind Signature scheme has signatures of size 4.28 KB and communication cost 10.98 KB. On the way, we develop techniques that might be of independent interest. In particular, we provide efficient relaxed range-proofs for large ranges with subversion zero-knowledge and compact commitments to elements of arbitrary groups. 4 The framework of Fischlin [42] yields round-optimal blind signatures with trusted setup generically, but efficient instantiations rely either on pairings [18,4,66] or lattices [37,7]. 5 Note that due to impossibility results for round optimal blind signatures [68,43,75], the reliance on random oracles can likely not be removed efficiently. 6 In the context of signatures, an all-but-one reduction allows to puncture the verification key in such a way that all-but-one message m * can be signed and given a signature on m * , a hard problem can be solved. We refer to [72] for more details. This work 4.28 KB 10.98 KB RSA, Groups sRSA, DDH We provide signature size, communication size, the algebraic setting, and the underlying assumptions for known round-optimal blind signatures in the ROM secure under non-interactive assumptions. We stress that our work relies on assumptions in prime-order groups without pairing. ( †): Communication of [18] scales linearly with the message size, and is given here for 256 bit messages. ( † †): [54] offers tradeoffs between signature and communication sizes. Reference Sig. size Comm. size #Rounds Assumption Blind RSA and variants [28, 69, 8] 768 B 384 B 2 One-more RSA Chairattana-Apirom et al. [25] ‡ 8.66 KB 8.08 KB 5 RSA This work 4.28 KB 10.98 KB 2 sRSA, DDH We provide signature size, communication size, number of rounds and the underlying assumption of known blind signatures in the RSA setting. ( ‡): [25] is not round-optimal and at most an a-priori fixed number of signatures can be issued, here 2 30 . Also, the signer is required to keep a state and communication scales logarithmically in the number sessions in size but linearly in computation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2a7ee6bc-cd7d-4ded-a60d-1b97e8e759a1Cited by top-tier papers2
- Pairing-Free Blind Signatures from CDH AssumptionsRutchathon Chairattana-Apirom, Stefano Tessaro, Chenzhi ZhuCRYPTO 2024 · 18 citations
- On the Impossibility of Round-Optimal Pairing-Free Blind Signatures in the ROMMarian Dietz, Julia Kastner, Stefano TessaroCRYPTO 2026 · 1 citation
Builds on16
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Blind Schnorr Signatures and Signed ElGamal Encryption in the Algebraic Group ModelGeorg Fuchsbauer, Antoine Plouviez, Yannick SeurinEUROCRYPT 2020 · 109 citations
- On the (in)security of ROSFabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù et al.EUROCRYPT 2021 · 74 citations
- Compressed -Protocol Theory and Practical Application to Plug & Play Secure AlgorithmicsThomas Attema, Ronald CramerCRYPTO 2020 · 73 citations
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 52 citations
Related papers
- A New Framework for More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor SamplingRafaël del Pino, Shuichi KatsumataCRYPTO 2022 · 50 citations
- Rai-Choo! Evolving Blind Signatures to the Next LevelLucjan Hanzlik, Julian Loss, Benedikt WagnerEUROCRYPT 2023 · 23 citations
- Blind Signatures from Proofs of InequalityMichael Klooß, Michael ReichleCRYPTO 2025 · 7 citations
- Round-Optimal Blind Signatures in the Plain Model from Classical and Quantum Standard AssumptionsShuichi Katsumata, Ryo Nishimaki, Shota Yamada, Takashi YamakawaEUROCRYPT 2021 · 12 citations
- Round-Optimal Threshold Blind Signatures Without Random OraclesGeorg Fuchsbauer, Fabian Regen, Hoeteck WeeCRYPTO 2026
