Blind Schnorr Signatures and Signed ElGamal Encryption in the Algebraic Group Model
Georg Fuchsbauer, Antoine Plouviez, Yannick Seurin
Abstract
The Schnorr blind signing protocol allows blind issuing of Schnorr signatures, one of the most widely used signatures. Despite its practical relevance, its security analysis is unsatisfactory. The only known security proof is informal and in the combination of the generic group model (GGM) and the random oracle model (ROM) assuming that the “ROS problem” is hard. The situation is similar for (Schnorr-)signed ElGamal encryption, a simple CCA2-secure variant of ElGamal. We analyze the security of these schemes in the algebraic group model (AGM), an idealized model closer to the standard model than the GGM. We first prove tight security of Schnorr signatures from the discrete logarithm assumption (DL) in the AGM+ROM. We then give a rigorous proof for blind Schnorr signatures in the AGM+ROM assuming hardness of the one-more discrete logarithm problem and ROS. As ROS can be solved in sub-exponential time using Wagner’s algorithm, we propose a simple modification of the signing protocol, which leaves the signatures unchanged. It is therefore compatible with systems that already use Schnorr signatures, such as blockchain protocols. We show that the security of our modified scheme relies on the hardness of a problem related to ROS that appears much harder. Finally, we give tight reductions, again in the AGM+ROM, of the CCA2 security of signed ElGamal encryption to DDH and signed hashed ElGamal key encapsulation to DL.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 60be1c93-4fe9-4752-a3c9-9f9d92f57e5aCited by top-tier papers17
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 52 citations
- Short Pairing-Free Blind Signatures with Exponential SecurityStefano Tessaro, Chenzhi ZhuEUROCRYPT 2022 · 47 citations
- A Classification of Computational Assumptions in the Algebraic Group ModelBalthazar Bauer, Georg Fuchsbauer, Julian LossCRYPTO 2020 · 45 citations
- Mempool Privacy via Batched Threshold Encryption: Attacks and DefensesArka Rai Choudhuri, Sanjam Garg, Julien Piet, Guru-Vamsi PolicharlaUSENIX Security 2024 · 41 citations
Related papers
- Two-Round Trip Schnorr Multi-signatures via Delinearized WitnessesHandan Kilinç Alper, Jeffrey BurdgesCRYPTO 2021 · 53 citations
- On Instantiating the Algebraic Group Model from Falsifiable AssumptionsThomas Agrikola, Dennis Hofheinz, Julia KastnerEUROCRYPT 2020 · 16 citations
- Schnorr Signatures are Tightly Secure in the ROM Under a Non-interactive AssumptionGavin Cho, Georg Fuchsbauer, Adam O'Neill, Marek SefranekCRYPTO 2025 · 4 citations
- On the (in)security of ROSFabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù et al.EUROCRYPT 2021 · 74 citations
- Playing Tag with Okamoto-Schnorr: Three-Move Pairing-Free Blind Signatures from DDHRutchathon Chairattana-Apirom, Michael Reichle, Stefano TessaroCRYPTO 2026
