Playing Tag with Okamoto-Schnorr: Three-Move Pairing-Free Blind Signatures from DDH
Rutchathon Chairattana-Apirom, Michael Reichle, Stefano Tessaro
Abstract
This paper presents the first blind signature scheme in a pairing-free group with the following properties: (1) the signing protocol consists of only three moves; (2) the proof of one-more unforgeability relies solely on the Decisional Diffie-Hellman (DDH) assumption in the Random Oracle Model (ROM); and (3) the construction makes only black-box use of the underlying group. This resolves a major open problem in the area, as all prior pairing-free blind signatures either additionally relied on the Algebraic Group Model (AGM) or required at least four moves. Moreover, a recent lower bound by Dietz et al. (ePrint, '26) shows that three moves are optimal for such constructions.
Both the communication complexity and the signature size in our scheme consist of a constant number of group elements. Our construction in fact achieves strong one-more unforgeability (which was not known for any of the recent AGM-free constructions requiring four moves), and we also present a partially blind variant. Furthermore, blindness is statistical (in the ROM). Our approach is based on a new construction paradigm that combines a conventional (yet, by itself, not fully secure) blind signature scheme (specifically, the blind Okamoto-Schnorr scheme) with a carefully crafted algebraic MAC.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Three-Move Blind Signatures in Pairing-Free GroupsYanbo ChenCRYPTO 2026
- Blind Signatures from Proofs of InequalityMichael Klooß, Michael ReichleCRYPTO 2025 · 7 citations
- Pairing-Free Blind Signatures from CDH AssumptionsRutchathon Chairattana-Apirom, Stefano Tessaro, Chenzhi ZhuCRYPTO 2024 · 18 citations
- On the Impossibility of Round-Optimal Pairing-Free Blind Signatures in the ROMMarian Dietz, Julia Kastner, Stefano TessaroCRYPTO 2026 · 1 citation
- Short Pairing-Free Blind Signatures with Exponential SecurityStefano Tessaro, Chenzhi ZhuEUROCRYPT 2022 · 47 citations
