BUFFing signature schemes beyond unforgeability and the case of post-quantum signatures
Cas Cremers, Samed Düzlü, Rune Fiedler, Marc Fischlin, Christian Janson
Abstract
Modern digital signature schemes can provide more guarantees than the standard notion of (strong) unforgeability, such as offering security even in the presence of maliciously generated keys, or requiring to know a message to produce a signature for it. The use of signature schemes that lack these properties has previously enabled attacks on real-world protocols. In this work we revisit several of these notions beyond unforgeability, establish relations among them, provide the first formal definition of non re-signability, and a transformation that can provide these properties for a given signature scheme in a provable and efficient way. Our results are not only relevant for established schemes: for example, the ongoing NIST PQC competition towards standardizing post-quantum signature schemes has six finalists in its third round. We perform an in-depth analysis of the candidates with respect to their security properties beyond unforgeability. We show that many of them do not yet offer these stronger guarantees, which implies that the security guarantees of these post-quantum schemes are not strictly stronger than, but instead incomparable to, classical signature schemes. We show how applying our transformation would efficiently solve this, paving the way for the standardized schemes to provide these additional guarantees and thereby making them harder to misuse.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 922b1c64-813c-4656-93a7-bc0b5c74dee0Cited by top-tier papers7
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck et al.EUROCRYPT 2026 · 15 citations
- On the (In)Security of the BUFF TransformJelle Don, Serge Fehr, Yu-Hsuan Huang, Patrick StruckCRYPTO 2024 · 14 citations
- Keeping Up with the KEMs: Stronger Security Notions for KEMs and Automated Analysis of KEM-based ProtocolsCas Cremers, Alexander Dax, Niklas MedingerCCS 2024 · 11 citations
- A Complete Security Proof of SQIsignMarius A. Aardal, Andrea Basso, Luca De Feo, Sikhar Patranabis et al.CRYPTO 2025 · 11 citations
- Limbo: Efficient Zero-knowledge MPCitH-based ArgumentsCyprien Delpech de Saint Guilhem, Emmanuela Orsini, Titouan TanguyCCS 2021 · 4 citations
Builds on4
- The SPHINCS+ Signature FrameworkDaniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen et al.CCS 2019 · 385 citations
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 128 citations
- The Provable Security of Ed25519: Theory and PracticeJacqueline Brendel, Cas Cremers, Dennis Jackson, Mang ZhaoS&P 2021 · 78 citations
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 53 citations
Related papers
- Bird of Prey: Practical Signature Combiners Preserving Strong UnforgeabilityJonas JanneckEUROCRYPT 2026 · 1 citation
- Breaking Rainbow Takes a Weekend on a LaptopWard BeullensCRYPTO 2022 · 170 citations
- Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and MoreMichael Meyer, Patrick Struck, Maximiliane WeishäuplCRYPTO 2025 · 1 citation
- Magic Pot: Cryptanalysis of Full AIM2 in the Standard and Related-/reused-Key Settings Using New Elimination FrameworkAlex Biryukov, Pablo García Fernández, Aleksei UdovenkoEUROCRYPT 2026 · 1 citation
- Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only IndifferentiabilityMihir Bellare, Hannah Davis, Felix GüntherEUROCRYPT 2020 · 35 citations
