On the (in)security of ROS
Fabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù, Mariana Raykova
Abstract
We present an algorithm solving the ROS (Random inhomogeneities in a Overdetermined Solvable system of linear equations) problem in polynomial time for l > log p dimensions. Our algorithm can be combined with Wagner’s attack, and leads to a sub-exponential solution for any dimension l with best complexity known so far. When concurrent executions are allowed, our algorithm leads to practical attacks against unforgeability of blind signature schemes such as Schnorr and Okamoto--Schnorr blind signatures, threshold signatures such as GJKR and the original version of FROST, multisignatures such as CoSI and the two-round version of MuSig, partially blind signatures such as Abe-Okamoto, and conditional blind signatures such as ZGP17.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get c786c437-ea92-4bef-94f6-3b9175d4ea2fCited by top-tier papers14
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Aggregatable Distributed Key GenerationKobi Gurkan, Philipp Jovanovic, Mary Maller, Sarah Meiklejohn et al.EUROCRYPT 2021 · 62 citations
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 54 citations
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 52 citations
- Threshold and Multi-signature Schemes from Linear Hash FunctionsStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 48 citations
Related papers
- M&M'S: Mix and Match Attacks on Schnorr-Type Blind Signatures with RepetitionKhue Do, Lucjan Hanzlik, Eugenio ParacucchiEUROCRYPT 2024 · 8 citations
- Short Pairing-Free Blind Signatures with Exponential SecurityStefano Tessaro, Chenzhi ZhuEUROCRYPT 2022 · 47 citations
- Blind Schnorr Signatures and Signed ElGamal Encryption in the Algebraic Group ModelGeorg Fuchsbauer, Antoine Plouviez, Yannick SeurinEUROCRYPT 2020 · 109 citations
- Just Guess: Improved (Quantum) Algorithm for the Underdetermined MQ ProblemAlexander May, Massimo Ostuzzi, Henrik ResslerEUROCRYPT 2026 · 3 citations
- Improved Concurrent-Secure Blind Schnorr SignaturesPierpaolo Della Monica, Ivan ViscontiCRYPTO 2026
