On the Multi-user Security of Short Schnorr Signatures with Preprocessing
Jeremiah Blocki, Seunghoon Lee
Abstract
The Schnorr signature scheme is an efficient digital signature scheme with short signature lengths, i.e., 4k-bit signatures for k bits of security. A Schnorr signature σ over a group of size p ≈ 2 2k consists of a tuple (s, e), where e ∈ 0, 1 2k is a hash output and s ∈ Zp must be computed using the secret key. While the hash output e requires 2k bits to encode, Schnorr proposed that it might be possible to truncate the hash value without adversely impacting security.
In this paper, we prove that short Schnorr signatures of length 3k bits provide k bits of multi-user security in the (Shoup's) generic group model and the programmable random oracle model. We further analyze the multi-user security of key-prefixed short Schnorr signatures against preprocessing attacks, showing that it is possible to obtain secure signatures of length 3k + log S + log N bits. Here, N denotes the number of users and S denotes the size of the hint generated by our preprocessing attacker, e.g., if S = 2 k/2 , then we would obtain secure 3.75k-bit signatures for groups of up to N ≤ 2 k/4 users.
Our techniques easily generalize to several other Fiat-Shamir-based signature schemes, allowing us to establish analogous results for Chaum-Pedersen signatures and Katz-Wang signatures. As a building block, we also analyze the 1-out-of-N discrete-log problem in the generic group model, with and without preprocessing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c8431f95-46d2-4eb6-8206-eff2baab19f5Cited by top-tier papers2
- To Label, or Not To Label (in Generic Groups)Mark ZhandryCRYPTO 2022 · 50 citations
- The Structured Generic-Group ModelHenry Corrigan-Gibbs, Alexandra Henzinger, David J. WuEUROCRYPT 2026
Builds on4
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz et al.S&P 2019 · 126 citations
- Two-Round Trip Schnorr Multi-signatures via Delinearized WitnessesHandan Kilinç Alper, Jeffrey BurdgesCRYPTO 2021 · 53 citations
- MuSig-DN: Schnorr Multi-Signatures with Verifiably Deterministic NoncesJonas Nick, Tim Ruffing, Yannick Seurin, Pieter WuilleCCS 2020 · 2 citations
Related papers
- Adaptively-Secure Three-Round Threshold Schnorr from DLGuilhem Niot, Michael Reichle, Kaoru TakemureEUROCRYPT 2026
- Short Pairing-Free Blind Signatures with Exponential SecurityStefano Tessaro, Chenzhi ZhuEUROCRYPT 2022 · 47 citations
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 54 citations
