Universally Composable Adaptor Signatures
Paul Gerhart, Daniel Rausch, Dominique Schroeder
Abstract
Adaptor signatures extend the functionality of digital signatures by enabling the computation of pre-signatures on messages relative to statements in NP relations. Pre-signatures are publicly verifiable objects that simultaneously hide and commit to a standard signature on the same message. Anyone possessing a valid witness for the statement can adapt the pre-signature into a full signature under the underlying signature scheme. Since adaptor signatures are commonly used as building blocks in larger systems, in particular blockchain protocols, it is natural to seek a security definition in the Universal Composability (UC) framework. Tairi et al. (CCS'23) recently took a first step in this direction by proposing a UC functionality for adaptor signatures. This paper investigates UC-secure adaptor signatures as a primitive, making both negative and positive contributions. On the negative side, we show that the functionality proposed by Tairi et al. suffers from critical limitations: -The functionality fails to guarantee extractability and adaptability, which are core security properties of adaptor signatures, to higher-level protocols. -No adaptor signature scheme can realize the functionality. On the positive side, we propose a new UC functionality that faithfully captures the latest security guarantees of adaptor signatures as formalized via game-based notions by Gerhart et al. (EUROCRYPT'24). -Our functionality guarantees extractability and pre-signature adaptability in a way that is composable and meaningful for higher-level protocols. -We show that it is realizable by an enhanced Schnorr-based adaptor signature scheme that we construct. Our construction maintains compatibility with existing infrastructure and is efficient enough for practical deployment, particularly in Bitcoin-like environments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cc40d9e6-38ef-446a-b362-25a1a309c1e4Builds on14
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- Universal Atomic Swaps: Secure Exchange of Coins Across All BlockchainsSri Aravinda Krishnan Thyagarajan, Giulio Malavolta, Pedro Moreno-SanchezS&P 2022 · 112 citations
- The Provable Security of Ed25519: Theory and PracticeJacqueline Brendel, Cas Cremers, Dennis Jackson, Mang ZhaoS&P 2021 · 78 citations
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 53 citations
- BUFFing signature schemes beyond unforgeability and the case of post-quantum signaturesCas Cremers, Samed Düzlü, Rune Fiedler, Marc Fischlin et al.S&P 2021 · 37 citations
Related papers
- Foundations of Adaptor SignaturesPaul Gerhart, Dominique Schröder, Pratik Soni, Sri Aravinda Krishnan ThyagarajanEUROCRYPT 2024 · 21 citations
- UC4Free! Existing Threshold Signatures are UC SecureJan Bobolz, Elizabeth C. Crites, Markulf Kohlweiss, Akira TakahashiEUROCRYPT 2026 · 1 citation
- Functional Adaptor Signatures: Beyond All-or-Nothing Blockchain-based PaymentsNikhil Vanjani, Pratik Soni, Sri Aravinda Krishnan ThyagarajanCCS 2024 · 4 citations
- AUC: Accountable Universal ComposabilityMike Graf, Ralf Küsters, Daniel RauschS&P 2023
- LedgerLocks: A Security Framework for Blockchain Protocols Based on Adaptor SignaturesErkan Tairi, Pedro Moreno-Sanchez, Clara SchneidewindCCS 2023 · 10 citations
