Lune

CRYPTO2024顶会

Pairing-Free Blind Signatures from Standard Assumptions in the ROM

Julia Kastner, Ky Nguyen, Michael Reichle

2024年份
11被引次数
2顶会引用

摘要

Blind Signatures are a useful primitive for privacy preserving applications such as electronic payments, e-voting, anonymous credentials, and more. However, existing practical blind signature schemes based on standard assumptions require either pairings or lattices. We present the first practical construction of a round-optimal blind signature in the random oracle model based on standard assumptions without resorting to pairings or lattices. In particular, our construction is secure under the strong RSA assumption and DDH (in pairingfree groups). For our construction, we provide a NIZK-friendly signature based on strong RSA, and efficiently instantiate a variant of Fischlin's generic framework (CRYPTO'06). Our Blind Signature scheme has signatures of size 4.28 KB and communication cost 10.98 KB. On the way, we develop techniques that might be of independent interest. In particular, we provide efficient relaxed range-proofs for large ranges with subversion zero-knowledge and compact commitments to elements of arbitrary groups. 4 The framework of Fischlin [42] yields round-optimal blind signatures with trusted setup generically, but efficient instantiations rely either on pairings [18,4,66] or lattices [37,7]. 5 Note that due to impossibility results for round optimal blind signatures [68,43,75], the reliance on random oracles can likely not be removed efficiently. 6 In the context of signatures, an all-but-one reduction allows to puncture the verification key in such a way that all-but-one message m * can be signed and given a signature on m * , a hard problem can be solved. We refer to [72] for more details. This work 4.28 KB 10.98 KB RSA, Groups sRSA, DDH We provide signature size, communication size, the algebraic setting, and the underlying assumptions for known round-optimal blind signatures in the ROM secure under non-interactive assumptions. We stress that our work relies on assumptions in prime-order groups without pairing. ( †): Communication of [18] scales linearly with the message size, and is given here for 256 bit messages. ( † †): [54] offers tradeoffs between signature and communication sizes. Reference Sig. size Comm. size #Rounds Assumption Blind RSA and variants [28, 69, 8] 768 B 384 B 2 One-more RSA Chairattana-Apirom et al. [25] ‡ 8.66 KB 8.08 KB 5 RSA This work 4.28 KB 10.98 KB 2 sRSA, DDH We provide signature size, communication size, number of rounds and the underlying assumption of known blind signatures in the RSA setting. ( ‡): [25] is not round-optimal and at most an a-priori fixed number of signatures can be issued, here 2 30 . Also, the signer is required to keep a state and communication scales logarithmically in the number sessions in size but linearly in computation.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper2

问问它们各自怎么用它

它引用的顶会 Paper16

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖