BUFFing signature schemes beyond unforgeability and the case of post-quantum signatures
Cas Cremers, Samed Düzlü, Rune Fiedler, Marc Fischlin, Christian Janson
摘要
Modern digital signature schemes can provide more guarantees than the standard notion of (strong) unforgeability, such as offering security even in the presence of maliciously generated keys, or requiring to know a message to produce a signature for it. The use of signature schemes that lack these properties has previously enabled attacks on real-world protocols. In this work we revisit several of these notions beyond unforgeability, establish relations among them, provide the first formal definition of non re-signability, and a transformation that can provide these properties for a given signature scheme in a provable and efficient way. Our results are not only relevant for established schemes: for example, the ongoing NIST PQC competition towards standardizing post-quantum signature schemes has six finalists in its third round. We perform an in-depth analysis of the candidates with respect to their security properties beyond unforgeability. We show that many of them do not yet offer these stronger guarantees, which implies that the security guarantees of these post-quantum schemes are not strictly stronger than, but instead incomparable to, classical signature schemes. We show how applying our transformation would efficiently solve this, paving the way for the standardized schemes to provide these additional guarantees and thereby making them harder to misuse.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck 等EUROCRYPT 2026 · 被引用 15 次
- On the (In)Security of the BUFF TransformJelle Don, Serge Fehr, Yu-Hsuan Huang, Patrick StruckCRYPTO 2024 · 被引用 14 次
- Keeping Up with the KEMs: Stronger Security Notions for KEMs and Automated Analysis of KEM-based ProtocolsCas Cremers, Alexander Dax, Niklas MedingerCCS 2024 · 被引用 11 次
- A Complete Security Proof of SQIsignMarius A. Aardal, Andrea Basso, Luca De Feo, Sikhar Patranabis 等CRYPTO 2025 · 被引用 11 次
- Limbo: Efficient Zero-knowledge MPCitH-based ArgumentsCyprien Delpech de Saint Guilhem, Emmanuela Orsini, Titouan TanguyCCS 2021 · 被引用 4 次
它引用的顶会 Paper4
- The SPHINCS+ Signature FrameworkDaniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen 等CCS 2019 · 被引用 385 次
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 被引用 128 次
- The Provable Security of Ed25519: Theory and PracticeJacqueline Brendel, Cas Cremers, Dennis Jackson, Mang ZhaoS&P 2021 · 被引用 78 次
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 被引用 53 次
相关 Paper
- Bird of Prey: Practical Signature Combiners Preserving Strong UnforgeabilityJonas JanneckEUROCRYPT 2026 · 被引用 1 次
- Breaking Rainbow Takes a Weekend on a LaptopWard BeullensCRYPTO 2022 · 被引用 170 次
- Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and MoreMichael Meyer, Patrick Struck, Maximiliane WeishäuplCRYPTO 2025 · 被引用 1 次
- Magic Pot: Cryptanalysis of Full AIM2 in the Standard and Related-/reused-Key Settings Using New Elimination FrameworkAlex Biryukov, Pablo García Fernández, Aleksei UdovenkoEUROCRYPT 2026 · 被引用 1 次
- Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only IndifferentiabilityMihir Bellare, Hannah Davis, Felix GüntherEUROCRYPT 2020 · 被引用 35 次
