On the (in)security of ROS
Fabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù, Mariana Raykova
摘要
We present an algorithm solving the ROS (Random inhomogeneities in a Overdetermined Solvable system of linear equations) problem in polynomial time for l > log p dimensions. Our algorithm can be combined with Wagner’s attack, and leads to a sub-exponential solution for any dimension l with best complexity known so far. When concurrent executions are allowed, our algorithm leads to practical attacks against unforgeability of blind signature schemes such as Schnorr and Okamoto--Schnorr blind signatures, threshold signatures such as GJKR and the original version of FROST, multisignatures such as CoSI and the two-round version of MuSig, partially blind signatures such as Abe-Okamoto, and conditional blind signatures such as ZGP17.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper14
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 被引用 79 次
- Aggregatable Distributed Key GenerationKobi Gurkan, Philipp Jovanovic, Mary Maller, Sarah Meiklejohn 等EUROCRYPT 2021 · 被引用 62 次
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 被引用 54 次
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 被引用 52 次
- Threshold and Multi-signature Schemes from Linear Hash FunctionsStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 被引用 48 次
相关 Paper
- M&M'S: Mix and Match Attacks on Schnorr-Type Blind Signatures with RepetitionKhue Do, Lucjan Hanzlik, Eugenio ParacucchiEUROCRYPT 2024 · 被引用 8 次
- Short Pairing-Free Blind Signatures with Exponential SecurityStefano Tessaro, Chenzhi ZhuEUROCRYPT 2022 · 被引用 47 次
- Blind Schnorr Signatures and Signed ElGamal Encryption in the Algebraic Group ModelGeorg Fuchsbauer, Antoine Plouviez, Yannick SeurinEUROCRYPT 2020 · 被引用 109 次
- Just Guess: Improved (Quantum) Algorithm for the Underdetermined MQ ProblemAlexander May, Massimo Ostuzzi, Henrik ResslerEUROCRYPT 2026 · 被引用 3 次
- Improved Concurrent-Secure Blind Schnorr SignaturesPierpaolo Della Monica, Ivan ViscontiCRYPTO 2026
