Paper 2024/2018
On the BUFF Security of ECDSA with Key Recovery
Abstract
In the usual syntax of digital signatures, the verification algorithm takes a verification key in addition to a signature and a message, whereas in ECDSA with key recovery, which is used in Ethereum, no verification key is input to the verification algorithm. Instead, a verification key is recovered from a signature and a message. In this paper, we explore BUFF security of ECDSA with key recovery (KR-ECDSA), where BUFF stands for Beyond UnForgeability Features (Cremers et al., IEEE S&P 2021). As a result, we show that KR-ECDSA provides BUFF security, except weak non-resignability (wNR). It is particularly noteworthy that the KR-ECDSA verification algorithm takes an Ethereum address addr as input. This address is defined as the rightmost 160 bits of the Keccak-256 hash of the corresponding ECDSA verification key. Crucially, the algorithm verifies that the hash of the recovered verification key matches addr. Our security analysis shows that the procedure of checking whether the hash value of the recovered verification key is equal to the address is mandatory to provide BUFF security. We also discuss whether wNR is mandatory in Ethereum or not. To clarify which part is mandatory to provide BUFF security in KR-ECDSA, we show that the original ECDSA does not provide any BUFF security. As a by-product of the analysis, we show that one of our BUFF attacks also works against Aumayr et al.'s ECDSA-based adaptor signature scheme (ASIACRYPT 2021) and Qin et al.'s blind adaptor signature scheme (IEEE S&P 2023), which is based on Aumayr et al.'s scheme. We emphasize that the attack is positioned outside of their security models.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published elsewhere. Minor revision. Designs, Codes and Cryptography
- Keywords
- ECDSA with Key RecoveryBUFF Security
- Contact author(s)
- k-emura @ se kanazawa-u ac jp
- History
- 2026-08-26: last of 9 revisions
- 2024-12-13: received
- See all versions
- Short URL
- https://ia.cr/2024/2018
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/2018,
author = {Keita Emura},
title = {On the {BUFF} Security of {ECDSA} with Key Recovery},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/2018},
year = {2024},
url = {https://eprint.iacr.org/2024/2018}
}