Paper 2024/2076

Blind Signatures from Proofs of Inequality

Michael Klooß, ETH Zurich
Michael Reichle, ETH Zurich
Abstract

Blind signatures are an important primitive for privacy-preserving technologies. To date, highly efficient pairing-free constructions rely on the random oracle model, and additionally, a strong assumption, such as interactive assumptions or the algebraic group model. In contrast, for signatures we know many efficient constructions that rely on the random oracle model and standard assumptions. In this work, we develop techniques to close this gap. Compared to the most efficient pairing-free AGM-based blind signature by Crites et. al. (Crypto 2023), our construction has a relative overhead of only a factor $3\times$ and $2\times$ in terms of communication and signature size, and it is provable in the random oracle model under the DDH assumption. With one additional move and $\mathbb{Z}_p$ element, we also achieve one-more strong unforgeability. Our construction is inspired by the recent works by Chairattana-Apirom, Tessaro, and Zhu (Crypto 2024) and Klooß, Reichle, and Wagner (Asiacrypt 2024), and we develop a tailored technique to circumvent the sources of inefficiency in their constructions. Concretely, we achieve signature and communication size of $192$ B and $608$ B, respectively.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
blind signaturesgroup-based cryptography
Contact author(s)
michael klooss @ inf ethz ch
michael reichle @ inf ethz ch
History
2024-12-26: approved
2024-12-25: received
See all versions
Short URL
https://ia.cr/2024/2076
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/2076,
      author = {Michael Klooß and Michael Reichle},
      title = {Blind Signatures from Proofs of Inequality},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/2076},
      year = {2024},
      url = {https://eprint.iacr.org/2024/2076}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.