Paper 2025/138
On the Preprocessing Security of Nonzero Schnorr Signatures with Adaptive Corruptions
Abstract
Modern cryptographic protocols rely on a relatively small collection of standardized hash functions and groups, raising the possibility of preprocessing attacks in which a computationally unbounded offline attacker generates a bounded-size hint that accelerates a later online attack. Blocki and Lee (EUROCRYPT~2022) analyzed the preprocessing security of key-prefixed short Schnorr signatures, where the public key is included in the random-oracle input. Their analysis imposed an a priori restriction on the number of oracle queries made during preprocessing and did not extend to standardized implementations of Schnorr, such as ISO/IEC 14888-3, which do not use key-prefixing but instead reject signatures whose hash challenge is zero. The preprocessing security of these nonzero Schnorr signatures was left as an open question. We resolve this question affirmatively in the ROM+GGM. Moreover, our analysis holds in a stronger model that permits unrestricted offline computation and oracle access, subject only to the size of the resulting hint, as well as adaptive corruption queries during the online phase. Suppressing lower-order terms, an online attacker making \(q\) total oracle queries, including \(q_\mathsf{H}\) random-oracle queries, forges a nonzero Schnorr signature for one of \(N\) users with probability at most $O(\sqrt{Sq^2/p} + q_\mathsf{H} N/2^{\lambda_\mathsf{H}})$, where \(p\) is the group order and \(\lambda_\mathsf{H}\) is the hash-output length. We show that the factor-\(N\) loss is inherent by giving a matching \emph{target-switching attack} with success probability \(\Omega(q_\mathsf{H} N/2^{\lambda_\mathsf{H}})\). By contrast, key-prefixing prevents this attack and the corresponding term in the security bound is just $q_\mathsf{H}/2^{\lambda_\mathsf{H}}$. Consequently, at the same \(\lambda\)-bit security level, key-prefixing enables signatures that are approximately \(\log N\) bits shorter than that of nonzero Schnorr. To support these results, we extend the Bit-Fixing-to-Auxiliary-Input framework of Coretti et al. (CRYPTO/EUROCRYPT 2018) to applications involving multiple idealized primitives. We also address a subtle technical challenge introduced by rejection sampling in the standardized nonzero Schnorr signing algorithm: although long rejection sequences are exceptionally unlikely, a signing query has no deterministic worst-case bound on the number of random-oracle and generic-group queries made by the challenger.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- Preprocessing AttacksAdaptive CorruptionNonzero Schnorr SignaturesKey-PrefixingConcrete Security
- Contact author(s)
-
jblocki @ purdue edu
seunghoon lee @ uwaterloo ca - History
- 2026-10-07: last of 4 revisions
- 2025-01-28: received
- See all versions
- Short URL
- https://ia.cr/2025/138
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/138,
author = {Jeremiah Blocki and Seunghoon Lee},
title = {On the Preprocessing Security of Nonzero Schnorr Signatures with Adaptive Corruptions},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/138},
year = {2025},
url = {https://eprint.iacr.org/2025/138}
}