Paper 2025/138

On the Preprocessing Security of Nonzero Schnorr Signatures with Adaptive Corruptions

Jeremiah Blocki, Purdue University West Lafayette
Seunghoon Lee, University of Waterloo
Abstract

Modern cryptographic protocols rely on a relatively small collection of standardized hash functions and groups, raising the possibility of preprocessing attacks in which a computationally unbounded offline attacker generates a bounded-size hint that accelerates a later online attack. Blocki and Lee (EUROCRYPT~2022) analyzed the preprocessing security of key-prefixed short Schnorr signatures, where the public key is included in the random-oracle input. Their analysis imposed an a priori restriction on the number of oracle queries made during preprocessing and did not extend to standardized implementations of Schnorr, such as ISO/IEC 14888-3, which do not use key-prefixing but instead reject signatures whose hash challenge is zero. The preprocessing security of these nonzero Schnorr signatures was left as an open question. We resolve this question affirmatively in the ROM+GGM. Moreover, our analysis holds in a stronger model that permits unrestricted offline computation and oracle access, subject only to the size of the resulting hint, as well as adaptive corruption queries during the online phase. Suppressing lower-order terms, an online attacker making \(q\) total oracle queries, including \(q_\mathsf{H}\) random-oracle queries, forges a nonzero Schnorr signature for one of \(N\) users with probability at most $O(\sqrt{Sq^2/p} + q_\mathsf{H} N/2^{\lambda_\mathsf{H}})$, where \(p\) is the group order and \(\lambda_\mathsf{H}\) is the hash-output length. We show that the factor-\(N\) loss is inherent by giving a matching \emph{target-switching attack} with success probability \(\Omega(q_\mathsf{H} N/2^{\lambda_\mathsf{H}})\). By contrast, key-prefixing prevents this attack and the corresponding term in the security bound is just $q_\mathsf{H}/2^{\lambda_\mathsf{H}}$. Consequently, at the same \(\lambda\)-bit security level, key-prefixing enables signatures that are approximately \(\log N\) bits shorter than that of nonzero Schnorr. To support these results, we extend the Bit-Fixing-to-Auxiliary-Input framework of Coretti et al. (CRYPTO/EUROCRYPT 2018) to applications involving multiple idealized primitives. We also address a subtle technical challenge introduced by rejection sampling in the standardized nonzero Schnorr signing algorithm: although long rejection sequences are exceptionally unlikely, a signing query has no deterministic worst-case bound on the number of random-oracle and generic-group queries made by the challenger.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Preprocessing AttacksAdaptive CorruptionNonzero Schnorr SignaturesKey-PrefixingConcrete Security
Contact author(s)
jblocki @ purdue edu
seunghoon lee @ uwaterloo ca
History
2026-10-07: last of 4 revisions
2025-01-28: received
See all versions
Short URL
https://ia.cr/2025/138
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/138,
      author = {Jeremiah Blocki and Seunghoon Lee},
      title = {On the Preprocessing Security of Nonzero Schnorr Signatures with Adaptive Corruptions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/138},
      year = {2025},
      url = {https://eprint.iacr.org/2025/138}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.