Paper 2025/1566
Lattice-based Threshold Blind Signatures
Abstract
Blind signatures are a central tool for privacy-preserving protocols. They allow users to obtain signatures from a signer without the signer seeing the signed message. For instance, it enables electronic cash: signatures correspond to coins which can be issued by the bank in a privacy-preserving manner via blind signing. To mitigate the risk of key compromise, threshold blind signatures allow the distribution of the signing key amongst N parties. While recent works have focused on improving the security of this primitive in the classical setting, no construction is known to date in the post-quantum setting. We present the first construction of a threshold blind signature secure in the post-quantum setting, based on lattices. We prove its security under an interactive variant of the SIS assumption introduced in [Agrawal et al., CCS’22]. Our construction has a reasonable overhead of a factor of roughly 1.4 X to 2.5 X in signature size over comparable non-threshold blind signatures over lattices under heuristic but natural assumptions.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. S&P 26
- Keywords
- Threshold CryptographyBlind SignaturesLatticesThreshold Blind Signatures
- Contact author(s)
-
sebastian faller @ ibm com
guilhem @ gniot fr
michael reichle @ inf ethz ch - History
- 2026-04-16: last of 3 revisions
- 2025-09-01: received
- See all versions
- Short URL
- https://ia.cr/2025/1566
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1566,
author = {Sebastian Faller and Guilhem Niot and Michael Reichle},
title = {Lattice-based Threshold Blind Signatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1566},
year = {2025},
url = {https://eprint.iacr.org/2025/1566}
}