Paper 2025/1848

Revisiting Lattice-based Non-interactive Blind Signature

Anindya Ganguly, Indian Institute of Technology Kanpur
Angshuman Karmakar, Indian Institute of Technology Kanpur
Suparna Kundu, KU Leuven
Debranjan Pal, Indian Institute of Technology Kanpur
Sumanta Sarkar, University of Essex
Abstract

Blind signatures (BS) allow a signer to produce a valid signature on a message without learning the message itself. They have niche applications in privacy-preserving protocols such as digital cash and electronic voting. Non-interactive blind signatures (NIBS) remove the need for interaction between the signer and the user. In the post-quantum era, lattice-based NIBS schemes are studied as candidates for long-term security. In Asiacrypt 2024, Baldimtsi et al. proposed the first lattice-based NIBS construction, whose security relies on the random one-more inhomogeneous short integer solution (rOM-ISIS) assumption. This rOM-ISIS is considered to be a non-standard assumption. Later, Zhang et al. introduced another lattice-based construction in ProvSec 2024, and proved its security under the standard module short integer solution (MSIS) assumption. We analyse the security of the latter scheme. In the random oracle model, we show that it fails to achieve both nonce blindness and receiver blindness. We present explicit attacks where an adversary breaks both properties with probability~1. Our attack is based on a crucial observation that uncovers a flaw in the design. Specifically, this flaw allows an attacker to link a message-signature pair with its presignature-nonce pair. In addition, we also identify a flaw in the unforgeability proof. Finally, we suggest a modification to address the issue, which is similar to Baldimtsi et al. construction, and its security relies again on the non-standard rOM-ISIS assumption. This work again raises the question of the feasibility of achieving NIBS from standard assumptions.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Blind-SignatureNon-interactive BSLattice-based NIBS
Contact author(s)
anindyag @ cse iitk ac in
angshuman @ cse iitk ac in
suparna kundu @ esat kuleuven be
debranjanp @ cse iitk ac in
sumanta sarkar @ essex ac uk
History
2025-10-08: approved
2025-10-06: received
See all versions
Short URL
https://ia.cr/2025/1848
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1848,
      author = {Anindya Ganguly and Angshuman Karmakar and Suparna Kundu and Debranjan Pal and Sumanta Sarkar},
      title = {Revisiting Lattice-based Non-interactive Blind Signature},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1848},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1848}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.