Paper 2025/2176

On the (Un)biasability of Existing Verifiable Random Functions

Davide Carnemolla, University of Catania
Dario Catalano, University of Catania
Valentina Frasca, University of Catania
Emanuele Giunta, ETH Zurich
Abstract

Verifiable Random Functions (VRFs) play a fundamental role in modern blockchain designs because of their applications in leader election protocols. In such contexts, however, the original definition by Micali, Rabin and Vadhan (FOCS 99), falls short at guaranteeing fairness when keys are sampled maliciously. The elegant notion of unbiasable VRF, recently proposed by Giunta and Stewart (Eurocrypt 24), addresses these concerns while remaining simple to state and easy to realize, at least in the random oracle model. Achieving unbiasability in the standard model is a different story, though: all known constructions rely on compilers that invariably reduce the efficiency of the VRF from which one starts. In this paper, we look at the unbiasability of existing VRFs in the standard model. Our findings are mostly negative; we show that, essentially, all known constructions are not natively unbiasable. We do so by showing classes of attacks that (almost) completely cover the set of existing VRF constructions. On the positive side, we show that some concrete schemes (and notably the well-known Dodis-Yampolskiy VRF) can be modified to achieve meaningful notions of unbiasability, while retaining their original efficiency.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Major revision. International Conference on Financial Cryptography and Data Security 2026
Keywords
Verifiable Random FunctionsUnbiasabilityStandard Model
Contact author(s)
davide carnemolla @ phd unict it
dario catalano @ unict it
valentina frasca @ phd unict it
emanuele giunta @ inf ethz ch
History
2026-04-07: last of 3 revisions
2025-12-01: received
See all versions
Short URL
https://ia.cr/2025/2176
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2176,
      author = {Davide Carnemolla and Dario Catalano and Valentina Frasca and Emanuele Giunta},
      title = {On the (Un)biasability of Existing Verifiable Random Functions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2176},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2176}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.