Paper 2025/715

Updatable Signature with Public Tokens

Haotian Yin, Xi'an Jiaotong-Liverpool University
Jie Zhang, Xi'an Jiaotong-Liverpool University
Wanxin Li, Xi'an Jiaotong-Liverpool University
Yuji Dong, Xi'an Jiaotong-Liverpool University
Eng Gee Lim, Xi'an Jiaotong-Liverpool University
Dominik Wojtczak, University of Liverpool
Abstract

The Updatable Signature (US) allows valid signatures to be updated by an update token without accessing the newly generated signing key. Cini et al. (PKC’21) formally defined this signature and gave several constructions. However, their security model requires the secrecy of the update token, which is not applicable in many common application scenarios where existing signatures have been distributed to many parties. In addition, one can use the same token to update both the signing key and signatures, and all signatures can be updated by a single token, whereas the adversarial signature generated by an adversary might also be updated. This work explores the (im)possibility of constructing an Updatable Signature with public tokens (USpt). Specifically, we first define the updatable signature with public tokens and present its security model. Then, from considering existing US schemes, we found that a secure USpt must properly handle a transform function from signature-update token to key-update token. We further formally proved the impossibility of constructing a secure USpt if (1) there is no transform function between key pairs and signatures, or (2) the signature-update token can be derived from the public keys of adjacent epochs. Finally, we present a concrete USpt scheme based on the BLS signature.

Note: Fischlin and Saçıak (Fast Updatable Message Authentication Codes and Signatures with Public Tokens, ACISP 2026) subsequently identified a flaw in the USpt-EUF-CMA definition of this work, showing that the notion as originally stated is unachievable. We refer readers to their work for the issue and the corrected security formulation.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Published elsewhere. Minor revision. Journal of Information Security and Applications
DOI
10.1016/j.jisa.2025.104058
Keywords
Updatable signatureWeb3BLS signature
Contact author(s)
haotian yin23 @ student xjtlu edu cn
History
2026-08-17: last of 2 revisions
2025-04-21: received
See all versions
Short URL
https://ia.cr/2025/715
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2025/715,
      author = {Haotian Yin and Jie Zhang and Wanxin Li and Yuji Dong and Eng Gee Lim and Dominik Wojtczak},
      title = {Updatable Signature with Public Tokens},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/715},
      year = {2025},
      doi = {10.1016/j.jisa.2025.104058},
      url = {https://eprint.iacr.org/2025/715}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.