Paper 2025/900
Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and More
Abstract
Exclusive ownership (EO) security is a feature of signature schemes that prevents adversaries from "stealing" an honestly generated signature by finding a new public key which verifies said signature. It is one of the beyond unforgeability features (BUFF) which were declared to be desirable features by NIST. The BUFF transform allows to generically achieve exclusive ownership (and other properties) at the cost of an increased signature size. In this work, we study the EO security of (different variants of) Fiat-Shamir signatures. As our main result, we show that the commonly used variant of Fiat-Shamir signatures (where signatures consist of challenge-response tuples) with λ-bit challenges, can achieve about λ-bit EO security through its implicit usage of the BUFF transform—this presents a significant improvement to existing results that only provide λ/2-bit of EO security. This benefit of our result comes without an increase in signature size. For other variants of Fiat-Shamir signatures, we show worse bounds, which nevertheless improve upon existing results. Finally, we apply our results to several signature schemes: SQIsign and LESS (both round-2 NIST candidates); ML-DSA (NIST standard); CSI-FiSh; and Schnorr signatures. This shows that all these schemes achieve significantly better bounds regarding their EO security compared to existing results.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A minor revision of an IACR publication in CRYPTO 2025
- Keywords
- Signature SchemesBeyond UnforgeabilityBUFFFiat-ShamirML-DSASQIsignLESS
- Contact author(s)
-
michael @ random-oracles org
patrick struck @ uni kn
maximiliane weishaeupl @ ur de - History
- 2025-05-21: approved
- 2025-05-20: received
- See all versions
- Short URL
- https://ia.cr/2025/900
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/900, author = {Michael Meyer and Patrick Struck and Maximiliane Weishäupl}, title = {Exclusive Ownership of Fiat-Shamir Signatures: {ML}-{DSA}, {SQIsign}, {LESS}, and More}, howpublished = {Cryptology {ePrint} Archive, Paper 2025/900}, year = {2025}, url = {https://eprint.iacr.org/2025/900} }