Paper 2025/900

Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and More

Michael Meyer, University of Regensburg
Patrick Struck, University of Konstanz
Maximiliane Weishäupl, University of Regensburg
Abstract

Exclusive ownership (EO) security is a feature of signature schemes that prevents adversaries from "stealing" an honestly generated signature by finding a new public key which verifies said signature. It is one of the beyond unforgeability features (BUFF) which were declared to be desirable features by NIST. The BUFF transform allows to generically achieve exclusive ownership (and other properties) at the cost of an increased signature size. In this work, we study the EO security of (different variants of) Fiat-Shamir signatures. As our main result, we show that the commonly used variant of Fiat-Shamir signatures (where signatures consist of challenge-response tuples) with λ-bit challenges, can achieve about λ-bit EO security through its implicit usage of the BUFF transform—this presents a significant improvement to existing results that only provide λ/2-bit of EO security. This benefit of our result comes without an increase in signature size. For other variants of Fiat-Shamir signatures, we show worse bounds, which nevertheless improve upon existing results. Finally, we apply our results to several signature schemes: SQIsign and LESS (both round-2 NIST candidates); ML-DSA (NIST standard); CSI-FiSh; and Schnorr signatures. This shows that all these schemes achieve significantly better bounds regarding their EO security compared to existing results.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A minor revision of an IACR publication in CRYPTO 2025
Keywords
Signature SchemesBeyond UnforgeabilityBUFFFiat-ShamirML-DSASQIsignLESS
Contact author(s)
michael @ random-oracles org
patrick struck @ uni kn
maximiliane weishaeupl @ ur de
History
2025-05-21: approved
2025-05-20: received
See all versions
Short URL
https://ia.cr/2025/900
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/900,
      author = {Michael Meyer and Patrick Struck and Maximiliane Weishäupl},
      title = {Exclusive Ownership of Fiat-Shamir Signatures: {ML}-{DSA}, {SQIsign}, {LESS}, and More},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/900},
      year = {2025},
      url = {https://eprint.iacr.org/2025/900}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.