Paper 2026/1574
Privacy-Preserving Multi-Signatures: Achieving Transcript-Aware Privacy
Abstract
Multi-signatures with key aggregation provide compact signatures verifiable under a single aggregated public key, but protect signer privacy only when public keys are used in a one-time manner. To address this limitation, recent privacy-preserving constructions provide stronger privacy guarantees under public-key reuse. However, they only guarantee privacy in the signature-only setting, where adversaries observe only the final aggregated public key and signature. In practical deployments, multi-signature protocols may be executed over public channels, where externally visible signing transcripts are exposed. These transcripts may link signing messages to public keys, thereby leaking signer identities and undermining existing privacy guarantees. In this paper, we formalize this gap by introducing transcript-aware privacy, a new framework that captures signer privacy in the presence of transcript exposure. Within this framework, we identify the strongest achievable privacy notion, in which signer identities remain hidden while the size of the signer set may be revealed. Our formulation departs from prior signature-only privacy models by explicitly modeling adversarial access to signing transcripts and allowing only inherent leakage such as the signer-set size. We present a new construction based on the MuSig2-H scheme of Tessaro and Zhu (EUROCRYPT'23). Our scheme achieves UNF-3 unforgeability in the AGM+ROM under the DL assumption and preserves full privacy in the signature-only setting. In the transcript-aware setting, it achieves weak set privacy in the ROM under the DDH assumption. In addition, we provide a concrete realization of the key-aggregation proof sharing procedure over public channels, eliminating the need for secure channels and improving practical deployability.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Published elsewhere. Major revision. The 20th International Conference on Provable and Practical Security (ProvSec 2026)
- Keywords
- Multi-signaturesKey aggregationPrivacy-preservingTranscript-aware privacy
- Contact author(s)
-
yz450 @ uowmail edu au
fuchun @ uow edu au
wsusilo @ uow edu au
nanl @ uow edu au - History
- 2026-08-03: approved
- 2026-07-31: received
- See all versions
- Short URL
- https://ia.cr/2026/1574
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1574,
author = {Yanzibo Zhou and Fuchun Guo and Willy Susilo and Nan Li},
title = {Privacy-Preserving Multi-Signatures: Achieving Transcript-Aware Privacy},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1574},
year = {2026},
url = {https://eprint.iacr.org/2026/1574}
}