Paper 2026/1888

BMuSig2: Schnorr-Compatible Blind Multi-Signatures

Kanchan Bisht, Indian Institute of Technology Hyderabad
Keerthi Aiswarya Varshini, Indian Institute of Technology Hyderabad
Shivam Sethi, Indian Institute of Technology Hyderabad
Maria Francis, Indian Institute of Technology Hyderabad
R. Kabaleeshwaran, Indian Institute of Information Technology Design and Manufacturing Kurnool
Abstract

Blind signatures and multi‑signatures are well‑known primitives, but blind multi‑signatures (BMS), which combine both these primitives, were only recently formalized by Karantaidou et al (CCS'24). A BMS scheme allows a user to obtain a compact signature on a common hidden message from a group of signers such that even if the signers collude, they cannot learn the message or link the final signature to any particular interaction. In this paper, we introduce BMuSig2, a 2-round concurrently secure blind multi-signature scheme whose signatures and verification match standard Schnorr signatures. This design enables systems using Schnorr signatures to adopt BMuSig2 as a drop-in replacement, requiring changes only to the issuance phase, while leaving verification unchanged. BMuSig2 builds on MuSig2 multi-signatures (CRYPTO’21) and integrates techniques from a recent blind signature scheme (CRYPTO’24) that leverages non-interactive zero-knowledge (NIZK) arguments and public-key encryption (PKE) to achieve concurrent security. We formally prove the security of BMuSig2 by relying on the unforgeability of MuSig2 and the security of the underlying NIZK and PKE components. We also provide a proof-of-concept implementation to demonstrate its practical efficiency.

Note: An earlier ASIACCS 2026 version contained a flaw in the blindness property, which has been corrected in this revised version.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. ACM Asia Conference on Computer and Communications Security, 2026 (AsiaCCS'26)
DOI
10.1145/3779208.3805986
Keywords
Blind multi-signaturesConcurrent securitySchnorr-compatible
Contact author(s)
cs20resch11003 @ iith ac in
keerthi av @ prjt cse iith ac in
cs24mtech12021 @ iith ac in
mariaf @ cse iith ac in
kabaleesh @ iiitk ac in
History
2026-09-07: approved
2026-09-04: received
See all versions
Short URL
https://ia.cr/2026/1888
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1888,
      author = {Kanchan Bisht and Keerthi Aiswarya Varshini and Shivam Sethi and Maria Francis and R. Kabaleeshwaran},
      title = {{BMuSig2}: Schnorr-Compatible Blind Multi-Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1888},
      year = {2026},
      doi = {10.1145/3779208.3805986},
      url = {https://eprint.iacr.org/2026/1888}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.