Paper 2026/2276
Concurrently secure variants of blind (Okamoto-)Schnorr signatures
Abstract
We present variants of blind Schnorr and blind Okamoto-Schnorr signatures that are not susceptible to ROS-style attacks. We prove the schemes unforgeable in the algebraic group model and the random oracle model: the Okamoto-Schnorr variant under the discrete-logarithm assumption; the Schnorr variant under the algebraic one-more discrete-logarithm assumption. Our Schnorr variant improves on the communication complexity of Snowblind (CRYPTO 2023), the state-of-the-art "pairing-free" blind signature scheme, while matching its signature size. Moreover, we show that this communication complexity is optimal: any blind "Schnorr-like" scheme whose first message is a single group element is susceptible to a variant of the ROS attack by Benhamouda et al. (EUROCRYPT 2021).
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- blind signaturesschnorr signaturesROS attack
- Contact author(s)
-
georg fuchsbauer @ tuwien ac at
fabian regen @ tuwien ac at
levente sulyok @ tuwien ac at - History
- 2026-10-03: approved
- 2026-09-30: received
- See all versions
- Short URL
- https://ia.cr/2026/2276
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2276,
author = {Georg Fuchsbauer and Fabian Regen and Levente Sulyok},
title = {Concurrently secure variants of blind (Okamoto-)Schnorr signatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2276},
year = {2026},
url = {https://eprint.iacr.org/2026/2276}
}