Paper 2026/2276

Concurrently secure variants of blind (Okamoto-)Schnorr signatures

Georg Fuchsbauer, TU Wien
Fabian Regen, TU Wien
Levente Sulyok, TU Wien
Abstract

We present variants of blind Schnorr and blind Okamoto-Schnorr signatures that are not susceptible to ROS-style attacks. We prove the schemes unforgeable in the algebraic group model and the random oracle model: the Okamoto-Schnorr variant under the discrete-logarithm assumption; the Schnorr variant under the algebraic one-more discrete-logarithm assumption. Our Schnorr variant improves on the communication complexity of Snowblind (CRYPTO 2023), the state-of-the-art "pairing-free" blind signature scheme, while matching its signature size. Moreover, we show that this communication complexity is optimal: any blind "Schnorr-like" scheme whose first message is a single group element is susceptible to a variant of the ROS attack by Benhamouda et al. (EUROCRYPT 2021).

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
blind signaturesschnorr signaturesROS attack
Contact author(s)
georg fuchsbauer @ tuwien ac at
fabian regen @ tuwien ac at
levente sulyok @ tuwien ac at
History
2026-10-03: approved
2026-09-30: received
See all versions
Short URL
https://ia.cr/2026/2276
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2276,
      author = {Georg Fuchsbauer and Fabian Regen and Levente Sulyok},
      title = {Concurrently secure variants of blind (Okamoto-)Schnorr signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2276},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2276}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.