Paper 2026/571

Playing Tag with Okamoto-Schnorr: Three-Move Pairing-Free Blind Signatures from DDH

Rutchathon Chairattana-Apirom, University of Washington
Michael Reichle, ETH Zurich
Stefano Tessaro, University of Washington
Abstract

This paper presents the first blind signature scheme in a pairing-free group with the following properties: (1) the signing protocol consists of only three moves; (2) the proof of one-more unforgeability relies solely on the Decisional Diffie-Hellman (DDH) assumption in the Random Oracle Model (ROM); and (3) the construction makes only black-box use of the underlying group. This resolves a major open problem in the area, as all prior pairing-free blind signatures either additionally relied on the Algebraic Group Model (AGM) or required at least four moves. Moreover, a recent lower bound by Dietz et al. (ePrint, '26) shows that three moves are optimal for such constructions. Both the communication complexity and the signature size in our scheme consist of a constant number of group elements. Our construction in fact achieves strong one-more unforgeability (which was not known for any of the recent AGM-free constructions requiring four moves), and we also present a partially blind variant. Furthermore, blindness is statistical (in the ROM). Our approach is based on a new construction paradigm that combines a conventional (yet, by itself, not fully secure) blind signature scheme (specifically, the blind Okamoto-Schnorr scheme) with a carefully crafted algebraic MAC.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
Blind SignaturesAlgebraic MACGroups
Contact author(s)
rchairat @ cs washington edu
michael reichle @ inf ethz ch
tessaro @ cs washington edu
History
2026-06-10: revised
2026-03-22: received
See all versions
Short URL
https://ia.cr/2026/571
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/571,
      author = {Rutchathon Chairattana-Apirom and Michael Reichle and Stefano Tessaro},
      title = {Playing Tag with Okamoto-Schnorr: Three-Move Pairing-Free Blind Signatures from {DDH}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/571},
      year = {2026},
      url = {https://eprint.iacr.org/2026/571}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.