Paper 2026/090
On the Impossibility of Round-Optimal Pairing-Free Blind Signatures in the ROM
Abstract
Blind signatures play a central role in cryptographic protocols for privacy-preserving authentication and have attracted substantial attention in both theory and practice. A major line of research, dating back to the 1990s, has focused on constructing blind signatures from pairing-free groups. However, all known constructions in this setting require at least three moves of interaction between the signer and the user. These schemes treat the underlying group as a black box and rely on the random oracle in their security proofs. While computationally efficient, they suffer from the drawback that the signer must maintain state during a signing session. In contrast, round-optimal solutions are known under other assumptions and structures (e.g., RSA, lattices, and pairings), or via generic transformations such as Fischlin’s method (CRYPTO~'06), which employ non-black-box techniques. This paper investigates whether the three-round barrier for pairing-free groups is inherent. We provide the first negative evidence by proving that, in a model combining the Random Oracle Model (ROM) with Maurer’s Generic Group Model, no blind signature scheme can be secure if it signs sufficiently long messages while making at most a logarithmic number of random oracle queries. Our lower-bound techniques are novel in that they address the interaction of both models (generic groups and random oracles) simultaneously.
Note: This version (July 2026) fixes issues in the proof that were pointed out by Thomas de Mol regarding a previous version. The result remains unchanged.
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- A major revision of an IACR publication in CRYPTO 2026
- Keywords
- Blind SignaturesImpossibility
- Contact author(s)
-
marian dietz @ inf ethz ch
julia kastner @ cwi nl
tessaro @ cs washington edu - History
- 2026-07-21: last of 2 revisions
- 2026-01-20: received
- See all versions
- Short URL
- https://ia.cr/2026/090
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/090,
author = {Marian Dietz and Julia Kastner and Stefano Tessaro},
title = {On the Impossibility of Round-Optimal Pairing-Free Blind Signatures in the {ROM}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/090},
year = {2026},
url = {https://eprint.iacr.org/2026/090}
}