CryptoDB
Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and More
Authors: |
|
---|---|
Download: | |
Conference: | CRYPTO 2025 |
Abstract: | Exclusive ownership (EO) security is a feature of signature schemes that prevents adversaries from "stealing" an honestly generated signature by finding a new public key which verifies said signature. It is one of the beyond unforgeability features (BUFF) which were declared to be desirable features by NIST. The BUFF transform allows to generically achieve exclusive ownership (and other properties) at the cost of an increased signature size. In this work, we study the EO security of (different variants of) Fiat-Shamir signatures. As our main result, we show that the commonly used variant of Fiat-Shamir signatures (where signatures consist of challenge-response tuples) with $\lambda$-bit challenges, can achieve about $\lambda$-bit EO security through its implicit usage of the BUFF transform—this presents a significant improvement to existing results that only provide $\lambda/2$-bit of EO security. This benefit of our result comes without an increase in signature size. For other variants of Fiat-Shamir signatures, we show worse bounds, which nevertheless improve upon existing results. Finally, we apply our results to several signature schemes: SQIsign and LESS (both round-2 NIST candidates); ML-DSA (NIST standard); CSI-FiSh; and Schnorr signatures. This shows that all these schemes achieve significantly better bounds regarding their EO security compared to existing results. |
BibTeX
@inproceedings{crypto-2025-35606, title={Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and More}, publisher={Springer-Verlag}, author={Michael Meyer and Patrick Struck and Maximiliane Weishäupl}, year=2025 }