RUS  ENG
Full version
JOURNALS // Prikladnaya Diskretnaya Matematika // Archive

Prikl. Diskr. Mat., 2024 Number 65, Pages 41–65 (Mi pdm846)

Mathematical Methods of Cryptography

On the unforgeability of the Chaum — Pedersen blind signature scheme

L. R. Akhmetzyanova, A. A. Babueva

CryptoPro, Moscow, Russia

Abstract: The paper is devoted to the analysis of the unforgeability property of the Chaum — Pedersen blind signature scheme in case an adversary is able to initiate parallel sessions of the signature generation protocol. It is shown that the scheme does not ensure strong unforgeability, i.e., it allows to create the forgeries for “old” messages that were legitimately signed. An analysis of the weak unforgeability property (the adversary's task is to create a forgery for a new message) is also conducted. Using the reduction method, we obtain a security bound on the weak unforgeability property in the algebraic group model and random oracle model. This estimation identifies the base problems whose complexity underpins the scheme security.

Keywords: blind signature scheme, Chaum — Pedersen blind signature, ROS attack.

UDC: 519.7

DOI: 10.17223/20710410/65/3



© Steklov Math. Inst. of RAS, 2026