Tight Security for BBS Signatures

πŸ“… 2026-08-06
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses the lack of tight security proofs for BBS signatures in the standard model, where a tightness gap arises from the q-SDH assumption. The authors establish separate security reductions for single-signature and multi-signature settings: they present the first tightly secure reduction for the single-message single-signature case, and employ meta-reduction techniques to prove that no tight algebraic reduction can exist for the multi-signature scenario. By integrating standard-model reduction techniques, a refined analysis of the q-SDH assumption, and meta-reduction methodology, this study precisely delineates the boundaries within which BBS signatures admit tight security guarantees. These results provide crucial theoretical foundations for the standardization and practical deployment of BBS signatures.
πŸ“ Abstract
This paper studies the concrete security of BBS signatures (Boneh, Boyen, Shacham, CRYPTO '04; Camenisch and Lysyanskaya, CRYPTO '04), a popular algebraic construction of digital signatures which underlies practical privacy-preserving authentication systems and is undergoing standardization by the W3C and IRTF. SchΓ€ge (Journal of Cryptology '15) gave a tight standard-model security proof under the q-SDH assumption for a less efficient variant of the scheme, called BBS+--here, q is the number of issued signatures. In contrast, the security proof for BBS (Tessaro and Zhu, EUROCRYPT '23), also under the q-SDH assumption, is \emph{not} tight. Nonetheless, this recent proof shifted both standardization and industry adoption towards the more efficient BBS, instead of BBS+, and for this reason, it is important to understand whether this tightness gap is inherent. Recent cryptanalysis by Chairattana-Apirom and Tessaro (ASIACRYPT '25) also shows that a tight reduction to q-SDH is the best we can hope for. This paper closes this gap in two different ways. On the positive end, we show a novel tight reduction for BBS in the case where each message is signed at most once--this case covers in particular the common practical use case which derandomizes signing. On the negative end, we use a meta-reduction argument to prove that if we allow generating multiple signatures for the same message, then {\em no} algebraic reduction to q-SDH (and its variants) can be tight.
Problem

Research questions and friction points this paper is trying to address.

BBS signatures
tight security
q-SDH assumption
standard-model security
algebraic reductions
Innovation

Methods, ideas, or system contributions that make the work stand out.

tight security
BBS signatures
q-SDH assumption
meta-reduction
algebraic reductions
πŸ”Ž Similar Papers
No similar papers found.