Cryptanalysis of Aggregate Γ-Signature and Practical Countermeasures in Application to Bitcoin [article]

Goichiro Hanaoka, Kazuo Ohta, Yusuke Sakai, Bagus Santoso, Kaoru Takemure, Yunlei Zhao
2020 IACR Cryptology ePrint Archive  
We present a sub-exponential forger by using a 𝑘-sum algorithm against the aggregate Γ-signature, which was proposed at AsiaCCS 2019 by Zhao. Our forger is a universal forger under a key-only attack and effective in the knowledge of secret key model. We also discuss the real impact of this attack in reality with Bitcoin applications. The discussions on the real impact of the attack also highlight the significant differences between the usage of individual signatures like EC-DSA and that of
more » ... gate signatures in the blockchain systems like Bitcoin, which might be of independent interest and could bring forth interesting questions for future investigations. CCS CONCEPTS • Security and privacy → Cryptanalysis and other attacks.
dblp:journals/iacr/HanaokaOSSTZ20 fatcat:csvivl5e3nejhoq3uwer3qa2mm