Efficient Round Optimal Blind Signatures

EUROCRYPT |

In this work, we construct the first blind-signature scheme that does not suffer from any of these limitations. In other words, besides being round optimal and having a standard model proof of security, our scheme is very efficient. Specifically, in our scheme, one signature is of size 6.5">6.5KB and the communication complexity of the signing protocol is roughly 100">100KB. An amortized variant of our scheme has communication complexity less that 1KB.