**Abstract:** All known round optimal (i.e., two-move) blind signature schemes either need a
common reference string, rely on random oracles, or assume the hardness of some
interactive assumption. At Eurocrypt 2010, Fischlin and Schröder showed that a
broad class of three-move blind signature scheme cannot be instantiated in the
standard model based on any non-interactive assumption. This puts forward the
question if round optimal blind signature schemes exist in the standard model.
Here, we give a positive answer presenting the first round optimal blind signature
scheme that is secure in the standard model without any setup assumptions. Our
solution does not need interactive assumptions.

Merged into (Schröder, Unruh, Garg, Rao, Sahai, Round Optimal Blind Signatures, 2011)

**Permalink:** http://www.ut.ee/~unruh/publications/2roundbs-orig.html