Gedankenexperiment Forgery

Eventually, the adversary outputs a forgery: it outputs public keys pk1, ..., pkn, a message m โˆˆ M, and a multi-signature ฯƒ.

The adversary has broken security if it did not issue a signature query for m and

outputs accept.

Last updated