Gedankenexperiment Forgery
Last updated
Last updated
Eventually, the adversary outputs a forgery: it outputs public keys pk1, ..., pkn, a message m โ M, and a multi-signature ฯ.
The adversary has broken security if it did not issue a signature query for m and
outputs accept.